Confidential computing is a technology that enables enterprises to securely run AI on sensitive data by protecting models and data in use with hardware-rooted Trusted Execution Environments (TEEs)—providing cryptographic verification that data is protected from insider and infrastructure threats.
Sensitive enterprise data is bound to on-premises infrastructure—shaped by the exacting requirements of GDPR, the EU AI Act, and sovereign mandates. At the same time, the powerful AI models have traditionally been delivered through cloud APIs, creating a fundamental tension for regulated workloads where remote inference falls short of the security and compliance bar. AI models must come to data.
Confidential computing makes this possible. AI models run on premises inside hardware-enforced enclaves that give model owners cryptographic assurance that proprietary weights are protected even on infrastructure they do not own. Data owners get a hardware-backed guarantee that sensitive data is never exposed during processing—not to the model provider, not to the infrastructure operator, and not to any privileged insider.
Regulated industries across healthcare, financial services, and sovereign AI can now deploy AI models with the security and compliance their environments demand.
Quick Links
Confidential computing secures AI workloads by encrypting application code, models, and data in use—not just at rest or in transit. It does this by creating hardware-rooted Trusted Execution Environments (TEEs) that are enforced by cryptographic attestation. NVIDIA has enabled confidential computing by enabling GPUs to be part of the TEE for Confidential Virtual Machines (CVM) and Confidential Containers (CoCo).
Confidential Virtual Machines isolate entire AI workloads from the host operating system and hypervisor. Even infrastructure administrators with full system privileges cannot access the data or models running inside a CVM. This creates a clean trust boundary between the workload and the underlying infrastructure.
Confidential Containers enable secure, cloud-native AI deployments. Confidential Containers are built on Kata Containers, which is an open source lightweight VM runtime that plugs into the container ecosystem and provides agility, scalability, and orchestration benefits enterprises expect from Kubernetes-based environments.
The key use cases for confidential computing include:
Protecting Model IP: Protecting model weights and preventing model theft when deploying in third-party environments.
Training on Sensitive Data: Using private data for training and fine-tuning AI models without exposing the underlying dataset to unauthorized parties.
Secure Inference on Proprietary Data: Unlocking value from proprietary data through RAG and agentic inference use cases, ensuring data remains protected throughout the inference pipeline.
Sovereign AI and Regulated Industries: Enabling any AI use case in industries that operate under strict regulatory standards, ensuring workloads meet data residency, compliance, and governance requirements.
Zero-Trust AI Factories: Providing the hardware-enforced security foundation for AI factories where model owners, data owners, and infrastructure operators share the same GPU clusters.
Key industry applications where confidential computing is critical are:
Healthcare and Pharma: Hospitals, research institutions, and pharma companies can collaborate on AI within hardware-enforced enclaves—without exposing patient records, genomic sequences, or clinical trial data to any party.
Financial Services: Fraud detection, risk modeling, and AML workloads run across institutions with cryptographic hardware guarantees—no proprietary customer data is exposed to counterparties or infrastructure providers.
Public Sector: Governments and national enterprises get the hardware-enforced foundation they need to keep AI workloads within their borders and beyond the reach of unauthorized external parties.
NVIDIA ecosystem partners are advancing production-ready confidential computing and enabling enterprises to unlock the value of AI.
In this Linux Foundation report, read how the future holds opportunities with AI and how organizations can protect those workloads with confidential computing.
Sign up for the latest news, updates, and more from NVIDIA. You can unsubscribe at any time.