the 2nd objective of confidential AI should be to acquire defenses from vulnerabilities that are inherent in the use of ML products, which include leakage of private information through inference queries, or generation of adversarial examples. ISO42001:2023 defines safety of AI techniques