


![]()



The current wave of technology innovation is often described as being driven by AI. While that is true, it is only part of the picture. What is really unfolding is a broader shift in how enterprise technology itself is being designed, deployed, and managed. AI is accelerating this change, but the impact is being felt across the entire stack.
Infrastructure is one of the first areas where this shift is visible. Organizations are no longer operating in neatly defined environments. Instead, they are working across a mix of data centers, cloud platforms, and increasingly, edge locations. Intelligence is moving closer to where data is generated, and decisions are expected to be made in real time. This is forcing a rethink of how systems are built, how workloads are distributed, and how performance is managed.
At the same time, the nature of applications is also evolving. Systems are no longer just processing data, they are beginning to interpret it and act on it. The rise of more autonomous, task-oriented systems is changing how work gets done across functions. This creates clear efficiency gains, but also raises new questions around control, accountability, and oversight.
Security and governance are being reshaped alongside these changes. Traditional models, which were designed for more static environments, are no longer sufficient. With data constantly moving and systems becoming more dynamic, organizations are focusing on continuous visibility, control, and assurance across the lifecycle of applications and data.
Another shift that is becoming increasingly visible is around control and flexibility. As dependence on external platforms grows, so does the need to retain ownership over critical systems and data flows. This is driving interest in hybrid approaches, open ecosystems, and architectures that reduce long-term dependency while still enabling innovation.
Taken together, these trends point to a clear direction. Enterprise technology is no longer a collection of separate systems. It is becoming a more connected, intelligence-driven layer that underpins business operations. For CIOs, the focus is no longer just on adopting new technologies, but on bringing them together in a way that delivers scale, resilience, and control.
RAMAN NARAYAN
Co-Founder & Editor in Chief narayan@leapmediallc.com Mob: +971-55-7802403
Ali Raza Designer
R. Narayan Editor in Chief, CXO DX
SAUMYADEEP HALDER
Co-Founder & MD
saumyadeep@leapmediallc.com Mob: +971-54-4458401
MALLIKA REGO
Co-Founder & Director Client Solutions mallika@leapmediallc.com Mob: +971-50-2489676

From data to cloud and now to AI, sovereignty is being redefined as control shifts toward the intelligence layer.
Apu Pavithran, Founder and CEO of Hexnode, explains why unifying management, security, and identity is critical to building a consistent and scalable Zero Trust framework.
Burcak Soydan, Managing Director for the Middle East at NTT DATA, discusses how the company’s acquisition-led DNA is shaping its Middle East expansion.
Gabriel Bernadett-Shapiro, Distinguished AI Research Scientist at SentinelOne of SentinelOne argues that current LLM evaluations fall short of capturing the complexity of security operations.
Hussam Sidani, VP, MENA at OPSWAT, shares insights on evolving attack patterns, architectural shifts, and the growing importance of proactive defence.
Khalid Aljamed, GM, META at Submer outlines why full-stack AI infrastructure is becoming central to achieving true sovereignty and long-term competitiveness in the AI era.
Patrick Smith, Field CTO EMEA at Everpure, explores how the success of AI initiatives increasingly depends on storage infrastructure that can keep pace with the scale, speed, and energy demands of modern AI workloads.
Craig Sanderson, Principal Cyber Security Strategist at Infoblox examines why National Institute of Standards and Technology’s SP 800-81r3 is forcing a rethink of DNS.
Mohammed Aboul-Magd, VP of Product at SandboxAQ discusses emerging threats including stealth exfiltration, rogue agents, and non-human identity risks.
Mostafa Kabel, CTO, Mindware Group explores the rise of Physical AI and how it is reshaping industries, infrastructure, and the future of human-machine collaboration.
Designed to deliver performance, compliance, and security for Agentic AI applications and help minimize aggregate token costs
Nutanix, a leader in hybrid multicloud computing, announced the Nutanix Agentic AI solution, a full software stack purpose built to help customers accelerate adoption of Agentic AI for business transformation.
With the shift to Agentic AI, enterprise adoption has hit a tipping point where the barrier to success is no longer the model or building individual agents, but the complexity of managing the infrastructure required to securely run thousands of agents at scale. Infrastructure and platform teams need better solutions to build and operate AI factories, and provide shared access to their resources, while maximizing performance, security, and compliance with sovereignty requirements. In addition, data scientists and Agentic AI developers expect easy access to tools and services to run and fine-tune models, build agents, and securely connect them to enterprise data.
“Contrary to AI infrastructure for mod-
el training that was optimized to run ‘one big job,’ production Agentic AI infrastructure needs to handle scale and high rates of change for thousands of AI services, agents, and concurrent users and developers. Nutanix Agentic AI extends our AHV hypervisor, Flow Virtual Networking, Nutanix Kubernetes Platform, and Nutanix Enterprise AI to deliver a cloud operating model to enterprise AI factories, enabling infrastructure and platform teams to simply build, operate, and govern AI factories, while providing Agentic AI developers with the performance and rich set of models and AI platform services they need,” said Thomas Cornely, Executive Vice President of Product Management at Nutanix.
The solution integrates with NVIDIA AI Enterprise at the Agent Builder layer and orchestrates the NVIDIA-certified ecosystem of AI factories for supported configurations. It enables customers with dynamic, multiuser AI environments to build, run,
AVEVA to maximise GPU efficiency and accelerate deployment of AI Factories at speed and scale in collaboration with NVIDIA
AVEVA, a global leader in industrial software, announced a new collaboration with NVIDIA, where they’re integrating their engineering and operations software into the NVIDIA Omniverse DSX Blueprint. Together, the two companies are creating physical and digital modules that can be deployed in large-scale data centres, known as AI Factories. The approach replicates the methods used in engineering, procurement and construction projects. The collaboration draws on AVEVA’s comprehensive portfolio, including the CONNECT industrial intelligence platform and industrial digital twin capabilities. It is projected to accelerate time-to-token for AI Factories, using domain-specific simulations, digital visualisation and collaborative design tools to maximise GPU efficiency and accelerate deployment of AI Factories at speed and scale.
AVEVA’s collaboration sits alongside its strategic partners Schneider Electric and ETAP. Together, they are jointly advancing
the design, simulation, build, operation, and optimisation of the NVIDIA Omniverse DSX Blueprint for AI Factories.
AVEVA is incorporating its solutions into the Omniverse DSX Blueprint, bringing benefits of digital twins to customers at every stage of the AI factory lifecycle. Customers may bring OpenUSD SimReady assets into AVEVA Unified Engineering through a new converter, enabling them to reuse existing assets, design new ones, and leverage high-fidelity SimReady data and environments built on NVIDIA Omniverse libraries.
With a single source of truth from AVEVA Asset Information Management, customers can manage equipment, systems and make changes seamlessly, ensuring alignment from design throughout operations. With AVEVA Process Simulation, customers can model and run simulations of advanced liquid-cooling networks for AI Factories to refine designs and maximise

Cornely
and protect agentic AI applications with a full suite of infrastructure orchestration and security software coupled with AI Platform Services (PaaS) and Models-as-a-Service (MaaS) for data scientists and Agentic AI developers.

Rob McGreevy Chief Product
Officer, AVEVA
cooling efficiency.
Rob McGreevy, Chief Product Officer, AVEVA said, “AVEVA and NVIDIA are creating a new approach to digital twin deployments, founded on domain-specific expertise, pioneering software and operational excellence. Together, our companies are creating this new digital twin at scale, combining SimReady assets, NVIDIA hardware, and IT and OT data-driven insights to design, build and AI-optimise the intelligent industries of the future.”
Collaboration connects data discovery and classification with runtime protection and continuous assurance to help organizations securely operationalize AI
F5 , a global leader in delivering and securing every app and API, and Forcepoint, a global leader in data security, has announced a new alliance to help enterprises secure AI across its lifecycle—from foundational data discovery and classification through runtime protection and continuous assurance.
As organizations rapidly deploy AI across copilots, assistants, and automated workflows, security practices are struggling to keep pace. Many enterprises face complex challenges in identifying where sensitive data resides, how it flows through AI systems, and the potential risks introduced during production. While data governance, application security, and runtime protections remain crucial, they commonly operate in silos, creating gaps between security policy and AI behavior in practice.
To solve this problem, Forcepoint’s AI-native Data Security Posture Management (DSPM) data discovery and classification
capabilities combine with F5’s red teaming and AI guardrails functionality in the F5 Application Delivery and Security Platform (ADSP). This approach provides runtime protections for AI applications, APIs, models, and agents to help organizations operationalize AI safely while maintaining control and visibility over sensitive enterprise data.
The combined capabilities help security teams identify and address data vulnerabilities in real time, prioritize AI use cases based on risk, enforce runtime controls over AI interactions, and monitor systems for misuse or abnormal behavior. Continuous telemetry and policy validation provide ongoing assurance that AI systems are operating securely and in line with enterprise governance requirements.
John Maddison, Chief Marketing Officer, F5 said, “By combining Forcepoint’s deep data intelligence and contextual awareness with F5’s advanced application security

John Maddison Chief Marketing Officer, F5
and runtime protections, organizations eliminate operational security gaps with unmatched confidence and control in their AI operations. As AI’s threat surface continues to expand, the combined power of DSPM technologies with F5’s AI Red Team and AI Guardrails equips enterprises with proactive tools to securely scale and govern AI at every stage of its lifecycle.”
New capabilities in the BeyondTrust Pathfinder Platform secure AI agent coworkers on endpoints and AI agent workloads across cloud infrastructure and SaaS platforms
BeyondTrust, a global leader in privilege-centric identity security protecting Paths to Privilege, has announced expanded capabilities across its Pathfinder Platform that deliver the industry’s first unified approach to securing AI agent coworkers that operate alongside users and autonomous AI workloads executing at scale across cloud and SaaS environments. The announcement is backed by new threat research from BeyondTrust Phantom Labs, which found that the majority of enterprises are running shadow AI agents with privileged access that security teams cannot see or govern.
AI agents are no longer experimental. They are production workloads, initiating API calls, using credentials, deploying code, and accessing sensitive data. Many are deployed in minutes on low-code platforms, often with privileges that rival or exceed those of human administrators. In many enterprise environments, machine and AI identities already far outweigh hu-
man identities, dramatically expanding the privileged-identity attack surface. Yet most organizations lack any visibility into how many AI agents are operating in their environments, what those agents can access, or what happens when one of those agents is compromised. These trends underscore the need for a unified approach to securing AI, human, and machine identities across environments.
“Agentic AI is not an isolated problem. It’s a subset of the broader non-human identity landscape,” said Marc Maiffret, Chief Technology Officer at BeyondTrust. “Organizations cannot secure agentic identities in a silo. These agents are interconnected with human identities, machine accounts, secrets, and entitlements across every environment. You need a platform that sees and secures the full spectrum, and that’s what Pathfinder delivers. Simply put, to get agentic AI right, you need to get privileged identity right.”

Marc Maiffret CTO, BeyondTrust
Unlike most AI security solutions, the Pathfinder Platform addresses both sides of the agentic AI challenge, providing defense for AI coworkers and local agents on endpoints, as well as for AI workloads running autonomously across cloud infrastructure and SaaS platforms.
Under the agreement, Mindware will distribute SUSE’s portfolio, including SUSE Linux, SUSE Cloud Native as well as SUSE Edge and SUSE AI solutions
Mindware, a leading value-added distributor (VAD) in the Middle East and Africa, has signed a strategic distribution partnership with SUSE, a global leader in enterprise open source solutions. The agreement aims to accelerate the adoption of SUSE’s enterprise portfolio across the Middle East and North Africa (MENA), supporting organizations seeking secure, flexible, and sovereign IT infrastructure.
Under the partnership, Mindware will distribute SUSE’s portfolio, including SUSE Linux, SUSE Cloud Native as well as SUSE Edge and SUSE AI solutions. The collaboration will focus on channel recruitment and enablement, joint go-to-market initiatives, demand generation, and comprehensive technical support.
The partnership comes as organizations across the region reassess their infrastructure strategies in response to rising virtualization costs, evolving regulatory requirements, and increasing demand for

digital sovereignty. By combining SUSE’s enterprise-grade open source technologies with Mindware’s regional expertise and partner ecosystem, the companies aim to deliver cost-effective and scalable infrastructure solutions across key industry verticals.
Commenting on the announcement, Nicholas Argyrides, Vice President Gulf & East Africa at Mindware said: “Partnering with SUSE strengthens our infrastructure portfolio with enterprise-grade, vendor-neutral solutions. As organizations modernize their environments and explore alternatives to traditional virtualization, SUSE enables our partners to address these needs confidently. Together, we are committed to equipping the channel with the tools, expertise, and support required to drive digital transformation across Middle East & North Africa.”
IFS.ai Logistics unites AI-driven planning, zero-touch execution, freight audit, and network optimization into a single closed operational loop
IFS, a leading provider of Industrial AI software, announced the launch of IFS.ai Logistics, an AI-powered logistics intelligence platform purpose-built for enterprises operating complex, multi-carrier, multi-region transport networks. The new solution extends Industrial AI into the physical movement of materials and goods – the operational heartbeat of industrial enterprises worldwide. IFS already manages $2.4 trillion in critical assets for its customers; IFS.ai Logistics adds the logistics intelligence layer that connects operational decisions to financial outcomes across the full supply chain.
Building beyond 7bridges technology, which was acquired in 2025, IFS.ai Logistics delivers a single closed operational loop spanning transport planning, automated execution, freight audit, cost governance, and continuous network optimization. It operates within IFS Cloud, alongside Enterprise Asset Management, Field Service Management, Enterprise Resource Planning and Supply Chain Management and is compos-
able with third-party platforms, reducing adoption friction for enterprises managing complex multi-system environments.
IFS.ai Logistics addresses this directly across four capability areas. AI-driven transport planning and carrier selection replace manual decision-making with intelligence-led optimization across modes, legs, and trade lanes. Zero-touch automated execution eliminates booking errors and operational overhead with real-time shipment visibility and intelligent exception handling. A finance-grade freight audit engine validates every invoice at line-item level, applying automated GL coding, surfacing billing discrepancies, and managing dispute workflows to recover leakage. In addition, a network intelligence and simulation layer enables continuous what-if scenario modelling, from carrier strategy and cost forecasting to emissions planning and procurement consolidation.
Philip Ashton, President, IFS.ai Logistics, commented, “Over the last five years we
Mindware will provide value-added services including architectural design, proof-of-concept (PoC) support, marketing-as-a-service, specialized logistics, and dedicated product management to ensure strong vendor-partner alignment.
“We are excited to partner with Mindware to expand enterprise open source adoption across the Middle East and North Africa,” said Ismail Ibrahim, Sales Director & General Manager for CEMEA at SUSE. “Together, we will empower customers with secure, scalable, and cost-effective infrastructure solutions.’’

