01 Quantum

Resources

← Back to Blog
June 5 2026 (2) blog image

Fri Jun 05 2026

Why Encrypt the AI Itself?

Organisations have spent years building walls around their AI systems — and the systems are still exposed, because the one thing left unencrypted is the model itself. A recent presentation by Tyson Macaulay, Deputy Director of Carleton University’s National Centre for Critical Infrastructure Protection, Security and Resilience (NC-CIPSeR), poses a question most enterprises have never seriously asked: instead of endlessly fortifying the systems and processes around an AI model, why not encrypt the model and its data directly? The answer he arrives at — cost and completeness — reframes how AI security should work, and it points squarely at fully homomorphic encryption (FHE) as the tool that makes it possible.

The Walls Have Gaps

Conventional AI security tries to protect the model by hardening everything surrounding it: the network, the access controls, the infrastructure. The problem is that the model and the data flowing through it remain in plaintext at the point of use — and that is exactly where the most damaging attacks land. The NC-CIPSeR material identifies three that perimeter defences struggle to close:

  • Eavesdropping (user privacy attack). Prompts are visible to platform hosts, model owners, system administrators — and anyone who breaches them. Every sensitive query is a sensitive disclosure.
  • Model extraction attack. An attacker derives a model’s “guardrail” safeguards and routes around them, bypassing safety controls entirely.
  • Model inversion attack. An attacker reconstructs the original training data — including personally identifiable information, trade secrets, and classified material — from a deployed model.

The common thread is that none of these requires breaking through the wall. They exploit the fact that, somewhere inside it, the data and the model are exposed in the clear.

Encrypt the Thing You’re Protecting

Fully homomorphic encryption changes the equation by allowing computation to be performed directly on encrypted data. A user sends an encrypted prompt; the AI computes on the ciphertext without ever decrypting it; the user receives an encrypted answer that only they can read. The model never sees plaintext, the platform host never sees plaintext, and an attacker who compromises the environment finds nothing usable.

This is why the NC-CIPSeR analysis frames FHE as a matter of completeness rather than just another layer. Perimeter hardening reduces the probability of exposure; encrypting the data and model end-to-end removes the exposure itself. And it is a matter of cost: rather than spending indefinitely to fortify every surrounding system against every possible path in, organisations protect the asset directly and close the whole class of attacks at once.

Crucially, FHE is also a form of quantum-safe cryptography. The lattice-based mathematics underpinning it is built to resist attack by quantum computers — which means encrypting AI workloads this way addresses both today’s exposure and the harvest-now-decrypt-later threat to the long-lived, sensitive data that AI systems ingest.

From Theory to Production

FHE is no longer the laboratory curiosity it was when Craig Gentry first proved arbitrary computation on encrypted data was possible in 2009. Successive breakthroughs — the BGV and BFV schemes, and the CKKS scheme that enabled efficient arithmetic for machine learning and AI inference — have improved performance by six to eight orders of magnitude. FHE inference is now increasingly practical for real machine-learning workloads.

The NC-CIPSeR material puts numbers to it: in a demonstrated FHE-protected inference filter, the encrypted pipeline ran roughly six times slower than plaintext — a measurable overhead, but a workable one for high-value workloads, and one that continues to shrink as both FHE techniques and model architectures are optimised. Encrypted AI has moved from “someday” to “deployable today” for the workloads that need it most.

01 Quantum: Hardened AI in Practice

This is precisely the problem 01 Quantum’s Quantum AI Wrapper (QAW) is built to solve. QAW uses FHE to bring artificial intelligence workloads into a quantum-safe operating environment — protecting both the model and the sensitive data it processes, so that prompts, training data, and model internals stay encrypted end-to-end, even during computation. The result is AI that is hardened against eavesdropping, extraction, and inversion attacks at the source, rather than guarded by walls that attacks are designed to slip past.

01 Quantum is demonstrating exactly this approach to Hardened AI in partnership with Carleton University, turning the attack scenarios above into working mitigations rather than theoretical concerns. The same IronCAP™ foundation that underpins this work — engineered to align with the finalised NIST post-quantum standards (FIPS 203, 204, and 205) — also powers 01 Quantum’s Quantum Crypto Wrapper (QCW) and Quantum DeFi Wrapper (QDW), which extend quantum-safe protection to digital assets across Bitcoin, Ethereum, Solana, and Hyperliquid.

These are working demonstrations of readiness, available now — reinforced by the counsel of strategic advisor Dr. Edoardo Persichetti, a NIST post-quantum standardisation contributor and co-author of the HQC algorithm.

The Question Worth Asking

As AI moves into the core of telecommunications, finance, intelligence, and critical infrastructure, the volume of sensitive data passing through these models — and the consequences of exposing it — only grow. The NC-CIPSeR analysis makes the case plainly: building higher walls around an exposed model is an endless, incomplete, and expensive strategy. Encrypting the model and its data directly is the one that actually closes the gap.

The most valuable thing in your AI system is the one part still running in the clear — and the quantum-safe technology to encrypt it, for both your AI workloads and your digital assets, exists today.

LEARN MORE ABOUT 01 QUANTUM PRODUCTS
Live Chat