The panel records live at Black Hat 2026 as part of HPE's Unleash artificial intelligence Momentum series. Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, hosts the discussion with Robin Braun of HPE, vice president of artificial intelligence business development; Ian Williamson of BigID, senior vice president of alliances; and Patrick Conte of Fortanix, chief revenue officer.
The conversation explores how organizations move artificial intelligence into production, covering data discovery and classification, shadow AI, confidential computing and integrated stacks such as HPE's Private Cloud AI. Case guides the discussion of practical integration and governance challenges at scale.
Braun states that trusted data forms the foundation for reliable AI. Williamson emphasizes the need for comprehensive discovery and governance to surface shadow AI and sensitive assets. Conte highlights protecting data in use through confidential computing and composite attestation. Analysts recommend assessments, targeted pilots including on-premises and adopting validated integrated stacks to accelerate safe production deployments.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Robin Braun, HPE, Ian Williamsom, BigID, Patrick Conte, Fortanix
The panel records live at Black Hat 2026 as part of HPE's Unleash artificial intelligence Momentum series. Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, hosts the discussion with Robin Braun of HPE, vice president of artificial intelligence business development; Ian Williamson of BigID, senior vice president of alliances; and Patrick Conte of Fortanix, chief revenue officer.
The conversation explores how organizations move artificial intelligence into production, covering data discovery and classification, shadow AI, confidential computing and integrated stacks such as HPE's Private Cloud AI. Case guides the discussion of practical integration and governance challenges at scale.
Braun states that trusted data forms the foundation for reliable AI. Williamson emphasizes the need for comprehensive discovery and governance to surface shadow AI and sensitive assets. Conte highlights protecting data in use through confidential computing and composite attestation. Analysts recommend assessments, targeted pilots including on-premises and adopting validated integrated stacks to accelerate safe production deployments.
Robin Braun, HPE, Ian Williamsom, BigID, Patrick Conte, Fortanix
Ian Williamson
SVP, AlliancesBigID
Patrick Conte
Chief Revenue OfficerFortanix
search
Krista Case
>> Welcome back to theCUBE's live coverage of Black Hat 2026. I'm Krista Case, and we have a special segment for you right now. This is part of our Unleash AI Momentum series that we're doing with HPE. And over this conversation, we're going to talk about the fact that organizations are beginning to move AI into production. But many companies lack confidence in the data that's actually fueling their AI initiatives. They lack visibility into things like what data is being used, where it resides, how it's protected, and whether or not they can trust it. And this is really a problem because AI begins with the foundation of trusted data, which really requires, again, that visibility, governance, protection, and these various infrastructure components working together. And so I'm joined here today by 3 guests. I'm joined by Robin Braun, who is VP of AI Business Development with HPE. Robin, thanks for joining us.
Robin Braun
>> Thank you.
Krista Case
>> Ian Williamson, SVP of Alliances with BigID.
Ian Williamson
>> Thank you.
Krista Case
>> Thank you for joining us, Ian. And Patrick Conte, Chief Revenue Officer with Fortanix.
Patrick Conte
>> Thanks for inviting us.
Krista Case
>> Thanks, Patrick. So Robin, why don't we start with you? So again, one thing that's really emerging time and time again in my conversations is that enterprise leaders are struggling with not so much building AI models, but building the confidence in the data that's fueling them. Can you talk about why trusted data has become such a foundational issue these days as we're trying to scale these AI initiatives?>> I think it's such a great place to start when you think about how do you start to scale out into production. You have to trust what you're doing, and at the foundation of all AI is data. And I think this has become an even more critical conversation as the whole conversation around tokens and how do you actually transition from frontier models to open-source models? How do you start to look at not just cloud compute, but private compute and private AI, and being able to do that, but do it in a trusted, secure, and confident way? And organizations have— they have SaaS applications, they have data in the cloud, they have data on-prem, they have data probably on somebody's laptop that they're not sure about. And Do they know how a model got trained? Do they know that it has the right parameters, right governance, right guardrails so that you're not exposing things like PII, but you may be able to get the intelligence that you need from it but not exposing it? I think those are the things that as we start to move out of the era of a ton of pilots to now, how do you scale? How do you move into production? How do you start to get that value out of AI we've all been talking about? Those are critical conversations that people need to understand so that they feel confident as they roll out that they're not suddenly going to expose data or be making inaccurate decisions based off of incomplete model understanding.
