Most agents today live inside a session. You open one, give it a task, and close it, and its memory is little more than a transcript. Ambient agents are different. They run continuously beside your calendar, files, messages, sensors or vehicle, and they build a picture of a person or a place over weeks and months.
That is the point of them. An agent that knows more is more useful, so context grows every hour it runs. The question is what that growing context turns into.
Context does not stay free. It has to be stored, ranked, compressed and sometimes forgotten, and each decision the agent makes draws on some part of it. An agent carrying a year of context into every action moves a lot of data and does a lot of inference, and the cost shows up as latency and as exposure.
That pulls the work toward the device, close to where the context lives, for speed and for privacy. It also means the device holding the context becomes the thing worth protecting.
Whoever can write into an agent's context can steer it. A poisoned calendar invite, a tampered log, a document with hidden instructions: each is a way to change what the agent believes without touching the agent itself. The longer the memory, the longer a bad entry persists, and later decisions build on it.
Context is also the richest thing to steal, since it is a detailed record of a person or an operation. And because agents act, corrupted context does not stay a data problem for long. It becomes corrupted actions.
The practical answer is to make every piece of context say where it came from. An observation signed by the device that made it, using an identity rooted in that device's silicon, carries something plain text never does: a claim about its origin that cannot be forged by copying a key.
With that, an agent can weigh signed observations differently from unsigned text, and an auditor can trace an action back to the inputs that drove it. The same idea of a receipt that binds input, output and chip identity applies to each step the agent takes.
Provenance does not make content true. It tells you who vouched for it and lets you decide how much that is worth.
An agent that earns more of your context should be able to answer all four.
The ML attack surface spans the model, the data, and the infrastructure. Silicon-rooted machine identity and signed receipts shut down a whole class.
Read →Certificates, API keys, and tokens are data — and data gets copied. Why the only machine identity that holds is one derived from physics, not assigned.
Read →We're talking with teams building verifiable, component-level trust into infrastructure and devices.