Confidential Computing moves into mainstream AI usage

Applications of AI


Confidential computing is moving from niche adoption to mainstream IT strategies as organizations seek stronger protection for data used in artificial intelligence and cross-border collaboration, according to a new global study from IDC.

The study was commissioned by the Confidential Computing Consortium (CCC) and surveyed more than 600 IT leaders across 15 industries. They found that while three-quarters of organizations have adopted some form of confidential computing, many still face adoption hurdles and skills shortages.

Confidential computing refers to technologies that protect data not only at rest or in transit, but also during processing. Vendors typically implement this through a hardware-backed trusted execution environment that isolates the workload from the rest of the system.

“Confidential Computing has grown from a niche concept to a critical strategy for data security and trusted AI innovation,” said Nelly Porter, Chair of the Confidential Computing Consortium Board of Directors. “As international security and compliance regulations tighten, organizations must invest in education and interoperability to meet enhanced data confidentiality, integrity, and availability standards and enable secure AI deployment across sensitive environments.”

Adoption accelerates

IDC reported that 75% of organizations surveyed have deployed confidential computing. Within this group, 18% are already operating the technology in production, and a further 57% are piloting or testing deployments.

This study highlights data integrity as a key benefit. It found that 88% of respondents reported improved integrity of data processed in sensitive computing environments. Additionally, 73% cited confidentiality through technology assurance, and 68% noted improved regulatory compliance.

Respondents reported that confidential computing supports a variety of business outcomes. They cited faster innovation, stronger compliance, and improved cost efficiency as key outcomes. The study states that the combination of confidential computing and AI-driven analytics supports secure model training, inference, and AI agents on sensitive data sets.

This report explains that confidential computing is a practical and scalable option when organizations compare it to more complex or resource-intensive privacy technologies. The organization says it can be applied to standard computing workloads. He also said that this does not require rewriting existing applications or algorithms.

Regulation and AI

The study associates increased adoption with stronger regulation and increased use of AI in regulated sectors. He said security, compliance and innovation challenges are converging as boards and regulators focus on data in use.

Regulatory frameworks such as the Digital Operational Resilience Act (DORA) are already impacting investment decisions. According to IDC, 77% of organizations are more likely to consider sensitive computing because DORA includes explicit requirements for protecting data in use.

Workload security and external threats were cited most frequently as direct drivers for adoption, cited by 56% of respondents. Protecting personally identifiable information (PII) followed at 51%, followed by broader compliance requirements at 50%.

New use cases in AI and the cloud are also driving demand. Organizations that participated in the survey said they use confidential computing to train AI models, run inference workloads, and deploy AI agents on regulated data, without exposing sensitive information.

Cloud-driven deployment

Highest utilization in public cloud environments. IDC found that 71% of public cloud users in their sample were most likely to implement sensitive computing technologies. Hybrid and distributed cloud users follow at 45%.

This study links this trend to the need for scalable security controls across distributed infrastructures and changing regulatory expectations for data hosted in the cloud.

Regional and sector gaps

Adoption patterns vary by region and sector. For example, financial services is the top industry, with 37% of organizations operating at full capacity. This is followed by healthcare at 29% and government at 21%.

The healthcare organizations in our sample demonstrated a focus on multi-stakeholder data projects. IDC reports that 78% of respondents in healthcare organizations prioritize data collaboration with multiple parties while protecting privacy, compared to 61% in financial services and 26% in government. The report links this to highly regulated medical data handling and emerging AI-based diagnostics leveraging shared datasets.

Barriers and standards

Despite this momentum, this study reveals significant barriers. These include challenges in verifying proofs, cited by 84% of respondents. Many organizations still view confidential computing as a niche technology, with 77% of those surveyed holding that perception. The skills gap affects 75% of respondents.

IDC said these issues require greater industry collaboration, workforce training, and technology standardization. Organizations are encouraged to start with limited pilot projects that demonstrate measurable value. It also recommended the adoption of open standards and vendor-neutral frameworks.

The study recommends investing in third-party certification services and interoperability testing. It also pointed to industry-led organizations such as the CCC that work on technology assurance and trust frameworks.

The consortium says the next phase of confidential computing will span identity, AI, multiparty collaboration, and privacy-preserving analytics across industries and geographies.



Source link