Key Insights:
- Confidential computing is gaining new relevance as AI workloads move across GPUs, NPUs, TPUs, and edge hardware. Its value is rising wherever sensitive data must stay protected during processing.
- The strongest near-term opportunity is not broad AI security positioning. It is targeted use cases such as sovereign AI, confidential AI workloads, and attested environments for higher-trust execution.
- Sovereignty is changing the buying criteria for confidential computing. Enterprise and government customers increasingly want proof of control, runtime integrity, and data governance rather than simple claims of privacy or compliance.
- Adoption will still be shaped by practical barriers such as integration complexity, hardware concentration, and vendor lock-in. Vendors that support supply chain resilience via interoperability and open source engagement will be better positioned.
Confidential Computing (CC) protects sensitive data while it’s being processed, something that is mission- and safety-critical in the face of growing sovereign Artificial Intelligence (AI) initiatives. Organizations increasingly leverage computing hardware to run AI workloads. Consistent attestation is a must to ensure data privacy during task execution, which makes CC an attractive addition to Information Technology (IT) stacks.
Awareness of CC is growing, but adoption decisions remain complex. Market traction is being shaped by technical capabilities, deployment challenges, and operational requirements for disparate buyer groups.
AI Is Expanding the Role of Confidential Computing
Generative AI (Gen AI) helped kick-start a wave of investment in CC in 2025. The expansion of CC from Central Processing Units (CPUs) into Graphics Processing Units (GPUs) made it possible to protect far more demanding AI workloads. Now, the technology is extending toward Neural Processing Units (NPUs), Tensor Processing Units (TPUs), edge devices, and other AI accelerators.
Several companies are pioneering this infrastructure shift. NVIDIA is extending confidential capabilities across increasingly large GPU environments. Meanwhile, Intel is advancing CPU-to-GPU protection. Trusted Execution Environment Device Interface Security Protocol (TDISP), TEE-I/O, and similar developments also help reduce the performance trade-offs associated with protecting demanding AI workloads.
Agentic AI introduces another security challenge for organizations. AI agents can interact with enterprise systems, access sensitive resources, and operate with less human involvement. The recent Hugging Face incident highlighted the security risks posed by rogue AI agents. CC can protect software guardrails and cryptographic evidence about the integrity of an agent's execution environment. That makes it particularly interesting for organizations concerned with auditing and governing autonomous systems.
Despite its increasing value, CC is not a silver bullet for Agentic AI security. It cannot address prompt injection, intent drift, poisoned models, or every form of rogue agent behavior. Vendors should carefully assess where CC can strengthen Agentic AI security, such as verifying agents and supporting audits. Since CC cannot address every vulnerability, vendors should pair it with complementary security technologies, including identity and access management.
Sovereign Initiatives Are Raising the Value of Verifiable Trust
Data sovereignty is also creating a commercial opportunity for CC providers. Ensuring in-country data residency is only one part of the equation. Organizations also seek more control over how sensitive AI workloads are processed and greater confidence that infrastructure providers cannot access them.
CC is well-suited to sovereignty requirements; attestation enables organizations to verify the trustworthiness of runtime environments, moving the conversation from simply having control to being able to prove it.
Confidential containers play a key role in facilitating silicon sovereignty. Compared with relying exclusively on Confidential Virtual Machines (CVMs), container-level attestation gives organizations more flexibility to move individual workloads between multi-cloud environments. Red Hat’s Confidential Containers, for example, can facilitate lift-and-shift capabilities across the public and private clouds. Confidential tenancy is also catching on as a viable means of achieving cloud sovereignty. Delivered by virtual data diodes, confidential tenancy can prevent exfiltration of data. And this is the case even when the CSP uses a backdoor. Such protection could prove critical in light of the implications of the Clarifying Lawful Overseas Use of Data (CLOUD) Act with regard to data access and states’ sovereign borders.
Technology providers should consider three primary customer groups in the sovereign market:
- Hyperscalers: Native CC support is increasingly becoming table stakes, making differentiation harder.
- National Clouds: CC could help address sovereignty requirements without requiring countries to recreate hyperscale infrastructure entirely within their borders.
- Enterprises: The opportunity is less mature, with awareness, integration complexity, and Total Cost of Ownership (TCO) still slowing adoption.
Demonstrating Supply Chain Resilience Is Key to CC’s Convergence with Other PETs
Widespread convergence between confidential computing and other Privacy Enhancing Technologies (PETs), including Fully Homomorphic Encryption (FHE) and Zero-Knowledge Proofs (ZKPs), is unlikely in the near term. Combining these technologies can provide significant value, but CC-enabled hardware (e.g., GPUs and chipsets) availability remains concentrated among a small number of vendors; notably, Intel, AMD, Arm, and NVIDIA dominate the hardware supply chain, creating vendor lock-in concerns. Therefore, organizations may favor other PETs when they offer simpler deployment or lower costs.
As of 2026, neither PETs nor combined CC-PET solutions have reached mass-market adoption. Dual solutions lag behind standalone PETs due to limited awareness, preference for established technologies, and standardization gaps. In contrast, pure CC solutions such as Multi-Party Computation (MPC) and ZKPs are among the most mature approaches, despite adoption remaining below mass-market levels.
Going forward, ABI Research recommends that large market players actively engage in open-source projects on the CC side of the market. Open-source offerings will prove consequential to alleviating the supply chain and vendor lock-in concerns of customers around CC.
What Next?
AI adoption and sovereignty requirements are expanding the role of confidential computing in enterprise and government security strategies. Marketing these solutions as purely “better security” will fail to move the needle. Messaging must center on easy deployment, greater control and verification of data governance, and solution diversity (e.g., hardware interoperability).
For cybersecurity stakeholders, that points to a few priorities:
- Integration complexity remains a barrier to Confidential AI adoption. Vertical and use case-specific solutions, such as AI Intellectual Property (IP) protection, could give customers a clearer reason to adopt CC.
- Attestation of the TEE, silicon provenance, and supply chain transparency could become meaningful differentiators as sovereignty influences more buying decisions.
- Hybrid deployment, hardware interoperability, open-source initiatives, and partnerships with other security providers can help reduce concerns about vendor lock-in.
As part of the company’s Quantum Safe Technologies Research Service, ABI Research has published three reports covering the CC opportunity across AI, cloud sovereignty, and CC-PET combinations. Reach out today to discuss a subscription plan and gain access to these reports, as well as adjacent cybersecurity advisory. Let’s talk