As AI becomes more pervasive and IT leaders experiment with the technology at the edge, it’s vital businesses have a robust understanding of potential risks.
“AI offers organisations an opportunity to transform their business, but it also introduces new risks. As we embrace its potential, we must prepare for a future where good AI will need to defend against bad AI,” explains J.R Balaji, Head of Software Product Management for the AMD Client Business Unit.
As Dr. Peter Garraghan, CEO/CTO of AI security testing vendor Mindgard and a Professor at the UK’s Lancaster University, told CSO.com: “If a legitimate user can find utility in using AI to automate their tasks, capture complex patterns, lower the barrier of technical entry, reduced costs, and generate new content, why wouldn’t a criminal do the same?”[1]
As AI expands, not all training and inferencing will be done in the cloud, and data will be increasingly processed at the edge. Many organisations are therefore looking to move AI processing on to endpoint devices.
This raises its own security challenges.
“Endpoints are often the weakest links in the security chain,” explains Balaji. “Valuable data on the endpoints is more susceptible to getting exfiltrated since endpoints are more easily exploited.”
“IT must also guard against inadvertent data leakage, where unsuspecting users providing data access to unsanctioned AI apps. As increasingly valuable IP and AI models come to sit on endpoints, security leaders should focus more on securing this footprint.”
Adversaries are also looking to weaken AI models by compromising the supply chain.
“If attackers manage to poison the training data or tamper with models during development or distribution, the blast radius could be enormous,” warns Balaji.
Building an AI security ecosystem
Just as smartphones needed a thriving app ecosystem to realise their potential, AI PCs will rely on software vendors as well as customer apps to optimise their AI capabilities.
In security, this opens new possibilities whereby businesses could run specialised use cases such as advanced detection on-device using neural processing units (NPUs).
In this world, security efforts will need to extend beyond the traditional focus on antivirus, firewalls, and encryption. Critical considerations around data integrity, data sovereignty, and the underlying computing infrastructure must take centre stage.
Built-in security for AI PCs
“While software-based security remains vital, it’s equally important to consider the trustworthiness of hardware,” Balaji explains. “Running AI on compromised infrastructure or endpoints poses a serious risk”.
“A compromised endpoint—where hardware or firmware is tampered with—can undermine AI models and corrupt their outputs – and this may be easier for adversaries to execute via endpoints.”
Securing the hardware starts before the OS even loads. From the moment a user presses the power button, hundreds of processes begin including firmware validation, BIOS execution, system checks—all of which must remain uncompromised.
This is where technologies like AMD’s ‘Root of Trust’ become critical, increasing the likelihood that every boot begins in a verified, secure state.
Once a system is running, attackers often bypass traditional defences by targeting less-protected areas like system memory, using techniques like Direct Memory Access attacks.
“Because these methods do not leave traditional file traces, they can evade even advanced detection tools,” says Balaji.
To address this, AMD has invested in countermeasures against memory-based threats and continues to evolve these protections through ongoing threat modelling. In addition, AMD’s Shadow Stack feature helps protect against techniques like buffer overflow attacks while helping to maintain supply chain integrity.
Balaji concludes: “AMD has been integrating secure enclaves into its silicon to provide trusted execution environments for better protection of sensitive data and code. After all, security for AI is just as important as AI for security.”
For all the opportunity AI brings, it is also ushering a new era of threats. Security leaders must ensure they work with vendors who understand this new world and can prove their hardware has the required resilience.
[1] CSO, “Top 5 ways attackers use generative AI to exploit your systems,” February 2025 https://www.csoonline.com/article/3819176/top-5-ways-attackers-use-generative-ai-to-exploit-your-systems.html
