AI processor with a broken chain in a dark data center, symbolizing hardware limitations and infrastructure bottlenecks.
Article Icon
Allyson Klein
@
TechArena
Sep 4, 2026

The Chip-to-Cloud Chain of Trust AI Infrastructure Still Needs

Modern AI infrastructure runs on components pulled from dozens of vendors, and each arrives with its own silicon, its own firmware and its own idea of what security should look like. That patchwork is the problem I set out to unpack on the latest episode of “The Control Plane,” an AMI-sponsored TechArena podcast. I sat down with Alex Williams, founder of The New Stack, and Stefano Righi, security and industry advisor at AMI, a Lattice company. We discussed what’s needed to trust a chip nobody can fully see inside.

A Familiar Fracture

Alex told us that elements of our conversation felt familiar. He spent a decade watching cloud infrastructure mature after founding The New Stack in 2014, when early cloud teams treated workloads as interchangeable since so little real state touched the infrastructure itself. At a recent KubeCon in Atlanta, Alex got an idea of the challenges AI infrastructure presents while sitting in on a session with a senior Uber engineer who described standing up a multicloud GPU environment.

“They had to configure every GPU from every different vendor,” Alex said. “And that became a nightmare for them. And it still is.”

The Chip as a Black Box

Alex drew a direct line to software’s own fragmentation problem three decades earlier. When the 1990s produced a dozen competing versions of Unix, the industry converged on Linux kernel. By 2014, containers ushered in the age of Kubernetes and open source tools such as Cilium, eBPF and Open Policy Agent emerged to manage workloads. All were built on the Linux kernel. No comparable tool ecosystem exists yet for AI hardware, he said. For example, Alex cited “the attestation issue,” one that becomes paramount when a chip does not get verified. The instinct is to blame a hallucination, he said, when the problem could be caught early with early detection of rogue behaviors.

‘Nobody Can Be the Cop of Himself’

Stefano said that modern AI systems assemble components from vendors that each bring their own silicon, firmware, update process and security model, and that variety is what creates the visibility gaps Alex had described. The industry’s identity conversation used to stop at the user logging into a system, Stefano said, but machines now need an identity of their own. His prescription is a genuine root of trust: hardware that carries a cryptographic identity, supports secure boot, and can produce its own measurement and attestation, all resting on a foundation that can be independently verified.

“We used to say that nobody can be the cop of himself,” he said, adding that an open, community-verified standard such as Caliptra, the Open Compute Project-backed silicon root of trust project, is the shared foundation the ecosystem needs.

Firmware Becomes the Control Plane

Alex said that firmware is already the closest thing the industry has to a software control plane, a shift he has watched play out inside the platform engineering teams that emerged once DevOps proved necessary but not sufficient on its own. He said those teams turned their attention to the cloud and to firmware, the layer that orchestrates data movement, manages power and configures interconnects, and that firmware’s reach has extended past traditional x86 and ARM CPUs over the past two or three years. Stefano tied that shift back to AMI’s own history: four decades of boot firmware experience now feed a combined offering spanning the data plane, control plane and security plane, aimed at building the chip-to-cloud chain of trust.

The TechArena Take

Our conversation made the case for treating chip trust as a shared industry problem rather than a single company’s responsibility. The language of cloud native computing is already finding a second life in hardware: Pets vs. cattle, control planes, attestation and identity are concepts platform teams once fought to standardize, and now they have to relearn them one layer down, closer to the metal, where data, Alex said, has been promoted from second-class citizen to first-class citizen with AI infrastructure. Stefano’s argument that no single vendor can police its own hardware reframes chip trust as a problem the industry must solve through open standards, not a feature any single company can attach and sell. The vendors that get there first will be the ones already fluent in both worlds, which is exactly the bet AMI is making with decades of firmware history behind it.

To hear the full conversation, listen to the podcast episode or visit AMI.com.

Subscribe to Our Newsletter

Read the latest in the world of AI, data center, and edge innovation.