Krista Case
>> Absolutely. It's kind of two potential issues, as you mentioned. One is potentially exposing the data and the other is kind of the problem of garbage in, garbage out. If you're training your AI model on data that's not trustworthy, you're not going to get good outcomes out of it. So, Ian, I know this is kind of the cornerstone of a lot of what BigID does. So, can you talk about, as organizations begin preparing their data for AI, what are they maybe learning as they start identifying and classifying the information that they're using to fuel their AI applications?
Ian Williamson
>> Yeah, it's that confidence that Robin mentioned that we're helping to build, and we have hyperfocus on the data. So, when we're discovering data and scanning for sensitive data, we also can look at the code and we're finding a lot of shadow AI, we're finding sandbox environments that are kind of rogue models that are being built. So, that compliance to IT standards is sometimes missing. And so, that's a big issue. The other is just around data access governance and both human and non-human access. So, agentic access to the data that's feeding these models or training the models is exposing a lot of sensitive data. So, some of those are some of the biggest issues. And then just around privacy and compliance, sometimes we, we look beyond just security, but actually governance on what data's being used and how it's being used for AI models is something that's really critical right now that we're looking at.
Krista Case
>> I agree, Ian. I think one of the headlines here at Black Hat is sort of this concept of AI governance. And I think it's, on one hand getting a little buzzworthy, but on the other hand, it's very true, right? Because as we try to really, again, operationalize AI and move it into production, we do need those guardrails. And that really does start with the data.
Ian Williamson
>> Yes, absolutely.
Krista Case
>> And so Patrick, I know the discovery piece is only the first step. We also need to make sure that this information is protected, especially as businesses start to use, these AI applications and the data that's fueling them. So can you talk about how we start to build that trust and protection in?
Patrick Conte
>> Sure. Yeah. And we've been partnered with BigID for quite a while now, and we don't do data discovery, we don't do the classification stuff, we don't do all the intelligence that they do. So it's actually a really great partnership for them to be able to discover and classify the data properly, and then for us to be able to take that and protect it. And we actually— this whole concept of data protection feeds into this AI governance challenge. The data needs to be protected at rest. And really the only proven way to do that is to encrypt it. So we have methods to do that. But to do anything with it, you have to move it. You have to move it into, for example, CPU encrypted memory so that you can actually do something with it and protect it while it's in use. So we actually have a solution that we're working with Rob and the team at HPE to deliver a straight-through solution that sits on top of HPE infrastructure where we can encrypt the data at rest, encrypt the data in motion. The data in motion stays inside an encrypted tunnel until it gets to the CPU and actually goes into the memory of the CPU. That memory is actually encrypted. Then we decrypt it inside that memory and it can run inside that memory in your entire solution. Data end-to-end is fully protected.
Krista Case
>> Yeah, like you say, from data at rest all the way through data in use. And that's especially critical in these hybrid environments that we've been talking about, I'm sure, as well, because the data is moving to where it needs to be processed for the AI application. So we were also talking a moment ago about AI governance, and I'd be curious to get all three of your perspectives on Step 1 being why this matters, but also, how do you find customers start to strike the balance between adopting AI, but also making sure that they have enough of these protection and guardrail technologies in place without, again, slowing down that innovation. So maybe we'll start with you, Robin.>> And I would say that it's a balance and to Ian's point, they're starting to see the shadow AI. And you're starting to see where they have models. And we all have heard the different stories of whether suddenly the model went and, wiped out a database or, an agent went and did this or that, which was an unintended consequence, or whether they ran up $1 million of tokens in a month. We've all heard the different tales of what can occur there. And I think the focus on governance is exact— it goes back to where you started the conversation, which is around what does it mean to bring AI into production? What we've all kind of come to think of as production, that it works, that it's repeatable, that it's secure, that it can be private, that it can be, for lack of a better term, kind of managed or controlled, not to stifle innovation, but to do it in a safe and secure manner that doesn't start to expose data of different sensitivities, whether it's of your employees or of your customers, in a way that could be problematic or cause damage, whether it's reputational harm or actual harm. And so, that's where I think AI governance is one of the top conversations that I'm having with people when they're first getting into AI, the types of models can be overwhelming, the different choices can be overwhelming. But I think being able to bring it back into some rigor and to move from kind of the pilot, let's just try things into how do we make this a repeatable tool set we can rely on and that then can drive value for the organization, that's where governance is so critical.
Krista Case
>> That makes sense. Ian?
