We recently launched our Gen AI Security product, Fortanix Armet AI. It has been a remarkable journey so far from the customer discovery session to the initial concept, prototyping, and productization of the product.
Armet AI is a turnkey secure data pipeline that allows enterprises to explore AI more aggressively without worrying about security.
Chapter 1: Product Discovery “The Problem Was Hiding in Plain Sight”
Our Gen AI product journey started six months back, when we started seeing that our existing customers are experimenting with Gen AI technology, understanding how it fits in with their business workflows, and how they can leverage this amazing technology to bring the next set of innovations in their products and services.
During our regular product discovery calls, we started seeing a pattern that the customers are done with experimentation /PoC’s and they want to deploy Gen AI in their production environment. However, they are concerned with security, privacy, and data regulations.
The enterprise leaders are looking for a path forward to implement a trusted and responsible Gen AI. The traditional security mitigation and risk framework may not be sufficient for emerging AI threats, but with Gen AI technology rapidly evolving on a daily basis, security and privacy need to advance.
With enough data points from customer discovery calls, partner interaction, and market research, we establish that security, privacy, and emerging AI regulation are the key factors slowing down enterprise GenAI adoption.
In a recent report from Google Cloud titled “State of AI infrastructure,” the most significant concerns with Gen AI adoption are security risks, data privacy concerns, and regulatory concerns. Certainly, GenAI has found its way into enterprises everywhere.
However, an organized, enterprise-grade strategy requires investigating a host of unknowns about where AI will truly be transformational, how much it will cost, and how it can be kept secure.
Chapter 2: Product Build “Where the Build Got Real”
Now comes the exciting part: Our team transitioned from the discovery phase to a product-build phase. This wasn't just about throwing features at the wall; it was about meticulously crafting a solution that directly addressed the pain points identified during our discovery phase and researching what is required to secure Gen AI.
We knew that for Armet AI to be successful, it needed to be more than just a security layer; it had to be a turnkey, enterprise-grade, hyper-secure Gen AI platform.
Our initial whiteboard sessions were a flurry of ideas but quickly coalesced around a few core tenets. We want to reimagine the AI infrastructure by leveraging our pioneering use of Confidential Computing.
We recognize that merely encrypting data at rest and in transit is no longer sufficient for the sophisticated demands of Generative AI. The true vulnerability lies when data, model, and model weights are actively being processed – in memory, during model training, and inference, as the bad actors are going after these important elements in the Gen AI pipeline.
Build AI Guardrails as a proactive defense mechanism against emerging AI threats. These guardrails prevent data exfiltration, block malicious inputs, reduce excessive agency, RAG security, and ensure responsible and Trusted AI behavior.
Our AI guardrails include:
- Intelligent Data Loss Prevention (DLP) for AI: Armet AI actively scans and filters both inputs to and outputs from LLMs, identifying and redacting sensitive information such as PII, PHI, or intellectual property before it can be processed by or leaked from the model. This prevents accidental or malicious data exposure.
- Prompt Injection and Jailbreak Prevention: We implement sophisticated techniques to detect and neutralize adversarial prompts designed to manipulate LLMs into revealing sensitive information or performing malicious actions.
- Model Tampering Detection: Armet AI scans for any vulnerabilities in LLM models before deploying them and continuously monitors the AI models within the secure enclaves, alerting and preventing any unauthorized modifications or attempts to compromise the model's behavior.
- Protection against excessive agency, a critical concern in the Gen AI application, is the risk of overly broad actions due to excessive functionality, permissions, or autonomy. To mitigate this, Fortanix Armet AI leverages source system Role-Based Access Control (RBAC) within the RAG pipeline, ensuring that the right user gets the right access at the right time by dynamically filtering retrieved information based on their existing permissions. Thus, the AI's agency is intrinsically limited to only the data the querying user is authorized to view.
- AI and Data Governance: Every interaction with sensitive data and AI models within Armet AI is logged, providing an immutable audit trail. This enables compliance reporting, 360-view Gen AI implementation, and an attestation report for Confidential Computing, which provides a comprehensive overview of AI and Data governance.
Chapter 3: The Path Forward: Armet AI and the Agentic Security Horizon
The journey of Fortanix Armet AI, from the initial product discovery to a fully realized, Security for Gen AI product, has been a testament to our commitment to innovation and empowering enterprises to secure sensitive Data and AI. We embarked on this path understanding that Generative AI, while revolutionary, presented unprecedented security and privacy challenges for regulated enterprises.
Conclusion: Glimpsing the Future – Agentic Security
Our journey with Armet AI has laid a strong foundation, demonstrating the power of confidential computing and intelligent AI guardrails. As the AI landscape shifts towards more autonomous systems, we are committed to extending these principles into the realm of Agentic Security, ensuring that enterprises can embrace the next wave of AI innovation with the same confidence and trust they find in Fortanix today. The problem was hiding in plain sight, and so too is the solution for the future of AI security.
Ready to unlock the full potential of Generative AI without compromising security?
Discover how Fortanix Armet AI can provide the turnkey, secure data pipeline for your enterprise needs.
- Request Your Personalized Armet AI Demo
- or sign up for public preview
- Learn More & Secure Your AI Future - Solution Brief