Philip Ashton President, IFS.ai Logistics
have seen that when AI is applied at scale, directly inside specific industry applications, like enterprise logistics operations, customers can capture value within weeks – they begin to protect margin, improve service reliability, and increase operational agility. With IFS.ai Logistics, this is exactly what we are delivering: an AI-driven platform that closes the loop between every operational logistics decision and its financial consequence. This is Industrial AI applied where it matters most.”
Omnix and Dataiku will jointly focus on government departments, the public sector, financial services, energy, utilities, telecommunications, and large enterprises involved in AI-led transformation.

Omnix International, a leader in digital transformation and innovative technology solutions in the Middle East, today announced a partnership with Dataiku. This partnership will help organizations adopt artificial intelligence at scale, with a strong focus on security, governance, and real-world business outcomes.
With this partnership, Omnix will be able to combine its regional expertise, strong government and enterprise relationships, and
proven delivery capabilities with Dataiku’s governed AI platform. Together, the companies will support organisations in accelerating their AI adoption journey and create measurable business value from data.
Walid Gomaa, CEO of Omnix International, said, “This partnership with Dataiku aligns with our strategic vision to be a trusted digital transformation partner to deliver leading technologies and enable smarter data-driven organisations across the GCC region. With Dataiku’s AI platform, we can help our customers move beyond experimentation and adopt AI in a scalable, secure way that aligns with regional regulatory and operational requirements.”
The partnership supports Omnix’s strategy to deliver advanced, data-driven solutions that enhance decision-making and opera-
tional efficiency, while enabling Dataiku to expand its presence in the region through a partner with deep local insight and execution capabilities.
“Across the GCC, organizations are under real pressure to move from AI experimentation to trusted, measurable impact,” said Sofian Benali, Area Vice President - EMEA Partnerships at Dataiku. “Together, Dataiku and Omnix will help customers operationalize responsible AI with the governance, confidence, and accountability required to scale.”
Omnix and Dataiku will jointly focus on government departments, the public sector, financial services, energy, utilities, telecommunications, and large enterprises involved in AI-led transformation. They will work together to address common challenges such as fragmented data landscapes, governance complexity, and the need for trusted AI in business-critical environments.
By delivering an integrated AI journey from data preparation and model development to deployment and governance, Omnix and Dataiku aim to help organizations across the UAE and GCC turn data into actionable intelligence and sustainable business value.
New partner program within VAST’s Cosmos Community creates a single, clear path for technology alliance, cloud and channel partners to build, validate, sell, and deliver AI-ready solutions
At VAST Forward 2026, VAST Data, the AI Operating System company, announced a unified, global partner program within VAST’s Cosmos Community that brings together VAST’s partner ecosystem of resellers, service providers, systems integrators and advisory partners, technology alliance partners, distributors, cloud service providers and hyperscalers – all under one consistent framework.
VAST Cosmos is a global community of developers, builders and experts in innovative AI solutions. Within Cosmos, this program is designed to make it simple for partners to engage VAST in the way that best fits their business and their customers – while providing a clear, transparent path to grow with VAST.
As enterprises race to operationalize AI, partner ecosystems have become the fastest way to deliver validated architectures, production-ready integrations, and repeatable services. The VAST Cosmos Partner
Program now formalizes how partners can participate in one or more routes to market while aligning around common training, enablement, governance, and goto-market resources through a centralized partner portal.
“Cosmos was created to transform how organizations build and advance AI by bringing AI practitioners together in a comprehensive, supportive community that nurtures innovation, collaboration, and growth,” said John Mao, Vice President, Global Technology Alliances at VAST Data. “Now, with the addition of the Cosmos Partner Program, we’re expanding that mission by giving technology, cloud, and channel partners a unified framework to build and validate solutions, differentiate service offerings, and bring the VAST AI Operating System to customers – across the data center, cloud, and at the edge.”
Cosmos brings together disparate part-

John Mao VP, Global Technology Alliances, VAST Data
ner tracks under one cohesive ecosystem story and engagement model. Together, these tracks provide a single, unified way for partners to build, validate, deliver, and scale customer solutions on the VAST AI Operating System
Yango Tech offers both ready-to-deploy solutions and a customizable platform for building AI agents
Yango Tech, B2B technology solutions provider by Yango Group, launched a new business practice focused on developing and deploying autonomous industrial AI agents. These AI agents are designed to execute real operational tasks across customer service, analytics, compliance, and decision-making, serving industries such as fintech, medtech, e-commerce, logistics, smart cities, and the public sector. Yango Tech offers both ready-to-deploy solutions and a customizable platform for building AI agents tailored to the specific needs of each business. This new business direction addresses the rapidly growing demand across the Middle East for scalable AI systems.
AI Agents connect directly to enterprise applications and data sources, including CRM, HR and finance systems, allowing AI to act like digital employees with memory, execution capabilities and built-in security. For governments and enterpris-
es building digital workforces and smart cities, Yango Tech deploys AI employees across customer support, sales, recruitment and debt recovery, delivering 95% first-contact resolution, faster hiring and up to $100K in monthly operational savings. Its Smart City stack enables digital twins, emergency navigation, mobility optimization and real-time urban analytics, helping municipalities accelerate decision-making, improve traffic flow, and reduce energy and operational costs through AI-powered city modelling and dispatch optimization.

clinicians to treat more patients. In financial services, AI functions support front-, middle- and back-office transformation through AI-powered chatbots, smart search, credit scoring, anti-fraud analytics and workflow automation.
In the medical world, Yango Tech reduces physician admin workloads through appointment transcription, smart search across electronic medical records, imaging analysis and AI and BI command centres. The solutions automate documentation, surface unified patient data in seconds, improve diagnostic accuracy and enable
Vladimir Razuvaev, Chief Executive at Yango Tech, said: “Enterprises today are under pressure to turn AI into practical outcomes. Our AI Agents were built to help organizations deploy autonomous digital employees that integrate securely into existing systems and deliver measurable productivity gains.”
Educational institutions in the UAE can use the video learning platform to create interactive lessons, assessments, and video content for free until May 31, 2026
Ankabut, the UAE’s advanced technology provider for the education and research ecosystem, is providing complimentary institutional access to WeVideo’s interactive video learning platform until May 31, 2026. The platform enables educators to easily create lesson videos, assignments, announcements and interactive learning content, while students can access ad-free videos and submit video-based assignments through a secure, cloud-based environment. The initiative helps schools, universities and educational institutions strengthen digital learning capabilities and ensure agility and continuity should remote learning be required.
“To ensure that students’ academic progress continues without disruption, educators need tools that allow them to adapt quickly to remote learning environments,” said Tarek Jundi, Chief Executive Officer, Ankabut. “We understand that transitioning to remote learning requires not just functional, but engaging methods. That’s why we are working towards meeting the
educational and technological needs of the moment. We are pleased to extend our support to the educational institutions in the UAE through Ankabut’s robust national infrastructure and delivery.”
Ankabut is supporting institutions across the UAE with immediate access to WeVideo’s platform. Through a simple signup process on Ankabut’s landing page, institutions can quickly provision free licenses and begin using the platform to create lesson videos, assignments and interactive learning content. Educators and students will also have access to quick-start guides to help them get started and make the most of the tools.

“Ankabut plays a vital role in enabling innovation across the UAE’s education
community, and we are proud to collaborate in making powerful video learning tools accessible to educators nationwide. With WeVideo, teachers can move beyond passive video instruction and create interactive learning experiences that keep students engaged and participating wherever learning takes place,” said Kevin Knight, Chief Executive Officer, WeVideo.
Transforms digital operations across banking services and cuts incident detection time by over 80%
Dynatrace, a leading AI-powered observability platform, announced that Bank Muscat, the Sultanate of Oman’s largest bank by market share, has deployed the Dynatrace platform to build the country’s first enterprise Command Center in the banking sector, that will strengthen operational resilience and accelerate incident response across critical digital banking services.
Since deploying the Dynatrace platform, the Command Center has reduced mean time to detect (MTTD) by more than 80% by consolidating over 20 monitoring tools into a single unified observability platform, fundamentally changing how the bank detects and responds to incidents.
To address the growing complexity of its critical digital banking services, Bank Muscat partnered with Dynatrace to establish a centralized Command Center operating model built on AI-powered observability and real-time, AI-driven insights.
The Command Center provides a single operational view spanning core banking systems, payment and channel services, and customer-facing digital applications, leveraging AI-assisted analysis to replace fragmented monitoring with coordinated, real-time service assurance and enabling the bank to move from reactive incident handling to faster, more proactive operations.

“The Command Center has enabled us to operate from a single, unified data view that empowers our teams to anticipate issues before they escalate. We’ve shifted from reactive incident response to proactive service assurance; strengthening resilience, enhancing customer experience, and delivering measurable improvements. This is not just an operational upgrade; it’s a foundation for smarter, faster, and more reliable service delivery in the future, with a strong commitment to provide better services for
our customers every day.” said Mohammed Saud Al Naamani, Deputy General Manager Business Applications at Bank Muscat.
The newly launched Command Center, based at Bank Muscat’s headquarters, reflects the bank’s commitment to operational excellence through a centralized, disciplined operating model. The model is designed to build and retain internal capability, reducing dependency on external vendors, and strengthening long-term operational resilience.
The solutions will offer a selection of pre-selected validated hardware and GPU partners
Submer, a leading end-to-end AI infrastructure company, has announced a strategic partnership with ZEDEDA, a leader in edge intelligence, to deliver rapid manufacturable modular, liquid-cooled edge AI infrastructure for high-density GPU inference in locations where traditional data centers are unavailable or impractical.
The joint solution combines Submer's fullstack AI infrastructure platform - spanning design, liquid-cooled compute infrastructure, and deployment that supports ultra-high-density racks exceeding 100kW — with ZEDEDA's edge intelligence software platform, enabling customers to create, secure and operate edge AI anywhere in the world, and at any scale.
“AI is rapidly moving from centralized cloud environments into real-world operations, from industrial sites to telecom networks and remote energy infrastructure,” said Patrick Smets, CEO of Submer. “Delivering that intelligence requires pur-
pose-built AI infrastructure that operates efficiently in environments where traditional data centers simply cannot exist. By combining Submer’s liquid-cooled high-density AI infrastructure with ZEDEDA’s edge intelligence platform, we’re enabling organizations to deploy scalable, resilient AI infrastructure anywhere it is needed.”

ers to bring their own hardware systems.
Submer will provide modular containerized infrastructure with immersion and directto-chip cooling designed for high-density GPU deployments. ZEDEDA’s Edge Intelligence Platform will provide complete edge AI lifecycle orchestration, to enable creating, securing, and operating edge AI at scale. The solutions will offer a selection of pre-selected validated hardware and GPU partners, along with the option for custom-
Said Ouissal, CEO and founder of ZEDEDA sais, “ZEDEDA's Edge Intelligence Platform ensures high-performance AI workloads at the edge are managed, secure, and scalable, and Submer's liquid cooling technology enables the high-density compute those workloads demand, even in the harshest global environments. Together, we are unlocking AI for the industries that need it most."
Video is increasingly a source of real-time data that informs broader operational decisions.
Axis Communications, the leading manufacturer of network security and surveillance solutions, has released its first annual Axis Perspectives Report. The publication brings together global research, expert input and real-world examples to explore how intelligent IP cameras are evolving beyond traditional surveillance into an increasingly embedded component of operational infrastructure, supporting security, safety and wider business performance.
While security remains the primary driver, the report shows a marked expansion in how video systems are being used. Use of video for business intelligence has nearly doubled in one year, rising from 20% to 38%, while 42% of organisations now use video to support operational efficiency. Video is increasingly a source of real-time data that informs broader operational decisions.
This shift is especially relevant across the Gulf Cooperation Council (GCC) and the wider Middle East, where large-scale smart city initiatives, transport networks and mixed-use developments are rapidly expanding. From major public venues to integrated urban infrastructure, organisations are managing complex, high-traffic environments that require real-time visibility and a coordinated response. As these ecosystems become increasingly connected, there is growing focus on cybersecurity, unified platforms and cloud-ready architecture to support secure, scalable operations.
The report highlights how intelligent video is being used beyond security, including in sectors such as transport, logistics and industrial operations. One example is BMW Group’s use of high-resolution cameras to support AI-driven quality inspection (AIQX) across its iFACTORY facilities. By capturing detailed images in real time, the system helps automate inspections, reduce errors and improve operational efficiency. Examples like this show why many organisations are starting to see video as more than a security tool.
“GCC nations, and the Middle East re-
gion overall, have been sites of exciting innovation where video systems are concerned,” said Assim Khedr, Engineering and Training Manager, Middle East at Axis Communications. “The region has served as the definitive example of not just the shift from analogue to digital, but also how video camera solutions have become powerful tools that deliver real-time insights and added business value. With resources like Axis Perspectives, we’re able to take such examples and quantify them, demonstrating how a brand like Axis, with its established history of innovation, can help businesses and governments extract the most value from investments in new technologies.”
Key findings from the Axis Perspectives Report 2026 include:
• Security and safety remain the strongest drivers: Security is still the primary purpose of video systems for 89% of end customers, while 81% prioritise safety.
• Video is now driving business value: Use of video for business intelligence has nearly doubled in one year, rising from 20% to 38%, while 42% now use video to support operational efficiency, reflecting the growing role of video in managing complex environments.
• Cybersecurity is now a top concern: 44% of end customers say cybersecurity and data protection will be a key priority over the next one to three years, as more systems connect across smart infrastructure and public services.
• Customers want simpler, joined-up systems: 41% say bringing different security systems into one platform is a top focus, supporting more integrated management across large sites and citywide deployments.
• Cloud adoption is accelerating: Cloud use in physical security is expected to rise from 27% to 44% within two years.
• Infrastructure upgrades are still a key driver: 64% of end users say modernising infrastructure is a leading reason for investing in video, as organisations look for systems that are easier to manage and more secure.

