Dr. Najwa Aaraj, Chief Executive Officer, Technology Innovation Institute.
For decades, cybersecurity has focused on protecting data in two states. Data at rest is encrypted. Data in transit is encrypted. But a third state is becoming increasingly important: data in use.
AI makes this challenge impossible to ignore.
AI systems are increasingly being asked to work with some of an organization’s most sensitive information, from medical records and financial transactions to industrial data, government information and proprietary enterprise knowledge. Yet to generate value from that information, AI systems need to compute on it. During that processing, when data traditionally becomes accessible to the systems working with it, an important security gap can emerge.
For organizations looking to deploy AI more widely, this creates a fundamental question of trust. Can sensitive data, intellectual property and critical information remain protected not only when they are stored or transmitted, but throughout the computation itself? Trust is therefore no longer simply a cybersecurity objective. It is becoming a prerequisite for innovation.
Protecting Data In Use
This is where confidential AI and privacy-enhancing technologies (PETs) become increasingly important.
The principle is straightforward: Organizations should be able to derive value from sensitive information without unnecessarily exposing it in the process, while protecting the data, models and computations working with it.
Protecting AI throughout its life cycle requires an ecosystem of technologies addressing different security and privacy challenges.
Trusted execution environments (TEEs) are one important part of that ecosystem. They create hardware-protected environments designed to isolate sensitive workloads from the underlying operating system, infrastructure and privileged users.
Combined with attestation mechanisms, these environments can also let organizations verify that an expected workload is running in a protected environment before making sensitive data or models available.
Other technologies approach the challenge differently.
Federated learning (FL) allows AI models to be trained across distributed datasets without centralizing the underlying data. Hospitals, banks, research institutions and government agencies can potentially contribute to shared models while keeping sensitive datasets within their respective environments.
Secure multi-party computation (MPC) provides another approach, allowing multiple parties to jointly compute results using private inputs without revealing those inputs to one another.
Fully homomorphic encryption (FHE) takes a different approach, enabling certain computations directly on encrypted data without first decrypting the sensitive information.
Differential privacy (DP) addresses yet another dimension of the problem by reducing the risk that information about individuals can be inferred from datasets, statistical results or model outputs.
These technologies are complementary, not interchangeable. Each comes with different assumptions, performance considerations and security properties. Organizations should understand the risk first, then apply the right combination of protections.
From Security Challenge To AI Opportunity
That distinction matters more as generative AI grows rapidly.
Foundation models increasingly interact with proprietary enterprise knowledge, confidential customer information and sensitive government data. As AI systems become more deeply integrated into business processes and critical infrastructure, the boundary between an AI system and an organization’s most valuable information is becoming thinner.
The risks are already visible. IBM’s 2025 Cost of a Data Breach Report found that 13% of organizations surveyed reported breaches involving AI models or applications, and that 97% of organizations that experienced an AI-related security incident lacked proper AI access controls.
But focusing only on the risk misses the larger opportunity.
Confidential AI can change security’s role in AI adoption. Instead of functioning only as a defensive layer that limits what organizations can do, security can enable what becomes possible.
If sensitive information can be processed with stronger protections, organizations can use information that would otherwise remain inaccessible.
That could enable hospitals to collaborate on better models without pooling sensitive patient records and financial institutions to identify patterns across private datasets. It could also let governments and enterprises use advanced AI while maintaining greater control over sensitive information and intellectual property.
Technology alone, however, does not create trustworthy AI.
Strong governance, transparent policies and responsible development practices remain essential. Privacy-enhancing technologies must sit alongside measures addressing accountability, robustness, fairness, access control and human oversight.
Regulation is beginning to reflect this broader view of AI risk. Obligations for providers of general-purpose AI models under the European Union’s AI Act began applying in August 2025, with additional obligations applying to models considered to pose systemic risk.
For countries investing heavily in AI, technological sovereignty is also a question.
Sovereignty is not simply about where data resides, where a model was developed or where computing infrastructure is physically located. It is also about who can access sensitive information while it is being processed, who controls the infrastructure performing that computation, and whether the protections around it can be independently verified.
For organizations, however, the immediate question is practical: Where should they begin?
First, map where sensitive data becomes exposed during computation. Many organizations understand where their information is stored and how it moves across networks, but have far less visibility into what happens when AI systems actually use it.
Prioritize workloads involving customer information, intellectual property, government data or other critical assets.
Second, match the protection to the problem. TEEs, federated learning, MPC, FHE and differential privacy address different risks. The architecture should follow the security requirement, not the other way around.
Finally, bring security and governance into the conversation before deployment. Decide early what information an AI system should be permitted to access, where it can be processed, what security assurances are required and who remains accountable.
Confidential AI will continue to evolve, and so will the technologies behind it. But organizations do not need to wait for the technology to mature before addressing the underlying question.
For decades, cybersecurity has protected information wherever it is stored and wherever it travels. The next frontier is protecting it while extracting value.
Because ultimately, the future of AI will not be determined only by how powerful our models become. It will also depend on how much of our most valuable information we can trust them to use.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

