Lattice Semiconductor completed its acquisition of AMI on July 27, closing a $1.65 billion cash-and-stock transaction first announced on May 4. The deal was framed on both ends as a data center management story — low-power FPGAs paired with platform firmware to manage AI racks. For anyone tracking hardware supply chain security, it is something more specific: the company that writes the firmware running underneath most of the world’s servers now belongs to the company that sells the silicon meant to verify that firmware.
AMI, formerly American Megatrends, is the largest independent BIOS vendor on the planet and the dominant supplier of MegaRAC baseboard management controller firmware. Its Aptio UEFI and MegaRAC code is the first thing that executes when a server powers on, and it ships almost entirely under other companies’ labels. Server OEMs and ODMs license it, brand it, and deliver it to enterprises and hyperscalers that in many cases have no idea whose code is sitting below their operating system. AMI is projected to clear $200 million in revenue this year on a footprint far larger than that number suggests.
Why BMC firmware is the highest-value target in the rack
A baseboard management controller is a small computer that sits beside the main processor with its own network interface, its own power domain, and total authority over the host. It boots the server, flashes firmware, mounts virtual media, monitors thermals, and stays alive when the operating system is off. Compromise a BMC and you own the machine at a level no endpoint agent can see and no reinstall can clear.
The past three years have made this concrete. Researchers have repeatedly found critical flaws in MegaRAC, including remote authentication bypasses in its Redfish management interface, at least one of which was serious enough to land in CISA’s known-exploited catalog. The pattern is consistent: a single firmware codebase, licensed to dozens of hardware vendors, patched on each vendor’s own schedule, with enterprises unable to determine their exposure because the branding obscures the provenance. Blast radius is the problem, not code quality.
Lattice’s existing business sits directly opposite this. Its low-power FPGAs have been sold for years as hardware roots of trust, positioned as the immutable component that measures and attests firmware before it is allowed to run, and as a defense against exactly the class of persistent implant that a compromised BMC enables. That was the pitch: an independent piece of silicon watching the firmware, precisely because the firmware could not be trusted on its own terms.
The verifier and the verified now share a balance sheet
Consolidation of this kind cuts two ways, and the case for it is real. Firmware and the silicon that attests it have never been co-designed. Integrating them removes the seams where attestation gaps live, shortens the path from vulnerability disclosure to a signed fix, and gives one vendor end-to-end responsibility for a boot chain that has historically been an orphan. Lattice and AMI have committed to remaining ecosystem-neutral and silicon-agnostic, keeping AMI’s multi-vendor support intact — a necessary promise, since AMI’s value depends on working across AMD, Arm, Intel, and Nvidia platforms simultaneously, and since dedicated BMC chip vendors ASPEED and Nuvoton still control the overwhelming majority of controller shipments.
The countervailing point is structural. Independent attestation derives its value from independence. When the entity supplying the root of trust also supplies the code that root of trust is measuring, the incentive to disclose aggressively against your own firmware weakens, and buyers lose a check that existed by accident of market structure rather than by design. Nothing about the transaction implies bad faith. It does mean that security teams who treated Lattice silicon and AMI firmware as separate procurement decisions with separate accountability no longer have that separation.
What buyers should ask for now
The practical response is procurement language, not vendor suspicion. Firmware SBOMs that identify the actual upstream author rather than the OEM label. Contractual patch-delivery timelines for BMC and UEFI components that survive a change of ownership. Attestation logs that can be independently verified rather than self-reported by the combined stack. Confirmation of whether the root of trust in a given platform is a Lattice device measuring AMI firmware, and what that now means for the vendor’s disclosure posture.
Lattice is buying its way from component supplier to system-level platform, and the market has rewarded the strategy. The security question is separate from the equity question. Enterprises spent the last several years learning that firmware is where sophisticated attackers live. They are about to learn that the supply chain beneath it has one fewer independent party in it.
Leave a Reply