Assim Khedr Engineering and Training Manager, Middle East, Axis
For organisations across the GCC and the wider Middle East, the implications are clear. Video is becoming part of everyday business systems, and the choices made now will shape security, risk and how smoothly complex environments are run in the future.
The report also introduces a five-stage maturity model to help organisations assess their current capabilities and future direction. It outlines a progression from passive recording systems to reactive and proactive systems powered by AI, through to predictive and autonomous environments where cameras can analyse patterns and trigger actions with minimal human intervention.
Axis Perspectives is designed to help organisations understand what is changing in intelligent video, what it means in practice and what to plan for next. With nearly three decades of innovation in network video, Axis continues to support customers and partners with technology and insight that helps build safer, smarter environments.
Expanded architecture lets businesses run AI at scale, from central data centers to the factory floor, without sacrificing performance or security.

Cisco announced a major expansion of its Secure AI Factory with NVIDIA, giving customers a framework for deploying AI across their entire infrastructure – from central data center to local sites where data is created and decisions are made.
Enterprises, neoclouds, sovereign clouds, and service providers can now move AI from pilot to full-scale production without stitching together disconnected systems, compressing deployment timelines from months to weeks and embedding security from the start.
"Most organizations understand the potential for AI to transform their businesses, but they're navigating how to deploy the technology safely and at scale," said Chuck Robbins, Chair and CEO, Cisco. "In partnership with NVIDIA, we're solving that challenge with an architecture that sets a new standard for performance –making it simpler to deploy, operate, and secure AI infrastructure."
“AI factories are transforming every industry, and security must be built into every layer - from silicon to software - to protect data, applications, and infrastructure,” said Jensen Huang, founder and CEO of NVIDIA. “Together, NVIDIA and Cisco are building the secure foundation for AI infrastructure - core to edge - so companies can scale intelligence with confidence.”
AI inference happens where data lives and decisions can't wait, whether on the hospital floor or for analyzing video of a factory
floor in real-time to keep workers safe. This reality fundamentally reshapes infrastructure by requiring inference workloads to operate locally — closer to the data, the devices, and the moment a decision must be made. Cisco and NVIDIA are enabling organizations to support edge inferencing use cases by transforming the enterprise edge. By now supporting NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs across the Cisco UCS and Cisco Unified Edge portfolios, Cisco enables enterprises to run mission-critical AI workloads at the edge without the energy cost and footprint of data center-scale hardware.
Driving performance and efficiency for massive-scale AI factories, Cisco is enhancing performance and simplifying how organizations deploy AI infrastructure at scale. Cisco’s latest high-speed switches power the most demanding AI workloads, including a new 102.4Tbps Cisco N9100 powered by NVIDIA Spectrum-6 Ethernet switch silicon. This joins the now generally available 800G N9100 powered by NVIDIA Spectrum-4 Ethernet switch silicon.
Cisco Nexus Hyperfabric, now a part of Cisco Nexus One, will support Cisco N9000 Series switches, including the N9100 Series powered by NVIDIA Spectrum-X Ethernet silicon. Organizations can now transform a complex, multi-vendor integration puzzle into a simple, full-stack solution to cut deployment times and reduce the burden on IT.
In an era where AI models are high-value assets and agents are more autonomous, taking actions, making decisions and interacting with other agents - security can’t be an afterthought. Cisco is embedding protection into the fabric of the Secure AI Factory with NVIDIA to safeguard against both external threats and rogue agent behavior.
Cisco also announced Cisco AI Defense will support and secure NVIDIA’s OpenShell runtimes – part of the NVIDIA Agent Toolkit – adding controls and guardrails to govern agent and claw actions.
New and expanded on-premises offerings deliver industry-leading, AI-powered security, giving customers complete control over their data while ensuring it never leaves their environment.
SentinelOne is bringing the power of autonomous AI security to on-premise and self-hosted environments. The new and expanded portfolio builds on SentinelOne's existing advantage as the only next-generation cybersecurity company to deliver modern, cutting-edge endpoint protection with zero cloud dependency. By ensuring all data is processed strictly within the customer's own environment, the offerings provide complete data privacy and sovereignty. Already deployed across millions of on-premises endpoints, the expanded portfolio will now secure servers, private clouds, and data pipelines at an unprecedented autonomous scale. As a result, highly regulated public and private sector organizations can now defend their most critical, airgapped environments with the power and speed of AI, without ever sacrificing control of their data.
“Empowering global organizations with the certainty that their data stays in their control is more urgent than ever given the need to adopt AI without compromising privacy. For too long, organizations in highly regulated sectors have faced a trade-off between the speed of AI security and total data sovereignty, privacy and control - especially for airgapped networks,” said Ana Pinczuk, President of Product and Technology at SentinelOne. “At SentinelOne, we are committed to breaking that trade-off. By delivering our most advanced autonomous engines and AI protections directly into the customer’s own hardware environment, we are giving them the freedom to innovate securely.”
The security market is shifting as governments and regulated industries increasingly demand total control over where their data lives and how it is processed. This is especially pronounced with the rapid rise of AI, causing these organizations to ensure that AI applications and data stay secure and fully aligned to their principles, without any third-party dependency. At the same time, rising geopolitical risks are forcing critical infrastructure to move toward airgapped systems that can stay secure even when disconnected from the internet.
Building on its successful FedRAMP and GovRAMP authorized on-premise endpoint security capabilities, the expanded offerings introduce AI-powered protection and the same level of security trusted in the public cloud to the world’s most sensitive organizations. By using a single, lightweight agent, national security agencies, financial institutions, and healthcare providers can standardize their security across any infrastructure. These deployments allow customers to keep all their data in-house, streaming telemetry directly into their own systems for threat hunting and investigations without ever sending information to a cloud service. This established global footprint already protects tens of millions of endpoints for critical infrastructure operators who require total data control.
To further secure private and sovereign clouds, SentinelOne provides real-time protection for servers, containers, and data storage that operates entirely within a customer’s own network. This technology is built to be stable and autonomous, using multiple detection engines that work on-device without needing a persistent internet connection. The solution also extends to local data stores, integrating with systems like NetApp and Dell to automatically

Ana Pinczuk President of Product Technology, SentinelOne
scan and quarantine malware at the point of entry.
SentinelOne’s Prompt Security On-Premise adds these same protections to the world of AI, even in fully disconnected environments. This self-hosted AI security discovers "shadow AI" usage and redacts sensitive information in real time across thousands of applications. By acting as a specialized firewall for both internal and external AI tools, Prompt Security blocks threats like prompt injections and data leaks while ensuring organizations maintain complete sovereignty over every interaction - no external connection required.
Beyond core security, SentinelOne is introducing a new AI Data Pipeline designed specifically for on-premises environments to optimize how local data flows. By using intelligent filtering, this pipeline helps security teams reduce alert fatigue and cut down on infrastructure costs by only processing what matters most. It also enriches telemetry and monitors the health of the entire data stream, giving organizations better visibility and more reliable insights. AI Data Pipelines allow moving data easily while sanitizing it between different sources and endpoints like Generative AI models - without the data ever leaving the premises or cloud processing needed.
The expanded offerings can be deployed anywhere so customers can easily meet in-country data residency and regulatory requirements, achieving true sovereignty without sacrificing platform capability.
Apu Pavithran, Founder and CEO of Hexnode, explains why unifying management, security, and identity is critical to building a consistent and scalable Zero Trust framework.
Hexnode views the endpoint as the definitive anchor of enterprise trust. While the industry often treats endpoint management and security as separate functions, we see them as an inseparable discipline. The primary challenge facing a CISO today is no longer just visibility, but the necessity of enforcing absolute policy consistency across a hyper-fragmented environment of laptops, mobile devices, kiosks, and other purpose-built endpoints.
Our strategy is built on the realization that management, security, and identity must operate as a single, continuous loop: Hexnode UEM establishes the baseline of control, Hexnode XDR provides active threat detection and response, and Hexnode IdP integrates identity with real-time device posture to govern access. By unifying these three pillars, we eliminate the structural gaps and "blind spots" that traditionally exist between disparate tools.
In high-compliance markets like the Middle East, enterprises require a dynamic system capable of determining, in real time, which devices are trusted, which are compromised, and exactly what level of access they should be granted.
Hexnode provides the intelligence and enforcement required to secure the digital perimeter in a Zero Trust environment, ensuring that management is never decoupled from security.
Your platform supports a wide range of operating systems and device types, including IoT and emerging endpoints. How are enterprise requirements changing when it comes to managing such diverse environments?
In a hyper-diversified environment, the challenge is no longer merely supporting multiple operating systems; it is managing endpoints with vastly different risk profiles, usage patterns, and ownership models within a single architectural framework.
A frontline rugged handheld, a customer-facing kiosk, and a corporate laptop are not used the same way, and they should not be governed the same way either. However, enterprises cannot afford to let their operations fragment into silos for every new device class.
The modern requirement is the ability to maintain a centralized control plane that is flexible enough to tailor security controls to each device's specific role. IT leaders are now demanding the ability to enforce granular, class-specific policies—while main-

