Security becomes the control plane for enterprise AI factories Dell Technologies Inc. and Intel Corp. are building security into AI infrastructure from the ground up rather than after deployment, according to SiliconANGLE Media's coverage of the "Securing the AI Factory With Dell Technologies and Intel" event. Dell senior cybersecurity evangelist Steve Kenniston said "AI changes the whole game," citing model inferencing, training data, prompt injection and identity management as new attack surfaces, while Dell fellow and VP of systems architecture Mukund Khatri warned that agents taking wrong actions is more detrimental than LLMs giving wrong answers. theCUBE Research chief analyst Dave Vellante said AI factories introduce a new class of risks because data is continuously generated, transformed and consumed across distributed environments and agents increasingly act autonomously with limited or no human intervention. Security becomes the control plane for enterprise AI factories Artificial intelligence is making companies into factories of intelligence. As AI becomes a new workload, it has also become a new attack surface. The factory model that enterprises are building to produce knowledge at scale was not designed with security at its center. Energy, compute and data go in. Intelligence in the form of tokens comes out. But so do new risks that traditional cybersecurity was never built to handle. “AI factories introduce a new class of risks that extend beyond traditional cybersecurity models. In this world, data is not static, bounded or easily classified. Rather it is continuously generated, transformed and consumed across distributed environments,” said Dave Vellante https://www.linkedin.com/in/dvellante , chief analyst at theCUBE Research, in a recent analysis https://thecuberesearch.com/securing-the-ai-factory-the-new-control-plane-for-data-models-and-agents/ . Models are supported by deterministic systems that behave predictably, but they are also adaptive, probabilistic engines that evolve over time, Vellante explained: “Agents increasingly act autonomously, interacting with enterprise systems, executing workflows and making decisions with limited – or sometimes no – human intervention.” This feature is part of SiliconANGLE Media’s exploration of how enterprises are securing AI factories as models, agents and data create new risks across infrastructure, identity and operations. Be sure to check out SiliconANGLE’s extensive coverage of the “Securing the AI Factory With Dell Technologies and Intel” event . Disclosure below. Agentic AI creates a new class of security risk In this new environment, Dell Technologies Inc. and Intel Corp. are building security https://siliconangle.com/2026/05/06/dell-intel-governance-ai-factory-deployments-securingtheaifactory/ into the infrastructure itself, instead of after deployment. The tech giants are working to secure AI infrastructure and build data protection https://siliconangle.com/2026/05/07/enterprise-ai-deployment-rewriting-security-rulebook-securingtheaifactory/ from the ground up. “AI changes the whole game,” said Steve Kenniston https://www.linkedin.com/in/skenniston , senior cybersecurity evangelist for portfolio marketing at Dell. “There’s the model inferencing; there’s the training model, training data. There are the systems where people can do things like prompt injection; there’s identity management that needs to be thought about. Every new application has a new attack surface.” AI does not just expand the attack surface. It changes what needs to be protected https://siliconangle.com/2026/05/07/ai-infrastructure-security-becomes-key-ai-factories-scale-securingtheaifactory/ . “AI brings additional threats,” said Mukund Khatri https://www.linkedin.com/in/mukund-khatri-7019b714/ , fellow and vice president of systems architecture at Dell. “The model … the LLMs look like code. They need to be protected like code, but they are essentially data. The model integrity is of paramount importance.” AI agents are becoming increasingly common across enterprise environments, creating new security questions as they gain the ability to act autonomously. Because those agents are created and managed by humans, organizations must consider how their actions and access could put sensitive data and systems at risk. Large language models could give wrong answers, but agents could take the wrong action, which is more detrimental, according to Khatri. When systems work autonomously, the risk of errors or malicious activity can increase, especially because actions are executed in real time, often without an opportunity for human review. Identity becomes a critical control point for AI agents Businesses are adopting AI at high speed, but it is not clear how agents operate and what they can access. Agent identity has become a basic layer of control because poorly governed agents could provide an opening for bad actors. According to the Darktrace 2026 “State of AI Cybersecurity” report https://www.darktrace.com/resource/the-state-of-ai-cybersecurity-2026 , which surveyed 1,540 cybersecurity leaders and practitioners across 14 countries, 92% said they were concerned about the security implications of AI agents across their workforce, while 46% said they did not feel adequately prepared to defend against AI-powered threats. The report also found that 87% believe AI is significantly increasing the sophistication and success rate of malware. In this context, traditional security models built around perimeter defense, static policy enforcement and human-speed response are increasingly insufficient. Practices such as model inversion, prompt injection and data poisoning can exploit weaknesses involving models and data rather than conventional software vulnerabilities alone. But knowing where the danger lies is just half the problem. The other half is speed. AI can help adversaries identify vulnerabilities and develop attacks more quickly, shrinking the time between vulnerability discovery and active exploitation in ways traditional enterprise security frameworks were not designed to address. AI models can analyze software, identify potential flaws and accelerate parts of the attack process. When agents move through systems at high speed, security becomes increasingly difficult to maintain. AI workloads bring a complexity that most security teams are not ready to handle. To make the use of agents safer https://thecuberesearch.com/identity-is-becoming-the-control-plane-for-ai-agents/ , the deployment of least-privilege access will be crucial. Extending governance concepts such as lifecycle management and least-privilege access from human identities