Ian Williamson
>> Yeah, you know, I'd add on, you know, on the governance side, it's really important for us to make sure that companies are up to speed around compliance, around audits. And so having your house in order, your data catalog, all of the sensitive data visible, fully classified and tagged is very important. The other thing is around the cost. These AI projects, everyone's watching costs. And so we're able to show a return on investment by doing things like data lifecycle management, reducing redundant, obsolete, trivial data, which has both a financial benefit and then in addition has the benefit of training the models in a more accurate way, right? We don't want misguided models with redundant data or obsolete data.
Krista Case
>> So using an incorrect version of a file, maybe.
Ian Williamson
>> Yeah, yeah, yeahSo there's the governance side. We're seeing a lot of customers really embracing this kind of broad concept of data lifecycle management, being able to do delegated remediation on, you know, risk or deletion of files. So those are a couple of key things I think are important right now is just helping these leaders launch an AI initiative while managing costs and having a return on investment.
Krista Case
>> Absolutely. I agree. And I think most enterprises don't even know where all their data is, never mind have that level of context and visibility into it.
Ian Williamson
>> Right. Yeah. Yeah,
Krista Case
>> absolutely. So Patrick, I'd love to get your
Patrick Conte
>> thoughts.For sure, they do not know where all their data is. And another thing, they don't know where their encryption keys are. So discovery has to be done really on both the cryptographic asset side as well as the data side. And those are all things that sort of feed into the ability to deliver governance. What we've seen as we've talked to customers is really two different kinds of approaches. One is a number of very large companies, sort of the largest banks in the world and others, have formed centers of excellence. And what they've really done in many cases is take the approach that they're going to build their own guardrails. They're going to take a bunch of off-the-shelf products, they're going to roll them together, and try to create something that will work for them. The challenge that those guys have is that's not protecting the data in use, that's actually protecting access and it's marrying different pieces of the front part of the process together. So I actually had this conversation with the CISO from a very, very large global bank. And we were talking about using confidential computing, which is our foundational technology, protecting data in use, right? Basically using encrypted memory. And we asked him about this as it related to AI. And he said, yeah, if I need that, I'm just going to ask my cloud guys to just turn it on. I can just turn it on if I want to turn it on. He did not understand that that actually doesn't do anything. You have to have other things to provide the governance and you have to provide workflows. You have to actually be able to connect to all of the hardware that's involved in any kind of an AI job, the CPUs, the GPUs, the job itself. You have to put agents on all these so that you can collect measurements. And make sure that all those pieces of hardware, the CPUs, GPUs, all the compute is as it was when it came from the factory, that hasn't been tampered with in the supply chain. You also have to put an agent on the workload and the model. And what this does is make sure that you don't have any tampering from the time when those were registered to be used in the job until you go to runtime. And we call this composite attestation, and that's what actually allows jobs to run. And that's where we see the governance piece going is Yeah, you have the guardrails piece, but what happens after you get past the guardrails? You still have insider threat, you still have data leakage that can occur.
Krista Case
>> Yeah. And you need that foundational trust in the infrastructure beyond making sure from a software perspective that we have the governance in place for the AI agents or the application itself.
Ian Williamson
>> Absolutely.
Krista Case
>> So, Patrick, you were talking a little bit about kind of integration. And it's a great segue because I know part of this Unleash AI program that's being led by HPE is to support customers with the integration piece of it. So, and I know, again, Patrick, you were just giving some commentary, so maybe I'll start this question with you, see if you have anything else. And then we'll maybe go to Robin and Ian. But what difference does this kind of, partnership and integration make when customers actually look to move their AI into production? Again, maybe any additional commentary?
Patrick Conte
>> Yeah, what Unleash AI does is give you the components of the stack, the stack that has to be delivered on top of the infrastructure. So HPE is delivering the infrastructure, they're delivering a lot of tools, models, a lot of things that can be used by those customers, but things need to be stacked on top of it. There needs to be orchestration, right? And so they partner with orchestration vendors that we've also partnered with. They partnered with model vendors, model builders, frontier model builders. We also have partnered with those guys. And so all parts of the stack and the security layer includes more than just confidential computing. It typically includes other parts of the zero trust spectrum, right? You know, endpoint or whatever. So the CrowdStrike of the world and others are part of the program. Those are also partners. And so what has to happen is you have to have integration up and down that stack to deliver to a customer a trusted solution. And I think that's what Robin and her team are doing, is building that, building a collection of capabilities that work together to create the stack or the stacks as customers need to deploy them. Did I get that right, Robin?
Robin Braun
>> You did. You did.
