The new [NewGCMWithRandomNonce] function returns an [AEAD] that implements AES-GCM by generating a random nonce during Seal and prepending it to the ciphertext.