Apu Pavithran Founder and CEO, Hexnode
taining a consistent standard of trust across the entire estate.
At Hexnode, we bridge the gap between diversity and discipline, allowing organizations to scale their hardware footprint without multiplying their operational complexity.April
With endpoints becoming a major attack surface, how is Hexnode integrating endpoint security with device management to deliver a more holistic approach?
Treating management and security as separate disciplines is no
longer viable. We are addressing this through the functional convergence of Hexnode UEM and Hexnode XDR. While UEM ensures every device is configured, patched, and compliant, XDR provides the active layer of threat detection and response.
The real advantage is contextual clarity. In fragmented environments, security teams often evaluate alerts in a vacuum. By integrating these pillars, security teams are not forced to evaluate alerts in isolation. They can see the device’s state, determine whether it is managed and compliant, and move from detection to containment much faster within the same environment.
This synergy closes the "response gap" between IT and security operations, eliminating the blind spots that attackers exploit.
As enterprises increasingly adopt BYOD and hybrid work models, what are the key challenges in balancing user flexibility with enterprise security and compliance?
The core conflict with BYOD is enforcing enterprise security and compliance on a device the organization does not fully own, without overstepping into the personal side. The requirement is to keep control over corporate data, access, and policy without turning the personal device into a fully managed asset. If the boundary between corporate oversight and personal use is blurred, the model fails; employees resist invasive management, and IT is forced into a compromise that is either too restrictive or dangerously permissive.
Achieving this balance requires architectural separation. By leveraging native frameworks like Android’s Work Profile and Apple’s Business Container, we create encrypted containers that isolate business data without touching the user’s personal content.
This distinction is particularly critical in regions like the Middle East, where data protection and sovereign governance mandates are intensifying. Organizations must be deliberate: the goal is to govern corporate data and access, not the individual's personal data. By maintaining this clear separation, enterprises can preserve the flexibility of hybrid work without diluting their security posture or weakening regulatory compliance.
How is Hexnode leveraging automation across deployment, patching, and lifecycle management to reduce IT overhead?
The value of automation lies in its ability to eliminate "operational drag." Endpoint management becomes a liability when growth requires a linear increase in headcount; therefore, our focus is to shift IT from repetitive maintenance to high-value architecture. We achieve this by turning recurring tasks into policy-driven workflows that operate without manual intervention.
To offload the "grunt work" across the entire device lifecycle, we leverage automation from the very start. For deployment, we leverage zero-touch enrollment to automate bulk provisioning and policy application from the moment a device is powered on. For patch management, the platform moves away from manual tracking by allowing admins to schedule, force, or defer updates based on patch criticality and maintenance windows.
Beyond these basics, we automate the transitions between onboarding, active use, and offboarding to streamline lifecycle management. The platform handles the heavy lifting of software distribution and compliance monitoring; when a device is ready for replacement or a user leaves the organization, it triggers automated workflows for remote wiping and policy removal.
This level of efficiency is vital in regions like the Middle East, where teams must support aggressive scaling without a proportional increase in administrative overhead. By automating these routine tasks, we minimize human error and ensure consistent management at any scale.
How important is integration with enterprise systems such as identity platforms and directories in delivering a truly unified endpoint management experience?
When identity and endpoint management systems are siloed, you create a dangerous sequencing problem where authentication can succeed before the platform has even evaluated whether the device is enrolled, compliant, or trusted. These gaps force IT to manually stitch together trust signals across disconnected systems, leading to slower remediation and imprecise access decisions.
We developed Hexnode IdP to bridge this divide. By bringing identity natively into the endpoint management layer, functions like SSO, MFA, and RBAC are no longer blind to the health of the hardware. Access is granted only when both the user’s credentials and the device’s real-time posture align.
Crucially, this doesn't require a rip-and-replace of existing infrastructure. Hexnode IdP leverages federated identity to seamlessly sync with established directories like Microsoft Entra ID and Google Workspace. For the organization, it means maintaining a single "source of truth" for identity while ensuring that every login attempt is verified against the device’s security state.
The Middle East is a focal point of our global growth strategy. Recently, we launched our new data center in the UAE, hosted on AWS. This was a strategic move to ensure we can deliver secure, high-performance endpoint management that is fully compliant with regional data residency laws.
Beyond compliance, localizing our infrastructure significantly improves operational efficiency. By processing data in-region, we minimize latency, making our cloud-based platform faster and more responsive for local administrators.
To support this growth, we also have a dedicated regional team and an office in the Middle East, supported by strategic partnerships with major resellers and distributors like Jumbo, VAD Technologies, and CyberKnight. These relationships allow us to provide localized expertise and better service to our customers. We aren't just offering a tool; we are providing a regionally compliant ecosystem that helps Middle Eastern enterprises scale their operations securely and efficiently.
Burcak Soydan, Managing Director for the Middle East at NTT DATA, discusses how the company’s acquisition-led DNA is shaping its Middle East expansion, cloud strategy, and AI focus, including the recent acquisition of Zero&One and its broader implications.
You recently acquired Zero&One, and acquisitions have long been central to your strategy. Can you elaborate on that journey?
NTT DATA is a company built through acquisitions across regions, including the acquisition of Dimension Data in 2010. The original entity is Nippon Telegraph and Telephone. It’s a Japanese company, one of the largest telco operators in the world, partially owned by the Japanese government. It’s a 150-year-old institution, and we even have ‘telegraph’ in our name, which reflects that legacy.
About 20 years ago, they realized there was no global SI coming out of Asia. So, they chose a path through acquisitions, and today we are a $30 billion global SI, almost in the top five.
When you grow with acquisitions, it gives you the flexibility to pick and choose what you want in your portfolio. Our capabilities span from submarine cables to AI; we often say we operate from under the sea to above the sky, including satellite capabilities.
The bulk of what we do is still in system integration, mainly infrastructure, cloud, applications, and data.
What was the opportunity gap you identified in the Middle East? When I started two and a half years ago, we were only representing about 20–25% of our portfolio in the Middle East. We then set out to bring our full capability into the region.
Some of it we decided to build locally, and some of it we said we would acquire. Within the cloud, we chose to accelerate through acquisition.
How does the Zero&One acquisition strengthen your go-tomarket strategy in the Middle East?
Saudi Arabia was a big trigger. The cloud market is opening up, with AWS and Microsoft announcing plans. We looked at hyperscaler ecosystems, and that led us to Zero&One. It’s a company founded by very technical people who see themselves as builders. They see AWS as a Lego set to build solutions, not just resell or consult.
That was a strong cultural fit, as we also like to get our hands dirty and build things. They are a services-driven company, and they also have strong recognition, including AWS Rising Partner Award in EMEA.
We currently operate in UAE, Saudi Arabia, and Qatar. With Zero&One, we now have operational capability and legal entities in

Managing Director, ME, NTT DATA
Egypt and Lebanon as well. It’s also a UAE-founded company, which we like. We call ourselves the most local global integrator, combining global capability with local agility.
What is the integration plan for Zero&One?
They will eventually be fully integrated, but we are taking it step by step. There should be no disruption to existing customers. We will move to the same office, align systems gradually, and integrate. Eventually, we will operate as one company, not as a separate brand.
They will form our Middle East cloud practice as part of our global cloud practice.
How strong are your hyperscaler partnerships?
Globally, we are in the top 10 partner list of Microsoft, Google, and AWS. We operate as a multi-cloud provider, and that business is growing fast.
We also recently signed a strategic collaboration agreement with AWS, creating a dedicated AWS practice with mutual investment.
What are your core practices as a company?
We have cloud, applications, data and AI, and infrastructure practices. In applications, we work with SAP, Salesforce, ServiceNow, Microsoft, and others.
In all these areas, we build, manage, and consult.
Where does AI fit into this structure?
AI cannot be confined to a single domain; it is embedded across all our practices.
We use AI in cloud to build solutions, in infrastructure through AIOps, in applications for testing, and in business processes through automation.
We also have a global AI unit focused on consulting and helping customers start their AI journey, and we have leadership for that in the Middle East.
What challenges are enterprises facing with AI today? It’s easy to do a POC, but very difficult to scale across the enterprise.
There are process changes, internal inertia, and, most importantly, a skills gap. There are not enough skills to retrain models for enterprise needs.
What is your view on enterprise AI adoption?
We bet a lot on enterprise, sovereign, private AI.
Large language models alone are not enough; you need customization, retraining, and tuning. In many cases, smaller, task-specific language models are more effective.
We work with partners like Mistral AI and are trying to replicate use cases from Europe in this region.
Which sectors are you focusing on in the Middle East? Banking and financial services is a major focus, especially in Saudi Arabia.
We also focus on aviation, both airports and airlines, where digital twins are important. Healthcare is another area with strong transformation potential.
Additionally, we are strong in infrastructure environments like stadiums and airports. We were the network and security provider for the Tokyo Olympics, with zero security incidents.
How are your key markets performing?
We are seeing growth across Saudi Arabia, the UAE, and Qatar. Saudi Arabia is the largest by scale, while in the UAE, we have doubled our headcount, especially in Abu Dhabi, and we are seeing promising results.
In Qatar, we recently hired a country manager and are building it as a growth market.
What about talent development in the region?
In Saudi Arabia, we launched a graduate program, hiring 10 graduates every year and training them for one year.
They are highly motivated and well educated. We also complement that by bringing global skills into the region.
Overall, we now have around 370 people in the Middle East, with about 30–40% year-on-year growth.
Do you have your own products or IP?
We don’t call them products, we call them assets.
For example, we have built a customer support platform that integrates multiple vendor systems into a single dashboard.
We also use AI-based tools for application development and testing. We don’t sell them as products but use them to improve our services.
What are your key priorities going forward?
One priority is large-scale AI infrastructure; we want to win and deliver those projects in the region.
Second is diversification into cloud and applications, especially through the integration of Zero&One.
Third is activating partnerships with Salesforce, ServiceNow, and others to drive more value.
"AI cannot be confined to a single domain; it is embedded across all our practices. We use AI in cloud to build solutions, in infrastructure through AIOps, in applications for testing, and in business processes through automation."
Hussam Sidani, Vice President for the Middle East & North Africa at OPSWAT, shares insights on evolving attack patterns, architectural shifts, and the growing importance of proactive defence.
As industries like energy, utilities, and manufacturing digitize, what are the biggest security gaps you are seeing in OT environments today?
This is something we track closely. We recently sponsored the SANS State of ICS/OT Cybersecurity 2025 report which found that over one in five organisations reported an incident affecting their OT environments in the past year. The leading cause was unauthorised external access, with roughly half of incidents originating there, often through third-party remote maintenance. This reflects a structural issue. Operational environments have become more connected, but access controls have not kept pace. Convenience still tends to outweigh security in day-to-day operations.
What stands out is that budget is not the main constraint. Many organisations are increasing spend, but not always in ways that reduce exposure. OT security requires targeted investment in segmentation, controlled remote access, and strict inspection of anything entering the environment, whether files, devices or updates.
The key point is that OT security needs to be treated on its own terms. The priority is not just data protection, but operational continuity and safety.
How should enterprises rethink security architectures as IT, OT, and cloud environments become increasingly interconnected?
Interconnectivity has fundamentally changed the risk profile for enterprises. The rules of engagement are different now, and security architectures need to reflect that reality.
Entry points remain familiar — phishing, credential misuse, the vectors organisations have long contended with. But these are only the beginning of the story. What matters is not how attackers get in; it is what they do once they are inside.
That is where lateral movement becomes the real danger. We are seeing a steady increase in attackers crossing from IT into OT environments, and once they reach operational systems, the consequences shift from data risk to physical disruption and safety risks. Traditional controls reduce that risk but do not remove it. If a pathway exists, it can be exploited. That is driving an architectural shift towards limiting those pathways altogether. Organisations are reducing unnecessary connections and enforcing clear separation between environments.
In that context, controlled one-way data transfer becomes increasingly important. True unidirectional flow allows organisa-

Hussam Sidani Vice President for the Middle East & North Africa, OPSWAT
tions to maintain visibility and data continuity without exposing operational systems to inbound risk.
What differentiates OPSWAT’s approach from traditional cybersecurity vendors that remain largely IT-centric?
Most cybersecurity vendors are built around IT environments, where systems can be patched, rebooted, and taken offline without consequence. OPSWAT takes a fundamentally different approach, designing its solutions from the ground up for critical infrastructure, where downtime usually halts production and a
misconfigured security tool can have real-world physical consequences.
The company specializes in securing industrial control systems (ICS) and operational technology (OT) environments such as power grids, water treatment facilities, and nuclear plants. Many proprietary industrial protocols were never designed with security in mind, and standard IT security tools simply don't support them.
Central to this is our prevention-first philosophy. Where most vendors focus on detecting and responding to threats after they've entered a network, OPSWAT's approach is to stop them from getting in at all — because in critical infrastructure, by the time you've detected a threat, the damage may already be done.
A good example of this mindset is our focus on data diode technology. Unlike traditional controls that rely on software policies, a data diode enforces security at the hardware level. It physically allows data to move in only one direction. There’s no return path, which means no opportunity for attackers to pivot back into OT systems. It’s absolute isolation by design.
Historically, organisations hesitated because of performance or complexity concerns, but that’s changed. Current solutions support high availability, throughput up to 10 Gbps, and much broader protocol compatibility, which can secure critical environments without the need to rip out legacy infrastructure.
How does the MetaDefender platform enable a defense-indepth strategy across IT and OT environments?
One of the biggest misconceptions in cybersecurity is that more detection equals more security. In reality, detection will never be perfect, and in OT environments, “almost perfect” simply isn’t good enough.
That’s where MetaDefender is designed differently. It’s built around a prevention-first, multi-layered approach. We combine multiscanning, sandboxing, file-based vulnerability assessment, and data loss prevention to inspect every piece of data entering or moving across environments.
But the real differentiator is our Deep Content Disarm and Reconstruction (Deep CDR™) technology. Instead of trying to decide if a file is malicious, we rebuild it from the ground up, removing any potentially harmful elements while preserving the original functionality. In an OT context, that’s critical. If you’re receiving a configuration file or firmware update, you can’t afford to “test and see.” You need certainty before it ever touches your systems. That’s what defense-in-depth should look like in practice.
With AI being leveraged by both defenders and attackers, how is OPSWAT preparing enterprises for the next wave of AI-driven threats?
Where most vendors apply AI to detection and response workflows, OPSWAT applies it at the data layer, before files reach the environment. The MetaDefender platform layers Deep CDR technology, Metascan™ Multiscanning, Predictive Alin AI and an adaptive Sandbox to prevent threats from executing rather than catching them afterward.
Predictive Alin AI is OPSWAT’s machine learning engine handling file-level risk assessment. It evaluates file structure, entropy patterns, and semantic relationships to predict malicious behaviour, returning a verdict in under 100 milliseconds with a 0.1% false positive rate. The model is continuously retrained through MetaDefender Aether telemetry, OPSWAT Threat Intelligence, and Unit 515 (OPSWAT’s elite red team) research, which keeps it current against zero-day and AI-generated threats that traditional AV engines don't see.
The engine runs as a confidence layer within the multi-engine architecture. When it is uncertain, MetaDefender automatically routes the file to additional workflows without manual intervention, maintaining defense-in-depth without adding operational burden.
AI-generated content detection is also embedded natively across the platform, addressing a threat category that legacy tools aren't built to handle. The full stack covers Cloud, IT, OT, and cross-domain environments from a single platform.
For CIOs and CISOs, what are the top three priorities they should focus on today to strengthen their cybersecurity posture?
First, tighten control over trust boundaries. Third-party access, supply chains and remote connections are now primary entry points. These relationships need continuous verification, not implicit trust.
Second, focus on prevention in critical environments. Detection remains important, but it cannot be the only line of defence where downtime or safety is at stake. Controls that reduce or remove exposure should be prioritised.
Third, build a strong security culture. Technology is only effective when supported by consistent processes and informed decision-making. Teams need to understand how attacks occur and where assumptions can break down.
In regions like the Middle East, where data sovereignty is gaining importance, how are you aligning your solutions with regulatory expectations?
One of the key ways we’re aligning with the local market is through focused investment. Our OPX Lab in Dubai is a good example. It’s not just a demo environment, but a fully operational testing ground where organisations can simulate real-world cyberattacks across sectors like energy, banking, and defence.
This is important because regulations aren’t just about compliance on paper anymore. Organisations need to have confidence that their systems remain resilient in practice. They need to know precisely how their systems will behave under pressure, where the gaps are, and how quickly they can respond.
By providing a world-class local facility where these scenarios can be tested safely, we’re helping organisations move from theoretical compliance to operational readiness. And that’s ultimately what regulators and businesses are aiming for.
From data to cloud and now to AI, sovereignty is being redefined as control shifts toward the intelligence layer.
The sovereignty conversation in the Middle East has been gaining momentum, now most visibly in the context of artificial intelligence. However, sovereignty itself has been an underlying concern across every phase of technology, closely tied to questions of control and ownership. It is a concept that has evolved in stages, shaped by how enterprises and governments have engaged with technology over the past decade.
It began with data. The earliest concerns were rooted in a simple but critical question: where does data reside, and who has access to it? As regulatory frameworks matured and digital transformation accelerated, that concern expanded into the cloud.
Organizations began to question not just where data was stored, but who controlled the infrastructure that hosted it, what jurisdictions applied, and what dependencies were being created on global providers.
Today, that conversation is shifting once again, this time toward the intelligence built on top of that data and infrastructure. AI is no longer a peripheral capability. It is increasingly embedded into enterprise workflows, influencing decisions, automating processes, and in some cases acting autonomously. That shift fundamentally changes what sovereignty means.
This transition is not just an expansion in scope. It represents a change in the nature of control itself. Data can be stored, moved, and protected. Infrastructure can be secured and governed. But intelligence, particularly AI-driven intelligence, introduces a new layer of complexity. It is dynamic, evolving, and often opaque.
At an enterprise level, this is forcing a rethink of long-standing assumptions.
Kiran Shinde, Vice President IT and Head of IT at Al Hamra Group, UAE elaborates, “In the MEA context, sovereignty has always meant more than geography, it has meant strategic autonomy. For years, the focus rightly centered on where data resides, who controls cloud infrastructure, and whether national regulatory frameworks could enforce jurisdiction over foreign cloud providers. That foundation matters and it remains incomplete in several markets. But the conversation has undeniably shifted. AI changes the nature of sovereignty fundamentally.”

