Conference Presentation, Fireside Chat, Product Demonstration
Running Secure Agents on Multi-Tenant Sovereign AI Infrastructure | Protopia AI x HPE | RAISE 2026
Market Challenge & Economic Friction
- Core Problem: Sovereign AI providers, neoclouds, and enterprise IT departments face friction when attempting to run sensitive agentic workflows on shared multi-tenant infrastructure without compromising trust or economics.
- Data Sensitivity: Agentic workflows involve continuous exchange of business context (source code, documentations, tool outputs, PII), which is decrypted into plain text upon ingress to AI factories, exposing it in logs, observability pipelines, and internal network traffic.
- Utilization vs. Isolation: Traditional hardware isolation (carve-outs) to ensure security results in severe GPU underutilization; small tenants cannot fill dedicated hardware, creating an ROI problem where supply exceeds demand.
- Operational Reality: Operators report a supply problem more than a demand problem; oversubscription of compute to satisfy privacy via isolation leads to lost revenue from compute that could have been sold to other entities.
- Workload Shift: Customer use cases are shifting from single-request GenAI to multi-step agentic workflows, requiring endpoints to handle repetitive requests carrying real business data.
Protopia AI Solution: Stained Glass Transform (SGT)
- Mechanism: SGT transforms raw data representations into a randomized stochastic form within the data owner's trust zone before data leaves for the AI factory.
- One-Way Conversion: The transformation is non-reversible (no keys involved), ensuring the factory processes only randomized representations while the model can still natively understand and respond.
- Exposure Elimination: This approach removes the need for physical isolation by ensuring data exists as "gibberish" (randomized text or images) if leaked on the factory's operational surfaces.
- Model Agnostic Deployment: The transform is a containerized neural network trained specifically for the target model (e.g., Nemotron Omni), allowing the underlying model to remain unchanged.
- Performance: Unlike homomorphic encryption, the learned stochasticity enables inference at near-baseline latency with minimal interactivity loss.
- Service Integration: HPE AI Services and Protopia offer joint support to train SGTs and integrate them at both the customer application side (ingress) and the AI factory (inference).
Agentic Workflow Integration: SafeClaw
- Secure Context: Addresses the gap between secure agent workspaces (e.g., NVIDIA OpenShell) and the actual transmission of sensitive tokens to the AI factory.
- Subagent Architecture: Protopia SafeClaw functions as a subagent within any harness, identifying sensitive requests based on policy.
- Transformation Pipeline: SafeClaw intercepts sensitive requests and applies the specific SGT for that model before transmission, preventing plain text exposure to the factory.
- Visualized Transformation: Demonstrated on Nemotron Omni, the system transforms entire visual scenes and text prompts into randomized representations; the model processes the randomized input to generate accurate responses visible only to the data owner.
Business Impact & Forward-Looking Statements
- Revenue Uplift: Operators can capture workloads serving sensitive information that were previously excluded due to privacy constraints, generating significant ROI uplift.
- Throughput Scalability: Moving from a baseline of non-sensitive or isolated workloads to a shared, transformed sensitive model allows for hundreds of times larger factory throughput.
- Market Momentum: Conversations with sovereign providers and neoclouds have been ongoing for six to seven months, with active engagement at recent events like HPE Discovery and NVIDIA GTC Taipei.
- Next Steps: Operators are encouraged to visit the Protopia booth or schedule meetings to discuss training SGTs for their specific models and integration strategies.