Krista Case
>> So, yes. Robin, any other commentary around Unleash AI and this concept of bringing these integrated solutions to bear for customers, not only to speed that adoption process, but also to make sure that that foundation is trusted.>> And I think it's— it really is my privilege to be able to lead this program. It's so much fun getting to work with partners such as Pat and Ian and build out this truly like innovation ecosystem and toolbox of being able to bring to Pat's point that entire stack, that entire solution, to be able to really answer the customer's challenges and how they're moving into production and scaling production. One of the things we've done is we've built Private Cloud AI in conjunction with NVIDIA, where we've already built out and integrated the AI stack, which is a fantastic starting point. You know, a number of customers have people who have managed VMware, and suddenly you're handing them Kubernetes and saying, good luck. And that, that's not fast. It's a little different.
Krista Case
>> Different worlds.>> Different worlds. So we've really put a lot of engineering focus and partnership in with HPE and NVIDIA working to create Private Cloud AI. And so then that AI stack is lifecycle managed over the course of that infrastructure. And so there's that huge simplification. But then to Pat's point, being able to build out with Unleash AI these integrated solutions on top that we go through, we validate, we test, we make sure we have the recipe for how to make this easy for our customers. And then of course, making sure that we're focusing on things like AI governance and those pieces that can help bring that confidence into expanding out into production.
Krista Case
>> Absolutely. And Ian, any commentary from you?
Ian Williamson
>> Yeah, on the infrastructure side, our biggest selling point to customers is the breadth with which we can go discover data. We want to look for all your unstructured, structured, semi-structured data, whether it's in the cloud, it's on-prem. We have a lot of customers who have air-gapped environments that are run on-prem and with infrastructure. So, you know, the relationship we have with HPE and Fortanix and kind of that integrated stack is critical to us differentiating in the market. We're not just looking at public cloud environments. We're looking at all the environments. And our platform is an open, you know, API-driven platform. We connect to over 220 data sources. So yeah, that connection with partners like this are very, very important to us.
Krista Case
>> Absolutely. So we like to make things very actionable for our audience. So as we start to close the segment, I'd like to pose a question to all three of you, which is if you were talking with a practitioner and they're feeling overwhelmed about where to start with establishing this AI governance, what might be your top recommendation for them to start with? So maybe we'll start with Robin.>> I would say that if I'm talking with a practitioner and, you know, how to get started with AI governance, it's first off, take a breath. We've been doing governance from an IT perspective and an infrastructure perspective for a long time. There's some new words, there's new things we have to worry about. We have to worry about the speed at which AI changes and the difference that that brings. But a lot of this thinking isn't necessarily new. It's just at a different scale and at a different level. So, first, take a breath and then work with trusted partners such as Fortanix, BigID, and of course HPE, who can— maybe we can help make it simpler and a little more approachable so that you don't have to go out and try to wire everything together yourself and learn it the hard way, but that we've already done a lot of that heavy lifting so that you can start to go through and understand where are the benefits and then where are things where your company may do something specific or unique and where we need to assist and how you might want to think about it and support that journey. And I think the big thing probably from all three of us is, we are here to support somebody's journey in doing it. And our goal is just to help make them successful in moving to production faster.
Krista Case
>> Absolutely. Ian, any thoughts from you?
Ian Williamson
>> Yeah, I'll keep it kind of short and succinct and really just say, we recommend companies that are evaluating this issue of looking at their data and taking control of their data to run an assessment, and we can allow them to use our software at no cost. We have partners, I think every partner works with HPE, and most of our partners work with Fortanix, so getting a partner, whether it's one of the big advisory firms, we work with all the big global system integrators, or a lot of the channel partners here at Black Hat, will go in and just run an assessment and kind of come back and give you a good idea of where you stand and, where the program needs to be built, which is around people, process, and technology. And that's a good way to, I think to Robin's point, to take a breath and get started in a really kind of well-rounded way with an assessment.
Krista Case
>> Absolutely. Patrick?
Patrick Conte
>> If I were going to be a tree, I'd be a mighty oak. Oh, that wasn't the question. If I were going to make recommendations to a customer that wanted to get started, I would— my recommendation would be don't be afraid to pilot. Don't be afraid to pilot on-premises. Don't be afraid to use the infrastructure that's here and that's modern, that's being built out of NVIDIA GPUs and being built out of CPUs by the leading CPU vendors and being put together by HPE. I would tell them that they don't need to go through the huge amount of work to try to build their own guardrails. That guardrails, guardrail and guardrail technology is actually in the toolkits that, for example, the Private Cloud AI, the toolkit that's part of that stack has the ability to build guardrails there. You don't have to go and get 4 or 5 startup companies to stitch their stuff together in something that can't even be supported because it's not standard. So, that would be my recommendation. I think a lot of companies, government agencies, and others are looking at how do I get started? Find an area, you want to get a model, and you want to get started because you don't want to be left behind and you're going to need to use this technology. It's absolutely there. We're seeing a lot of rehoming coming back on-premises because customers want the model to be close to the data. And a lot of times that data can't go anyplace else. If it's banks, if it's, let's say security agencies or whatever the case may be, or healthcare. So that would be my recommendation is get started, do the pilot.
