As AI agents begin acting on users’ behalf, eMemory’s subsidiary, PUFsecurity, believes that device identity, attestation and protected on-chip state will decide how far they can be trusted

SAN JOSE, Calif., Oct. 9, 2026 /PRNewswire/ — The first wave of generative AI answered questions and produced content, and a person still decided what to do with it. Agentic AI goes further: AI agents book travel, send email, fill in forms and make purchases [1], often while the user is busy with something else. PUFsecurity, a subsidiary of eMemory Technology, believes this shift changes where trust has to come from. In a new technical perspective, "Building Trusted AI Agents from the Silicon Root of Trust," the company explains that the security of these agents ultimately rests on hardware Roots of Trust in the chips that run them.

Agents raise the stakes

A chatbot produces content, and a person decides what to do with it. An agent acts on its own output. It runs persistently, holds delegated credentials, browses the web, executes code and calls connected services.

In PUFsecurity’s view, that changes what a compromise costs. When a chatbot is misled, the result is a bad answer that a person can still catch. When an agent is misled, it can act with the user’s credentials before anyone has a chance to check.

Software isolation is necessary, but it rests on the platform

Meta’s Muse offers a clear picture of how the industry is approaching agent security. According to Meta, each user’s agent runs inside a dedicated cloud virtual machine (VM), in an isolated runtime cell with its own file system and network interface. A separate Sentinel agent is the sole authority for network egress and connector actions. Code inside the cell only ever sees surrogate tokens; real credentials are swapped in at the network boundary after a request is approved [2].

Meta is also clear about the next step. The company states that the launch Secure VM "does not prevent Meta from accessing data when necessary to support, secure or operate the service" [2], and it plans a Muse Confidential VM in which the entire VM is encrypted with a key only the user holds [1].

PUFsecurity notes that this next step depends on hardware. Software boundaries that share one host are only as strong as the platform beneath them, and a key held only by the user can be released safely only to a platform that can prove it is genuine and booted the expected software.

A multi-year collaboration with Arm

That proof starts in the processor, an area where PUFsecurity has worked with Arm for several years. In 2022, Arm selected PUFrt, PUFsecurity’s hardware Root of Trust IP, for the secure subsystem in its reference implementation of the Armv9 Confidential Compute Architecture [3]. eMemory has since joined Arm Total Design and introduced PUFrt as a hardware Root of Trust for the Runtime Security Engine (RSE) in Arm Neoverse Compute Subsystems (CSS).

Arm’s newest data-center processor builds on that same platform. Arm AGI CPU, which Arm positions for agentic AI infrastructure [4], is built on Neoverse CSS V3, with an RSE serving as its Root of Trust [5].

Attestation needs a hardware-bound identity

For an agent platform, the party that needs proof is usually remote: a key service deciding whether to unlock a user’s confidential VM, or a fleet controller deciding whether a server may run agent workloads. Remote attestation provides that proof. The device signs a report of what it booted, and a verifier checks the report against expected values before releasing any secrets [6].

Three properties are at stake: identity establishes which physical device is running the workload; integrity records what it actually booted; confidentiality ensures that secrets reach only a verified environment. As PUFsecurity points out, the whole chain hinges on one detail: an attestation report is only as trustworthy as the key that signs it. If compromised software can read or forge that key, the report proves nothing. The signing identity has to be anchored in silicon.

Roots of Trust are multiplying across the data center

Data-center processors increasingly build the Root of Trust directly into the die, and modern designs often contain more than one. At Hot Chips 2026, Arm presented Arm AGI CPU as two compute chiplets, each with its own RSE, and lists support for Arm’s Realm Management Extension, the hardware basis for Arm confidential computing [5]. A single package therefore holds two Roots of Trust, and a two-socket server holds four.

The CPU is only part of the picture. Meta notes that limited data leaves the Muse VM for inference [2], so prompts and context reach accelerators, network interfaces and storage. The Open Compute Project (OCP) security model calls for a Root of Trust in every device, with each one reporting its integrity through attestation [7]. OCP’s Caliptra moves that function inside the silicon as an integrated Root of Trust block for data-center SoCs such as CPUs, GPUs and DPUs [8]. And as multi-vendor chiplet designs emerge, industry efforts such as the Arm-led Foundational Chiplet System Architecture (FCSA), contributed to OCP, address how chiplets from different suppliers boot together and secure the system [9].