to agents will not require starting from scratch because the basic frameworks already exist, according to Krista Case https://www.linkedin.com/in/krista-case/ , principal analyst and practice lead for cyber resilience and security at theCUBE Research. The challenge is to adapt them to a fast-growing population of non-human identities, such as agents. “As AI agents gain autonomy, identity becomes a critical control point,” Case said. “Enterprises need to know which agents are operating, what they can access, what actions they can take and when those permissions should expire. Least privilege and lifecycle governance have to extend to agents as they become a growing class of enterprise identities.” That makes early involvement from security teams increasingly important as organizations move agentic systems into production. Identity controls and governance need to be considered before those systems begin interacting with sensitive data and business processes. “I’m hearing more and more from our services organization that when they start to go into a customer environment and they start talking about AI and implementing AI, about 85% or 90% of those get stopped because the security team hadn’t been involved up until that point,” Kenniston said. “At Dell, we integrate security into everything that we do, from the supply chain through the chips to the device that gets delivered to you.” The company designs its AI infrastructure from the ground up with roots of trust embedded in its components, building cyber resilience into the hardware and firmware rather than layering it on afterward. Dell Enterprise Hub also uses cryptographic image signing and SHA-384 hash verification to help organizations verify the integrity and provenance of AI model containers before deployment. The AI factory also demands security at the networking and operations level. Dell’s rack-scale infrastructure integrates compute, networking and storage into a single system where telemetry is consistent and security teams can monitor the full environment rather than chasing individual components. This capability is critical because AI workloads generate constant data movement between nodes, systems and models. That visibility also matters after an agent takes an action, particularly when organizations need to determine what happened and return operations to a trusted state. “As agents take on more responsibility for business processes, cyber resilience has to account for the state of the business,” Case said. “Recovery will then require understanding what an agent did, what decisions led to that action and how to restore operations to a known good state.” Trusted hardware forms the foundation for AI security For many enterprises, the answer to strengthening security is to keep sensitive AI workloads on-premises, bringing intelligence to the data rather than moving it to the cloud. This approach can give organizations greater control over sensitive information, infrastructure access and where AI processing occurs. It also puts more emphasis on securing the hardware foundation that supports models, data and inference workloads. “Security software and security measures running up the stack can’t be trusted unless the hardware underneath them is trustworthy,” said Mike Ferron-Jones http://linkedin.com/in/mike-ferron-jones-3906012 , go-to-market lead for platform security and integrity at Intel. “The CPU is kind of the fundamental hardware root of trust in the entire security stack. Your choice of a CPU is your very first security decision that you are making.” Intel organizes its data center security capabilities into four broad areas: platform protection, confidential computing through SGX and TDX, software behavior enforcement through control flow technologies and encryption acceleration. Together they create a hardware foundation for the entire software stack. Confidential AI environments place AI workloads inside a trusted execution environment with hardware-enforced isolation, cryptographic attestation and encryption keys controlled by the organization. Intel has also developed reference architecture work with Nvidia Corp. that combines CPU trusted execution environments, including Intel TDX, with Nvidia’s confidential-computing capabilities for GPUs, extending confidential AI protection to GPU-accelerated workloads. Post-quantum security enters the AI factory roadmap Advances in quantum computing are increasing concern about the future security of widely used public-key cryptography, although the timing of a cryptographically relevant quantum computer remains uncertain. One security risk is the “harvest now, decrypt later” scenario, in which attackers collect encrypted data today with the goal of decrypting it once sufficiently capable quantum computers become available. Dell and Intel are preparing for this potential threat. “By 2029, we expect that all cryptographic operations inside Intel platforms will be using quantum safe technology,” said Ferron-Jones. Intel’s current public roadmap separately calls for full post-quantum cryptography compliance across all new platforms by 2030. Dell is also moving toward quantum-resistant protections and post-quantum cryptography across parts of its portfolio. In the AI era, where knowledge becomes tokens, security must be the foundation for every technology layer. “It must become the control plane that governs how intelligence is produced,” Vellante said. “If you cannot secure the AI factory https://siliconangle.com/2026/05/13/dell-intel-ai-factory-security-securingtheaifactory/ , you do not control the outcome.” Disclosure: TheCUBE is a paid media partner for the “Securing the AI Factory With Dell Technologies and Intel” event. Neither Dell, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE. Image: SiliconANGLE/ChatGPT A message from John Furrier, co-founder of SiliconANGLE: Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network , where technology leaders connect, share intelligence and create opportunities. - 15M+ viewers of theCUBE videos , powering conversations across AI, cloud, cybersecurity and more - 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/ https://siliconangle.com/aws-marketplace/ About SiliconANGLE Media SiliconANGLE https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552 , theCUBE Network https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da , theCUBE Research https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f , CUBE365 https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6 , theCUBE AI https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683 and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.