Krista Case
>> Take the first step, right?
Robin Braun
>> Yep.
Krista Case
>> Yep. I think that's a great comment to leave on. So Robin, Ian, Patrick, thank you so much for joining. Really appreciate it.
Patrick Conte
>> Thank you.
Krista Case
>> Thank you. Thank you. And stay tuned. We'll be back in just a little bit here at theCUBE with more of our ongoing coverage of Black Hat 2026. Thanks so much.
Robin Braun, HPE, Ian Williamsom, BigID, Patrick Conte, Fortanix
search
Krista Case
>> Welcome back to theCUBE's live coverage of Black Hat 2026. I'm Krista Case, and we have a special segment for you right now. This is part of our Unleash AI Momentum series that we're doing with HPE. And over this conversation, we're going to talk about the fact that organizations are beginning to move AI into production. But many companies lack confidence in the data that's actually fueling their AI initiatives. They lack visibility into things like what data is being used, where it resides, how it's protected, and whether or not they can trust it. And this is really a problem because AI begins with the foundation of trusted data, which really requires, again, that visibility, governance, protection, and these various infrastructure components working together. And so I'm joined here today by 3 guests. I'm joined by Robin Braun, who is VP of AI Business Development with HPE. Robin, thanks for joining us.
Robin Braun
>> Thank you.
Krista Case
>> Ian Williamson, SVP of Alliances with BigID.
Ian Williamson
>> Thank you.
Krista Case
>> Thank you for joining us, Ian. And Patrick Conte, Chief Revenue Officer with Fortanix.
Patrick Conte
>> Thanks for inviting us.
Krista Case
>> Thanks, Patrick. So Robin, why don't we start with you? So again, one thing that's really emerging time and time again in my conversations is that enterprise leaders are struggling with not so much building AI models, but building the confidence in the data that's fueling them. Can you talk about why trusted data has become such a foundational issue these days as we're trying to scale these AI initiatives?>> I think it's such a great place to start when you think about how do you start to scale out into production. You have to trust what you're doing, and at the foundation of all AI is data. And I think this has become an even more critical conversation as the whole conversation around tokens and how do you actually transition from frontier models to open-source models? How do you start to look at not just cloud compute, but private compute and private AI, and being able to do that, but do it in a trusted, secure, and confident way? And organizations have— they have SaaS applications, they have data in the cloud, they have data on-prem, they have data probably on somebody's laptop that they're not sure about. And Do they know how a model got trained? Do they know that it has the right parameters, right governance, right guardrails so that you're not exposing things like PII, but you may be able to get the intelligence that you need from it but not exposing it? I think those are the things that as we start to move out of the era of a ton of pilots to now, how do you scale? How do you move into production? How do you start to get that value out of AI we've all been talking about? Those are critical conversations that people need to understand so that they feel confident as they roll out that they're not suddenly going to expose data or be making inaccurate decisions based off of incomplete model understanding.
Krista Case
>> Absolutely. It's kind of two potential issues, as you mentioned. One is potentially exposing the data and the other is kind of the problem of garbage in, garbage out. If you're training your AI model on data that's not trustworthy, you're not going to get good outcomes out of it. So, Ian, I know this is kind of the cornerstone of a lot of what BigID does. So, can you talk about, as organizations begin preparing their data for AI, what are they maybe learning as they start identifying and classifying the information that they're using to fuel their AI applications?
Ian Williamson
>> Yeah, it's that confidence that Robin mentioned that we're helping to build, and we have hyperfocus on the data. So, when we're discovering data and scanning for sensitive data, we also can look at the code and we're finding a lot of shadow AI, we're finding sandbox environments that are kind of rogue models that are being built. So, that compliance to IT standards is sometimes missing. And so, that's a big issue. The other is just around data access governance and both human and non-human access. So, agentic access to the data that's feeding these models or training the models is exposing a lot of sensitive data. So, some of those are some of the biggest issues. And then just around privacy and compliance, sometimes we, we look beyond just security, but actually governance on what data's being used and how it's being used for AI models is something that's really critical right now that we're looking at.