He adds, “Data sovereignty asks: where is your information stored? AI sovereignty asks: who controls the decisions being made on your behalf? When a model is trained on your organization’s data, when it recommends your hiring decisions or flags financial risk, the question of who owns and governs that intelligence becomes existential. In MEA, we are in an early-to-mid transition and the shift is happening, but most enterprises are still laying the cloud sovereignty groundwork while forward-looking CIOs are already designing AI governance frameworks in parallel.”
That distinction, between storing data and controlling decisions, captures the essence of the shift.
However, the level of understanding about sovereignty across enterprises is far from uniform. Many organizations are still anchored in earlier phases of the sovereignty conversation.
Jacob Mathew, Technology and Cybersecurity Leader highlights this gap when he says, “Sovereignty in the MEA context is often looked at ensuring national data remains within local borders. In my opinion, this is only partially correct - we need to also consider legal jurisdictions, who can access to administer and use, and from where, and the encryption keys. The region is in an early stage of moving into AI and intelligence sovereignty. I can see that many organisations are adopting AI, but fewer are asking about governance - who controls the outcomes, the biases, and the long-term dependency on an external provider”
While enterprises are adopting AI at speed, governance models are still catching up.
As organizations begin to grapple with this shift, sovereignty is being redefined in broader and more operational terms. It is no longer limited to data residency or infrastructure control. Instead, it is emerging as a framework that encompasses governance, accountability, transparency, and end-to-end control across digital systems.
This evolution is particularly visible in sectors where regulation is tightly coupled with operational outcomes. In healthcare, for example, sovereignty is not an abstract principle, it is embedded in everyday processes.
Dr. Shijin Prasad, Group IT Head, Elyzee Hospital, explains“In the MEA region, sovereignty has evolved from a narrow focus on data residency to a broader mandate of end-to-end digital control, governance, and accountability. Today, it covers data ownership, jurisdictional control, access governance, processing transparency, and full auditability of decisions.”
In such environments, sovereignty has already moved beyond the standard compliance checklists. It is a foundational requirement for trust, resilience, and operational continuity.
But the introduction of AI is expanding this scope further. AI systems do not just process data; they interpret it, generate insights, and increasingly influence decisions. This creates new challenges around explainability, bias, and accountability.
“The conversation has clearly moved beyond cloud and data into AI and intelligence. With AI now embedded in clinical decision support, diagnostics, and operations, and the emergence of Agentic AI, sovereignty extends beyond data to models, datasets, algorithms, decision outcomes, and AI-driven actions,” adds Dr. Shijin.
This extension, from data governance to intelligence governance, is where the real complexity begins to emerge. At a broader level, this shift is now being framed not just as an enterprise challenge, but as a strategic capability for nations.
Dr. Sreejit Chakrabarty, Group Head, Technology, AI & Innovation at Fortes says, “In the Middle East and Africa (MEA), sovereignty has transitioned from merely emphasizing data residency to pursuing ‘sovereign intelligence’. This concept refers to a nation's capacity to exercise strategic autonomy over the entire AI infrastructure, covering the physical location of GPU clusters, control over model weights, ownership of local intellectual property, and legal jurisdiction over algorithmic outputs. The discourse has moved beyond cloud and data issues, developing

into a field in which regional stakeholders aim to "own" the intelligence shaping their economies rather than merely "consuming" Western-developed frameworks. The GCC has advanced in this trend, securing "compute sovereignty" through large-scale projects such as the UAE’s Stargate and Saudi Arabia’s HUMAIN AI data centers, and by deploying sovereign LLMs such as Jais and Allan.”
The transition toward sovereign intelligence is not being driven by a single factor. It is the result of multiple forces converging, each reinforcing the other and accelerating the overall shift.
Regulation remains the foundation, particularly in sectors where data sensitivity is high. It establishes the baseline for how data must be handled, accessed, and protected.
Dr. Shijin explains, “In the MEA healthcare context, the shift is driven by a combination of all three, but regulatory pressure is the primary catalyst, reinforced by the strategic value of AI.”
However, regulation alone does not explain the urgency of the shift. Increasingly, geopolitical considerations are shaping how technology decisions are made. AI is no longer just a tool for efficiency; it is a strategic asset.
Jacob points out, “In my opinion, the shift is being driven most strongly by geopolitical dynamics, as AI has become a strategic asset which the governments want to protect. The recent situation in the region also stresses the importance of geopolitical dynamics. Governments are clearly pushing for strategic autonomy. Control over critical technology is now treated in the same category as energy or defence. If I were to summarise then geopolitics drives the ‘why’, regulation the ‘how’, and AI the ‘urgency’.”
This perspective reflects a broader global trend, where control over technology infrastructure, data, and AI capabilities is becoming a matter of national importance.
At an enterprise level, these forces manifest differently depend-

ing on the market. In the Gulf, for example, national strategies are playing a significant role in shaping priorities.
Kiran says, “It is a confluence of factors, but the weights differ by market. In the UAE and Saudi Arabia, strategic value is the primary engine. Government-led initiatives such as the UAE's National AI Strategy 2031 and Saudi Vision 2030 have elevated AI from an IT initiative to a national priority, which means sovereign AI is a matter of national competitiveness, not just compliance. Geopolitics is the accelerant. As supply chains of technology, i.e. semiconductors, foundational models, and cloud platforms become instruments of geopolitical leverage, MEA governments are acutely aware of the risks of strategic dependency.”
He adds, “The question of which nation's AI infrastructure underpins your economy is no longer hypothetical. Regulatory pressure, while real and growing, tends to follow strategy rather than lead it in this region. The UAE's Cloud First Policy and emerging AI regulations are formalizing what progressive CIOs have already embedded in their roadmaps. My experience is that the organizations moving fast on sovereign AI are doing so because they see competitive advantage in owning their intelligence layer and not because a regulator told them to.”
This convergence of regulation, geopolitics, and strategic ambition is what is accelerating the shift from sovereign cloud to sovereign intelligence.
As the sovereignty conversation evolves, one of the most significant shifts is how enterprises are positioning it internally. What was once treated as a compliance requirement is now being reframed as a strategic capability.
This change is driven in part by the growing realization that sovereignty directly impacts resilience. In an environment where dependencies on external providers can create vulnerabilities, control becomes a competitive advantage.
Dr. Sreejit elaborates, “Enterprises in the Middle East and Africa are transitioning from a compliance-centric focus on data residency toward treating sovereignty as a board-level strategic imperative for long-term resilience.”
At the same time, the nature of risk itself is changing.
Jacob says, “Most enterprises in the region still treat sovereignty as a compliance exercise. But it is slowly being overtaken by strategic necessity. The organisations that move early will design sovereignty as a capability. The rest will discover it the hard way, usually after an incident, or a regulator asking uncomfortable questions. Today, the risks have moved from fines to total operational failure. If a geopolitical event or a change in trade laws cuts off access to a foreign cloud, a business could lose its entire intelligence overnight and hence it is slowly becoming a strategic priority.”
This shift, from regulatory risk to operational risk, is a key driver behind the repositioning of sovereignty.
For CIOs and technology leaders, this is translating into concrete decisions around architecture, vendor strategy, and capability development. Organizations that can build and control their own intelligence layers are beginning to see structural advantages over those that rely entirely on external providers.
As sovereignty extends into AI, the complexity of governance increases significantly. What was once a relatively well-defined framework around data and infrastructure is now becoming a multi-layered challenge involving models, training data, compute environments, and evolving system behavior.
Kiran explains, “Sovereign AI multiplies that complexity across several new dimensions. First, there is model governance: who trained the foundational model, on what data, with what biases embedded? Even if your data is stored locally, your inference engine may have been trained on foreign datasets that carry embedded assumptions your governance framework has never examined. Second, there is infrastructure sovereignty: AI workloads, particularly LLM inference and model training which require specialized GPU compute that is predominantly controlled by a handful of global providers. Building sovereign AI capabilities without sovereign compute infrastructure is structurally incomplete. Third, there is operational sovereignty: AI systems learn and evolve. Governing a static dataset is very different from governing a model that updates its behavior over time, often in ways that are difficult to audit. The enterprise governance frameworks that served us for cloud are necessary but insufficient for AI.”
This shift introduces more fundamental questions around model training, data lineage, validation, and ultimately, accountability for outcomes. This layered view of governance highlights how AI shifts the problem from managing assets to managing behaviour. It is no longer enough to know where data sits, enterprises must now understand how models evolve, how decisions are made, and where accountability ultimately rests.
In sectors such as healthcare, these questions have real-world implications.
Dr. Shijin adds “With AI now embedded in clinical decision support, diagnostics, and operations, and the emergence of Agentic AI, sovereignty extends beyond data to models, datasets, algo-

rithms, decision outcomes, and AI-driven actions. In regulated environments like Abu Dhabi, organizations must ensure AI outputs are explainable, traceable, clinically validated, and fully compliant. This shift is being driven by strong regulatory enforcement and the growing strategic value of AI, making sovereignty a strategic, clinical, and compliance imperative—not just a technology concern.”
This highlights how governance challenges are already moving from theory to practice in highly regulated environments.
He adds, “From a healthcare leader perspective, I would say the MEA market is quite mature in sovereign cloud, but still evolving in sovereign AI. Most healthcare organizations are well aligned on data residency, security, access control, and compliance—driven by Department of Health – Abu Dhabi and Abu Dhabi Healthcare Information and Cyber Security Standard (ADHICS)—with secure exchange through Malaffi. However, when it comes to AI, we are still in the early to mid stage. Hospitals are already using AI in diagnostics, patient engagement, and operations—but governance is still catching up. This becomes even more important with the rise of Agentic AI.”
While sectors such as healthcare are already confronting these challenges head-on, the broader market is still in transition, with adoption often moving faster than governance frameworks.
Tejas Gajjar, CIO at Meysan notes, “The GCC market is transitioning rapidly from sovereign cloud to sovereign AI, driven by state-level capital and high-level government mandates, but it has yet to adopt a complete AI-focused initiative. In other regions, AI is advancing through private investment, strong data privacy, and strict frameworks such as GDPR. In my view, the GCC still needs to adopt the right frameworks, guidelines, and privacy standards. There is more to be done beyond how the market is currently moving. As I mentioned earlier, Arabic AI models will make a significant impact.”
This gap is likely to define the next phase of the region’s AI journey.

