Why Confidential AI Is Moving Beyond the CPU

AI security is moving beyond the processor at the center of a server. Confidential computing, once tied mainly to CPUs, now reaches GPUs, multi-GPU environments, containers, and the agentic AI workflows beginning to shape enterprise systems.
That shift matters because AI workloads handle sensitive data, model weights, and memory while processing tasks. GPU-based confidential computing is becoming a major catalyst for Confidential AI adoption, giving organizations a way to protect those assets while AI systems run. On Sep. 10, 2026, Aisling Dawson, senior analyst at ABI Research, summed up the change: “Confidential computing is no longer a CPU-only conversation.”
GPUs Become the Center of Confidential AI
CPU-based confidential computing remains closest to mass-market adoption, but GPU deployments are gaining strong momentum. They address one of the biggest gaps in AI security: protecting data while it is being processed, rather than only protecting it before or after a workload runs.
This focus is pushing the market toward Confidential AI architectures that cover inference and training, along with newer agentic workflows. The goal is to protect data and models without giving up the performance production environments need. That balance matters because security controls have limited value if they prevent organizations from running the AI workloads they want to use.
NVIDIA continues to set the pace in confidential GPUs, with advances spanning its Hopper, Blackwell, and Vera Rubin platforms. Intel, AMD, and Arm are strengthening the CPU and heterogeneous compute foundations that support broader Confidential AI deployments.
The result is a security conversation that now covers more than one type of chip. Confidential computing is expanding across the hardware used to run AI, creating a foundation for protection in systems that combine CPUs, GPUs, and other forms of compute.
Containers Add Another Layer to the Security Challenge
Hardware is only part of the picture. Enterprises running cloud-native and Kubernetes-based environments are showing rising interest in confidential containers alongside confidential virtual machines. These organizations want lower complexity, reduced attack surfaces, and deployment models that fit AI workloads more flexibly.
Confidential containers can help connect protected computing with the way many enterprises organize and run software. Their importance grows as AI workloads move across different environments and as organizations look for security controls that match both their infrastructure and their operating needs.
Companies including Anjuna, Red Hat, Fortanix, Decentriq, and IBM are developing platforms and controls for this market. Their work covers secure AI model weights, attestation, confidential containers, and the governance requirements created by agentic AI.
Attestation is an important part of that picture because it helps establish trust in the environment running a workload. Alongside protection for data, models, and memory, these controls give enterprises a way to build confidence around where and how AI systems operate.
Agentic AI Raises the Stakes
Agentic AI is creating a new security inflection point for confidential computing. These systems bring new requirements for protecting agent execution, sensitive memory, and the records needed to understand what happened during a task.
Confidential computing will not solve every agentic risk. Still, it is emerging as one of the most credible hardware-rooted approaches for securing agent execution, protecting sensitive memory, strengthening auditability, and building trust in high-value enterprise AI systems.
That makes confidential computing more than a feature tied to a particular processor. It is becoming a foundational security layer for AI, extending from CPUs into GPUs, multi-GPU systems, containers, and agentic workflows.
The market will test which vendors can turn that foundation into practical products. Vendors that pair strong attestation, performance optimization, and ecosystem collaboration will be best positioned to capture the opportunity.
For enterprises, the direction is clear: protecting AI means securing the full environment in which AI works. That includes the chips processing workloads, the containers and virtual machines hosting them, the memory holding sensitive information, and the agents carrying out tasks. Confidential AI is expanding because each part of that environment now matters.
Based on




