# Building a trusted foundation for confidential AI

> Source: <https://blogs.cisco.com/datacenter/building-a-trusted-foundation-for-confidential-ai>
> Published: 2026-09-24 20:07:52+00:00

AI is creating enormous opportunities for businesses. But as organizations move beyond experimentation and start putting AI into production, a harder question emerges:

## How do you use your most sensitive data with advanced AI models without losing control of either one?

Imagine a bank that wants an AI model to analyze sensitive financial records. Or a healthcare organization that wants to use AI to uncover insights from clinical data. The potential value is significant—but simply sending that information to an external AI service may not be an option.

That’s where confidential AI comes in.

## Protecting data while AI is using it

For years, organizations have focused on protecting data when it is stored and when it is moving across a network.

AI introduces another challenge: protecting data **while it is actually being processed.**

That matters because many of the organizations with the most valuable AI opportunities also have some of the strictest requirements around their data. Financial institutions, healthcare organizations and government agencies may not be able to move sensitive information outside their security boundaries.

At the same time, AI model providers have something important to protect too: their proprietary models and intellectual property.

And if a cloud or neocloud provider is hosting the infrastructure? Ideally, it shouldn’t be able to see either one.

The goal is simple to describe, even if it is technically difficult to deliver: **let the model and the data work together without exposing either of them to parties that shouldn’t have access.**

That requires more than a single security feature. Confidentiality has to be built into the infrastructure from the start—across compute, networking, data, security, attestation and observability.

## Bring the model to the data

Cisco is working with VAST to help make that possible.

VAST DataEnclave, the confidential AI capability within the VAST DataEngine, provides a secure runtime and attestation service for running AI workloads inside hardware-isolated environments.

Instead of moving sensitive data to an external model or service, organizations can **bring the model to the infrastructure where the data already lives.**

The architecture follows a straightforward principle:

## Verify before decrypting.

Before a workload begins, cryptographic attestation checks the hardware, firmware, runtime environment and workload policy. Sensitive information such as encryption keys is released only when the environment matches the approved configuration.

Only then are the model and data decrypted and processed inside the confidential environment.

The result is an important separation: the organization can use its sensitive data, the model provider can protect its intellectual property, and the infrastructure operator does not need access to either.

That protection matters most at the moment when both the data and the model are actively being used—and potentially most exposed.

## Confidential AI is a full-stack problem

Secure execution is an essential piece of the puzzle. But production AI needs much more than an isolated compute environment.

Consider that bank again. Protecting the data inside a server is important. But the AI workload still needs to move information between GPUs and storage, communicate across the network, enforce security policies and give operations teams enough visibility to know that everything is working as expected.

That’s why Cisco approaches confidential AI as a full-stack infrastructure challenge.

**Scalable AI compute** provides the foundation for accelerated workloads across enterprise data centers, neoclouds and sovereign AI environments. Confidential-computing capabilities in modern CPUs and GPUs help establish hardware-level trust boundaries for sensitive workloads.

**High-performance networking** moves data quickly and predictably between compute, storage, accelerators and services, while encryption and policy-based controls help protect information in transit.

**Intelligent data infrastructure from VAST** provides a scalable platform for AI workloads, while DataEnclave adds the confidential runtime and attestation needed to protect models and data during processing.

**Cisco AI Defense** helps address security risks across AI models and applications, complementing confidential computing with protection across the broader AI lifecycle.

And **Splunk and Isovalent provide observability** across applications, infrastructure, networks and cloud-native environments. Combined with auditable records of attestation, policy decisions and workload activity, organizations can understand what is happening without breaking the isolation that confidential AI depends on.

Together, these capabilities advance Cisco’s Secure AI Factory strategy: bringing compute, networking, data, security, observability and ecosystem software together as one trusted foundation for enterprise AI.

## More freedom in where AI can run

A full-stack confidential AI architecture can also give organizations more flexibility in how and where they deploy AI.

An enterprise could run an advanced model against proprietary information while keeping that data within infrastructure it controls.

A model provider could make its technology available to more customers without exposing its model weights.

A neocloud provider could host AI services without gaining visibility into customer data or models.

And a sovereign-cloud operator could support sensitive workloads that need to remain within specific geographic or administrative boundaries.

This can enable use cases ranging from secure retrieval-augmented generation and AI agents working with proprietary information to financial analysis, fraud detection, clinical research and sensitive government applications.

It can also help organizations think differently about resilience. For example, a government agency may want critical data to remain under strict control while still maintaining the ability to fail over workloads to another region during an outage. Confidential AI creates a path toward that kind of flexibility without simply giving up control of the underlying information.

## Building trust into the infrastructure

As AI moves deeper into the enterprise, performance alone won’t define a strong AI infrastructure.

Organizations will also ask: **Where is my data? Who can see it? Who can access the model? And how do I know the environment can be trusted before anything sensitive is exposed?**

Those questions can’t be answered by adding security after the fact.

Trust has to be engineered into the compute, network, data, security and operational architecture from the beginning.

By working with VAST, Cisco is extending its full-stack AI approach to help organizations protect sensitive information and proprietary models while still delivering the performance and scale production AI demands.

That’s the opportunity with confidential AI: not simply protecting another AI workload, but making it possible to bring powerful models to some of an organization’s most valuable data—with greater confidence and control.

Additional resources:

### Cisco Secure AI Factory with NVIDIA

[Explore more](https://www.cisco.com/site/us/en/solutions/artificial-intelligence/secure-ai-factory/index.html)
