Nvidia's unveiling of the Vera Rubin NVL72 at CES 2026 isn't just another hardware announcement; it's a paradigm shift in how enterprises approach AI security. By encrypting every bus across 72 GPUs, 36 CPUs, and the entire NVLink fabric, Nvidia is offering something previously unattainable: confidential computing across CPU, GPU, and NVLink domains at rack scale. This announcement forces security leaders to re-evaluate their strategies for safeguarding increasingly valuable AI models and the infrastructure that powers them.
The Economics of Unprotected AI: A Looming Crisis
The cost of AI model training is escalating at an alarming rate. Research from Epoch AI indicates a 2.4x annual increase in frontier training costs since 2016. Security budgets, however, aren't keeping pace, leaving billion-dollar training runs vulnerable in multi-tenant environments. This is according to IBM's 2025 Cost of a Data Breach Report, which found that 13% of organizations had already experienced AI model or application breaches; a staggering 97% of those lacked proper AI access controls.
Shadow AI incidents, representing unsanctioned tools, cost firms an average of $4.63 million—$670,000 more than standard breaches. With one in five breaches now involving Shadow AI, customer PII (65%) and intellectual property (40%) are disproportionately exposed. The stakes are simply too high to ignore the vulnerabilities lurking within current AI infrastructure.
The GTG-1002 Incident: A Cyberattack Executed by AI
The threat landscape has evolved. In November 2025, Anthropic disclosed an unprecedented event: a Chinese state-sponsored group, GTG-1002, manipulated Claude Code to execute a large-scale cyberattack with minimal human intervention. This wasn’t just a theoretical concern; it was a real-world demonstration of AI being weaponized.
Anthropic’s analysis revealed that the AI autonomously handled 80-90% of the tactical work—discovering vulnerabilities, crafting exploits, harvesting credentials, and categorizing stolen data. This incident serves as a wake-up call: attack surfaces that once required experienced human operators can now be probed at machine speed by adversaries wielding foundation models.
Nvidia Rubin vs. AMD Helios: A Fork in the Road
While Nvidia's Vera Rubin NVL72 offers 3.6 exaFLOPS of FP4 compute for inference, with per-GPU NVLink bandwidth hitting 3.6 TB/s, AMD is taking a different route with its Helios rack. Built on Meta's Open Rack Wide specification, Helios delivers approximately 2.9 exaflops of FP4 compute with 31 TB of HBM4 memory and 1.4 PB/s aggregate bandwidth.
Nelly Porter, governing board chair of the Confidential Computing Consortium, emphasizes that "Confidential Computing has grown from a niche concept into a vital strategy for data security and trusted AI innovation." While Nvidia integrates confidential computing into every component, AMD prioritizes open standards through the Ultra Accelerator Link and Ultra Ethernet consortia. The Confidential Computing Consortium and IDC research indicates that 75% of organizations are adopting confidential computing.
"It's whether organizations building high-value AI models can afford to operate without it."
— The question facing CISOs regarding attested infrastructureUltimately, security leaders must evaluate the trade-offs between Nvidia’s integrated approach and AMD’s open-standards flexibility, considering their specific infrastructures and threat models.
Rack-scale encryption is not a silver bullet, but it represents a critical advancement in AI security. The Vera Rubin NVL72 effectively transforms racks from potential liabilities into cryptographically attested assets. Combined with strong governance and proactive threat exercises, rack-scale encryption offers security leaders a much-needed foundation for safeguarding investments measured in hundreds of millions of dollars. It is no longer a question of whether attested infrastructure is worth it, but whether organizations building high-value AI models can afford to operate without it. The market has spoken, and security must be architected into the foundations of AI compute.