One of the most complex and nuanced aspects of the sovereignty conversation is the role of hyperscalers, balancing their scale and innovation with the need for control.
Jacob explains, “Hyperscalers are evolving, but within clear boundaries. They are adding sovereign constructs, dedicated regions, local control planes, data residency guarantees, and restricted operator access are now becoming standard. This is not just positioning, there is real architecture behind it. They are adapting their AI stacks. More of the AI lifecycle can now sit within defined boundaries. They are partnering locally, joint ventures, in-country entities, and regulated cloud offerings are aligning more closely with national sovereignty agendas. But the constraints are still very real. Control is still shared, as core platform dependencies, update cycles, and underlying IP remain with the provider. You are not fully sovereign, you are operating within a controlled perimeter. AI sovereignty is still early. Owning data is one step, owning models, training pipelines, and decision logic without external reliance is where the real gap still sits.”
This makes it clear that while hyperscalers are adapting, they are not relinquishing core control. This reality forces organizations to rethink how they design their architectures.
Kiran says, “The practical answer is a sovereignty-by-design architecture that is deliberately layered.”
Such architectures allow organizations to balance innovation with control, rather than treating them as mutually exclusive.
At the same time, flexibility is becoming a key requirement. This balance also requires a shift in how CIOs approach deployment and flexibility.
Tejas adds, “We should move away from a one-solution-fits-all approach. Instead, CIOs should focus on building strong connectivity between data to achieve the best outcomes. They must clearly define models, portability, and control features. There are

also many open-source AI options that can be aligned to specific requirements. This way, organizations do not lose innovation and can apply the best-fit scenarios. AI should not replace humans, or the thinking process.”
Execution: skills and operating models
Sovereign AI is not just a technology challenge; it requires a fundamental shift in how organizations build capabilities and operate.
Kiran says, “Sovereign AI requires a fundamentally different talent and operating model than conventional IT or even cloud, and the skills gap across MEA is significant and underestimated. On the talent side, organizations need what I call the sovereign AI triad: engineers who understand model behavior and can govern AI systems, data architects who can design sovereignty-compliant pipelines, and governance professionals who can translate regulatory and strategic requirements into operational controls. Today, most enterprises have fragments of this capability, but rarely is it integrated into a coherent function.”
This is not just a capability gap; it reflects a deeper shift in how organizations approach AI itself.
He adds, “On the operating model side, the critical shift is from procurement-led AI to engineering-led AI. When AI is sourced as a service from a hyperscaler, the model is vendor-led. In a sovereign AI setup, organizations are running infrastructure, governing models, and making architectural decisions that require internal capability. I would also emphasize the importance of AI governance at the board level. Organizations making genuine progress on sovereign AI have boards that understand what is at stake and are investing accordingly. AI sovereignty is not a technology decision, it is a business strategy decision.”
This shift reflects a broader transition, from consuming technology to owning and building it. Beyond individual organizations, this shift is also reshaping how governance is structured at a systemic
level.
Dr. Sreejit adds, “In a sovereign AI context, organisations must transition from viewing digital governance as a compliance task to a strategic enterprise capability by establishing institutionalized AI Governance Boards and appointing Chief AI Officers to oversee "sovereign-by-design" architectures. Operating models must evolve to include an integrated governance stack that manages data provenance and resident compute while adopting FinOps to navigate the financial "sovereign premium" and ensure jurisdictional resilience. To bridge a profound skills gap affecting approximately 70% of workers, organisations should prioritize specialized training for ML engineers and AI system assessors alongside building universal AI literacy that blends technical proficiency with critical thinking and cultural nuance.”
For CIOs, this transition ultimately comes down to execution as to how these principles translate into day-to-day decisions.
Tejas says, “Audit AI supply chains by mapping where AI vendors host data, where their models are trained, and who owns the intellectual property. Adopt hybrid and open-source models by investing in open-source options that can run on secure internal infrastructure. Implement strict data provenance with clear tracking systems to know exactly what data was used to train or fine-tune operational models. Design for portability by ensuring AI workflows can be easily migrated between cloud providers or brought back on-premise without losing historical data.”
Looking ahead, sovereignty is set to evolve further as AI becomes embedded into enterprise operations.
Dr. Shijin says, “Sovereignty will move from just data control to full control of AI—how it is built, used, governed, and how it acts.”
Kiran concludes, “Three to five years from now, I believe the sovereignty conversation will have bifurcated into two distinct tracks. The first track, the regulatory and compliance dimension which will have largely been resolved. The second track, sovereign intelligence, will be where the real strategic competition plays out. As AI becomes embedded in enterprise operations, the organizations that have invested in building proprietary intelligence, models trained on their own data, tuned to their specific contexts, and governed by frameworks they own will have compounding advantages. Those that have outsourced their intelligence layer to commoditized external models will find themselves in a structurally weaker position.”
The sovereignty conversation in the Middle East is entering a new phase, one defined not just by data or infrastructure, but by control over intelligence itself.
For enterprises, the implications are significant. Sovereignty is no longer a compliance requirement or a technical consideration. It is becoming a defining factor in resilience, competitiveness, and long-term strategic positioning.
Organizations that recognize this shift early, and invest in building, governing, and owning their intelligence, will be better positioned to navigate the next phase of digital transformation. Those that do not risk becoming dependent on external ecosystems in a world where control over intelligence is rapidly becoming the ultimate differentiator.
Patrick Smith, Field CTO EMEA at Everpure, explores how the success of AI initiatives increasingly depends on storage infrastructure that can keep pace with the scale, speed, and energy demands of modern AI workloads.
It’s clear that the AI gold rush cannot be ignored, however, it takes significant investment to participate. So, how do organisations maximise the chances of success for AI projects, and what considerations need to be made for the underlying infrastructure?
AI workloads fall into two broad categories: training — when a model learns from a dataset — and inference, when it applies what it’s learned to new data. However, critical steps are taken even before training, including data collection, preparation, and curation. The nature of this data varies widely, from archive data to structured transactional databases, often with unpredictable data governance.
What is consistent, is that AI is resource-intensive. The energy consumption and voraciousness of GPU processing during training is well-known. Frequent checkpointing during training only adds to the demands on infrastructure. These checkpoints ensure model recoverability, rollback capability, and compliance, further increasing data storage capacity needs and associated energy consumption.
Retrieval-augmented generation (RAG), which integrates internal datasets into LLMs, introduces additional storage complexity, relying on vectorised data — datasets translated into high-dimensional vectors to enable similarity comparisons. This transformation can inflate dataset size significantly, sometimes by a factor of 10.
Post-training, inference generally requires less compute power but still involves ongoing data storage — both for logging results and the data itself being analysed.
AI’s growing energy footprint is another critical factor. Some sources have it that AI processing takes north of 30x more energy to run than traditional task-oriented software and that datacentre energy requirements are set to more than double by 2030. At the rack level, power usage has jumped from under 10kW to 100kW, or even more in some AI clusters, driven largely by the demands of high-performance GPUs.
This introduces a trade-off: every watt used by data storage is a watt not available to GPUs. Efficient, high-performance storage is essential to feed data to GPUs at pace, while minimising the strain on already constrained power budgets. Data storage can also deliver additional performance gains, for example, through key value caches which hold onto frequently accessed data, prompts,

and conversations to reduce repetitive GPU processing. Cached information can improve responsiveness, even for high-frequency workloads like RAG, trading, and chatbots. Overall, caching can accelerate inference by up to 20 times, maximising GPU efficiency, reducing costs, energy consumption, and empowering scalable and responsive enterprise AI applications.
The role of data storage in AI infrastructure is to provide high-throughput, low-latency access to large datasets. Poor storage performance can create GPU bottlenecks, undermining the value of expensive compute hardware.
AI workloads typically require hundreds of terabytes, if not petabytes of capacity, and the ability to retrieve data rapidly — whether for training new models, running inference, or integrating fresh data sources. This applies not only to real-time needs, but also to archival data that may be re-used or reprocessed. High density QLC flash has emerged as an ideal solution for high performance AI storage needs, due to its combination of speed, capacity, reliability and energy efficiency, when used in the right modern storage platform. Use of QLC means customers can store data on flash storage at costs that approach those of spinning disk, but can get to it at the speed essential for AI workloads.
Some vendors now offer storage systems tailored for AI workloads, including solutions certified to work with Nvidia compute stacks. These may come bundled with optimised RAG pipelines and integrated with Nvidia microservices — simplifying deployment and improving performance consistency.
Delivering AI at scale requires more than powerful GPUs. It depends on a foundation of robust, efficient, and responsive infrastructure.
Data storage plays a pivotal role in that foundation. From the earliest stages of data preparation, through training to customer facing inference, AI workloads depend on fast, scalable, and increasingly energy-conscious storage solutions. Without it, even the best-funded projects risk faltering under the weight of their own complexity.
Mohammed Aboul-Magd, VP of Product at SandboxAQ discusses emerging threats including stealth exfiltration, rogue agents, and non-human identity risks
For years, cybersecurity experts have echoed the refrain that humans are the weakest link. If something went wrong, it was usually because someone clicked the wrong link, reused a password, or fell for a well-crafted phishing email.
As a result, entire security strategies were built around fixing human behaviour. We trained staff relentlessly, ran phishing simulations, rolled out password managers, then layered on zero trust, privileged access management and ever more sophisticated controls designed to protect people from themselves. The assumption was simple: secure the human, and you secure the organisation. Today, stopping here is no longer sufficient.
Imagine a company with 100 employees and, traditionally, 100 identities to protect. Now what if that same organisation was to take on thousands or even millions identities almost overnight? This isn’t a hypothetical. Across enterprises, API keys, tokens, certificates and cryptographic secrets are being spun up, allowing systems to talk to each other, act autonomously and make decisions at machine speed. As a result, the dynamic has shifted and today humans are no longer the weakest link. Non-human identities (NHIs) are.
AI agents represent a fundamental shift from automation to autonomy. Traditional automation followed scripts. AI agents pursue objectives within the permissions they’re given, choosing their own paths to get there. In doing so, they operate as delegated digital actors, each requiring its own cryptographic identity.
The scale is hard to overstate. In large enterprise environments, non-human identities already outnumber human ones by as much as 40,000 to one. Yet while human users are closely monitored, trained and governed, machine identities often exist in the shadows, poorly inventoried and rarely rotated.
Unsurprisingly, attackers have noticed. According to the 2025 Verizon Data Breach Investigations Report, credential abuse is now the top initial access vector, involved in 22% of breaches. The message is blunt: attackers are not breaking in, they are logging in.

Mohammed Aboul-Magd VP of Product, SandboxAQ
One of the most worrying shifts enabled by AI agents is the move away from noisy, smash-and-grab attacks towards silent, longterm residency. AI-powered attackers don’t get tired. They can probe APIs and authentication flows continuously, testing credentials, mapping permissions and looking for misconfigurations at
a pace no human team could match. When they find an orphaned API key or a forgotten service account, they don’t need malware. They simply authenticate.
Once inside, compromised machine credentials allow attackers to blend seamlessly into legitimate system traffic. There are no suspicious logins from unusual locations, no panicked employees reporting odd behaviour. From the defender’s perspective, everything looks normal, because the attacker is using exactly the same credentials the system expects.
This is where stealth exfiltration becomes so dangerous. Data doesn’t leave in dramatic bursts. It trickles out quietly, via authorised paths, signed with trusted keys.
A major contributor to this problem is the continued reliance on long-lived machine credentials. Many AI agents depend on static keys that are rarely rotated, if they are rotated at all. In fast-moving environments, credentials are created for short-term projects and never properly retired.
The result is a vast, unmonitored credential graveyard. Security teams often lack a real-time inventory of which keys exist, what they’re connected to, or whether they’re still in use. That visibility gap gives attackers exactly what they want: credentials that still work, but that no one is watching.
Of course, none of this is happening in a vacuum. Organisations are under intense pressure to deploy AI faster. Board-level oversight of AI has surged, with disclosures among S&P 500 companies increasing by more than 84% between 2023 and 2024. Speed has become a strategic imperative.
But speed without guardrails is not innovation, it’s risk. The SandboxAQ AI Security Benchmark Report 2025 found that only 6% of organisations have reached an AI-native security posture, with protections integrated across both IT and AI systems. That leaves the vast majority running AI agents on top of identity foundations that were never designed for autonomy at scale.
We have seen this pattern before. From missed patches at Equifax to stolen signing keys in the Storm-0558 incident, the lesson is consistent: credentials are treated as an afterthought, until they aren’t.
Defending against agent-driven threats requires a mindset shift. Human-speed processes cannot govern machine-speed systems.
Security policies must be defined programmatically, so agents can act quickly within safe boundaries rather than waiting for manual approval. Runtime controls that inspect prompts, inputs, outputs and data flows allow organisations to protect sensitive
information without strangling innovation. This is how security moves from “block by default” to “safe by design”.
Equally critical is real-time visibility. Organisations need a continuously updated inventory of every non-human identity, mapped to where it’s used and what it can access. Without that, defenders are always reacting after the fact.
Finally, isolation matters. Secrets should never be exposed directly to applications or agents. Trust needs to be anchored in hardened cryptographic services that can authenticate and sign without ever releasing the underlying keys.
The cybersecurity battleground has shifted. It is no longer centred on careless employees, and it is not yet about runaway artificial general intelligence. It sits squarely in the identity layer, grounded in the reality that non-human identities now outnumber us by tens of thousands to one.
Attackers already understand this. Until defenders catch up, organisations aren’t being breached, but slowly bled dry.
Security policies must be defined programmatically, so agents can act quickly within safe boundaries rather than waiting for manual approval. Runtime controls that inspect prompts, inputs, outputs and data flows allow organisations to protect sensitive information without strangling innovation.
Gabriel Bernadett-Shapiro, Distinguished AI Research Scientist at SentinelOne argues that current LLM evaluations fall short of capturing the complexity of security operations, highlighting the gap between impressive benchmark results and meaningful outcomes in live SOC environments.
For security leaders today, it is impossible to escape the flood of claims around AI. Every new model comes with colorful charts, long benchmark names, and bold numbers that promise state-of-the-art performance. On paper, it looks impressive, but in a live SOC, the reality is far more complicated.
Over the past few years, LLMs have been positioned as game changers for cyber defense. They are marketed as tools that will identify and patch vulnerabilities, write secure code, shorten investigations, and remove the friction from daily security processes. Their value proposition is to raise the cost for attackers and reduce it for defenders.
To support these claims, vendors rely heavily on benchmarks. They assume that if a model scores highly on a benchmark that is labelled “security”, then it must be ready to help real analysts in real SOCs. Independent research, such as the SECURE benchmark, highlights that many existing evaluations focus on general language abilities and fail to assess realistic security understanding and reasoning, underscoring the gap between benchmark scores and operational cybersecurity value. We don't have a shortage of benchmarks, but there is a mismatch between what they measure and what defenders actually need.
The first generation of LLM benchmarks in 2023 focused on multiple choice exams over clean text. These tests were useful in the early days. They provided simple, reproducible numbers that allowed researchers to compare models. Over time, two things happened. Firstly, models grew more capable, and scores started to bunch at the top. Many benchmarks became “saturated”, with leading models all scoring close to perfect. Second, the tests themselves drifted further away from the day-to-day experience of a SOC analyst.
In response, more specialized cybersecurity benchmarks emerged. Some simulate realistic logs in a cloud tenant. Others transform malware sandbox reports or cyber threat intelligence (CTI) documents into multiple choice questions. A few attempt to map model behavior to risk themes such as phishing, exploit generation, or insecure code suggestions. Taken together, these

