Businesses have traditionally focused on protecting data in two major states:
Data at rest — information stored in databases, servers, or cloud storage.
Data in transit — information moving between systems.
But there is another critical state:
Data in use.
When applications process information, sensitive data may temporarily exist in system memory. This creates a security challenge for organizations running sensitive workloads in cloud and shared infrastructure environments.
Confidential Computing addresses this challenge by using hardware-based security mechanisms to protect data while it is being processed.
In May 2026, NIST published an initial public draft specifically focused on hardware-enabled security and Confidential Computing for cloud workloads, including protection of AI workloads.
Confidential Computing is a security approach designed to protect sensitive data while it is actively being processed.
It commonly uses hardware-based Trusted Execution Environments (TEEs) to isolate sensitive workloads and restrict unauthorized access to data during computation.
The goal is to extend data protection beyond storage and network transmission into the actual processing environment.
This becomes particularly valuable when businesses use cloud infrastructure for sensitive workloads.
Traditional encryption protects stored information and information moving across networks.
However, applications need access to data in order to process it.
For example, a business application may need to:
Confidential Computing introduces mechanisms that help protect sensitive information during these processing operations.
NIST describes this as an important advancement for protecting data in cloud environments, particularly as organizations increasingly move sensitive workloads to cloud platforms.
A simplified Confidential Computing architecture typically involves a protected execution environment.
Data is provided to a trusted workload rather than being exposed broadly across the underlying infrastructure.
The Trusted Execution Environment isolates sensitive computation and helps prevent unauthorized access.
Security mechanisms help ensure that protected data can only be accessed by authorized code running within the trusted environment.
Remote attestation can help verify that the expected workload is running inside an appropriate trusted environment before sensitive information or cryptographic keys are released.
This creates a stronger foundation for cloud security.
The growth of AI makes Confidential Computing particularly relevant.
AI workloads can process highly sensitive information, including:
Organizations may want to use cloud-based AI services without unnecessarily exposing sensitive data during processing.
NIST's 2026 Confidential Computing work specifically discusses protecting data processed by AI workloads in cloud infrastructure.
This makes Confidential Computing an increasingly relevant component of secure AI architecture.
As businesses adopt AI, security teams are moving beyond protecting only the AI interface.
They also need to consider:
Confidential Computing can help create stronger security boundaries around sensitive AI workloads.
The technology is also being explored for AI inference and fine-tuning workloads where organizations need stronger privacy guarantees.
Confidential Computing extends protection into the processing stage.
It can help organizations reduce risks associated with sensitive workloads running on shared cloud infrastructure.
Organizations can explore AI applications while applying additional protections to sensitive datasets and processing environments.
Businesses can strengthen privacy controls when handling sensitive information.
Confidential Computing can provide technical mechanisms for verifying that workloads are running in approved environments.
Banks and financial technology companies can use Confidential Computing for sensitive analytics, fraud detection, and financial workloads.
Healthcare organizations can explore protected environments for processing sensitive medical and patient information.
SaaS and enterprise applications can use confidential environments for workloads requiring stronger data isolation.
Confidential Computing can support sensitive AI inference, model processing, and data analysis.
Public-sector organizations handling confidential information can benefit from stronger workload isolation.
Multiple organizations may need to analyze data without unnecessarily exposing the underlying information to one another.
A modern security architecture can protect:
Data at Rest + Data in Transit + Data in Use
This broader approach is particularly relevant for organizations moving sensitive applications to cloud platforms.
Confidential Computing is promising, but organizations should evaluate several factors before implementation.
Security mechanisms can introduce technical overhead depending on the workload and architecture.
Existing applications may require changes to operate effectively inside protected execution environments.
Organizations need infrastructure that supports the required Confidential Computing capabilities.
Strong key-management processes remain essential.
Security teams need appropriate tools and expertise to monitor and manage confidential workloads.
Therefore, Confidential Computing should be implemented as part of a broader security architecture rather than treated as a standalone solution.
Businesses considering Confidential Computing can start by identifying workloads where data sensitivity and cloud exposure create significant security requirements.
A practical approach is:
Cloud computing continues to become the foundation for modern applications, analytics, and AI.
As workloads become more sensitive, organizations need security mechanisms that protect information throughout its lifecycle.
Confidential Computing represents an important shift toward protecting data during computation, rather than relying only on storage and network encryption.
The growing attention from organizations such as NIST demonstrates that data-in-use protection is becoming an important area of modern cybersecurity research and implementation.
Confidential Computing is emerging as an important security technology for organizations that need to process sensitive information in cloud and AI environments.
Its core principle is simple:
Sensitive data should remain protected not only when it is stored or transmitted, but also when it is being processed.
As businesses adopt cloud services, AI applications, and distributed computing architectures, protecting data in use will become increasingly important.
Organizations that start evaluating Confidential Computing today can build stronger foundations for secure cloud adoption and privacy-focused AI.
Confidential Computing is a security approach that protects sensitive data while it is being processed, commonly using hardware-based Trusted Execution Environments.
A Trusted Execution Environment, or TEE, is a protected computing environment designed to isolate sensitive workloads and restrict unauthorized access.
Yes. Confidential Computing can help protect sensitive datasets and AI workloads during processing, particularly in cloud environments.
No. It complements traditional encryption by addressing security risks associated with data while it is being processed.
Financial services, healthcare, technology companies, government organizations, cloud-based businesses, and enterprises handling sensitive data can all potentially benefit.
As businesses move toward cloud-first applications and AI-powered operations, security needs to evolve alongside technology.
Riotech focuses on helping organizations build modern, scalable, and technology-driven solutions with security and future readiness in mind.
Looking to modernize your cloud or enterprise technology infrastructure? Connect with Riotech to explore the right technology strategy for your business.