
Security leaders are moving quickly to secure AI systems — often faster than the threat landscape affecting those systems is fully understood.
Encryption is extended from existing data programs. Access controls are enforced. Monitoring is adapted. Governance processes are implemented. Much of this work is happening incrementally, which makes sense. AI adoption is still new, and compliance frameworks are evolving. As a result, many architectural decisions are made with uncertainty.
On paper, these incremental steps can look reassuring. In practice, critical questions remain unanswered — particularly at runtime, where AI systems operate continuously and concentrate both sensitive data and decision logic in ways traditional security controls were never designed to handle. This creates a knowledge and protection gap, jeopardizing companies’ compliance efforts.
That gap between intent and provability is where risk accumulates.
Runtime Exposure Is a Governance Problem
Security and compliance frameworks assume systems are well understood before they are widely deployed. AI reverses that order.
Models are trained and deployed while teams are still learning how they behave under stress or misuse. Sensitive data is processed continuously. Proprietary decision logic is embedded directly into model parameters. Runtime environments are long-lived and difficult to observe with precision.
When something goes wrong — a misconfiguration, a credential compromise, an insider issue — regulators ask a simple question:
Can you demonstrate that sensitive data and regulated decision logic were protected?
For most companies using AI systems today, the answer is no. Once data and models are decrypted in memory, exposure cannot be conclusively ruled out. Logs and policies may show intent, but proof is unavailable.
That uncertainty becomes the risk.
How CISOs Evaluate AI Risk in Practice
Experienced CISOs do not expect perfect prevention – that is an impossible goal. Instead, they focus on what they can control – containment.
But in AI environments, containment is overlooked, mainly because CISOs lack the right tools. This calls into question a couple of critical runtime elements:
- Whether sensitive data was accessible during execution
- Whether proprietary or regulated models were exposed, copied, or altered
When either of these is present in cleartext at runtime, the consequences of a breach or compromise can be significant. Investigations widen. Compliance escalates. Leadership prepares for the broadest possible interpretation of exposure.
The foundational runtime architecture determines whether that escalation is inevitable.
Encryption In Use: The CISO Perspective
Encrypting data and models in use allows security teams to mitigate uncertainty.
When sensitive assets remain encrypted during execution, a compromised environment does not automatically imply compromised information. Incident response becomes more precise, and scope is easier to control. Assertions are grounded in system properties rather than inference.
This is architectural risk reduction — removing classes of failure rather than attempting to monitor for them after the fact.
Encryption In Use: The Compliance Perspective (Chief Compliance Officer)
Compliance accountability is about defensibility, not effort.
Regulators focus on whether sensitive information was accessible and whether safeguards were enforceable. Plaintext runtime processing creates ambiguity that compliance teams cannot resolve after an incident. Logs cannot prove non-access.
Encrypted computation reduces that ambiguity. When data and models remain encrypted throughout processing, compliance positions can be based on how the system works, not on reconstructing what may have happened.
For compliance leaders, this materially lowers regulatory exposure in an environment where understanding is still evolving.
A Financial Services Reality Check
Consider a financial institution deploying an internal AI application built on an open model trained with nonpublic customer data and proprietary risk features.
A hacker accesses the runtime environment through a compromised credential.
If data and model weights are decrypted in memory, the institution cannot demonstrate that they were not accessed. Compliance teams assume exposure, regulatory obligations expand, and model governance considers revalidation or retirement.
However, if data and models remain encrypted during execution, exposure is constrained. Regulatory thresholds may not be met, and the incident remains operational rather than systemic.
The difference is significant. In the first instance, operational disruption (potentially major) ensues. In the second, business continues as usual.
Where Many AI Programs Are Most Vulnerable
Most AI programs underestimate the inherent risk where understanding is weakest: runtime behavior.
Traditional approaches are widely understood and adopted: encryption at rest and in transit, access controls, and monitoring. Runtime decryption introduces dependence on a complete understanding of threats that does not yet exist.
Architectures that eliminate plaintext runtime exposure avoid the need for that level of understanding, as they ensure exposure cannot occur, rather than attempting to prove after the fact that it did not.
From Managing Risk to Designing It Out
Fully Homomorphic Encryption (FHE) enforces confidentiality at the mathematical level. Data and models remain encrypted at rest, in transit, and during computation. Access to infrastructure no longer implies access to information.
For leaders evaluating new encryption technologies, durability matters. FHE schemes are lattice-based and widely regarded as quantum-resistant, meeting a baseline expectation that encryption deployed today should remain viable over the system’s lifespan.
This avoids a second round of risk later.
AI security and compliance are evolving in real time, amid an incomplete understanding. Runtime exposure of sensitive data and proprietary models is one of the clearest places where uncertainty translates directly to risk.
Encrypting data and models in use reduces dependence on perfect foresight. It limits the consequences of what cannot yet be fully understood.
For organizations deploying AI in regulated environments, that shift — from assuming understanding to designing for uncertainty — will increasingly determine whether AI adoption remains manageable or becomes a long-term liability.


