# When Your AI Infrastructure Goes Dark: The Security Gap Inside Neo-Clouds
The shared responsibility model — that foundational agreement between cloud providers and their customers about who owns which security controls — is a lie inside neo-clouds. Not a small lie. A structural one, baked into hardware that the security industry spent precisely zero years preparing for.
That's the problem Stealthium is selling against. And whether or not their solution holds up, the problem itself is real.
## The Infrastructure Nobody Budgeted for Securing
Let's be precise about what we're talking about, because "AI accelerators" is a term that gets thrown around loosely.
These are not GPUs. They're not CPUs. They're specialized silicon — built by companies like Tenstorrent, Groq, Cerebras, and Graphcore — designed specifically to run the matrix operations that underpin AI training and inference. They're faster and more efficient at AI workloads than general-purpose compute. They also operate with a fundamentally different memory architecture: high-speed video memory that sits completely outside the observability stack that decades of endpoint and network security tooling was designed around.
Neo-clouds are what happen when you build a cloud around these chips instead of retrofitting them. CoreWeave, Nebius, and a growing list of competitors offer AI-first infrastructure — massive parallelism, low-latency inference, flexible deployment — that hyperscalers like AWS and Azure can't match economically for AI-heavy workloads. Customers use them to train large models, run high-throughput inference, and power internal chatbots at scale.
The catch: nobody can see inside them.
## The Telemetry Black Hole
Traditional security tooling — EDR, SIEM, network detection, the whole stack — was built around CPU-centric operating systems. It instruments OS calls, network flows, process trees, file events. None of that applies to what's happening inside an accelerator's memory.
"Organizations are increasingly uncomfortable because they lack meaningful security and observability controls, in real time, for that silicon accelerator layer," says Chris Hosking, GTM Advisor at Stealthium. "Our go-to thinking has always been that if you cannot see something happening, then nothing is happening."
That last sentence is the part that should unsettle security leaders. In any other context, "absence of evidence is not evidence of absence" is a cliché. Here, it's operational reality. A compromised neo-cloud — a provider that has been stealthily subverted — would be invisible to the customers running workloads on top of it.
The threat model this enables is ugly. If an attacker gains persistent access to a neo-cloud's accelerator layer, they sit upstream of every customer using that infrastructure. They can observe training runs, exfiltrate model weights, or inject data into inference pipelines without leaving a footprint in any log that current tooling can see.
## Januscape as the Proof of Concept
The story gets more concrete with Januscape, malware that surfaced recently and exploited a vulnerability in nested virtualization. The attack enabled an adversary to offer — or effectively resell — compromised virtualization environments to third parties without the original host's knowledge.
Translate that to a neo-cloud: a successful Januscape-style exploit could create cross-tenant leakage where a malicious third party gains visibility into a legitimate customer's inference workloads. A company running a proprietary chatbot on neo-cloud infrastructure could have its model behavior observed, its prompts logged, and its responses intercepted — while every security dashboard shows green.
Januscape didn't fully land. But it demonstrated the attack surface exists, and that existing tooling would have missed it.
## What Stealthium Is Actually Doing
Stealthium's approach is constrained by the same hardware limitations it's trying to defend against: the company admits it cannot see inside the accelerators either. What it can do is watch the edges.
They deploy an agent inside customer infrastructure — not at the neo-cloud provider level — that monitors telemetry signals emanating from the neo-cloud. The agent is trained to detect subtle behavioral anomalies: hints that something has changed in how the accelerator layer is responding, even when no direct visibility into that layer exists.
It's side-channel analysis applied to security monitoring. You can't read the contents of the accelerator memory, but you can detect when patterns of latency, throughput, or behavior diverge from a known-good baseline. An attacker exploiting nested virtualization, for example, changes timing characteristics. A compromised fabric leaks differently than a clean one.
The technology, as Hosking notes, is not new. It's the training — what signals constitute a hint of compromise, versus normal variance — that's the hard problem.
## The Shared Responsibility Model Doesn't Exist Here
This is the part that deserves more attention than it's getting.
Cloud security is built on explicit agreements. AWS tells you exactly which security controls it owns and which it hands to you. Compliance frameworks, certifications, audit reports — all of these exist because there's a shared understanding of the boundary.
Neo-clouds have accelerators at their core, and no security framework currently defines accountability for that layer. There is no SOC 2 control for accelerator-layer observability. There's no shared responsibility matrix that specifies what a neo-cloud provider must log or monitor in its silicon. Customers are signing contracts and building compliance programs against an infrastructure layer that is, from a security accountability standpoint, effectively undefined.
For organizations pursuing sovereign AI — running sensitive workloads on infrastructure they're supposed to control — this is a fundamental problem. Sovereignty requires observability. You cannot claim your AI system is secure and under your control when you have no visibility into the hardware layer executing it.
---
## HackWire Analysis
The emergence of neo-clouds as serious AI infrastructure is happening faster than the security industry's ability to reason about them, which is a pattern we've seen before: cloud adoption outpaced cloud security by nearly a decade; containerization arrived before container security was remotely mature; and IoT still hasn't recovered from its original sin of shipping with no security model at all.
What's different this time is the stakes. The organizations using neo-clouds aren't running experimental workloads. They're training proprietary models, running production inference for customer-facing products, and increasingly hosting what they call "sovereign AI" — AI systems that are supposed to be isolated, controlled, and auditable. If the hardware layer is invisible to defenders, that sovereignty claim is hollow.
The Januscape malware is worth tracking closely. The fact that it targeted nested virtualization — a mechanism that appears in both traditional cloud environments and accelerator-powered neo-clouds — suggests adversaries are already mapping this attack surface. A more capable, better-resourced threat actor could take the same technique and weaponize it against AI infrastructure at scale, with no current detection mechanism in place.
Stealthium's side-channel approach is reasonable given the constraints. But buyers should ask hard questions: What's the false positive rate? What adversarial techniques can defeat telemetry-based detection? And critically — what happens when neo-cloud providers change their hardware or hypervisor configuration and invalidate the behavioral baselines?
The deeper issue is that this can't be solved by a single startup. It requires hardware attestation, accelerator-aware security frameworks, and regulatory attention to the accountability gap in neo-cloud contracts. Until those exist, any AI workload on accelerator infrastructure is operating on trust without verification.
— HackWire Editorial
---
## Related Coverage