For decades, enterprise cybersecurity has focused on protecting the network perimeter through firewalls, identity management, and access controls. While these remain essential, the rise of Generative AI introduces new trust boundaries that extend beyond the traditional perimeter.
Modern AI applications, particularly those built on Retrieval-Augmented Generation (RAG), retrieve enterprise data dynamically, process it at inference time, and generate responses based on information distributed across multiple systems. As data moves through the AI pipeline, organizations must ensure that access is governed, sensitive information remains protected, and every interaction can be trusted and audited.
This shift is not simply another cybersecurity challenge; it is an architectural evolution. Securing enterprise AI requires cryptographic trust that spans identities, data, models, and AI workloads, ensuring that AI systems remain secure, governed, and ready for the post-quantum era.
The Numbers Tell the Story
The 2026 Utimaco Digital Trust Report, produced by 451 Research / S&P Global based on a survey of 250 enterprise security decision-makers, puts hard numbers to what security leaders are quietly wrestling with.
78% of respondents say addressing GenAI-related data privacy and security risks is very or critically important to their organization over the next 12 months. That is not a surprise. What is striking is what comes next: only 43% have already deployed new risk mitigation solutions. The remaining majority are still considering, experimenting, or planning.
There is a significant gap between stated urgency and actual deployment. And every day that gap remains open; enterprise AI systems are operating without the cryptographic controls they need.
The Architecture Behind the Exposure
Retrieval-Augmented Generation (RAG) has become the dominant enterprise GenAI deployment model. The reason is straightforward: RAG allows AI systems to dynamically access live organizational data rather than relying solely on pre-trained knowledge. For enterprises, that means faster answers, better context, and more relevant outputs.
But it also means sensitive data is now in motion in ways that traditional security architectures were never designed to handle. At the moment of retrieval and inference, data is decrypted and exposed across distributed environments, often without policy-enforced controls over who can access what, under which conditions, and with what level of auditability.
This is precisely the security gap that perimeter tools cannot close. The exposure does not happen at the network edge. It happens inside the AI pipeline itself.
Why Cryptographic Trust Changes the Equation
The answer is not a new perimeter. It is a new layer entirely: the cryptographic trust layer.
Hardware Security Modules (HSMs) and Key Management Systems (KMS) provide what perimeter security cannot. They establish a hardware root of trust that operates at the data and model level. In practical terms this means:
- Data is protected at rest and in transit, with decryption controlled precisely at inference and processing time
- Model integrity is verified cryptographically, preventing unauthorized model usage or tampering
- Every interaction across the AI pipeline generates a tamper-proof audit trail
- Cryptographic keys are protected in hardware and never exposed, even to the systems that use them
The 2026 Utimaco Digital Trust Report also reveals where enterprises believe this trust must be anchored. When asked about the primary root of trust for securing the post-quantum AI ecosystem, respondents pointed to cryptographic integrity of the AI model itself (24%) and cryptographic provenance of training and inference data (21%) as the top priorities. Hardware-enforced trust anchors, runtime behavioral verification, and human governance layers each followed at 18%.
The signal is clear: enterprises understand that trust in AI must be cryptographically verifiable, not assumed.
The Next Frontier: Agentic AI and Machine Identity
RAG is only the beginning. The enterprise AI landscape is already moving toward something more complex: agentic AI, where autonomous systems communicate, make decisions, and act on behalf of organizations, often without direct human oversight in the loop.
In this environment, the concept of identity shifts. It is no longer enough to know which human authorized an action. You need to know which agent acted, under whose authority, with what data, and within what policy boundaries. Without cryptographic machine identities and policy-driven controls, that level of accountability is simply not achievable.
HSM-backed machine identities provide exactly this foundation, enabling verifiable trust between AI agents at enterprise scale. As the report findings suggest, the organizations investing in cryptographic governance frameworks now will be the ones positioned to scale agentic AI responsibly as autonomous systems multiply.
Three Actions Security Leaders Should Take Now
The gap between urgency and deployment identified in the 2026 Utimaco Digital Trust Report is not just a statistic. It is a window of risk that is actively widening as AI adoption accelerates. Here is where to start closing it:
First, audit your RAG security posture. Map where sensitive data is retrieved, processed, and exposed across your AI pipelines. Identify every point where cryptographic controls are absent or insufficient.
Second, anchor your AI architecture to a hardware root of trust. HSMs provide non-extractable key protection, secure cryptographic execution, and model integrity verification. These are not optional capabilities for enterprise AI. They are foundational ones.
Third, build your machine identity strategy before agentic AI scales. The organizations defining cryptographic governance frameworks for autonomous agents today will be the ones able to scale agentic AI responsibly tomorrow.
The Path Forward
78% of enterprises know GenAI security is critical. The question is no longer whether to act. It is whether your organization will be in the 43% that has already deployed the controls it needs or still planning while the exposure grows.
Cryptographic trust, anchored by HSMs and KMS, is not a back-office security concern. It is the foundation on which secure, governable AI ecosystems are built.
Watch the Webinar
Securing the GenAI Revolution, Part 3: From RAG to Agentic AI Trust here
Download the Report
2026 Utimaco Digital Trust Report by 451 Research / S&P Global here
Learn More About Utimaco's Solutions
General Purpose HSMs: General Purpose HSM - Utimaco here
Key Management Systems: Key Management - Utimaco here
Your download request(s):

Your download request(s):

About Utimaco's Downloads
Visit our Downloads section and select from resources such as brochures, data sheets, white papers and much more. You can view and save almost all of them directly (by clicking the download button).
For some documents, your e-mail address needs to be verified. The button contains an e-mail icon.
A click on such a button opens an online form which we kindly ask you to fill and submit. You can collect several downloads of this type and receive the links via e-mail by simply submitting one form for all of them. Your current collection is empty.