The policy is calculated right into a PCR on the Confidential VM's vTPM (that is matched in The true secret release policy over the KMS with the predicted policy hash with the deployment) and enforced by a hardened https://deannagimh392429.bcbloggers.com/29996184/the-definitive-guide-to-confidential-ai-tool