The plan is calculated into a PCR with the Confidential VM's vTPM (which is matched in The real key release plan within the KMS with the anticipated plan hash for the deployment) and enforced by a hardened container https://darreniivz061214.blogzet.com/the-best-side-of-confidential-ai-nvidia-45108907