By Ravi Srivatsav and Luigi Caramico

Participating in the Early Stage Expo at RSAC 2025 felt like standing at a major inflection point for cybersecurity, where AI’s promises and risks collided, and the urgency to rethink data protection became crystal clear. The convergence of data and AI security is no longer theoretical – it’s happening, fast. And as AI adoption accelerates across industries, the conversations are shifting from “if” to “how” we secure these systems at scale.
Here are the common themes and discussions that prevailed at the RSA Conference.
Ethical AI: A Business Imperative, Not a Buzzword
One of the most talked-about topics this year was the ethical deployment of AI with an emphasis on transparency, accountability, and regulatory compliance, particularly under GDPR and similar mandates. Executives are clear-eyed about the risks. AI systems handle massive amounts of sensitive data, and that data must be protected at every stage.
But there’s a catch – they’re using the tools they know. Firewalls, Identity Access Management (IAM), and Virtual Private Networks (VPNs) are familiar defenses that work to prevent malicious actors from gaining access, so they’re naturally being repurposed to guard AI. But when it comes to ensuring that the model – and the data it’s trained on – are unusable to a bad actor who does gain access, business and technology leaders don’t yet know what’s possible with next-generation Fully Homomorphic Encryption (FHE).
This scenario is best illustrated through an analogy we at DataKrypto often use: protecting AI with traditional methods is like locking cash in a vault and hiring a team of security guards. If robbers breach the vault, the money is immediately usable to the thieves. What companies need is the digital equivalent of explosive ink for cash, which renders data useless if it is stolen. This is where DataKrypto’s FHEnom for AI comes in. (More on that below.)

AI as Both Offense and Defense
Another important area of discussion was around AI’s evolution – no longer just a productivity booster but a central component of offensive and defensive cybersecurity strategies. A major concern among leaders is how to prevent bias or poisoning in AI models, both of which can lead to poor decision-making and ethical, reputational, and financial damage.
A head of security at a major bank said her biggest fear is deploying an AI model at scale that ends up being biased, compromised, or both. Right now, she’s trying to mitigate risk by leveraging isolation mechanics that limit AI access to a handful of people – a costly tactic that can’t scale and minimizes AI innovation.
What she (and many others) are looking for is a new standard of protection, one that’s baked into the foundation of AI systems.

DataKrypto’s FHE for AI: A New Standard
In the sea of vendors touting various AI security products, FHE emerged as the only method that ensures models can be trained and analyzed on encrypted data, shielding both the model and inputs from tampering or exposure. As expressed by more than a few visitors to our booth, DataKrypto was a clear standout at the Early Stage Expo, with our new FHEnom for AI. Our solution uses FHE and Trusted Execution Environments (TEEs) to create a zero-knowledge AI framework. This dual-layer security protects AI models from theft and data leakage by keeping data encrypted throughout its lifecycle and ensuring models are only functional within the TEE.
Here’s what makes DataKrypto’s approach different:
- We encrypt both the model and the training data.
- We allow models to be trained on or queried against encrypted data, so even in the event of a breach, what’s stolen is useless.
- Only authorized users with the proper encryption keys can access or interpret the data.
In essence, it’s the digital equivalent of dye-packing stolen cash – you can’t use what you can’t read.

A Common Chorus: Data Must Be Protected Everywhere
Whether we spoke with firewall vendors, cloud providers, SaaS platforms, or hardware giants, one message was consistent: data is either passing through or being stored by these platforms, and it must be protected at all times. This is especially true with AI, which represents a single point of failure for data leakage, including intellectual property (IP) and personally identifiable information (PII). Companies using third-party AI tools need assurances that their data is protected and secure at all times and cannot be accessed or used by unauthorized parties, including the AI provider itself. In other words, AI providers should not have access to the data or the ability to use or train its models with proprietary information. Consider a hospital providing a medical chatbot using third-party AI. To offer this service, the hospital requires the AI provider’s guarantee that it cannot access any patient or other sensitive data.
The CSO of a F500 company was excited by DataKrypto’s ability to solve this problem, something we’ve known about since the 1970s – continuous encryption. For decades, FHE was considered the “holy grail” of encryption, but was hindered by performance and scalability challenges. According to him, solving that, as we have done, unlocks a cascade of other benefits: better productivity, fewer tools to manage, and ultimately, bulletproof data security.
We heard similar stories from SaaS and firewall vendors. They’re all chasing the same goal: foolproof data protection for compliance, customer trust, and long-term business continuity.
Beyond Observability: The Push for Proactive Security
Another clear trend: cybersecurity teams are drowning in dashboards. Observability tools do a great job of telling you what happened after an event occurs, but that’s not enough. In a world moving at digital speed, reacting in real-time still isn’t fast enough.
Executives are now shifting their focus to preventative tools that stop threats before they execute. This applies to both general security and AI-specific challenges. Instead of thousands of alerts, they want systems that automatically block unauthorized users and proactively detect bad actors – something we’ll see more of in the near future.
Securing AI Agents: The New Identity Frontier
Another area of focus at the conference was the emergence of AI agents as a new identity category that must be secured.
These agents perform tasks, access resources, and make decisions, much like human users. Securing these agentic identities is a growing concern. Some vendors at RSAC even discussed early-stage “GenAI firewalls” that restrict or allow access to generative AI systems based on identity, both human and non-human.

Final Takeaway: Encryption Is Having Its Renaissance
There was a clear shift in interest from generalized encryption to AI-specific protection. And rightfully so. With models being trained on proprietary data, used to make critical decisions, and embedded in customer-facing tools, protecting the model and the data is essential.
In this regard, we’re not facing a lack of intent – we’re facing a lack of awareness. Executives are ready to protect AI. They just need to know that solutions like DataKrypto’s FHEnom for AI exist and are ready for primetime.
As AI becomes more embedded in how we do business, the tools we use to protect it must evolve in lockstep. Those who get ahead of that curve will not only protect their assets but also build lasting trust in a world where AI and data are inseparable.


