Trusted AI proxies must be anchored within the silicon wafer.
As the AI agents begin to act on behalf of users, PUFsecurity, a subsidiary of eMemory, believes that device identity, remote authentication, and protected on-chip state will determine to what extent these agents can be trusted.
San Jose, California, USA, October 9, 2026 / PRNewswire / -- The first wave of generative AI is answering questions and generating content, but it is still up to humans to decide how to use this content. Proxy-based AI goes a step further: AI proxies can book trips, send emails, fill out forms, and make purchases [1], often doing so while users are busy with other things. eMemory Technology's subsidiary PUFsecurity believes that this change also alters where trust must come from. In a new tech perspective article titled " Building Trusted AI Agents from the Sil Token Issuance n Root of Trust ", the company explains that the security of such proxies ultimately depends on the hardware root of trust in the chips that run them.
Proxying increases risk.
Chatbot-generated content is subject to human decision on how to handle it; whereas agents will take action based on their own output. It runs continuously, holds delegate credentials, browses web pages, executes code, and invokes connected services.
In the view of PUFsecurity, this changes the cost when a system is breached. When a chatbot is misled, the result is just a wrong answer, and people still have a chance to detect it; however, when an agent is misled, it may take action using user credentials before anyone can check.
Software isolation is necessary, but it depends on the platform.
Muse clearly demonstrates how the industry addresses proxy security issues. According to Meta, each user's proxy runs within a dedicated cloud virtual machine (VM), in an isolated runtime environment with its own file system and network interface. An independent Sentinel proxy is the sole authorized entity for outbound network operations and connector management. The code within this unit can only access substitute tokens; the actual credentials are replaced only at the network boundary, after the request has been approved [2].
Meta also clearly outlines the next steps. The company stated that the launch of Secure VM "will not prevent Meta from accessing data when necessary to support, protect, or operate the service" [2], and they plan to introduce Muse Confidential VM. In this version, the entire VM will be encrypted, with the keys being held solely by the users [1].
PUFsecurity points out that this step relies on hardware. The security of the software boundaries shared on the same host is only as strong as the platform beneath it; whereas the keys held solely by users can be securely released only when the platform can prove its authenticity and has started up as expected with the correct software.
Years of collaboration with Arm
This type of certification originated in the field of processors, where PUFsecurity has been collaborating with Arm for many years. In 2022, Arm selected PUFsecurity's hardware trust root IP —– PUFrt [3] – in the security subsystem of its Armv9 Confidential Compute Architecture reference implementation. Subsequently, eMemory joined Arm Total Design and adopted PUFrt as the hardware trust root within Arm Neoverse Compute Subsystems ( CSS ), specifically for Runtime Security Engine ( RSE ).
Arm The latest data center processors are built on the same platform. Arm It is positioned for proxy-based AI infrastructure, with Arm AGI CPU [4] constructed upon Neoverse CSS V3, and RSE serves as its trust root [5].
Remote proof requires an identity that is bound to hardware.
For proxy platforms, the party that needs to provide proof is usually located remotely: it could be the service that decides whether to unlock the user's confidential VM key, or it could be the cluster controller that determines whether a certain server can run the proxy workload. Remote proof provides this kind of verification. The device will generate a report by signing its startup content, and the verifying party will compare this report with the expected values before releasing any secrets [6].
There are three key attributes involved here: identity, which is used to determine which physical device is running the workload; integrity, which is used to record what actually started; and confidentiality, which is used to ensure that secrets only reach verified environments. PUFsecurity points out that the entire chain depends on one detail: the credibility of the report is only as good as the credibility of the signing key. If the compromised software is able to read or forge this key, then the report loses all its probative value. The signing identity must be anchored in the silicon chip itself.
The number of trust roots in data centers is increasing.
Data center processors are increasingly integrating trust roots directly into the chip die, and modern designs often contain more than one. As demonstrated in Hot Chips 2026 by Arm, Arm AGI CPU consists of two computing chiplet; each chiplet has its own RSE and also supports Arm Realm Management Extension. This constitutes the hardware foundation for Arm confidential computing [5]. Therefore, there are two trust roots within a single package, and a dual-core server would have four.
CPU is just a part of the whole. Meta indicates that limited data will leave Muse VM for reasoning [2]; therefore, prompts and context will also enter accelerators, network interfaces, and storage. The security model of Open Compute Project ( OCP ) requires that each device have a root of trust and report its integrity through remote proof [7]. The Caliptra of OCP incorporates this function within the silicon chip, serving as an integrated root of trust module for data centers such as CPU , GPU , and DPU [8]. With the emergence of multi-supplier chiplet designs, industry efforts led by Arm and contributed to by OCP ( FCSA ) are addressing how components from different suppliers [BJWKEEP_00017__ ] can be coordinated to start up and protect the entire system [9].
Common security primitives are located at the underlying level.
These architectures vary, but PUFsecurity believes that the fundamental capabilities required at their core are the same. Regardless of whether the chip uses Arm's RSE, Caliptra, or a proprietary design, their trust roots all require a device-specific secret that is protected in a static state, a high-quality entropy source, as well as secure non-volatile storage for states that must be preserved across power-off cycles (such as lifecycle states and revocation data).
Caliptra illustrates this point very well. Its specification anchors the device identity to a unique secret generated by on-chip entropy and stored in a one-time programmable fuse, and then expands this secret into a DICE ( Device Identifier Composition Engine ) identity chain for remote verification [8][10].
PUFrt: The Silicon Foundation of Trusted Agents
PUFrt integrates these primitives into a single hardware trust root IP. Its 1024-bit physically unclonable function (PUF) derives a unique device value from the natural variations of the silicon chip, providing four 256-bit fingerprints that can be used as unique identifiers or seed values for root keys [11]. Since the secret comes directly from the silicon chip itself, there is no need to inject it during the manufacturing process; PUFsecurity believes that this becomes increasingly important as chiplet from multiple suppliers are assembled into a single package.
PUFrt also includes a true random number generator, as well as secure storage based on NeoFuse, anti-fuse, and OTP. The process range provided by eMemory ranges from 0.15 micrometers to 3 nanometers [13], with 2 nanometers also under development [BJWKEEP_00007__]. Combined with anti-tampering protection, these features support secure startup, secure debugging, entropy generation, and key configuration, among other functions [11][12].
Building Trust from the Silicon Chip Upward
Generative AI generates content. AI agents take action on this content and continue to operate with increasing autonomy, performing tasks on behalf of users. In the view of PUFsecurity, the next step is physical AI. At this stage, the same level of autonomy will drive robots, vehicles, and industrial machines, and the misdirected systems could result not only in digital losses but also potential physical harm.
Software protection is making rapid progress at every stage. However, the ultimate guarantee—ensuring that keys and permissions are only released to a platform that can prove who it is and what it has initiated—must come from hardware, from every chip along the path, from data centers all the way to edge devices.
The complete article " Building Trusted AI Agents from the Sil Token Issuance n Root of Trust " can be viewed here.
Reference materials










