Every security system answers a single question: who is allowed to know. The perimeter answers “anyone inside”, which is why it does not hold: a room where everyone hears everything protects nothing. The opposite answer was set down in a public document on 22 March 2006 — application ITMI2006A000528, later WO 2007/108034. For the twenty years that followed, the industry went on building walls.
You protect the infrastructure and hope the data stays inside. It works as long as the data stays inside. The data never stays inside.
Protection travels inside the data. Wherever it is copied, forwarded or archived it stays protected. For those with the keys nothing changes. For everyone else the contents are mathematically inaccessible.
Who needs to know what. It is a rule older than computers: it comes from places where a mistake cannot be undone, and for decades the only thing holding it up was the discipline of the people involved. Someone decides who is let in on a thing, and everything else follows from that decision.
The perimeter replaced that decision with a door. Whoever gets in knows, whoever stays out does not: it is convenient, it can be bought, it draws nicely on a diagram. And it amounts to telling a secret in a crowded room and trusting the door.
The patent does nothing different from that rule: it writes it in mathematics instead of in a standing order. The key belongs neither to the room nor to the list of authorised people. It belongs to the document. Whoever was let in opens it. For everyone else there is no door to force, because there is no door.
Among people the rule can be taught, and teaching it is a trade: it is the subject of the programme on keeping secrets. Machines cannot be taught anything, which is exactly where the other half is needed.
The technical name is data-centric security: protection sits inside the data rather than in the infrastructure holding it. It stays encrypted wherever it is copied, forwarded or archived — for whoever holds the keys nothing changes, for anyone else the content is mathematically out of reach. This is the principle of US 12,596,770, granted in the United States on 7 April 2026, and EP 4,427,154, granted by the European Patent Office on 3 September 2025 with unitary effect across seventeen member states. Filings and dates are in the record →
Criminal groups and state actors are already collecting vast quantities of encrypted data today, intending to decrypt it tomorrow. It is called harvest now, decrypt later. For a board thinking in multi-year horizons the question is not whether the data is protected today, but whether it will still be in ten years. Post-quantum cryptography is not a technical matter: it is risk governance.
Every time an employee uploads a contract or a financial report to an external AI platform, control is gone, and the organisation can be in breach even while formally compliant. That is why models are needed that stay inside the organisation's own perimeter. Artificial intelligence is not bolted on afterwards: it is designed alongside the protection of the data.
In the end it always comes down to one question.Who is allowed to know what.
An AI agent inherits the permissions of whoever runs it, and there is no way to teach it discretion. Not a metaphor: we demonstrated it live.
At Beyond the Perimeter, in front of an audience of security leaders, the risk was not explained. It was executed.
We built an AI agent. An ordinary tool, of the kind thousands of companies now install to raise productivity.
We placed it on a target machine, with the normal permissions of any employee in the organisation.
From a remote location we launched a commercial AI assistant and asked it to read everything held in the corporate cloud store.
It read every single document. The person sitting at that machine noticed nothing at all.
No perimeter breach. No suspicious activity. No alert. An agent with access to the data is all it takes.
A zero-signal attack surfaceThe large cloud platforms do encrypt data, at rest and in transit. But it is the platform that encrypts, not the data. Which means the platform decrypts for anyone it considers authorised.
An agent acting on an employee's behalf is, to the system, that employee. It reads in the clear, within seconds, generating nothing anomalous. And when a document is shared externally, it leaves that control along with all its protections.
A person who receives an odd request can notice, and can be trained to notice. An agent cannot: the list of authorised users cannot tell the two apart, and no course will ever make it cautious.
The problem is not the AI agent. The problem is that the data it reads is not protected.
If every document were encrypted at the moment of creation, and the key belonged to the document rather than to the platform, that same back door would read nothing but unusable ciphertext.
The agent would go on working for whoever uses it legitimately. For everyone else, and for any unauthorised automated system, the contents would remain mathematically inaccessible.
Artificial intelligence can be adopted quite safely. It just has to stop being added on top of data that cannot defend itself.
The demonstration runs twelve minutes and is given in boardrooms and lecture rooms. It changes the tone of the meeting.
Bring it to your companyTwo halves of one rule: compartmentation between people is taught, compartmentation between systems is designed.