The plan is calculated right into a PCR in the Confidential VM's vTPM (which happens to be matched in The true secret release plan within the KMS While using the anticipated policy hash with the deployment) and https://oisicawb327264.blogrelation.com/36639682/the-smart-trick-of-is-ai-actually-safe-that-no-one-is-discussing