
This article explains how confidential computing and confidential AI work, distinguishes between the two terms, and outlines concrete first steps for implementing them in a business setting.
Key Takeaways
- Confidential Computing additionally encrypts data during active processing, not just during transmission and storage.
- The technical foundation is a Trusted Execution Environment (TEE) directly at the processor level.
- Not even the operator of the AI model has access to the processed data.
- According to accompio, the performance difference compared to traditional AI usage is 5 to 10 percent.
- The technology currently supports open-source AI models, which are sufficient for 90 to 95 percent of use cases.
What is Confidential Computing?
Confidential Computing is a security technology that keeps data encrypted at the hardware level even during active processing. Traditional encryption protects data during transmission between systems and while it is stored on a server. In traditional systems, as soon as a program or AI model begins processing the data, it is typically stored in unencrypted form and is therefore visible to the infrastructure operator.
Confidential Computing closes this very gap using a Trusted Execution Environment (TEE), an isolated, encrypted environment directly on the processor. In an interview, Leonard Püttmann describes the principle as a safe in which even the infrastructure operator has no access to the contents.
Core definition: Confidential Computing encrypts data during active processing in addition to encryption during transmission and storage. The technical foundation is a Trusted Execution Environment at the processor level.
Why is sensitive corporate data currently left unused for AI?
Many AI models run in the cloud, sometimes on servers outside the European Union. For companies with patents, internal documents, or other sensitive information, feeding this data into such a model is risky because the data is exposed to the infrastructure operator during processing.
Without additional protection, companies therefore often stall on their AI use cases because relevant data isn’t utilized in the first place due to data protection concerns. If it does happen, data leaks are a risk. Sensitive information is incorporated into the training of additional models, ends up in the hands of third parties, or becomes a target of hacker attacks.
How does confidential computing work from a technical standpoint?
Access to a confidential AI model begins with remote attestation—a verification process to determine whether access is even permitted. The system then transmits the data to the model in encrypted form, down to the processor level. The AI model processes the data normally within this protected environment, just like other AI models. The output is sent back to the user in encrypted form and is only decrypted once it reaches the user.
“It’s really like a small safe. Even if I have physical access to the AI model, no one can extract any data from it,” explains Leonard Püttmann, Solution Architect at accompio AI.
The encryption takes place at the hardware level, not in an additional software layer. According to Leonard Püttmann, this is precisely what makes the crucial difference in security.
Confidential Computing and Confidential AI: What’s the Difference?
Confidential Computing describes the underlying hardware technology for encryption during processing, regardless of the specific application. Confidential AI is the application of this technology specifically to AI models and AI processes. A company uses Confidential Computing as a technical foundation upon which to build Confidential AI for specific AI use cases.
Confidential AI Compared to Data Masking and Anonymization
Data masking and anonymization aim to remove sensitive information from documents before processing. A residual risk remains: if individual sensitive data points slip through the filter, a data protection issue still arises. Confidential AI takes a different approach and protects the data directly during processing at the hardware level, regardless of whether anonymization took place beforehand.
Integration, Performance, and Limitations of the Technology
Confidential AI is integrated into existing systems via an external interface, similar to a standard cloud AI model. No new hardware or major system changes are required, and existing cloud providers do not need any special prerequisites either.
According to accompio, the performance difference is 5 to 10 percent compared to traditional AI usage, and real-time interaction remains possible. One limitation concerns model selection: Confidential AI currently works exclusively with open-source AI models; proprietary models such as ChatGPT or Claude cannot be used for this purpose due to technical constraints. According to accompio, this selection of open-source models already covers 90 to 95 percent of enterprises’ AI use cases.
Trust Through Independent Auditing
For many companies handling sensitive data, contractual assurances alone are not sufficient. That is why accompio also relies on technical and independent verification at the hardware level.
“For example, the entire system was also audited by TÜV IT to verify that this is indeed the case. Ernst & Young, for instance, also conducted a major audit of this technology,” says Leonard Püttmann, Solution Architect at accompio AI.
First Steps: How Companies Can Get Started with Confidential AI
According to Leonard Püttmann, the level of maturity of confidential computing in Germany currently varies widely. Some companies are already using the technology in production, while for many others it is still new—and in some cases even unknown—as a viable alternative to traditional cloud AI.
Regardless of a company’s level of maturity, the first concrete step is always the same: conducting an assessment of its own day-to-day business processes.
Two questions are central to this:
- Where do pain points arise in day-to-day operations that can be resolved with AI support?
- Do these processes involve sensitive data, such as patents, internal documents, or personal information?
If the answer to the second question is yes, Confidential AI is often the appropriate next step for technical implementation, according to accompio. The subsequent integration itself requires no new hardware and no fundamental system overhaul. It runs via an external interface, similar to a standard cloud AI model.
Conclusion
Confidential computing closes the last remaining gap in data encryption: the moment of active processing. For companies with sensitive data, Confidential AI thus opens up AI use cases that were previously impossible to implement for data protection reasons.
– – – – –
Further Reading
👉 www.accompio.com
Photo: unsplash