On Thursday, 5 March, the TDL webinar series continued with a distinguished panel discussing the current state of confidential computing, its successes and challenges and its short term future.
Confidential computing protects data while it’s being processed, not only at rest or in transit. The area experienced rapid progress in recent years, in confidential AI, multi-party analytics and as an areas of strong interest in regulated industries. The challenges remain, however, including complexity (e.g., in attestation), performance trade-off, insufficient direct hardware support, relatively slow practical adoption and emerging quantum readiness concerns. With today’s focus and significant resource allocation to AI, confidential computing is likely to benefit from improvements the paradigm can offer to AI security, such as protection of input data and models, remote attestation, better supply chain security and more.
Summary
This panel discussion focused on the current state and future prospects of confidential computing in 2026. The panellists discussed various aspects of confidential computing, from its current implementation challenges to potential killer applications and history of the technology. Key topics covered included the complexity of attestation processes and potential remedies to overcome this issue, the need for interoperability across different platforms, and the role of AI in driving adoption. The panellists agreed that while significant progress has been made in hardware capabilities, major challenges remain in standardising attestation methods as well as making confidential computing more accessible and appealing to developers. They expressed cautious optimism about the future of confidential computing, particularly in AI and regulated sectors, noting that while universal adoption may not be immediate, specific use cases will likely drive significant growth in the next two to three years.
Background
The panellists were asked to comment on their view on the most important areas, challenges, achievements and prospects of confidential computing. The questions included addressing what the most important benefits and the most important challenges of confidential computing are and where, in which areas, confidential computing is currently implemented on a large scale and why; and as a corollary, what are considered the greatest challenges to large scale deployment. From an evolutionary perspective, it is important to understand what specific threats confidential computing mitigates against and how it can be used for AI (machine learning and agentic AI).
Benefits and uses
Digging further into what the main benefits are, it’s of interest to know how confidential computing can be used in hybrid cloud and whether it can improve the implementation (and architecture) for multi-party secure computation. More questions follow from asking how confidential computing is employed to improve AI security and trustworthiness, to how it improves data integrity and whether it can be supportive with regard to regulatory compliance (e.g., GDPR). Undoubtedly there are numerous other use cases!
Deployment and technical challenges
The headline topic is what the main challenges associated with confidential computing are, and to explore this further raises questions as to whether performance trade-off is still a serious issue, whether confidential computing implies higher infrastructure costs. A conundrum is why it has been difficult to obtain vendor lock-in which begs the question as to whether confidential computing (especially attestation) is too complex and whether there are still observability challenges within enclaves. If these are real concerns, there should be an understanding of what the main mitigations to these and other challenges are, as well as what research is needed to ensure confidential computing can achieve broad adoption in the future.
Prospects and future
So the key question concerns what the short term future of this technology is and what will define it; for example, will AI be a significant driver of its future success and what will be the immediate accelerators of adoption, from resolved challenges to new use cases. Given Gartner’s prediction of significant growth for confidential computing in the next three years, we wanted the panellists to share their views and indicate whether they were over all optimistic with regard to the broad adoption of confidential computing.
A lot of known unknowns and opportunities for further deliberations over the months to come!
Speakers
The panel comprised:
Henk Birkholz, Principal Architect, Fraunhofer Institute for Secure Information Technology (SIT}; Chair, Trusted Computing Group; Co-chair, IETF IoT Operations Working Group and IETF Operations and Management Area Working Group
Jan Camenisch, Distinguished Researcher, Subzero Labs
Greg Kazmierczak, Principal Investigator, NKrypt
Ian Oliver, Professor of Practice (Cybersecurity), University of Oulu
Ron Perez, Intel Fellow, Chief Security Architect, Office of the CTO (retired)
The session was moderated by TDL strategic advisor, Claire Vishik
Confidential Computing: Challenges and Evolution
The panel discussed the current status of confidential computing, noting that, while it provides better transparency and isolation than trusted computing, it presents new challenges for remote attestation. The importance of simplifying evidence for relying parties was emphasised, highlighting the diversity of confidential computing platforms across vendors, which creates complexity in platform selection. The discussion touched on how confidential computing has evolved from its earlier trusted computing roots, with a focus on the need for better differentiation between platform capabilities and simplified verification processes
Infrastructure Complexity Challenges
The conversation moved on to the current state and challenges of confidential computing, particularly focusing on sovereignty and the need for secure data processing in edge and far-edge environments. The main challenge was identified as the complexity of the infrastructure around confidential computing, including attestation processes, supply chain security and the need for standardised attestation interfaces. Simplifying these processes for developers was agreed as important as was the risk of ad-hoc solutions emerging. It was noted that complexity in attestation is a common issue with the suggestion that developers should use the technology in real-world scenarios to better understand and address the challenges.
Evolution and Challenges
The discussion followed the evolution and current state of confidential computing, highlighting advancements such as the transition to virtual machine-based memory encryption and hardware-backed remote attestation. The importance of interoperability across different vendor implementations to facilitate broader adoption was emphasised, noting that, while specific solutions offer benefits, a common set of services and interfaces is crucial for progress. Also mentioned were the ongoing challenges, including fragmentation and operational complexity, and it was suggested that confidential computing will likely be adopted primarily for high-value, high-sensitivity workloads in AI and regulated sectors such as finance rather than becoming universally adopted.
Confidential Computing: Challenges and Prospects
The panellists discussed the current state and future prospects of confidential computing, identifying key challenges including attestation, interoperability between different hardware platforms and long-term trust management. The group agreed that AI applications, particularly in areas like international finance and payroll systems, represent promising use cases for confidential computing. While acknowledging significant technical challenges remain, particularly around standardisation and verification processes, the panellists expressed cautious optimism about the technology’s adoption in the next two to three years, driven by AI deployments and improvements in hardware capabilities like ARM CCA (confidential compute architecture), although it was questioned whether CCA would provide security against physical attacks on a host, particularly an “untrustable” platform to which we don’t have all the answers yet. And a good reason to come back again soon to find out!
Finally ... A Question From The Audience
It was asked whether the availability challenges and psychological issues of remote processing were a hindrance, is it realistic to expect that data sovereignty will lose most of its criticality if confidential computing is properly implemented and available from the public cloud ?
The responses were both, ‘yes’: if confidential computing is properly implemented and available at a global scale, data sovereignty should be addressed and thus less critical in terms of the lack of sovereignty (i.e., not the need for it). Secure compute protocols that run on the Internet on TEEs will eventually provide sovereign compute and data.
And ‘no’: depending on the levels of trust, some things can be allowed to run (confidentially) anywhere and preserve sovereignty while others must be kept as local as possible.
Separately, mention was made about a paper from 2018 on ontology-based reasoning about trustworthiness in cyber-physical systems, which was related to previous work done with NIST.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.