The takeaways, in brief
- Compute is shifting back to the edge as AI agents move onto local devices: Worldwide edge spending is projected to climb from about $261 billion in 2025 to $380 billion by 2028, with AI being a top driver of that increase.
- That edge is already the most-attacked and least-watched layer of the enterprise, where attackers can hand off access in as little as 22 seconds, on devices that “typically lack” endpoint detection
- Cloud trust decisions should be enforceable locally through lightweight, certificate-based identity
The Pendulum Swings Back to the Edge
Computing has never sat still between the center and the edge.
Across human endeavors, there’s often a continuous struggle between centralization and decentralization. Computing is no different. Mainframes gave way to PCs, then data centers and the cloud brought back consolidation. [1] AI is the latest force pulling on the pendulum.
An AI coding agent like Claude Code or Cursor runs on a developer’s laptop, reading files and executing commands on the machine in front of it. New laptops and phones ship with neural processing units that run language models on the device, with no round trip to a data center.
By the end of 2025, Gartner expected AI PCs to make up 31% of worldwide PC shipments. [3] They also project half of all critical enterprise applications to sit outside centralized public cloud locations by 2027 [4].
Data that used to live behind a cloud provider’s security stack is increasingly created and processed on the device itself. While it’s a privacy gain, it’s also a governance and security problem. The cloud is still the best place to make a trust decision, but that decision now has to be enforceable at the edge, per device, workload, and agent, so access holds even when the link to the cloud does not.
The Trust Model Was Built for the Cloud
The security model most enterprises run was built for the cloud era, when identity, trust, and access decisions could all live in one place that every device reached up to. It also assumes the device can always reach that place.
Move the workload, the inference, and the AI agent down onto the local network, though, and that assumption starts to strain. If the thing being secured now sits at the edge, the machinery that decides who it is and what it may do has to be reachable from the edge, too.
The edge is already the most-attacked and least-watched layer of the enterprise. And a new class of autonomous AI agents is arriving on that edge faster than anyone has given it an identity.
The Edge is Already the Battlefield
The place that enterprises are now loading with AI compute is the same place where attackers already concentrate.
Mandiant’s M-Trends 2026 found that threat clusters “deliberately target edge and core network devices, such as virtual private networks (VPNs) and routers, that typically lack standard endpoint detection and response (EDR) telemetry.” And once inside, attackers move quickly. The time between an initial access event and hand-off to a secondary threat group is now 22 seconds. [5]
In fact, in recent years, the Cybersecurity & Infrastructure Security Agency (CISA), a part of the U.S. Department of Homeland Security, has documented the Chinese-associated Volt Typhoon group sitting inside U.S. critical infrastructure on end-of-life edge routers, pre-positioned for “disruptive or destructive” cyberattacks in a future crisis. [4]
And moving compute local doesn’t automatically make it safe. At USENIX Security 2025, researchers reconstructed the prompts and outputs of an on-device language model through a hardware cache side-channel, with no special privilege, at 98.7% and 98.0% similarity. The question of who a device, workload, or agent is, and what it may do, doesn’t disappear when the compute goes local. It just has to be answered there.
When the Path to the Cloud Goes Dark
The cloud is where a trust decision is best made. But a decision made in the cloud still has to reach the device that needs it, and in late 2025, that path failed twice in a single month.
In October, an AWS outage in northern Virginia took down dozens of services, including AWS STS and IAM authentication. Weeks later, an Azure Front Door failure disrupted Microsoft Entra ID and Microsoft 365. In both cases, the identity service itself went dark, because it rode the same infrastructure that broke.
Regulators have started to treat that concentration as systemic. U.K. financial authorities designated major cloud providers as Critical Third Parties, warning in a news release that a “disruption or failure could affect multiple firms or markets at the same time, potentially impacting UK financial stability and services used by millions of consumers and businesses.” [11]
Speed sharpens the point. When an attacker can hand off access in 22 seconds, enforcement that can only happen after a round trip to the cloud has no margin when that round trip slows down, or disappears.
