Agentic AI Challenges Progress in Confidential Computing
Artificial intelligence is driving increased adoption of confidential computing, but the proliferation of AI agents within enterprises poses a new security challenge. These agents can retain sensitive data and secrets, exceeding the capabilities of current confidential computing systems. Google’s Nelly Porter advocates for a new approach, including dedicated encryption keys and ‘crypto-shredding’ to address this issue. Despite these challenges, confidential computing is advancing, with Apple’s Private Compute Cloud and ServiceNow’s use of confidential computing on Nvidia GPUs demonstrating progress. The technology is expected to become a significant driver of AI adoption and a multi-billion dollar market by 2030.
Artificial intelligence is driving increased adoption of confidential computing, but the proliferation of AI agents within enterprises poses a new security challenge. These agents can retain sensitive data and secrets, exceeding the capabilities of current confidential computing systems. Google’s Nelly Porter advocates for a new approach, including dedicated encryption keys and ‘crypto-shredding’ to address this issue. Despite these challenges, confidential computing is advancing, with Apple’s Private Compute Cloud and ServiceNow’s use of confidential computing on Nvidia GPUs demonstrating progress. The technology is expected to become a significant driver of AI adoption and a multi-billion dollar market by 2030.
Confidential computing establishes a secure boundary to protect data from being stolen when in storage, transit, or use. Encrypted data is stored in secure vaults and protected by mutual attestations and specialized hardware. However, as companies rush to adopt AI, armies of agents in enterprises create a new threat model that confidential computing isn't designed to protect, Google’s Porter said. Agents don’t forget and as AI models train and execute prompts, they could retain enterprises’ most sensitive secrets, he said. Porter shared an example of AI agent evaluating a company for a potential acquisition, and absorb sensitive financial and business details. If the deal falls apart, the agent may not automatically forget those details or remove it from memory.
Porter’s solution was a dedicated encryption key for each agent to protect short-term and long-term memory and data it retains or distills. Data can be deleted by “crypto-shredding” it, which involves killing the encryption key, as opposed to the data. "We have all Lego blocks and all the capability to make it happen," Porter said.
Apple announced in May the most prominent confidential computing deployment to date by implementing the technology in its Private Compute Cloud infrastructure to secure AI access across billions of its devices. Apple announced PCC to much fanfare in 2024, but delayed it over a slower Siri rollout, unresolved security guarantees and hardware challenges.
Apple has a history of building technology using internal tools, but had to break tradition for confidential computing, Sanchit Vir Gogia, CEO of Greyhound Research, tells Dark Reading. The new arrangement involves Google Cloud, Nvidia’s confidential computing on Blackwell graphics processing units (GPUs), Intel central processing units (CPUs) with trust domain extension (TDX), and Google’s Titan security chip. The new implementation has at least two independent secure hardware roots of trust.
“Confidential AI is a multi-layer architecture that spans hardware, cloud, accelerator, attestation and model serving. Privacy now has to travel with the workload,” Gogia says. For example, an iPhone establishes a trust boundary with a server where it sends secure data. The Nvidia GPU identifies itself as a secure environment, receives secure data, decrypts and processes on the GPU, and re-encrypts and sends it back to the phone.
“Apple is creating the best of both worlds where they're getting performance, efficiency, and maintaining the privacy of the user data,” says Nvidia’s Harris. And it is just the start; by 2030, confidential computing use cases are expected to reach about $160 billion, he says.
ServiceNow uses confidential computing so 9,000 sales employees get quick answers to commission-related inquiries, such as forecasts and income, says Kellie Romack, chief digital information officer. Previously, the sales staff had to submit tickets to the compensation and finance department, a manual process that took four days. The new system instantaneously analyzes the sensitive data using secure enclaves and generates responses within eight seconds. The technology runs on Nvidia’s H100 GPUs, Opaque Systems’ confidential AI computing framework and Microsoft’s Azure Cloud.
“It created trust in the technology,” says Romack. “The system ‘freed up mindshare for my finance and HR team… and those sellers took a worry off their shoulders so they could go and serve our customers,” she says.
