
F-Secure and AMD Silo AI Partner to Strengthen Security for Agentic AI
F-Secure and AMD Silo AI are demonstrating how consumer cybersecurity and AI model-routing technologies can work together to make digital experiences safer, more private and more efficient as agentic AI becomes increasingly integrated into everyday online activities.
The collaboration brings together F-Secure Trust technology with AMD Silo AI’s model-routing capabilities to determine how and where individual pieces of data should be processed. Depending on factors such as data sensitivity, cost, model capability and performance requirements, information can be handled locally on a device or routed to AI models running in the cloud.
F-Secure plans to incorporate this approach into its upcoming F-Secure TrustPath solution, which is designed to evaluate digital interactions based on their individual context rather than automatically treating an entire website or online destination as trusted.
Why Agentic AI Requires a New Approach to Trust
AI agents are increasingly capable of performing tasks on behalf of consumers. These activities can include comparing products, managing subscriptions, navigating websites and completing purchases. While such capabilities can simplify digital experiences, they also introduce new security and privacy challenges.
Research from F-Secure highlights the growing uncertainty surrounding trust in the digital environment. The company reports that 84% of consumers are concerned that AI is making it increasingly difficult to determine what is real online. Meanwhile, 44% are concerned about using AI itself, and only 17% are currently prepared to allow AI to take actions on their behalf.
These F-Secure findings underline the challenge facing agentic AI. Consumers may be willing to use AI to assist with online tasks, but they also need confidence that an AI agent can distinguish between legitimate information, potentially malicious instructions and sensitive actions.
F-Secure TrustPath is intended to address this challenge by assessing each stage of a digital journey according to its specific context. Instead of extending blanket trust to an entire domain, the system considers what is happening at each individual step.
Trust Is Granted Per Moment, Not Per Domain
The companies’ approach is built around a central principle: trust should be determined at the moment it matters, rather than automatically applied to an entire website.
A legitimate and trusted website, for example, can still contain third-party content, manipulated reviews or other elements that an AI agent should not automatically treat as reliable. Similarly, an otherwise routine browsing activity can become significantly more sensitive when an agent begins interacting with a page on behalf of a user.
Actions such as logging in, entering personal information or making a payment can change the risk profile of an interaction. An AI agent therefore needs to understand not only where it is operating but also what it is being asked to do and what information it is processing.
“The goal is not to send more events to the largest models. The goal is to handle each event as close to the user as possible, to help keep it safe, private and efficient,” said Jaakko Vainio, senior director at AMD Silo AI.
This context-driven model requires multiple AI capabilities rather than relying on a single large model for every interaction.
F-Secure Brings Contextual Trust to the Consumer Journey
F-Secure contributes its trust model through TrustPath, extending security evaluation across the consumer’s digital journey.
The objective is to evaluate individual steps according to their context and risk, allowing the system to distinguish between ordinary browsing activities and interactions that involve sensitive information or consequential decisions.
“Consumers will not hand their money, their identity or their decisions to an agent operating under a brand they don’t trust,” said Timo Laaksonen, president and CEO of F-Secure.
“Working with AMD Silo AI lets us take F-Secure TrustPath from principle to practice, protecting the whole journey in a practical and comprehensive way.”
The approach is particularly relevant as AI agents move from simply answering questions toward taking actions. An agent that recommends a product presents one set of risks; an agent that logs into an account, enters payment information or completes a purchase presents another.

Dynamic AI Model Routing Across Device and Cloud
AMD Silo AI provides the model-routing layer that can dynamically distribute AI workloads across on-device and cloud-deployed models.
The routing policy can determine where information should be processed and which model should handle an event based on several factors, including sensitivity, cost, model capability and performance.
This creates a flexible architecture in which not every request needs to be sent to the most powerful available model. Lower-risk or latency-sensitive interactions can potentially be processed locally, while more complex or ambiguous tasks can be directed toward more capable infrastructure.
AMD supports this architecture across client, edge and cloud environments.
On client devices, AMD Ryzen AI platforms provide local AI processing through the CPU, NPU and integrated graphics. AMD Radeon integrated and discrete graphics can provide additional acceleration for AI models and multimodal workloads.
For private and cloud environments, AMD EPYC server CPUs and AMD Instinct GPUs can support more demanding models, offering greater throughput, longer context windows and centralized governance for controlled deployments.
This infrastructure allows organizations to match the processing environment to the requirements of each workload.
Turning Device-to-Cloud Routing Into a Deployable Architecture
An example of this approach is Lemonade, an open-source local AI serving layer built on AMD products. Lemonade provides developers with a familiar API for exposing local AI models while making use of available AMD client hardware rather than automatically sending every request to a remote service.
The architecture effectively turns the device-to-cloud concept into a deployable model.
Lower-risk requests can be routed through a Lemonade endpoint running on AMD client systems, using Ryzen AI CPU and NPU resources as well as Radeon graphics where available. More demanding or higher-risk workloads can instead be directed to endpoints supported by AMD EPYC processors and AMD Instinct GPUs.
This separation allows application developers to concentrate on routing policies while the endpoint abstraction determines where inference is ultimately performed.
For privacy-sensitive applications, keeping appropriate interactions close to the user can also reduce the amount of information that needs to leave the device.
Addressing New Threats From AI Agents
The need for contextual security becomes particularly important when AI agents interact with websites that may contain manipulated reviews, hidden instructions or unsafe decision paths.
These risks can become more significant when an AI agent moves beyond displaying information and begins acting on that information.
An AI system may encounter text that appears to be an instruction but was not intended for the agent. Without appropriate safeguards, an agent could potentially treat website content as commands, creating new avenues for manipulation.
“When AI agents start acting on our behalf, they bring a new class of challenges and threats to digital journeys and user trust,” said Santeri Kangas, chief technology officer at F-Secure.
“This trust is built by AI models that preserve the user’s privacy while protecting both the user and their agent. To run these models effectively requires dynamic routing decisions. What we are building is a significant step forward in protecting consumers’ digital journeys and their privacy.”
Applying the Approach to Agentic Shopping
Agentic shopping illustrates why this layered approach is becoming important. A single online purchase can involve searching for products, comparing reviews, evaluating offers, logging into an account and ultimately entering payment information.
Each stage carries different levels of risk and requires different forms of AI processing.
The companies’ approach is designed around the idea that a trusted domain does not automatically make every piece of content on that domain trustworthy. Similarly, an AI agent capable of sophisticated reasoning should not automatically interpret every piece of text it encounters as an instruction.
By combining F-Secure’s contextual trust model with AMD Silo AI’s dynamic model routing and AMD’s device-to-cloud AI infrastructure, the companies aim to give developers a way to make those distinctions in real time.
As agentic AI becomes more capable and increasingly involved in consumer decisions and transactions, the combination of contextual trust, privacy-aware processing and dynamic AI model selection could become an important part of how digital journeys are secured.
Source Link: https://newsroom.amd.com/