Common security primitives sit underneath

These architectures differ, but PUFsecurity sees the same foundational needs beneath all of them. Whether a chip uses Arm’s RSE, Caliptra or a proprietary design, its Root of Trust needs a device-unique secret protected at rest, a high-quality source of entropy, and secure non-volatile storage for state that must survive power cycles, such as lifecycle status and revocation data.

Caliptra illustrates the point. Its specification anchors device identity in a unique secret generated from on-chip entropy and kept in one-time-programmable fuses, then expands that secret into a Device Identifier Composition Engine (DICE) identity chain for attestation [8][10].

PUFrt: a silicon foundation for trusted agents

PUFrt brings these primitives together in a single hardware Root of Trust IP. Its 1024-bit physical unclonable function (PUF) derives device-unique values from natural variation in the silicon, providing four 256-bit fingerprints that can serve as unique identifiers or root-key seeds [11]. Because the secret comes from the silicon itself, a root key does not need to be injected during manufacturing, which PUFsecurity sees as increasingly valuable as chiplets from multiple suppliers are assembled into one package.

PUFrt also includes a true random number generator and secure storage based on NeoFuse anti-fuse OTP, which eMemory offers from 0.15 µm down to 3 nm FinFET [13], with 2 nm GAA under development. Combined with anti-tamper protections, these support functions such as secure boot, secure debug, entropy generation and key provisioning [11][12].

Building trust from the silicon upward

Generative AI produced content. AI agents act on it, running persistently and with growing autonomy on people’s behalf. In PUFsecurity’s view, the next step is physical AI, where the same autonomy drives robots, vehicles and industrial machines, and a misled system can cause physical harm rather than only digital loss.

Software safeguards are advancing quickly at every stage. But the final guarantee, that keys and authority are released only to a platform that can prove what it is and what it booted, has to come from hardware, in every chip along the path, from the data center to the device at the edge.

The full article, "Building Trusted AI Agents from the Silicon Root of Trust," is available here.

References

1. Meta, "Introducing Muse: The World’s First Personal AI Agent Built for Everyone," Sept. 8, 2026. Source

2. Meta AI Research, "How We Built Safety Into Muse," Sept. 8, 2026. Source

3. PUFsecurity and eMemory, "PUFsecurity and eMemory Launch Next-Gen PUF-based Hardware Root of Trust IP for Future Computing," Feb. 7, 2022. Source

4. Arm, "Arm expands compute platform to silicon products in historic company first," Mar. 24, 2026. Source

5. S. Pradhan and D. Goel, Arm, "Arm AGI: A Disaggregated, Chiplet-Based Server SoC for Scalable Coherency and Memory Bandwidth in the Terabyte/s Era," Hot Chips 2026, Aug. 24, 2026.

6. IETF, "Remote ATtestation procedureS (RATS) Architecture," RFC 9334, Jan. 2023. Source

7. Open Compute Project, "OCP Security Announces version 1.0 specs for Root of Trust," Nov. 9, 2020. Source

8. CHIPS Alliance, "Caliptra Specification," GitHub. Source

9. Open Compute Project, "OCP Open Chiplet Economy is Leading the Next Wave of AI: Inference," Feb. 17, 2026. Source

10. Trusted Computing Group, "DICE Attestation Architecture," Version 1.1. Source

11. PUFsecurity, "PUFrt – Hardware Root of Trust." Source

12. PUFsecurity, "PUFrt Hardware Root of Trust Datasheet." Source

13. eMemory, "NeoFuse." Source

 

Source link

This content was prepared by our news partner, Cision PR Newswire. The opinions and the content published on this page are the author’s own and do not necessarily reflect the views of Siam News Network
You May Also Like

Literacy for All in the Digital Era

Education Cannot Wait funding through its strategic partners provides foundational learning opportunities…

Singapore's Largest Spanish Gastronomic Fiesta, Eat Spain Drink Spain Returns with Over 40 Spanish Food & Drink Experiences from 1 to 15 September

From Spanish markets to tapas Sundays, the fourth edition of ESDS returns…

Nestlé and NBA announce multi-year international marketing partnership

Milo,Nescau and Nesquikwill become Official Partners of the National Basketball Association (NBA) The partnership will…