2026 looks set to be the year in which enterprise adoption of AI PCs gathers pace. Gartner predicts that AI PCs’ share of the total PC market will reach 55% this year and will become the norm by 2029.
With AI PCs, enterprises can move more AI workloads to the edge rather than processing them centrally in the cloud. As well as reducing latency, this approach promises to make AI more sustainable, largely thanks to energy-efficient neural processing units.
As Melchor Sanz, CTO at HP Iberia Sales, pointed out: “Cloud computing for AI is limited, expensive and often unsustainable; by placing AI at the edge you can distribute computing between PCs and other devices.”
However, the more that enterprises come to rely on a technology, the more attractive that technology becomes to cybercriminals and other bad actors. Gartner believes that nearly one-third of organisations have already experienced attacks targeting AI infrastructure. This number will rise as the volume of data processed at the edge increases in coming years.
The supply-chain threat
Security controls can be implemented once the devices are received by IT, but what happens if the attack is launched further up the supply chain before the devices even reach the enterprise?
The risk of supply-chain attacks is already well understood. The SolarWinds attack, for example, saw attackers insert malicious code into legitimate SolarWinds Orion software updates, compromising around 18,000 organisations.
Supply-chain attacks can also target hardware; a threat that CIOs and CISOs should have front of mind when deploying AI PCs. Alex Holland, Principal Threat Researcher in the HP Security Lab, explained it this way: “If an attacker compromises a device at the firmware or hardware layer, they’ll gain unparalleled visibility and control over everything that happens on that machine. Just imagine what that could look like if it happens to the CEO’s laptop.”
Cybersecurity should therefore begin before the AI PC reaches the enterprise. One key challenge in this respect is that AI PCs are built from components that have been sourced from a global supplier ecosystem. Device manufacturers must therefore ensure that only untampered components enter their factories and that devices remain uncompromised as they make their way through manufacturing, warehousing, customs, shipping partners, resellers and finally into the hands of the enterprise IT team.
Pelle Aardewerk, Cyber Security Consultancy Lead at HP, comments: “By the time a PC is deployed, it may have passed through six or seven different custodians, each representing a potential point of risk. Best practice must therefore go beyond securing software or relying solely on operating-system protections.”
Embedding security in hardware
For HP, supply-chain security should be built on a “Root of Trust,” hardware-based foundation where security is embedded in the silicon itself. The approach verifies the integrity of firmware and BIOS at every startup to ensure nothing beneath the OS has been altered and validates the device’s configuration throughout its life cycle.
In addition, HP implements signed bills of materials and platform certificates throughout the manufacture process. By cryptographically signing the device configuration at build and enabling verification at delivery, enterprises can confirm that removable components have not been swapped, altered or compromised.
Ensuring supply chain security for AI PCs therefore requires a layered approach comprising trusted suppliers, controlled manufacturing processes, cryptographic validation of components and hardware-embedded security mechanisms. As enterprises decentralise AI processing to the edge, these controls are fast becoming non-negotiable.
For more information about the business benefits of AI PCs, click here.
