
17.07.2026
Confidential Computing encrypts data during transmission, storage, and additionally during active processing by an AI model.
For companies with sensitive data such as patents, internal documents or health information, Confidential Computing makes a central difference compared to classic cloud AI, where the provider of the model technically has insight into the data during processing.
Leonard Püttmann, AI Solutions Architect at accompio, In the discussion, it identifies how the technology works, what use cases it is suitable for, and where its limitations lie. This article explains how Confidential Computing and Confidential AI work, differentiates between the two terms, and outlines concrete first steps for use in enterprises.
For this focus topic, accompio spoke with Leonard Püttmann, Solutions Architect AI, who is responsible for the secure deployment of AI technology for accompio's clients in his day-to-day work.
Confidential Computing is a security technology that keeps data encrypted at the hardware level, even during active processing. Traditional encryption protects data during transmission between systems and when stored on a server. Once a program or an AI model works with the data, in traditional systems it is usually decrypted and therefore visible to the infrastructure operator.
Confidential Computing closes exactly this gap via a Trusted Execution Environment (TEE), an isolated, encrypted environment directly on the processor. In an interview, Leonard Püttmann describes the principle as a safe, where even the infrastructure operator has no access to the content.
Core definition Confidential Computing encrypts data during active processing, in addition to encryption at rest and in transit. The technical basis is a processor-level Trusted Execution Environment.
Many AI models run in the cloud, partly on servers outside the European Union. For companies with patents, internal documents, or other sensitive information, entering this data into such a model is risky, as the data is openly available to the infrastructure operator during processing.
Without additional protection, companies often get stuck with their AI use cases because relevant data is not used in the first place due to data protection reasons. If it does happen, data breaches are a risk. Sensitive information flows into the training of further models, reaches third parties or falls prey to hacker attacks.
Accessing a Confidential AI model begins with a remote attestation, a check to see if access is permitted at all. The system then transmits the data encrypted down to the processor level to the model. The AI model works with the data within this protected environment as usual, comparable to other AI models. The output is sent back encrypted to the user and is only decrypted there.
„It's really like a little vault. Even if I have physical access to the AI model, no one can extract any data from it.“
— Leonard Püttmann, Solution Architect at accompio AI
The encryption is at the hardware level, not in an additional software layer. According to Leonard Püttmann, this is precisely what makes the crucial difference in security.
Confidential Computing describes the underlying hardware technology for encryption during processing, irrespective of the specific application. Confidential AI is the application of this technology specifically to AI models and AI processes. A company uses Confidential Computing as a technical foundation to subsequently leverage Confidential AI for specific AI use cases.
Data masking and anonymisation attempt to remove sensitive information from documents before processing. A residual risk remains: if individual sensitive data points slip through the filter, a data protection problem still arises. Confidential AI takes a different approach and protects the data directly during processing at the hardware level, regardless of whether anonymisation has taken place beforehand.
Confidential AI is integrated into existing systems via an external interface, similar to a conventional cloud AI model. No new hardware or major system changes are necessary for this, and existing cloud providers do not require any special prerequisites.
According to accompio, the performance difference is 5 to 10 percent compared to classic AI usage, with real-time interaction still possible. One limitation concerns model selection: Confidential AI currently works exclusively with open-source AI models; proprietary models such as ChatGPT or Claude cannot be used technically. According to accompio, this selection of open-source models covers 90 to 95 percent of companies' AI use cases.
Contractual assurances alone are not enough for many companies when handling sensitive data. accompio therefore also relies on technical and independent evidence at the hardware level.
„For example, the entire thing was also checked by TÜV IT and verified to ensure it was indeed the case. Ernst & Young, for instance, also conducted a major audit for this technology.“
— Leonard Püttmann, Solution Architect at accompio AI

Are you planning specific AI use cases with sensitive company data and looking for a secure technical foundation? accompio supports you with an inventory assessment, selection of suitable open-source models, and the technical integration of Confidential AI into your existing infrastructure.
According to Leonard Püttmann, the maturity of Confidential Computing in Germany is currently very varied. Individual companies are already using the technology productively, but for many others, it is still new, and in some cases, they are not even aware of it as a real alternative to traditional cloud AI.
The first concrete step, regardless of your own maturity level, is always the same: an inventory of your own processes in daily operations.
This centres on two questions:
If the answer to the second question is "yes", then according to accompio, Confidential AI is often the right next step for the technical implementation. The subsequent integration itself requires no new hardware and no fundamental system change. It runs via an external interface, comparable to a conventional cloud AI model.
Confidential computing closes the last remaining gap in data encryption: the moment of active processing. For companies with sensitive data, confidential AI therefore opens up AI use-cases that were previously impossible for reasons of Data protection were not feasible.

Leonard Püttmann works as a Solutions Architect AI at accompio, dealing daily with the secure implementation of AI technology for corporate clients.
Normal encryption protects data during transmission and storage. Confidential Computing additionally encrypts data during active processing by a program or AI model, via a processor-level Trusted Execution Environment.
No, ChatGPT and Claude are proprietary models and cannot be used for this purpose technically. Confidential AI currently works with open-source AI models, which, according to accompio, already cover 90 to 95 percent of enterprise use cases.
In principle, every industry with sensitive data benefits from Confidential AI. According to accompio, the technology is particularly relevant for the finance and healthcare sectors, as highly sensitive personal or company-critical information is often involved, such as examination results or financial data that must not fall into the hands of third parties.
The performance difference compared to classic AI usage is 5 to 10 percent. Interaction with the model remains possible in real-time.
The first step is to take stock of your own processes and pain points, along with the question of where sensitive data is involved. This forms the basis for deriving the appropriate technical implementation.

Arrange an initial consultation