Krista Case
>> I agree, Ian. I think one of the headlines here at Black Hat is sort of this concept of AI governance. And I think it's, on one hand getting a little buzzworthy, but on the other hand, it's very true, right? Because as we try to really, again, operationalize AI and move it into production, we do need those guardrails. And that really does start with the data.
Ian Williamson
>> Yes, absolutely.
Krista Case
>> And so Patrick, I know the discovery piece is only the first step. We also need to make sure that this information is protected, especially as businesses start to use, these AI applications and the data that's fueling them. So can you talk about how we start to build that trust and protection in?
Patrick Conte
>> Sure. Yeah. And we've been partnered with BigID for quite a while now, and we don't do data discovery, we don't do the classification stuff, we don't do all the intelligence that they do. So it's actually a really great partnership for them to be able to discover and classify the data properly, and then for us to be able to take that and protect it. And we actually— this whole concept of data protection feeds into this AI governance challenge. The data needs to be protected at rest. And really the only proven way to do that is to encrypt it. So we have methods to do that. But to do anything with it, you have to move it. You have to move it into, for example, CPU encrypted memory so that you can actually do something with it and protect it while it's in use. So we actually have a solution that we're working with Rob and the team at HPE to deliver a straight-through solution that sits on top of HPE infrastructure where we can encrypt the data at rest, encrypt the data in motion. The data in motion stays inside an encrypted tunnel until it gets to the CPU and actually goes into the memory of the CPU. That memory is actually encrypted. Then we decrypt it inside that memory and it can run inside that memory in your entire solution. Data end-to-end is fully protected.
Krista Case
>> Yeah, like you say, from data at rest all the way through data in use. And that's especially critical in these hybrid environments that we've been talking about, I'm sure, as well, because the data is moving to where it needs to be processed for the AI application. So we were also talking a moment ago about AI governance, and I'd be curious to get all three of your perspectives on Step 1 being why this matters, but also, how do you find customers start to strike the balance between adopting AI, but also making sure that they have enough of these protection and guardrail technologies in place without, again, slowing down that innovation. So maybe we'll start with you, Robin.>> And I would say that it's a balance and to Ian's point, they're starting to see the shadow AI. And you're starting to see where they have models. And we all have heard the different stories of whether suddenly the model went and, wiped out a database or, an agent went and did this or that, which was an unintended consequence, or whether they ran up $1 million of tokens in a month. We've all heard the different tales of what can occur there. And I think the focus on governance is exact— it goes back to where you started the conversation, which is around what does it mean to bring AI into production? What we've all kind of come to think of as production, that it works, that it's repeatable, that it's secure, that it can be private, that it can be, for lack of a better term, kind of managed or controlled, not to stifle innovation, but to do it in a safe and secure manner that doesn't start to expose data of different sensitivities, whether it's of your employees or of your customers, in a way that could be problematic or cause damage, whether it's reputational harm or actual harm. And so, that's where I think AI governance is one of the top conversations that I'm having with people when they're first getting into AI, the types of models can be overwhelming, the different choices can be overwhelming. But I think being able to bring it back into some rigor and to move from kind of the pilot, let's just try things into how do we make this a repeatable tool set we can rely on and that then can drive value for the organization, that's where governance is so critical.
Krista Case
>> That makes sense. Ian?
Ian Williamson
>> Yeah, you know, I'd add on, you know, on the governance side, it's really important for us to make sure that companies are up to speed around compliance, around audits. And so having your house in order, your data catalog, all of the sensitive data visible, fully classified and tagged is very important. The other thing is around the cost. These AI projects, everyone's watching costs. And so we're able to show a return on investment by doing things like data lifecycle management, reducing redundant, obsolete, trivial data, which has both a financial benefit and then in addition has the benefit of training the models in a more accurate way, right? We don't want misguided models with redundant data or obsolete data.
Krista Case
>> So using an incorrect version of a file, maybe.
Ian Williamson
>> Yeah, yeah, yeahSo there's the governance side. We're seeing a lot of customers really embracing this kind of broad concept of data lifecycle management, being able to do delegated remediation on, you know, risk or deletion of files. So those are a couple of key things I think are important right now is just helping these leaders launch an AI initiative while managing costs and having a return on investment.
Krista Case
>> Absolutely. I agree. And I think most enterprises don't even know where all their data is, never mind have that level of context and visibility into it.