Gabriel Bernadett-Shapiro
Distinguished AI Research Scientist, SentinelOne
efforts are a step forward from generic language exams. However, they share an important limitation of measuring isolated tasks, not the continuous workflows that define real security operations. Across the industry, several well-known benchmarks have tried to evaluate LLM performance for cybersecurity, including Microsoft’s ExCyTIn-Bench, Meta’s CyberSOCEval and CyberSecEval 3, and Rochester Institute’s CTIBench. Each offers valuable insights, yet all share the same constraint: they measure tasks, not the real, continuous workflows that define SOC and CTI operations.
Microsoft’s ExCyTIn-Bench simulates a realistic Azure-like
environment and sees whether LLM agents can run multi-step investigations across logs. Despite the controlled setup, models struggled, with top scores below 40%, suggesting that even structured investigations are challenging.
Meta’s CyberSOCEval transforms malware sandbox logs and CTI reports into multiple-choice questions. While models perform above random baselines, they still miss most malware classifications and nearly half of threat-intel questions, showing that LLMs can surface signals but cannot reason like analysts.
CTIBench, designed for threat-intelligence workflows, assesses tasks such as mapping vulnerabilities, interpreting attacker techniques, and assigning severity. These are useful knowledge checks, but don’t reflect the extended investigations, evolving intelligence, and judgment calls that define real CTI work.
Together, these benchmarks have the same main issue. They reduce complex, multi-stage investigations into isolated exam-style questions with predefined answers, a structure that does not match the messy reality of live security operations.
In the SOC, work is not a clean PDF with a single question at the end. It is a queue of alerts from different tools, fragments of telemetry, chat messages between teams, and external intelligence that may or may not be relevant. Analysts must triage, correlate, pivot, escalate, and sometimes start again when a hypothesis fails. Most current benchmarks compress this reality into a static question-and-answer format. The model is given a carefully prepared slice of context and asked to pick the correct answer or generate a short response. There is no cost for missing a subtle but critical indicator. There is no way it decides when to stop, when to escalate, or when to challenge the premise of the question itself.
Some log-based benchmarks go further by placing the model in a constrained environment and asking it to issue queries over time. Even there, the fundamental unit of evaluation remains a question with a predefined ground truth answer. The model is not asked to run an incident to completion, to weigh conflicting signals, or to trade speed against certainty the way a human team must.
In other words, we are measuring how well models perform on security-themed tasks, not how much they improve the end-toend security workflow. For defenders, that distinction matters. The goal is not to pass the exam but to reduce the overall business risk.
Another pattern that appears across several evaluations is the gap between general reasoning and security-specific reasoning. Models that perform extremely well on coding and math benchmarks do not automatically excel at malware analysis, CTI interpretation, or multi-step investigations over heterogeneous logs. In multiple studies, reasoning models that think in more steps don't show the same uplift on security tasks as they do on pure math or programming challenges.
This tells us something important. LLMs can store a significant amount of security knowledge. They can recognize familiar patterns and restate context. But it doesn't mean they can think like an experienced analyst who has spent years deciding which questions to ask, signals to trust, and alerts to discard safely. If organizations assume that high scores on generic reasoning benchmarks translate directly into analyst-level performance, they risk overestimating what the model can safely automate.
Benchmarks are attractive because they seem objective, but practically, many evaluations have gaps in basic statistical hygiene.
Results are often reported from a single run with one set of parameters, without confidence intervals or robustness checks. Contamination, where benchmark data overlaps with what the model saw during training, is rarely tested in a systematic way. Many benchmarks also rely on LLMs to generate questions or grade answers, frequently using a model from the same vendor that is being evaluated.
This creates a closed loop. If the judging model has a certain bias or blind spot, that bias is baked into the evaluation. If the prompts for the judge are public, it becomes easier to tune a model or a prompting strategy that performs well on the benchmark, without necessarily performing better in real incidents. Numbers that appear precise may be fragile under small changes in setup.
"Together, these benchmarks have the same main issue. They reduce complex, multi-stage investigations into isolated exam-style questions with predefined answers, a structure that does not match the messy reality of live security operations"

For governance decisions that affect customers, regulators, and critical infrastructure, that is not a strong foundation.
Real SOCs operate across hybrid environments and a patchwork of tools like on-prem infrastructure, cloud providers, identity platforms, EDR agents, ticketing systems, collaboration tools, wikis, and more. Telemetry is uneven, sensors are sometimes misconfigured, and documentation is incomplete.
Most benchmarks do not reflect this complexity. They focus on a single fictional tenant, very few logs, or a curated collection of reports. PDFs and JSON logs are flattened into text and turned into questions. Time and change are not included. New intelligence never arrives halfway through an investigation. Attacks will not adapt to the model’s behavior. These simplifications are understandable in a research context, but they are not enough to understand how an LLM will behave as a copilot for live operations or as a component in an autonomous detection and response stack.
None of this means that LLMs have no place in security. They can add value as assistive tools by helping with summarizing long reports, standardizing narrative formats, generating candidate hypotheses, or drafting initial responses with human supervision.
The issue is not whether we should use AI but whether our current benchmarks allow us to make informed decisions on how it should be used.
For that, defenders need evaluations that measure the workflow level outcomes, such as time to detect, time to contain, and mean time to remediate, not just answer accuracy on isolated questions. It should also show heterogeneous, noisy environments with incomplete and conflicting data, not only clean and fully labelled examples. Also, assign real costs to missed signals, unnecessary data collection, and incorrect escalation decisions, so that tradeoffs become visible. Additionally, treat checking and validating as a needed and sometimes optimal behavior, rather than forcing a confident answer every time. Lastly, using diverse, well-calibrated judges and incorporating human validation where there is a high risk.
As vendors, we also have a responsibility to align our claims with this reality. Benchmark charts are useful, but they should never be the only input to a deployment decision. Security teams should feel empowered to ask how a model was evaluated, what assumptions were made, and how those conditions compare to their own environment.
LLMs are here to stay in cybersecurity. The question is not whether they will be used, but how intelligently and safely we deploy them.
Today’s benchmarks represent an important step beyond generic language testing. They also reveal how far we still have to go in terms of multi-hop investigations. General reasoning skills do not automatically translate into security reasoning and evaluation pipelines can introduce their own blind spots.
Until we design benchmarks that reflect the lived experience of defenders, high scores on security exams will remain a poor proxy for real-world uplift. For organizations across the META region and beyond, choose AI systems that are tested against operational outcomes, not just academic metrics. Also, make sure that every claimed improvement can be traced back to tangible risk reduction. Only then will AI in the SOC move from promise to proof.
"Benchmark charts are useful, but they should never be the only input to a deployment decision. Security teams should feel empowered to ask how a model was evaluated, what assumptions were made, and how those conditions compare to their own environment. "
Khalid Aljamed, GM, META at Submer outlines why full-stack AI infrastructure is becoming central to achieving true sovereignty and long-term competitiveness in the AI era.

Khalid Aljamed General Manager, META, Submer
Building a full-stack AI infrastructure solution gives enterprises and governments complete ownership and control over their AI capabilities. In an era where AI is becoming central to economic and national strength, infrastructure is no longer just a technical detail, it is a strategic requirement for sovereignty. Sovereignty is not defined by access alone, but by the ability to design, build, and operate infrastructure as a fully integrated system.
AI didn’t appear overnight; it is the culmination of decades of progress in high-performance computing, cloud expansion, and advanced chip design. What has changed is the pace. AI is now scaling at an industrial level, transforming how we must design and deliver the underlying hardware.
Training large models requires immense computing power, while real-time applications depend on ultra-low latency. This makes purpose-built infrastructure essential. However, much of today’s landscape remains fragmented. This siloed approach creates inefficiencies and limits control, a growing concern for nations that view AI as a pillar of resilience.
One of the most significant hurdles today is the gap between demand and delivery. Traditional datacentre build cycles can take
up to three years, which is far too slow for the current pace of AI adoption.
To close this gap, we must rethink how we deploy:
• Modular Datacenters: Utilizing standardized, pre-engineered designs allows organizations to build faster and scale more easily.
• Edge Flexibility: Infrastructure must extend from core facilities to the edge to support real-time processing.
• Speed as a Requirement: In this market, speed is no longer just a competitive advantage; it is a necessity for survival.
Full-stack AI infrastructure is about the bigger picture. It isn't just about building a facility; it’s about managing the entire ecosystem that supports AI. Fragmented management is a bottleneck; at this level of complexity, you cannot treat cooling and compute as separate silos.
This integrated approach starts with the fundamentals: land, power, and design and extends to high-density liquid cooling solutions. It requires the seamless integration of compute hardware, network connectivity, and edge nodes. When these elements are "tuned" to work together, the result is an infrastructure that is powerful, efficient, and truly scalable.
Delivering this level of infrastructure requires coordination across multiple domains, from engineering and construction to supply chain and operations.
Success is determined by the ability to manage these elements as a single, cohesive program. This ensures that connectivity and performance are built-in from the start rather than added as an afterthought.
The Middle East is in a prime position to lead this transformation. With clear national strategies and fewer legacy constraints, the region can move directly toward a full-stack, sovereign approach. We see this already in the UAE’s ambition to become an AI-native government, ensuring critical data and workloads remain within its borders.
This is more than a technology shift; it is a strategic one. Those who take control of their infrastructure today will define the economies of tomorrow.
Full-stack infrastructure is the foundation for long-term digital sovereignty and regional competitiveness.
Craig Sanderson, Principal Cyber Security Strategist at Infoblox examines why National Institute of Standards and Technology’s SP 800-81r3 is forcing a rethink of DNS—from a background utility to a critical control point for security, resilience, and emerging AI-driven networks.
The release of the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-81 Revision 3 marks a pivotal moment for the cybersecurity and networking community. For years, SP 800-81 has been regarded as the gold standard for DNS deployment and operational best practices. But until now, it lagged behind the rapid evolution of both the DNS protocol and the threat landscape.
That gap has finally been addressed.
Why This Update Matters
DNS remains one of the most critical, and paradoxically overlooked, services in modern IT environments. It underpins every digital interaction, yet too often operates quietly in the background, escaping the scrutiny applied to other parts of the security stack.
NIST SP 800-81r3 changes that dynamic.
This revision incorporates years of innovation in DNS technology, including:
• The rise of encrypted DNS (DoH, DoT) to protect user privacy and integrity
• Advances in DNS security controls and architectures
• Recognition of DNS as a strategic control plane, not just a utility service
Crucially, it also acknowledges the emerging role DNS will play in AI-enabled enterprises. With initiatives like the Internet Engineering Task Force (IETF) DNS for AI Discovery (DNSAID) draft, DNS is evolving into a foundational layer for service discovery, orchestration and trust in AI-driven environments.
In short, DNS is no longer just infrastructure. It is becoming mission-critical intelligence infrastructure.
For full details, see the updated NIST guidance: NIST SP 80081r3
Despite its importance, DNS continues to “fly under the radar” in many organizations.
• Network and IT teams focus on availability and performance
• Security teams often lack visibility into DNS risks and controls

