This week, the AI security industry moved fast.
HiddenLayer raised $100 million to protect AI models and agents at runtime. Microsoft launched Entra Agent ID to give AI agents software-issued identities across the enterprise. The Booz Allen Cyber Weapon Index revealed that critical vulnerabilities across 21 major software companies have jumped from under 100 per month to over 600 per month since spring. And the IDScan.net breach exposed 153 million driver's licences — including infrared and ultraviolet scans — on the dark web, breaking every assumption the identity verification industry had built its controls on.
Each story describes a real problem being solved at the right layer for that problem.
And each story leaves the same layer untouched.
HiddenLayer tells you what the AI agent did inside the model. It cannot tell you which hardware the model ran on.
Entra Agent ID tells you what the agent is authorised to do within the Microsoft ecosystem. It cannot tell you which specific hardware is executing the agent, proven independently of Microsoft's own infrastructure.
The Booz Allen Cyber Weapon Index measures vulnerabilities at the software and network layer. It does not measure whether the hardware executing the patched software is the enrolled, unmodified infrastructure.
The IDScan.net breach exposed document images, UV scans, IR scans — all the data that makes a driver's licence verifiable as genuine. It exposed it because that data is information, and information can be stolen. The assumption underlying every identity verification control was that the document data was secure. It was not.
In every case, the solution proposed operates at the software layer. And in every case, the software layer assumes the hardware beneath it is what it claims to be.
That assumption is currently unverifiable. Every software security solution built above it inherits the same gap.
The IDScan breach is the clearest illustration. Every feature that makes a driver's licence verifiable as genuine — front and back images, UV features, IR scans — is data. Data that can be captured at scale and used to produce convincing fakes that pass every control designed to detect them.
The one property that cannot be replicated from captured data is a property derived from the physical variation in silicon created during manufacturing. Not a stored key. Not a certificate. Not anything written into the chip after fabrication. A characteristic of the chip itself, unique to each piece of silicon, that does not exist as information anywhere in the system.
You can scan every feature of the document. You cannot clone the enrolled silicon.
The same principle applies to AI agents. An AI agent carrying an identity derived from the physical variation in the silicon it runs on cannot be impersonated by any adversary who lacks that specific enrolled hardware. Even if the credentials are stolen. Even if the software layer is compromised. Even if the operator's logs are falsified. The execution receipt the agent produces is signed by physics, not by anyone's promise.
The cluster of events this week is not coincidental. It reflects a single underlying shift: AI systems are moving from advisory roles to consequential authority. They are settling payments, autonomously executing military missions, diagnosing patients, granting access to power grids, and identifying people at borders and checkpoints.
As that shift accelerates, the question changes. It is no longer "did the AI reach the right conclusion?" It is "which specific system, running on which specific hardware, under whose authority, produced this output — and can any party with a legitimate interest verify that independently?"
The software security stack answers the first question reasonably well and is getting better every week. HiddenLayer, Entra Agent ID, and the entire runtime security industry are building the right tools for the right layer.
The second question requires a different layer entirely. Not a better model. Not faster runtime detection. Not more granular software permissions. It requires hardware that knows what it is — and can prove it to anyone, without trusting the operator.
Security has always had trust layers. HTTPS made web communication trustworthy. PKI made financial transactions trustworthy. Neither was the product. Both were the infrastructure everything else ran on, invisibly, at civilisational scale.
AI does not yet have its hardware trust layer.
Every story this week is a story about solutions being built above that layer. The IDScan breach is a story about what happens when the layer does not exist for physical identity documents. The HiddenLayer raise is a story about an excellent solution for the model layer that still assumes its execution environment is trustworthy. The Entra Agent ID launch is a story about governance built above hardware whose identity is unverified.
These are not criticisms. They are the natural order of how infrastructure gets built: the application layer first, the trust layer after the application layer has proven why the trust layer is necessary.
That proof is now in. The hardware trust layer for AI is the next infrastructure primitive. The industry will build it.
The question is what happens in the meantime — and how long the glass doors stay up.
We're talking with teams who want hardware-rooted accountability beneath their AI deployments — not just software-layer controls that assume the execution environment is clean.