Ian Williamson
>> Right. Yeah. Yeah,
Krista Case
>> absolutely. So Patrick, I'd love to get your
Patrick Conte
>> thoughts.For sure, they do not know where all their data is. And another thing, they don't know where their encryption keys are. So discovery has to be done really on both the cryptographic asset side as well as the data side. And those are all things that sort of feed into the ability to deliver governance. What we've seen as we've talked to customers is really two different kinds of approaches. One is a number of very large companies, sort of the largest banks in the world and others, have formed centers of excellence. And what they've really done in many cases is take the approach that they're going to build their own guardrails. They're going to take a bunch of off-the-shelf products, they're going to roll them together, and try to create something that will work for them. The challenge that those guys have is that's not protecting the data in use, that's actually protecting access and it's marrying different pieces of the front part of the process together. So I actually had this conversation with the CISO from a very, very large global bank. And we were talking about using confidential computing, which is our foundational technology, protecting data in use, right? Basically using encrypted memory. And we asked him about this as it related to AI. And he said, yeah, if I need that, I'm just going to ask my cloud guys to just turn it on. I can just turn it on if I want to turn it on. He did not understand that that actually doesn't do anything. You have to have other things to provide the governance and you have to provide workflows. You have to actually be able to connect to all of the hardware that's involved in any kind of an AI job, the CPUs, the GPUs, the job itself. You have to put agents on all these so that you can collect measurements. And make sure that all those pieces of hardware, the CPUs, GPUs, all the compute is as it was when it came from the factory, that hasn't been tampered with in the supply chain. You also have to put an agent on the workload and the model. And what this does is make sure that you don't have any tampering from the time when those were registered to be used in the job until you go to runtime. And we call this composite attestation, and that's what actually allows jobs to run. And that's where we see the governance piece going is Yeah, you have the guardrails piece, but what happens after you get past the guardrails? You still have insider threat, you still have data leakage that can occur.
Krista Case
>> Yeah. And you need that foundational trust in the infrastructure beyond making sure from a software perspective that we have the governance in place for the AI agents or the application itself.
Ian Williamson
>> Absolutely.
Krista Case
>> So, Patrick, you were talking a little bit about kind of integration. And it's a great segue because I know part of this Unleash AI program that's being led by HPE is to support customers with the integration piece of it. So, and I know, again, Patrick, you were just giving some commentary, so maybe I'll start this question with you, see if you have anything else. And then we'll maybe go to Robin and Ian. But what difference does this kind of, partnership and integration make when customers actually look to move their AI into production? Again, maybe any additional commentary?
Patrick Conte
>> Yeah, what Unleash AI does is give you the components of the stack, the stack that has to be delivered on top of the infrastructure. So HPE is delivering the infrastructure, they're delivering a lot of tools, models, a lot of things that can be used by those customers, but things need to be stacked on top of it. There needs to be orchestration, right? And so they partner with orchestration vendors that we've also partnered with. They partnered with model vendors, model builders, frontier model builders. We also have partnered with those guys. And so all parts of the stack and the security layer includes more than just confidential computing. It typically includes other parts of the zero trust spectrum, right? You know, endpoint or whatever. So the CrowdStrike of the world and others are part of the program. Those are also partners. And so what has to happen is you have to have integration up and down that stack to deliver to a customer a trusted solution. And I think that's what Robin and her team are doing, is building that, building a collection of capabilities that work together to create the stack or the stacks as customers need to deploy them. Did I get that right, Robin?
Robin Braun
>> You did. You did.
Krista Case
>> So, yes. Robin, any other commentary around Unleash AI and this concept of bringing these integrated solutions to bear for customers, not only to speed that adoption process, but also to make sure that that foundation is trusted.>> And I think it's— it really is my privilege to be able to lead this program. It's so much fun getting to work with partners such as Pat and Ian and build out this truly like innovation ecosystem and toolbox of being able to bring to Pat's point that entire stack, that entire solution, to be able to really answer the customer's challenges and how they're moving into production and scaling production. One of the things we've done is we've built Private Cloud AI in conjunction with NVIDIA, where we've already built out and integrated the AI stack, which is a fantastic starting point. You know, a number of customers have people who have managed VMware, and suddenly you're handing them Kubernetes and saying, good luck. And that, that's not fast. It's a little different.
Krista Case
>> Different worlds.>> Different worlds. So we've really put a lot of engineering focus and partnership in with HPE and NVIDIA working to create Private Cloud AI. And so then that AI stack is lifecycle managed over the course of that infrastructure. And so there's that huge simplification. But then to Pat's point, being able to build out with Unleash AI these integrated solutions on top that we go through, we validate, we test, we make sure we have the recipe for how to make this easy for our customers. And then of course, making sure that we're focusing on things like AI governance and those pieces that can help bring that confidence into expanding out into production.
