White Paper

Confidential AI: Bringing Frontier Models to Regulated Enterprise Data

Research Finder

Find by Keyword

Confidential AI: Bringing Frontier Models to Regulated Enterprise Data

How VAST Data enables consistent security, policy, and audit across data at rest, in transit, and in use

Some of the highest-value enterprise data cannot simply move to wherever the preferred AI model runs. Regulation, residency requirements, latency, data-movement costs, and internal controls can keep sensitive information inside enterprise, sovereign, and isolated environments. At the same time, model providers need to protect proprietary weights when execution occurs on infrastructure they do not control.

This HyperFRAME Research Brief examines the architecture required to bring those two trust requirements together. VAST Data is positioning its AI Operating System to manage models alongside enterprise data, treating models as logical resources that can be placed, governed, and controlled alongside that data. DataEnclave adds a protected execution path based on confidential virtual machines, hardware trusted execution environments, GPU confidential computing, attestation, and independent key custody.

Confidential execution extends protection from data at rest and in transit into data in use. The execution environment can be verified before protected assets are released, while enterprises and model providers retain independent control of the keys protecting their respective assets. That creates a path for sensitive enterprise data and proprietary models to meet inside a trusted runtime without requiring either side to surrender control.

The architecture also changes how enterprises can think about model placement. Model location, data access, security policy, infrastructure choice, and execution requirements become connected decisions. For regulated organizations, that can expand the portion of the enterprise data estate available to AI while maintaining existing custody and governance requirements.

Model providers gain a complementary benefit. Attested execution can extend proprietary models into customer-controlled, sovereign, on-prem, and isolated environments while keeping model weights protected. That opens new deployment options and new customer environments without requiring providers to distribute valuable intellectual property into infrastructure they cannot verify.

For VAST, DataEnclave extends the AI Operating System from managing enterprise data and computation toward managing models as logical resources. As enterprises assemble larger portfolios of proprietary, open, fine-tuned, and internally developed models, the ability to govern where those models run, what data they can access, and under which policies becomes part of the infrastructure control plane.

The brief also examines key ownership, attestation, performance, deployment models, auditability, governance continuity, and operating responsibility. DataEnclave is being previewed now and is scheduled to ship in Q1 2027, allowing the paper to distinguish current platform capabilities from launch-stage functionality and longer-term model-management plans.

Key Questions This Research Addresses

  • How can enterprises run AI models against regulated data without moving that data?
  • How can enterprises protect sensitive data when models run outside their own infrastructure?
  • Why is protecting data in use different from encryption at rest or in transit?
  • How does confidential computing protect AI workloads?
  • Why do proprietary AI model weights require governance and protection?
  • What does it mean to manage models as part of an AI operating system?
  • Who should control the keys for enterprise data and model weights?
  • How do organizations integrate confidential AI with existing identity, key management, policy, and audit systems?
  • How should enterprises choose where confidential AI workloads run?
  • How does GPU architecture affect the boundaries of confidential AI?
  • When should enterprises use confidential computing for AI workloads?
  • What should enterprises evaluate when selecting a confidential AI platform?

Download the full report now

Author Information

Don Gentile | Analyst-in-Residence, Data Platforms & Resiliency

Don Gentile analyzes the technologies, market dynamics, and enterprise priorities driving the AI-era data stack: the infrastructure that enables AI and the architectures that keep organizations running. His research helps technology vendors refine product strategy, strengthen market positioning, and communicate business value to enterprise customers.

Before joining HyperFRAME Research, Don held executive leadership roles at IBM and Hewlett Packard Enterprise, where he led product marketing, communications, external relations, and go-to-market strategy for enterprise infrastructure businesses. That experience informs his research, combining executive leadership with industry analysis to evaluate how technology decisions affect enterprise adoption, competitive differentiation, and long-term market direction.

Don's research practice focuses on AI infrastructure, enterprise data platforms, data architecture, control planes, enterprise storage, hybrid cloud, cyber resiliency, data protection, backup and recovery, and data governance. His work examines how these technologies enable production AI while improving governance and business outcomes.