Sixth-generation (6G) networks will be AI-native: machine-learning models will decide how radio resources are allocated, where functions are placed, which control loops run, and how traffic is routed. Recent orchestration frameworks show that sharing common AI functions and xApps across services yields large resource and revenue gains, yet these gains are computed as if security were free. In reality, every shared function must also satisfy authentication, trust, confidentiality, attestation, and auditability requirements—and adding these requirements changes the structure of the underlying placement and sharing optimisation problems. This article presents a cross-layer framework for making AI-native 6G radio access networks secure, privacy-preserving, and revenue-aware at the same time. The framework is built from nine interlocking pillars organised in three layers: (i) an O-RAN orchestration substrate covering functional-split-aware placement, conflict-aware RIC control-loop scheduling, and joint radio–compute slicing; (ii) a confidential intelligence layer covering trust-weighted robust federated learning, attested confidential edge inference with hybrid post-quantum sessions, and security-aware xApp sharing; and (iii) network-wide assurance covering security-aware revenue-optimal orchestration, cross-domain zero-trust slice access, and an end-to-end resilience and formal-verification capstone. Each pillar is presented with a research question, a precise problem formulation with objective and constraints, a candidate solution strategy expressed as pseudocode, and evaluation methodology. We further show how the nine pillars interlock through four vertical threads—placement–sharing, trust, post-quantum protection, and audit—so that, taken together, they answer a single central question: can security constraints be made first-class terms of revenue-optimal 6G orchestration while the resulting system remains scalable, provable, and practical?