

The Cybersecurity Infrastructure & Security Agency (CISA) recently published AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems in collaboration with the National Security Agency’s Artificial Intelligence Security Center (AISC), the Federal Bureau of Investigation (FBI), the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), New Zealand’s Government Communications Security Bureau’s National Cyber Security Centre (NCSC-NZ), and the United Kingdom’s National Cyber Security Centre (NCSC-UK).
The document “provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems. It also highlights the importance of data security in ensuring the accuracy and integrity of AI outcomes and outlines potential risks arising from data integrity issues in various stages of AI development and deployment.”
According to the guidelines, there are six essential components of a comprehensive AI data security program, as outlined below. Continuous encryption (encryption of data in transit, at rest, and in use) is at the heart, as it plays a role at every stage of the AI lifecycle.
Continuous Data and Model Protection Requires Continuous Encryption
Encryption is an obvious necessity. Companies share sensitive corporate data with AI models to enhance decision-making, automate workflows, and unlock operational gains — but current AI tools often lack robust security capabilities to protect against malicious access, data breaches, and adversarial attacks, such as model poisoning. These vulnerabilities enable hackers to manipulate AI outputs, compromise decision-making processes, and expose organizations to regulatory penalties for violating data privacy mandates, such as the GDPR and HIPAA.
In essence, AI systems handle massive amounts of sensitive data, and that data must be protected at every stage. However, CISA’s encryption guidelines are not specific enough: “Adopt advanced encryption protocols proportional to the organizational data protection level. This includes securing data at rest, in transit, and during processing. AES-256 encryption is the de facto industry standard and is considered resistant to quantum computing threats. Use protocols, such as Transport Layer Security (TLS) with AES-256 or postquantum encryption, for data in transit. Refer to NIST SP 800-52r2, “Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations.”
We agree that companies must incorporate advanced encryption to ensure data is protected while at rest, in transit, and during processing. However, the guidance to leverage AES-256 encryption as the de facto industry standard is misleading. AES-256, while it may be quantum-resistant, does not natively support computation on encrypted data. AES is a symmetric-key encryption standard designed for confidentiality, not for performing operations on ciphertext. To perform analysis, including AI queries, data must be decrypted, which creates gaps in protection.
DataKrypto FHEnom for AI™ Sets the Standard for AI and Data Security
Continuous encryption ensures that models can be trained and analyzed on encrypted data, shielding both the model and inputs from tampering or exposure. Specifically, DataKrypto’s new FHEnom for AI™ uses fully homomorphic encryption (FHE) and Trusted Execution Environments (TEEs) to create a zero-knowledge AI framework. This dual-layer security protects AI models from theft and data leakage by keeping data encrypted throughout its lifecycle, including training, inference, and deployment, and ensuring models are only functional within TEE.
FHE enables direct computation on encrypted embeddings, keeping both model weights and user data protected in ciphertext throughout processing, while TEEs provide hardware-enforced isolation for secure tokenization and output within a cryptographically verified enclave. As a result, queries and AI models are blind to each other throughout the query, analysis, and output process.
Additionally, if an AI model is stolen, it will be useless, as it can only function within the TEE. The encryption key, which only exists within the TEE, protects data by ensuring that only users with the key can view the results generated by each query.
Our solution is the digital equivalent of dye-packing stolen cash, which refers to the use of hidden, radio-controlled devices – called dye packs – placed within stacks of banknotes to foil robberies. When a bank robbery occurs, a teller discreetly includes a dye pack in the stolen cash. As the robber leaves the bank, the dye pack is triggered by a radio signal, typically after passing through the bank’s exit. After a short delay, the device explodes, releasing a permanent, brightly colored dye (often red) and sometimes tear gas, which stains the cash, the robber’s hands, and clothing. The stained money becomes easily identifiable as stolen, making it difficult or impossible to use or exchange, and often leads to the apprehension of the suspect.
Similarly, FHEnom for AI makes it impossible for cybercriminals to access AI models and data, as you can’t use what you can’t read.
DataKrypto’s approach promises to transform AI data security – and companies’ ability to leverage AI for complex problem-solving, product and service innovation, and creating a competitive advantage – for a few important reasons:
- We encrypt both the model and the training data.
- We allow models to be trained on or queried against encrypted data, so even in the event of a breach, what’s stolen is useless.
- Only authorized users with the proper encryption keys can access or interpret the data.
We applaud CISA’s efforts – and the collaboration with other national government agencies – to establish necessary guidelines for achieving AI security. But when it comes to protecting data and AI models, companies need more advanced capabilities than the guidelines suggest. DataKrypto is proud to offer the type of solution that companies need to ensure continuous data and model security, and reap the many benefits that AI can offer without fear of malicious activities.