Craig Sanderson
Principal Cyber Security Strategist, Infoblox
This disconnect creates a dangerous blind spot.
We’ve already seen what happens when DNS fails or is exploited. The large-scale disruptions affecting major cloud providers like Azure and AWS in October 2025 demonstrated how systemic DNS issues can cascade into widespread outages. At the same time, threat actors are increasingly targeting DNS for command and control, data exfiltration and evasion.
For many organizations, DNS risk remains hidden, until it suddenly isn’t.
Protective DNS: From Niche to National Strategy
One of the most significant shifts reflected in SP 800-81r3 is the growing importance of Protective DNS (PDNS) as a frontline cybersecurity control.
Governments around the world are already moving in this direction:
• The U.K.’s National Cyber Security Centre (NCSC)
• U.S. federal adoption through the Cybersecurity and Infrastructure Security Agency (CISA) and other agencies
This is not a coincidence. Protective DNS provides a scalable, preventative control that can stop threats before they reach endpoints or users.
NIST’s updated guidance reinforces what many national cybersecurity agencies already recognize: DNS is one of the most effective, and underutilized, security enforcement points available.
The “Tick-Box” Trap in DNS Security
Despite growing awareness, many organizations have approached DNS security as a feature to be enabled, rather than a discipline to be engineered.
A common pattern is the reliance on existing security platforms, such as firewalls or secure web gateways, to provide “good enough” DNS protection. While these tools may offer DNS-related features, they were not designed to address the full scope of DNS risk.
This has led to a false sense of security.
NIST SP 800-81r3 makes it clear that DNS security is far broader and more complex than a single control point. It spans:
• Architecture and infrastructure design
• Availability and resilience engineering
• Data integrity and trust (e.g., DNSSEC)
• Privacy protections (e.g., encrypted DNS)
• Threat detection and prevention (e.g., Protective DNS)
• Operational visibility and governance
In other words, DNS security is not something that can be “bolted on.”
This shift is particularly important in the context of evolving regulation. Increasingly, regulators are focusing on outcomes. Resilience, risk reduction and service continuity. Rather than box-ticking exercises.
Organizations that rely on partial or superficial controls will struggle to demonstrate those outcomes.
To meet both the spirit and the letter of emerging requirements, organizations must adopt a holistic view of DNS security; one that aligns with the breadth of guidance outlined in SP 800-81r3.
If organizations haven’t yet prioritized DNS security, regulation may soon force the issue.
The European Union’s NIS2 Directive explicitly references NIST SP 800-81, cementing its position as the global benchmark for DNS best practices. This has significant implications:
• Over 180,000 organizations fall within the scope of NIS2.
• DNS will need to be addressed as part of cybersecurity and resilience strategies.
• National regulators are likely to adopt and enforce these best practices.
And this is just the beginning.
In the United Kingdom, the proposed Cyber Security and Resilience Bill signals a significant shift in how cyber risk will be regulated, particularly for critical infrastructure and essential digital services.
As this framework evolves, it is expected to drive more detailed technical expectations for organizations operating critical services. Given the central role DNS plays in those systems, it is difficult to envisage a scenario where DNS is not explicitly addressed, and where globally recognized best practices, such as those outlined in NIST SP 800-81r3, are not reflected in future guidance.
More broadly, there is a growing opportunity for regulators globally to align around common frameworks like SP 800-81r3. Doing so would bring:
• Consistency across jurisdictions
• Clarity for organizations navigating compliance
• Stronger security and resilience outcomes at both technical and business levels
The release of SP 800-81r3 should serve as a clear signal: Now is the time to re-evaluate your DNS security strategy.
Organizations need to ask themselves:
• Do we have visibility into DNS activity across our environment?
• Are we leveraging DNS as a proactive security control?
• Is our architecture aligned with modern best practices and emerging standards?
• Are we prepared for regulatory expectations tied to DNS resilience?
For many, the honest answer will be “not yet.”
NIST SP 800-81r3 is more than just an update. It is a reset moment for how organizations think about DNS. It highlights a reality that can no longer be ignored:
• DNS is foundational to cybersecurity
• DNS is critical to resilience
• DNS will be central to the future of AI-driven networks
Organizations that act now can turn DNS into a strategic advantage. Those that don’t may soon find themselves catching up under pressure from regulators, or worse, in response to an incident.
Mostafa Kabel, CTO, Mindware Group explores the rise of Physical AI and how it is reshaping industries, infrastructure, and the future of human-machine collaboration.
Artificial intelligence is rapidly moving beyond screens and software into the physical world. While generative AI has captured public attention, a more consequential shift is underway. One that will reshape industries, infrastructure, and the way humans interact with machines. This shift is toward what we call Physical AI.
At its core, Physical AI refers to systems that can sense, decide, and act in real-world environments. Unlike software-only AI, which generates outputs without immediate consequences, Physical AI operates under the constraints of physics, time, safety, and uncertainty. Its decisions do not live in abstraction. They directly affect people, assets, and environments. A mistake is not just an incorrect answer; it can result in real-world damage or risk.
This distinction fundamentally changes how these systems must be designed. Physical AI requires tightly integrated perception, reasoning, and control, with a strong emphasis on reliability, safety, and accountability.
It is tempting to think of Physical AI as simply robotics enhanced with AI. In reality, it is better understood as AI that happens to have a physical embodiment. Traditional robotics has long relied on predefined rules and controlled environments. Physical AI, by contrast, prioritizes intelligence - systems that can learn, adapt, and reason under changing conditions.
The “body” of Physical AI, whether a robot, vehicle, or industrial machine, is merely the interface through which intelligence interacts with the world. This broader perspective expands its relevance far beyond robotics, encompassing autonomous vehicles, medical devices, energy systems, and smart infrastructure.
Moving AI from controlled digital environments into the physical world introduces a fundamental challenge: uncertainty. Real-world environments are noisy, incomplete, and constantly changing. Sensors fail, data arrives late, and conditions rarely match training scenarios.
At the same time, these systems must make decisions in real

Mostafa Kabel CTO, Mindware Group
time, often within milliseconds, and with limited computational resources. Safety and reliability become paramount, as errors can have irreversible consequences. Integration across hardware, software, networking, and control systems adds another layer of complexity, while testing and validation remain inherently difficult because not every scenario can be anticipated.
To overcome these challenges, simulation and digital twins are becoming essential tools. Training Physical AI purely in the real world is slow, expensive, and risky. Simulation enables systems to experience millions of scenarios rapidly, including rare or dangerous edge cases.
Digital twins (virtual replicas of physical assets) allow continuous learning by combining simulated and real operational data. Synthetic data further fills gaps where real-world data is scarce. Together, these approaches accelerate development, reduce risk, and improve system robustness.
Industries with complex physical operations and high demands for safety and efficiency will see the earliest impact. Manufacturing and logistics are already benefiting from gains in productivity and predictive maintenance. Healthcare will follow with intelligent medical devices and robotic assistance. Energy and utilities will use Physical AI for grid optimization and asset inspection, while defense and smart city infrastructure will adopt it for autonomous systems and large-scale coordination.
Physical AI represents a shift from rigid automation to adaptive intelligence. Traditional automation excels in controlled environments but struggles with variability. Physical AI systems, on the other hand, learn from experience and adapt to changing conditions.
This transforms how organizations think about operations. Instead of automating predefined tasks, they build systems that continuously optimize performance, safety, and efficiency over time.
A critical enabler of Physical AI is edge computing. Many physical decisions must be made instantly, where cloud latency is unacceptable. Real-time inference at the edge allows systems to perceive and act immediately, ensuring both responsiveness and safety.
Edge computing also improves resilience. Systems can continue operating even with limited connectivity and reduces bandwidth and data privacy concerns. In practice, Physical AI relies on a hybrid model: centralized systems for training and distributed edge systems for real-time execution.
Perhaps the most profound impact of Physical AI will be on the relationship between humans and machines. Rather than replacing people outright, these systems are more likely to augment human capabilities.
Machines will take on repetitive, hazardous, or precision-intensive tasks, while humans focus on supervision, judgment, and exception handling. This shift will require new skills centred on system understanding and decision-making. Trust will become a critical factor. Workers must understand both the capabilities and the limits of intelligent systems.
In the near and medium term, Physical AI is more likely to transform jobs than eliminate them. While some roles will evolve, new ones will emerge around system design, supervision, maintenance, and optimization.
The real promise of Physical AI is not replacement, but amplification. By extending human capability into environments that are complex, dynamic, and often dangerous, it opens the door to safer, more efficient, and more intelligent systems across every sector of the economy.
"The “body” of Physical AI, whether a robot, vehicle, or industrial machine, is merely the interface through which intelligence interacts with the world. This broader perspective expands its relevance far beyond robotics, encompassing autonomous vehicles, medical devices, energy systems, and smart infrastructure"
Hewlett Packard Enterprise has introduced a comprehensive set of security innovations aimed at enabling enterprises to adopt AI securely while strengthening overall resilience across distributed environments. Central to this announcement is the launch of the HPE Juniper Networking SRX400 Series Firewalls, designed to extend carrier-grade security from the data center core to the edge, particularly as AI workloads expand into remote sites such as campuses, branches, and industrial environments.
The SRX400 series combines high performance with a compact footprint and hardware-rooted protections, ensuring secure operations even in space-constrained locations. Alongside this, HPE has enhanced its hybrid mesh firewall architecture with new AI governance capabilities, enabling organizations to monitor and control AI application usage, enforce policies, and prevent sensitive data exposure through prompt-level inspection and identity-based protection.
Additional advancements include resilience-focused improvements across HPE’s portfolio, such as enhanced cyber recovery with HPE Zerto, confidential computing integrations for securing data in use, and post-quantum cryptography readiness to address emerging threats. These innovations collectively reinforce HPE’s approach of embedding security directly into infrastructure, helping organizations maintain visibility, compliance, and control while scaling AI adoption across hybrid cloud environments.

Highlights:
• SRX400 Series firewalls: Extend carrier-grade, hardware-rooted security from core to edge
• AI governance capabilities: Control AI app usage with visibility, prompt inspection, and policy enforcement
• Resilience-focused security: Enhancements across recovery, confidential computing, and hybrid cloud protection
• Future-ready cryptography: Post-quantum security capabilities aligned with emerging standards
Seagate Technology has introduced its next-generation Mozaic 4+ platform, marking a major leap in high-capacity storage designed for AI-scale data environments. Built on heat-assisted magnetic recording (HAMR) technology, the platform is the industry’s only HAMR-based solution deployed at production scale, already qualified and in use by leading hyperscale cloud providers.
Mozaic 4+ supports hard drive capacities of up to 44TB today, with a clear roadmap toward 100TB through higher per-disk densities. The platform integrates ad-
vanced nanophotonic laser technology, a next-generation suspension architecture, and an enhanced system-on-chip, enabling precise data recording at ultra-high densities while maintaining enterprise-grade reliability.
Designed for modern data center demands, Mozaic 4+ addresses the explosive growth of AI-driven workloads, including training datasets, archival storage, and multimodal content. By increasing capacity without expanding physical infrastructure, it improves rack density and energy efficiency. In large-scale deployments, it can
reduce data center footprint, lower power consumption, and significantly optimize total cost of ownership.
With vertical integration of key HAMR components, Seagate ensures better manufacturing control, faster qualification cycles, and improved supply chain resilience, positioning Mozaic 4+ as a foundational technology for sustainable, high-performance AI data infrastructure.
Highlights:
• Industry-first HAMR at scale: Only
NetApp has introduced the latest generation of its EF-Series storage systems, designed to deliver high-performance, scalable infrastructure for data-intensive workloads across AI, high-performance computing (HPC), and enterprise databases. The new EF50 and EF80 models are built to support emerging use cases such as sovereign AI clouds and AI-powered industrial environments, where speed, throughput, and efficiency are critical.
Engineered for demanding environments, the updated EF-Series delivers over 110GBps read throughput and 55GBps write throughput—representing a significant performance improvement over previous generations. With up to 1.5PB of storage in a compact 2U footprint and power efficiency reaching 63.7GBps per kW, the systems enable organizations to maximize rack density while reducing energy consumption and operational costs.
The systems are optimized for integration with high-performance parallel file systems such as Lustre and BeeGFS, ensuring efficient GPU utilization for AI model training and HPC simulations. In addition to performance gains, NetApp has focused on simplifying deployment and management, offering streamlined operations and enterprise-grade reliability backed by a proven installed base.
With these enhancements, the EF-Series strengthens its position as a cost-effective, high-throughput storage solution for organizations seeking to scale performance-driven workloads while maintaining efficiency and control.

• High-performance throughput: Delivers over 110GBps read and 55GBps write speeds
• Dense and efficient design: Up to 1.5PB storage in 2U with strong power efficiency
• Optimized for AI and HPC: Supports GPU-intensive workloads with parallel file system compatibility
• Simplified operations: Streamlined deployment, management, and enterprise-grade reliability
commercially deployed HAMR-based platform supporting hyperscale environments
• Up to 44TB capacity (scaling to 100TB): Enables massive data storage growth without infrastructure expansion
• AI-optimized efficiency: Improves capacity per rack and per watt, reducing energy use and footprint
• Vertically integrated innovation: Inhouse photonics and advanced architecture enhance reliability and production scalability

LLMs in 2030 Will Be up to 100 Times More Cost-Efficient Than the Earliest Models of Similar Size Developed in 2022
By 2030, performing inference on a large language model (LLM) with one trillion parameters will cost GenAI providers over 90% less than it did in 2025, according to Gartner, Inc. a business and technology insights company.
AI tokens are the units of data that GenAI models process. For the purposes of this analysis a token is 3.5 bytes of data, or approximately 4 characters.
“These cost improvements will be driven by a combination of semiconductor and infrastructure efficiency improvements, model design innovations, higher chip utilization, increased use of inference-specialized silicon, and application of edge devices for specific use cases,” said Will Sommer, Sr. Director Analyst at Gartner.

applications. Agentic models, for example, require between 5-30 times more tokens per task than a standard GenAI chatbot, and can perform many more tasks than a human using GenAI.
As a result of these trends, Gartner forecasts LLMs in 2030 will be up to 100 times more cost-efficient than the earliest models of similar size developed in 2022.
The forecasted model results are split between two sets of semiconductor scenarios:
Frontier scenarios: Model processing is based on a representation of cutting edge chips.
Legacy blend scenarios: Model processing is based on a representative blend of available semiconductors benchmarked to Gartner forecasts.
Modeled costs in the “blend” forecast scenarios are considerably higher than in the “frontier” scenarios, given lower computational power (see Figure 1).
However, falling GenAI provider token costs will not be fully passed on to enterprise customers. Moreover, frontier intelligence will demand significantly more tokens than current mainstream
While lower token unit costs will enable more advanced GenAI capabilities, these advancements will drive disproportionately higher token demand. As token consumption rises faster than token costs fall, overall inference costs are expected to increase.
“Chief Product Officers (CPOs) should not confuse the deflation of commodity tokens with the democratization of frontier reasoning,” said Sommer. “As commoditized intelligence trends toward near-zero cost, the compute and systems needed to support advanced reasoning remain scarce. CPOs who mask architectural inefficiencies with cheap tokens today will find agentic scale elusive tomorrow.”
Value will accrue to platforms that can orchestrate workloads across a diverse portfolio of models. Routine, high-frequency tasks must be routed to more efficient small and domain-specific language models, which perform better than generic solutions at a fraction of the cost when aligned to specialized workflows. Expensive inference of frontier-level models must be heavily gated and reserved exclusively for high-margin, complex reasoning tasks.


