Confidential Computing Is Having Its AI Moment. Here's Why It Matters.

As AI moves into more sensitive and regulated environments, Confidential Computing offers a useful lens into a bigger question: what guarantees will organizations need to trust AI with valuable data, decisions, and authority?

image

If you've been following AI infrastructure over the past year, you've probably noticed a term appearing more and more often: Confidential Computing.

It's being discussed by hyperscalers, chip manufacturers, model providers, governments, and enterprise security teams. At recent industry events, nearly every conversation about securing AI systems eventually led back to Confidential Computing, Trusted Execution Environments (TEEs), or hardware-based trust.

For many people, though, it's still an unfamiliar concept.

What is Confidential Computing? Why is it suddenly gaining momentum? And where does it fit alongside technologies like zero knowledge proofs and fully homomorphic encryption (FHE)?

Here's our perspective.

The Trust Problem Is Changing

For years, organizations have focused on protecting data in two states:

  • At rest, while stored on disks or databases.
  • In transit, while moving across networks.

Encryption has become the standard answer for both.

But there's always been a third state that's harder to protect: data while it's being processed.

Whenever an application runs, sensitive information is decrypted so the processor can actually use it. Traditionally, this means you're trusting the operating system, hypervisor, cloud provider — and increasingly, the frontier AI labs whose models sit in the processing path — not to leak that data, whether intentionally or unintentionally.

To be clear, this isn't a claim that cloud providers or model providers are untrustworthy. Most of the world runs on that trust, and providers have largely earned it over many years of operating at scale. But "largely earned trust" and "cryptographically verifiable trust" are different things, and as AI systems begin processing increasingly sensitive information from financial data, healthcare records, proprietary models, to enterprise workflows, the gap between the two starts to matter more. Even a well-intentioned provider can be compromised, misconfigured, or legally compelled in ways outside its control, and confidential computing is fundamentally about not having to make that bet.

In Comes Confidential Computing

Confidential Computing offers another approach: stronger guarantees about how sensitive data is processed even when the underlying infrastructure belongs to someone else.

At a high level, it allows applications to run inside isolated hardware-protected environments known as Trusted Execution Environments (TEEs).

Think of a TEE as a secure room inside a processor. Code and data running inside that room are isolated from the rest of the system, making it significantly harder for cloud operators, administrators, or other software to inspect or tamper with what's happening during execution.

The goal isn't simply encryption. It's creating stronger guarantees about where computation takes place and the integrity of the environment performing that computation.

These environments can also produce cryptographic attestations, or evidence that a workload actually executed within a genuine, untampered TEE. In other words, they don't just say, "Trust us." They provide real cryptographic evidence about the environment in which the computation occurred.

There are already familiar examples of this idea in practice. Apple's Private Cloud Compute allows certain Apple Intelligence requests to run in the cloud while being designed so that the personal data being processed isn't accessible even to Apple. Signal has used secure enclaves to let users discover which of their contacts use Signal without revealing their address book to Signal itself.

The use cases are different, but the underlying goal is the same: getting the benefits of computation happening elsewhere while reducing how much trust has to be placed in whoever operates the infrastructure.

Why Now?

Confidential Computing is not a new idea. Its underlying concepts and technologies have been developing for decades.

What has changed is AI.

As organizations deploy increasingly capable AI systems, they are placing more valuable models, more sensitive datasets, and more business-critical decisions into cloud infrastructure.

That changes the threat model.

Organizations increasingly need to know whether infrastructure providers can inspect proprietary models or prompts, whether customer data remains protected during processing, and whether multiple parties can collaborate without exposing their underlying information. They are also facing growing expectations to demonstrate that sensitive workloads comply with internal policies and external regulations.

These concerns were reflected throughout the recent Confidential Computing Summit hosted by the Linux Foundation, where conversations consistently centered on three themes: user trust, data and model sovereignty, and verifiable compliance.

Interestingly, we observed that much of the discussion focused less on applications themselves and more on proving the integrity of the environments in which they run. Across the ecosystem from chip manufacturers and cloud providers to an emerging layer of Confidential Computing middleware vendors, the emphasis was on strengthening the chain of trust beneath AI workloads.

It is a sign that the industry increasingly sees trusted infrastructure as a prerequisite for trusted AI.

An Ecosystem Is Taking Shape

One of the clearest takeaways from the conference was that Confidential Computing is no longer a niche research topic. Hardware companies continue expanding support for trusted execution capabilities. Cloud providers are integrating Confidential Computing services into their platforms. And there’s a growing ecosystem of middleware companies emerging to manage attestation, identity, policy, and secure workload orchestration.

Even AI model providers appear to recognize that customers increasingly care about stronger security guarantees and greater control over how their models and data are processed.

Exactly how quickly enterprise adoption follows remains an open question. Conferences naturally attract builders and vendors, making it difficult to separate genuine customer pull from industry enthusiasm and decipher true supply and demand.

But regardless of the pace, the direction of travel is becoming clearer: trusted execution is moving from a specialist capability toward becoming part of the standard AI infrastructure stack.

Different Problems Require Different Guarantees

There is unlikely to be a single technical architecture for private and trustworthy AI.

The right approach will depend on the application, the sensitivity of the data involved, the threat model, and, importantly, what the system needs to guarantee.

A healthcare application analyzing patient records may prioritize keeping sensitive data protected while it is processed. An AI agent authorized to make financial transactions may need to demonstrate that specific policies were followed before an action was taken. Organizations collaborating on proprietary datasets may need to perform useful computation without revealing the underlying information to one another.

These problems call for different tools.

TEEs can protect data and computation within an isolated hardware environment and provide evidence about the integrity of that environment. ZK proofs can demonstrate that specific properties or rules were satisfied without revealing the underlying information. FHE can enable certain computations to be performed directly on encrypted data.

In practice, these techniques can be combined or applied selectively. A system might rely primarily on Confidential Computing to protect a workload, while using cryptographic proofs for a particular decision or policy check where independent verification matters. Another application, with a different threat model, might require a different combination entirely.

Rather than looking for one technology to solve every trust and privacy problem, we think of these approaches as a growing toolbox. As AI moves into more industries and higher-stakes applications, the important question will be less which technology wins? and more what guarantees does this particular system need, and which combination of tools can provide them?

Looking Ahead

Broad commercial adoption of Confidential Computing has yet to happen. But we see a few forces that could accelerate it: companies increasingly treating proprietary data as a competitive advantage worth protecting, and AI systems in regulated industries running into a practical limitation where they can't safely access some of the most valuable data available to them.As those pressures grow, Confidential Computing could become less of a security nice-to-have and more of an enabler for what organizations can actually do with AI. Enterprises will still need to decide which trust assumptions they are prepared to accept, while vendors will need to demonstrate that the added complexity delivers real business value.

What feels increasingly clear is that AI is changing both the value of protected data and how the industry thinks about trust.

The conversation is moving beyond protecting data toward producing evidence about the environments, policies, and systems responsible for processing it.

The strongest architectures are therefore unlikely to rely on a single technology. They will combine multiple layers of trust from hardware, software, cryptography, and carefully designed policies to deliver stronger guarantees than any one layer can provide alone.

As AI systems take on more valuable data, decisions, and authority, trust will need to become something systems can demonstrate—not something users are simply asked to assume.