Now Add Autonomous AI Agents
The next wave of edge compute doesn’t just process data locally. It acts.
An agent like Claude Code can read a codebase, run commands, and call external APIs on its own. Give thousands of agents that latitude across an enterprise, and the question of what each one is allowed to do stops being hypothetical. HiddenLayer’s 2026 AI Threat Landscape report found that autonomous agents “now account for more than 1 in 8 reported AI breaches.” [12]
The standards world is scrambling to keep up. CISA, NIST, and the FIDO Alliance have all recently issued similar conclusions: an agent that can browse, execute code, and call APIs needs a verifiable, least-privilege identity of its own. [13, 14, 15]
Non-human identities already outnumber humans by an estimated 109:1 in enterprises, and 144:1 in cloud-native environments. [16] Passwords buckle under that load; compromised credentials were an initial access vector in 22% of 2025 DBIR breaches. [17]
The Answer is Not the Old On-Prem
Enterprises spent a decade moving away from on-premises infrastructure, and “put security back at the edge” can sound like a proposal to undo it, to rack up appliances, patch operating systems, and expose management ports all over again.
But the liability was never locality. It was the heavy, hard-to-patch appliance.
The rest of security has been moving the other way for years, toward less standing infrastructure rather than more. The CIS Critical Security Controls tell organizations to “uninstall or disable unnecessary services” [22]. CISA’s secure-by-design guidance treats a smaller attack surface, and a lighter maintenance burden on operators, as the goal [23].
So the edge presence that makes sense now looks little like the appliance it replaces. Small rather than a full operating system, so there isn’t much to patch or exploit. Managed and updated from the cloud rather than by hand. Reaching outward instead of listening for inbound connections. It keeps the trust decision close to where access happens, without handing back the operational simplicity that made the cloud worth adopting.
Certificate-Based Authentication Fits the Edge
Underneath all of this sits a single primitive: a trust anchor that works locally and doesn’t depend on a shared secret.
An X.509 certificate is this trust anchor. It binds a private key to an identity, and because that key never leaves the device holding it, a relying party can verify who’s calling without a password to steal or replay. On the network, that is EAP-TLS and 802.1X: A device proves itself with a certificate and checks the server’s certificate in return, so it refuses a rogue access point instead of handing over credentials. Delivered through a service like SecureW2 JoinNow Cloud RADIUS, it replaces the password, the credential behind roughly a fifth of breaches, with something an attacker cannot pull out of the air.
The same primitive extends to workloads and agents. Frameworks like SPIFFE and SPIRE give services and AI agents short-lived cryptographic identities, with a managed authority like PKI as the root of trust beneath them.
The edge does not need a new trust model. It needs the one already securing enterprise Wi-Fi and VPN, built on certificates, Cloud RADIUS, and PKI, to run where the compute has gone: decided in the cloud, provable at the edge.