Krista Case
>> Absolutely. And Ian, any commentary from you?
Ian Williamson
>> Yeah, on the infrastructure side, our biggest selling point to customers is the breadth with which we can go discover data. We want to look for all your unstructured, structured, semi-structured data, whether it's in the cloud, it's on-prem. We have a lot of customers who have air-gapped environments that are run on-prem and with infrastructure. So, you know, the relationship we have with HPE and Fortanix and kind of that integrated stack is critical to us differentiating in the market. We're not just looking at public cloud environments. We're looking at all the environments. And our platform is an open, you know, API-driven platform. We connect to over 220 data sources. So yeah, that connection with partners like this are very, very important to us.
Krista Case
>> Absolutely. So we like to make things very actionable for our audience. So as we start to close the segment, I'd like to pose a question to all three of you, which is if you were talking with a practitioner and they're feeling overwhelmed about where to start with establishing this AI governance, what might be your top recommendation for them to start with? So maybe we'll start with Robin.>> I would say that if I'm talking with a practitioner and, you know, how to get started with AI governance, it's first off, take a breath. We've been doing governance from an IT perspective and an infrastructure perspective for a long time. There's some new words, there's new things we have to worry about. We have to worry about the speed at which AI changes and the difference that that brings. But a lot of this thinking isn't necessarily new. It's just at a different scale and at a different level. So, first, take a breath and then work with trusted partners such as Fortanix, BigID, and of course HPE, who can— maybe we can help make it simpler and a little more approachable so that you don't have to go out and try to wire everything together yourself and learn it the hard way, but that we've already done a lot of that heavy lifting so that you can start to go through and understand where are the benefits and then where are things where your company may do something specific or unique and where we need to assist and how you might want to think about it and support that journey. And I think the big thing probably from all three of us is, we are here to support somebody's journey in doing it. And our goal is just to help make them successful in moving to production faster.
Krista Case
>> Absolutely. Ian, any thoughts from you?
Ian Williamson
>> Yeah, I'll keep it kind of short and succinct and really just say, we recommend companies that are evaluating this issue of looking at their data and taking control of their data to run an assessment, and we can allow them to use our software at no cost. We have partners, I think every partner works with HPE, and most of our partners work with Fortanix, so getting a partner, whether it's one of the big advisory firms, we work with all the big global system integrators, or a lot of the channel partners here at Black Hat, will go in and just run an assessment and kind of come back and give you a good idea of where you stand and, where the program needs to be built, which is around people, process, and technology. And that's a good way to, I think to Robin's point, to take a breath and get started in a really kind of well-rounded way with an assessment.
Krista Case
>> Absolutely. Patrick?
Patrick Conte
>> If I were going to be a tree, I'd be a mighty oak. Oh, that wasn't the question. If I were going to make recommendations to a customer that wanted to get started, I would— my recommendation would be don't be afraid to pilot. Don't be afraid to pilot on-premises. Don't be afraid to use the infrastructure that's here and that's modern, that's being built out of NVIDIA GPUs and being built out of CPUs by the leading CPU vendors and being put together by HPE. I would tell them that they don't need to go through the huge amount of work to try to build their own guardrails. That guardrails, guardrail and guardrail technology is actually in the toolkits that, for example, the Private Cloud AI, the toolkit that's part of that stack has the ability to build guardrails there. You don't have to go and get 4 or 5 startup companies to stitch their stuff together in something that can't even be supported because it's not standard. So, that would be my recommendation. I think a lot of companies, government agencies, and others are looking at how do I get started? Find an area, you want to get a model, and you want to get started because you don't want to be left behind and you're going to need to use this technology. It's absolutely there. We're seeing a lot of rehoming coming back on-premises because customers want the model to be close to the data. And a lot of times that data can't go anyplace else. If it's banks, if it's, let's say security agencies or whatever the case may be, or healthcare. So that would be my recommendation is get started, do the pilot.
Krista Case
>> Take the first step, right?
Robin Braun
>> Yep.
Krista Case
>> Yep. I think that's a great comment to leave on. So Robin, Ian, Patrick, thank you so much for joining. Really appreciate it.
Patrick Conte
>> Thank you.
Krista Case
>> Thank you. Thank you. And stay tuned. We'll be back in just a little bit here at theCUBE with more of our ongoing coverage of Black Hat 2026. Thanks so much.