After years of struggles, artificial intelligence is boosting enterprise adoption of confidential computing, but AI agents are creating new security challenges that current technology isn’t designed to tackle.
This is pushing proponents of the technology back to the drawing board. At last month’s Linux Foundation’s Confidential Computing Summit in San Francisco, these proponents advocated for a whole new paradigm.
AI has boosted enterprise adoption of confidential computing systems to protect data and AI assets. Architects thought they had solved cost, speed and complexity challenges, but the scope and sprawl of AI agents are posing new system challenges.
“We have work to do. Please don’t stop,” said Nelly Porter, director of product management for confidential computing and encryption at Google Cloud. “We’re here to protect the AI ‘mind.'”
Confidential computing establishes a secure boundary to protect data from being stolen when in storage, transit or use. Encrypted data is stored in secure vaults and protected by mutual attestations and specialized hardware.
Core issues that slowed down confidential computing adoption – speed, cost and workload complexity – are resolved, said Mark Russinovich, chief technology officer and the deputy chief information security officer at Microsoft Azure.
At the Summit, Russinovich said he wrongly predicted confidential computing breakouts for years, but “this year I may get it right.”
“That progress came in stages. Google, for instance, said it first supported confidential computing only on single GPUs before extending it across Nvidia’s newer Blackwell chips, closing the performance gap that had held the technology back,” Russinovich said.
But as companies rush to adopt AI, armies of agents in enterprises create a new threat model that confidential computing isn’t designed to protect, Google’s Porter said. Agents don’t forget and as AI models train and execute prompts, they could retain enterprises’ most sensitive secrets, he said.
“The problem with agentic [models is], when they see or have even read access to this data, they cannot forget,” Porter said. “It’s all about context window. It’s all about active state of execution,” he said .
Porter shared an example of AI agent evaluating a company for a potential acquisition, and absorb sensitive financial and business details. If the deal falls apart, the agent may not automatically forget those details or remove it from memory.
Porter’s solution was a dedicated encryption key for each agent to protect short-term and long-term memory and data it retains or distills. Data can be deleted by “crypto-shredding” it, which involves killing the encryption key, as opposed to the data.
“We have all Lego blocks and all the capability to make it happen,” Porter said.
Dion Harris, senior director of high-performance and AI factory solutions at Nvidia, tells Dark Reading that Nvidia’s hardware is ready for agentic AI confidential computing.
New Opportunities, New Risks
The agent challenges aside, Microsoft’s Russinovich said confidential computing has advanced enough to provide enterprises and nations with guarantees that no one can see their models, data, or agents.
“With the adoption of AI, now it’s introduced a new area in terms of opportunity, but also a new area in terms of risk,” Russinovich said.
Apple announced in May the most prominent confidential computing deployment to date by implementing the technology in its Private Compute Cloud infrastructure to secure AI access across billions of its devices. Apple announced PCC to much fanfare in 2024, but delayed it over a slower Siri rollout, unresolved security guarantees and hardware challenges.
Apple has a history of building technology using internal tools, but had to break tradition for confidential computing, Sanchit Vir Gogia, CEO of Greyhound Research, tells Dark Reading.
Apple originally built the PCC security on Apple silicon. The new arrangement involves Google Cloud, Nvidia’s confidential computing on Blackwell graphics processing units (GPUs), Intel central processing units (CPUs) with trust domain extension (TDX), and Google’s Titan security chip. The new implementation has at least two independent secure hardware roots of trust.
“Confidential AI is a multi-layer architecture that spans hardware, cloud, accelerator, attestation and model serving. Privacy now has to travel with the workload,” Gogia says.
For example, an iPhone establishes a trust boundary with a server where it sends secure data. The Nvidia GPU identifies itself as a secure environment, receives secure data, decrypts and processes on the GPU, and re-encrypts and sends it back to the phone.
“Apple is creating the best of both worlds where they’re getting performance, efficiency, and maintaining the privacy of the user data,” says Nvidia’s Harris. And it is just the start; by 2030, confidential computing use cases are expected to reach about $160 billion, he says.
“It’s a critical segment for AI adoption and driving AI services across enterprises worldwide, not just hyperscalers,” Harris says.
Creating Trust in Technology
ServiceNow uses confidential computing so 9,000 sales employees get quick answers to commission-related inquiries, such as forecasts and income, says Kellie Romack, chief digital information officer. These inquiries typically include protected information, such as compensation, personally identifiable information, and customer data related to closed deals.
Previously, the sales staff had to submit tickets to the compensation and finance department, a manual process that took four days. The new system instantaneously analyzes the sensitive data using secure enclaves and generates responses within eight seconds. The technology runs on Nvidia’s H100 GPUs, Opaque Systems’ confidential AI computing framework and Microsoft’s Azure Cloud.
“It created trust in the technology,” says Romack. The system “freed up mindshare for my finance and HR team… and those sellers took a worry off their shoulders so they could go and serve our customers,” she says.
Confidential computing, especially GPUs, can be expensive, but “of course I’m going to choose it, because a breach is unacceptable,” Romack says.


