AI workloads are moving faster than the security tools designed to protect them. A key reason is the rise of AI accelerators: specialized chips that accelerate the exact computations AI systems need, distinct from standard CPUs and GPUs. At the same time, a new class of infrastructure—often called neo-clouds—has emerged to deliver AI training and high-throughput inference with low latency and massive parallelism.
Yet this shift creates a problem. When accelerators sit underneath the services people rely on, security teams may lose visibility into what happens inside that silicon layer. That gap can turn a compromise into a silent, hard-to-detect supply chain risk.
This article explains what drives these AI accelerator security blind spots, why traditional monitoring struggles, and how Stealthium is attempting to close the visibility gap using telemetry-based detection.
Why AI accelerators change the security picture
Accelerators are purpose-built hardware that offload and speed up the workloads required for AI. In practice, that means more of the critical processing moves away from the CPU-centric environment where many security controls and monitoring frameworks historically developed.
Common accelerator producers include Tenstorrent, Groq, Cerebras, Graphcore, and Google. Regardless of the vendor, the pattern is similar: security workflows built around CPU-centric operating systems may not keep pace with the accelerator layer’s internal behavior and performance data.
The consequence is visibility loss. Some cybersecurity approaches lack insight into high-speed memory used by accelerators and cannot readily determine what is happening at accelerator runtime. When defenders can’t see inside the relevant layer, they also can’t easily validate whether the system is behaving safely.
Neo-clouds bring AI-first infrastructure—and new risk
Neo-clouds are a newer infrastructure model that differs from hyperscalers such as Azure, Google Cloud, and AWS. They are AI-first, often built around accelerators, and positioned for customers that need AI training, inference, and model-building services.
In many deployments, neo-clouds support:
- Massive parallelism for large training workloads
- Low-latency edge-style compute for responsive AI services
- Flexible deployment to support different AI pipelines
- Cheaper or more predictable economics compared with traditional setups
Because accelerators help achieve high throughput and fast response times, neo-clouds are attractive for operations like running high-volume inference. For example, an organization building in-house chatbots may rely on accelerator-optimized, low-latency hardware to deliver rapid answers.
However, the same accelerator-centric design that enables performance can also complicate defense. If a neo-cloud is compromised without reliable detection at the accelerator layer, neither providers nor customers may notice the event quickly—or at all.
Security blind spots: “absence of proof” is not proof
A critical theme in AI accelerator security is that monitoring gaps can lead to false confidence. When telemetry is missing—or when tools can’t interpret what’s happening inside specialized hardware—organizations may assume nothing is wrong simply because they cannot observe a specific threat.
The risk isn’t hypothetical. If an attacker stealthily compromises part of a neo-cloud used by many customers, the impact may resemble a supply chain problem: attackers can potentially affect multiple downstream teams relying on the same underlying environment.
In this situation, defenders face a difficult paradox. Even if the compromise is real, lack of visibility may prevent detection, and the system may continue to function in ways that look normal from the outside.
Supply chain impact on AI development
Supply chain attacks have been a recurring issue in software for years. But AI accelerator environments add new stakes because attackers may target not only the software stack but also the behavior of models or the integrity of AI outputs.
The source of concern is that compromising a neo-cloud node could allow an attacker to gain access to a customer’s AI weights. From there, attackers might poison or corrupt the model’s behavior without immediate detection.
Potential outcomes described include:
- Changing model behavior so outputs align with an attacker’s agenda
- Extortion by threatening the integrity of AI services
- Cryptomining using shared or compromised compute environments
- Establishing a new operational base inside the compromised infrastructure
The concern is amplified for organizations doing AI development on neo-cloud platforms. The more foundational the compute environment is to training and inference, the more impactful a hidden compromise could be.
Why traditional security tools struggle
Traditional cybersecurity approaches were largely developed around the operating assumptions of CPU-centric systems. Those controls often focus on environments where defenders can inspect system behavior, observe logs, and correlate events with known patterns.
In contrast, accelerator-driven infrastructure introduces layers that are harder to observe with the same methods. Specifically, defenders may lack ready visibility into accelerator high-speed video memory and other internal dynamics that matter for runtime integrity.
As a result, current security solutions may not be able to detect what is happening within neo-cloud hardware in real time. And without real-time insight, responding to subtle signs of compromise becomes far more challenging.
How Stealthium approaches AI accelerator security
Stealthium is positioned to tackle these visibility gaps. While it cannot directly “see into” the accelerators in the neo-cloud hardware, it uses an agent deployed in the customer’s environment. The agent is trained to detect subtle hints that indicate compromise.
The core idea is straightforward: when you can’t inspect the hardware directly, you look at the signals available. In this case, Stealthium deploys an agent that searches telemetry coming from the neo-cloud.
Importantly, the company frames the approach as specialized rather than entirely new. The technology concept—using agents and analyzing signals—is known, but the focus on accelerator-runtime hints and the continuously updated detection approach makes it distinct for this threat model.
Example: virtualization abuse and cross-tenant leakage
The potential consequences of an accelerator-layer compromise can be illustrated by past exploitation patterns. The source mentions Januscape as a relevant example: it exploited a vulnerability in nested virtualization that allowed an attacker to offer, or sell, an environment to a third party.
If a similar exploit were possible in a neo-cloud context, it could lead to cross-tenant leakage. That means a third party might gain insights and possibly access to legitimate in-house chatbot data or related assets.
Stealthium’s role in this scenario would be to detect subtle hints in neo-cloud telemetry that suggest this type of compromise—or other accelerator-related attack patterns.
Who benefits from these attacks—and why they may grow
Supply chain compromise attempts already occur across digital ecosystems. The expectation described is that incidence could increase because the payoff is attractive.
Attackers may include financially motivated cybercriminals and nation-state actors seeking intelligence or influence. If attackers can compromise an accelerator-backed neo-cloud node and then access model weights or influence model output behavior, the value of the access rises significantly.
The article also highlights the strategic risk: hypothetically, if advanced systems like ChatGPT or Gemini were influenced or changed at scale, that could shape information flows and outcomes far beyond individual targets.
What this means for security teams
The broader lesson for organizations using AI-first infrastructure is that AI accelerator security requires different thinking than classic CPU-focused monitoring. It’s not enough to rely on controls that were designed for a different runtime environment, especially when defenders cannot confirm what happens inside the accelerator layer.
Teams should evaluate whether their security and observability practices cover the infrastructure components that actually execute the AI workloads. Where direct visibility is not available, the goal becomes building detection around available telemetry and training signals to catch subtle compromise indicators.
Stealthium represents an early example of security companies shifting toward accelerator-aware runtime observability. Instead of looking into the hardware itself, the approach centers on analyzing telemetry with a specialized agent continuously updated to recognize potential compromise patterns.
Conclusion
As accelerators and neo-clouds become standard for AI training and high-throughput inference, new blind spots emerge in the security stack. Traditional tools were built for CPU-centric systems and may not provide the visibility needed to detect accelerator-layer compromise. That invisibility can enable stealthy supply chain attacks that affect customers without clear warning.
By deploying an agent that analyzes neo-cloud telemetry for subtle hints of compromise, Stealthium aims to improve observability in AI accelerated runtime. In a world where absence of evidence doesn’t equal evidence of absence, this kind of telemetry-driven detection may become essential for organizations that depend on accelerator-backed infrastructure.
