Brands
Latest top stories
Start-ups
Technology

AI agents need identities. Can those identities be anchored in silicon?

14 September 2026

 

A robot in a warehouse receives an instruction to move a pallet. In a laboratory, an AI agent tells an automated system to mix two chemicals. Somewhere else, two autonomous drones exchange their positions in the air. Before any of those machines act, it must be established who issued the instruction.

Dutch startup Fortaegis Technologies believes that proof should begin inside the silicon.

The company has raised an oversubscribed $50 million Series A, led by Singapore-based Serendipity Capital, to move its secure-computing architecture from technical validation towards commercial production.

Its proposition sounds almost biological: give every chip its own physical fingerprint.

 

What is a hardware root of trust?

 

Computers already perform numerous security checks. They verify passwords, inspect digital signatures and determine whether software has been altered. Yet every chain of checks needs a first link that is assumed to be reliable.

That starting point is known as a root of trust: a protected foundation from which a computer can verify its hardware, software and communications.

It resembles a passport office whose own identity must be established before anyone can trust the passports it issues. Inside a computer, the root of trust can be a protected piece of hardware or firmware that stores cryptographic keys, checks the system during start-up and confirms that approved software is running.

Fortaegis wants to root identity in the physical characteristics of the silicon itself, then extend that trust through firmware and software across large networks of machines.

 

A fingerprint no factory intended to create

 

Semiconductor factories operate at extraordinary precision. They reproduce designs containing billions of microscopic components across wafer after wafer.

Even so, no two chips emerge completely identical.

Minute variations arise during manufacturing. A conducting path may be fractionally wider, a transistor may switch at a subtly different speed or an electrical signal may take slightly longer to cross part of the circuit. These variations are normally too small to affect the chip’s intended function.

They can nevertheless help distinguish one chip from another.

The principle resembles a physical unclonable function, commonly abbreviated to PUF. Such systems measure combinations of manufacturing variations and use the resulting response to establish a distinctive hardware identity. Because the variations were not deliberately programmed and are extremely difficult to reproduce precisely, copying that identity should be much harder than copying a stored password.

It is rather like producing two apparently identical keys and then discovering, under a microscope, that each carries its own landscape of tiny ridges.

Fortaegis says every semiconductor in its architecture incorporates a unique physical identity. Cryptographic keys can be generated when needed rather than sitting permanently in memory, where an attacker might attempt to extract them.

The company is not simply offering a conventional PUF as a standalone component. It describes a broader secure-computing architecture spanning silicon, firmware, cryptography and software. The physical properties of the chip provide the foundation; the rest of the system carries that trust upwards into applications and networks.

 

A chip identity is not an AI agent identity

 

This is where the language requires some care.

A chip, a machine and an AI agent are not the same thing.

A silicon fingerprint may identify a particular chip. That identity can help authenticate the server, robot or vehicle containing it. But an AI agent is software. It may move between computers, use several digital tools, delegate parts of a task to temporary sub-agents and disappear when its work is complete.

Hardware alone cannot establish who authorised that agent, which data it may access or whether its latest decision is sensible.

Those questions still require software identity management, cryptographic certificates, permissions and detailed records of what the agent has done. Hardware-backed attestation can strengthen that system by proving that an agent is running on an approved machine with authorised software.

Suppose an attacker copies an AI agent’s access token and uses it from another server. The token may appear valid. If access also depends on a hardware identity, however, the system can detect that the request is coming from the wrong machine.

Silicon would therefore not become the agent’s complete identity. It would provide the anchor connecting a digital identity to something considerably harder to copy.

That could become valuable as AI agents move from demonstrations into everyday business systems. A large organisation might eventually operate thousands of agents that retrieve confidential information, approve transactions or control equipment. The more freedom those agents receive, the more important it becomes to verify the infrastructure beneath them.

 

Why Fortaegis still has something to prove

 

Existing processors and security modules already protect keys and verify software. Fortaegis must therefore demonstrate more than an interesting use of silicon physics.

Its architecture will need to be sufficiently secure, fast and easy to integrate to persuade semiconductor companies and infrastructure operators to adopt it. That is a formidable commercial test. Chip customers are reluctant to redesign systems around an unproven security technology, particularly when established suppliers already provide hardware roots of trust.

The physical fingerprint must also remain readable as a chip ages and as temperature and voltage change. At the same time, it must remain unpredictable to an attacker. A system that occasionally fails to recognise its own hardware would be secure in roughly the same way as a front door that sometimes refuses to admit its owner.

Moving from laboratory results to manufactured products adds further obstacles. Semiconductor development involves lengthy design cycles, expensive tape-outs and extensive testing. Fortaegis must integrate its architecture with processors, networking hardware and existing software without creating unacceptable delays or costs.

This helps explain the size of the investment. A $50 million Series A is not merely funding faster sales. It supports the costly transition from validated technology to repeatable production. Fortaegis plans to begin commercial manufacturing in 2027.

The company has been assembling the industrial network required for that step. Tokyo Electron, one of the world’s largest suppliers of semiconductor-production equipment, invested through its venture arm in 2025. In May 2026, Fortaegis announced a partnership with Dutch manufacturer Prodrive Technologies covering engineering, system integration, industrialisation and manufacturing.

Fortaegis says its technology has been evaluated by national laboratories and organisations including the Netherlands Organisation for Applied Scientific Research, TNO. Its intended markets include defence, space, telecommunications, data centres and advanced manufacturing.

 

Can silicon identity be quantum-safe?

 

Fortaegis also describes its architecture as quantum-safe.

Current quantum computers cannot simply unlock the encryption protecting modern networks. A sufficiently powerful future system, however, could defeat some of the public-key cryptography used to secure digital communications. The concern is serious enough for the US National Institute of Standards and Technology to have finalised its first post-quantum cryptography standards in 2024.

Physical chip identities and post-quantum cryptography address different vulnerabilities. A silicon fingerprint helps determine which device is present. Quantum-resistant algorithms protect the cryptographic exchanges through which that device proves its identity and communicates.

Combining them avoids building a difficult-to-copy hardware identity on top of encryption that may eventually become vulnerable.

“Quantum-safe” does not mean impossible to hack. Software bugs, faulty implementations, supply-chain attacks and careless users do not disappear. Hardware security strengthens the foundations of a system; it does not magically secure everything constructed above them.

 

Sovereign AI begins below the cloud

 

Sovereign AI is generally discussed in terms of where models are trained, where data is stored and which company operates the cloud.

Fortaegis raises a more basic question. Can an organisation genuinely claim control over an AI system if it cannot independently verify the hardware on which that system is running?

Hardware-backed identity could allow companies or governments to confirm that sensitive AI workloads are operating on approved equipment within authorised infrastructure. They would not have to depend entirely on credentials controlled by an external cloud provider.

That does not make the resulting technology purely national. A security architecture designed in the Netherlands may rely on international foundries, Japanese production equipment and components sourced across several continents. Fortaegis itself works across Europe, Asia and the United States.

Technological sovereignty does not necessarily mean making everything at home. It may mean retaining the ability to verify what is running, where it came from and what it is permitted to do.

AI agents will continue to introduce themselves through software. As they gain access to machines and critical systems, however, software credentials may no longer be enough.

The strongest proof of identity could come from much deeper inside.

 

 

Liked this article? You can support our independent journalism via our page on Buy Me a Coffee. It helps keep MoveTheNeedle.news focused on depth, not clicks.

👉 https://buymeacoffee.com/movetheneedle.news