What AMD Changed: TSME Disappears From Consumer Ryzen
AMD memory encryption removal refers to the decision to disable Transparent Secure Memory Encryption (TSME) on consumer Ryzen CPUs through firmware, leaving hardware RAM encryption active only on PRO and server-grade chips and creating a security feature gap between consumer vs pro chips that previously did not exist. Transparent Secure Memory Encryption is a hardware feature that encrypts all data stored in system RAM, aiming to reduce exposure to cold boot attacks and other physical memory theft scenarios. For several Ryzen generations, many mainstream desktop processors quietly benefited from this protection when enabled in the BIOS. With AGESA firmware version 1.2.7.0, that changed: boards using newer firmware now report Ryzen TSME disabled or “not supported” on non‑PRO models, even if the BIOS toggle remains set to Enabled, while PRO and EPYC parts continue to show TSME as active.

How Users Discovered TSME Was Quietly Disabled
The turning point came in April when privacy‑focused Linux user Ben Kilpatrick installed a new OS on a Ryzen 7 9700X system based on Zen 5. As part of his routine, he ran Host Security ID (HSI) to confirm that key protections, including encrypted RAM, were active. Earlier logs from the same machine had shown that TSME was working. This time, HSI reported “encrypted RAM: not supported,” despite the BIOS still listing TSME as enabled. That mismatch sparked months of investigation. Kilpatrick pushed motherboard vendor MSI to compare different boards and firmware levels. Their testing showed that with older AGESA versions, consumer Ryzen chips still reported TSME as supported, but once firmware updated to AGESA 1.2.7.0, those same CPUs reported the feature as unavailable, suggesting a deliberate firmware‑level change rather than a hardware failure.
Inside the Firmware: Evidence of a Policy Lock
MSI engineers expanded their checks to multiple vendors and CPUs to understand the emerging CPU security vulnerability gap. On MSI and Gigabyte boards, consumer Ryzen processors retained TSME support only on pre‑1.2.7.0 AGESA firmware. With AGESA 1.2.7.0, TSME status flipped to “not supported,” even while PRO‑branded Ryzen chips kept reporting active encryption. MSI went further with an Asus X870E board, swapping a consumer Ryzen 9800X3D and a Ryzen 9945 PRO in and out under the same BIOS configuration. According to MSI’s tests, “tsme_status = 1 on the PRO processor and tsme_status = 0 on the consumer processor with the same board and BIOS.” Memory dumps of the AMD Boot Loader showed the internal flag DfIsTsmeEnabled reading FALSE on the consumer part and TRUE on the PRO chip, reinforcing the idea that this is a model‑based lock enforced in firmware.
AMD’s Response and the New Consumer–PRO Security Divide
When Kilpatrick filed a bug report on AMD’s public GitHub, initial responses from AMD engineers suggested checking the BIOS setting or contacting the board maker, framing the situation as a possible firmware bug. After MSI’s deeper analysis, Kilpatrick asked whether DfIsTsmeEnabled being FALSE on consumer chips was a silicon limit or an AGESA policy decision. AMD declined to elaborate further, and the thread was closed without a technical explanation. Meanwhile, MSI’s product marketing reportedly stated that AMD had communicated TSME is “exclusively supported on PRO series processors.” The practical result is clear: memory encryption is now restricted to PRO‑tier chips, leaving mainstream Ryzen users without a protection they may have assumed was present. This raises questions about how AMD balances security between consumer vs pro chips, and whether future firmware could restore TSME—or if the lock‑out is permanent.