References
- Garcia Lopez, P. et al., “Edge-centric Computing: Vision and Challenges,” ACM SIGCOMM Computer Communication Review, Vol. 45 No. 5, October 2015. https://dl.acm.org/doi/10.1145/2831347.2831354
- IDC, “Global Spending on Edge Computing to Grow 13.8% Reaching Nearly $380 Billion by 2028,” press release prUS53261225, March 18, 2025. https://my.idc.com/getdoc.jsp?containerId=prUS53261225
- Gartner, “Gartner Says AI PCs Will Represent 31% of Worldwide PC Market by the End of 2025,” August 28, 2025. https://www.gartner.com/en/newsroom/press-releases/2025-08-28-gartner-says-artificial-intelligence-pcs-will-represent-31-percent-of-worldwide-pc-market-by-the-end-of-2025
- Gartner, “Gartner Says 50% of Critical Enterprise Applications Will Reside Outside of Centralized Public Cloud Locations Through 2027,” October 30, 2023. https://www.gartner.com/en/newsroom/press-releases/2023-10-30-gartner-says-50-percent-of-critical-enterprise-applications-will-reside-outside-of-centralized-public-cloud-locations-through-2027
- Mandiant / Google Cloud, “M-Trends 2026,” March 2026. https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
- Verizon, “2025 Data Breach Investigations Report,” 2025. https://www.verizon.com/business/resources/reports/dbir/
- CISA, “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure” (AA24-038A, Volt Typhoon), February 7, 2024. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a
- Gao et al., “I Know What You Said: Unveiling Hardware Cache Side-Channels in Local Large Language Model Inference,” USENIX Security 2025, June 15, 2025. https://arxiv.org/pdf/2505.06738
- Amazon Web Services, “Summary of the Amazon DynamoDB Service Disruption in the Northern Virginia (US-EAST-1) Region,” October 2025. https://aws.amazon.com/message/101925
- ThousandEyes, “Microsoft Azure Front Door Outage Analysis — October 29, 2025,” October 2025. https://www.thousandeyes.com/blog/microsoft-azure-front-door-outage-analysis-october-29-2025
- Bank of England, “Critical Third Parties,” Critical Third Parties regime. https://www.bankofengland.co.uk/financial-stability/operational-resilience-of-the-financial-sector/critical-third-parties
- HiddenLayer, “2026 AI Threat Landscape Report,” March 18, 2026. https://www.hiddenlayer.com/news/hiddenlayer-releases-the-2026-ai-threat-landscape-report-spotlighting-the-rise-of-agentic-ai-and-the-expanding-attack-surface-of-autonomous-systems
- CISA and partners, “Careful Adoption of Agentic AI Services,” May 2026. https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services
- NIST, “Announcing the AI Agent Standards Initiative,” February 17, 2026 (https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure); NIST NCCoE, “Accelerating the Adoption of Software and AI Agent Identity and Authorization,” concept paper, February 5, 2026 (https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd)
- FIDO Alliance, “FIDO Alliance to Develop Standards for Trusted AI Agent Interactions,” April 28, 2026. https://fidoalliance.org/fido-alliance-to-develop-standards-for-trusted-ai-agent-interactions/
- Palo Alto Networks, “2026 Identity Security Landscape” (machine-to-human identity ratio), May 14, 2026 (https://www.helpnetsecurity.com/2026/05/14/2026-identity-security-landscape-report/); Entro Security, “H1 2025 NHI & Secrets Risk Report,” July 22, 2025 (https://www.globenewswire.com/news-release/2025/07/22/3119538/0/en/Entro-Reports-44-Increase-in-Machine-Identities-Nearly-Half-of-Secret-Exposures-Occur-Outside-Code.html)
- Verizon, “2025 DBIR: credential-based initial access,” 2025. https://www.verizon.com/business/resources/articles/credential-stuffing-attacks-2025-dbir-research/
- CA/Browser Forum, “Ballot SC-081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods,” April 11, 2025. https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/
- Wireless Broadband Alliance, “Wi-Fi Security Guidelines,” April 14, 2026. https://wballiance.com/wba-wi-fi-security-guidelines/
- CISA, FBI, and UK NCSC, “Reducing the Attack Surface for End-of-Support Edge Devices,” February 5, 2026. https://www.ic3.gov/CSA/2026/260205.pdf
- GreyNoise, “2026 State of the Edge Report,” February 24, 2026. https://www.greynoise.io/resources/2026-state-of-the-edge-report
- Center for Internet Security, “CIS Critical Security Controls v8,” Safeguard 4.8. https://cas.docs.cisecurity.org/en/latest/source/Controls4/
- CISA and partners, “Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design,” 2023. https://www.cisa.gov/sites/default/files/2023-10/SecureByDesign_1025_508c.pdf
- Haque, M. U. and Babar, M. A., “Well Begun is Half Done: An Empirical Study of Exploitability & Impact of Base-Image Vulnerabilities,” arXiv:2112.12597, December 2021. https://arxiv.org/abs/2112.12597