SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
VAST launches confidential AI system for sensitive data

VAST launches confidential AI system for sensitive data

Wed, 23rd Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

VAST Data has launched DataEnclave, a confidential AI system for running AI models on sensitive corporate data. The product is built on NVIDIA confidential computing technology.

DataEnclave is designed to let organisations use proprietary and open AI models inside their own data centres or trusted cloud environments without exposing either customer data or model weights to infrastructure operators. The system is intended to address a common problem in regulated sectors, where data cannot be moved to external AI services and model owners are reluctant to place their software in environments they do not trust.

The service extends VAST's AI Operating System and DataEngine software with a hardware-isolated runtime and cryptographic attestation. In practice, the environment and its policy must be verified before encrypted models and data are released for use inside a secure enclave, where they remain protected during processing in CPU and GPU memory.

Customers retain control of their own data keys, while model builders keep control of model keys and weights. Administrators and infrastructure operators cannot access either while workloads are running.

Sensitive sectors

The offering is aimed at industries including financial services, healthcare and government, where privacy, sovereignty and internal controls can limit the use of external AI platforms. VAST is also positioning the system for sovereign and air-gapped deployments, including installations that rely on open-source attestation services or partner infrastructure.

NVIDIA's role centres on confidential computing across its Hopper, Blackwell and Rubin platforms. VAST said its software uses those capabilities to establish secure container runtimes through CPU and GPU trusted execution environments, while protecting guest memory, GPU memory and traffic moving across NVLink connections.

Other elements include attestation checks before decryption keys are released, support for separate key management systems for enterprises and model providers, and audit logs stored in VAST's database layer. The same secure runtime can also be used to isolate AI agents and govern what data, systems and tools they can access.

Renen Hallak, Founder and Chief Executive Officer, VAST Data, linked the product to a broader shift in how companies manage AI software. "Models are becoming a resource the operating system has to manage, the same way it manages data," Hallak said. "That means knowing which model fits which task, what it can see, who can use it and under what rules, and doing all of that inside the same security and operational boundaries an enterprise applies to everything else. Bringing leading AI models securely to the world's most sensitive data is where this starts. Where it leads is a world where every organisation is managing an ecosystem of fine-tuned models that represent its true intellectual property. The VAST AI Operating System is what keeps them secure, governed and useful."

Partner backing

Several technology companies and infrastructure providers backed the launch, including NVIDIA, CrowdStrike, Cisco, Supermicro, Cohere and Sharon AI. Their support points to a broader effort to create trusted environments in which model developers, cloud providers and customers each maintain control over their own intellectual property and data.

James Manning, Chief Executive Officer and Co-founder, Sharon AI, said the product would help meet demand for local AI services in Australia and the wider Asia-Pacific region. "As a trusted AI infrastructure provider, Sharon AI exists to make secure, scalable and sovereign AI compute available to every organisation that needs it," Manning said. "Our customers across Australia and Asia-Pacific need to run AI at full speed without compromising data sovereignty, and increasingly they also want access to frontier models that were previously available only offshore. Building on our sovereign data foundation with VAST, DataEnclave lets us host those models onshore, inside attested environments where the model owner's weights and the customer's data are both protected from everyone, including us. That gives our customers the flexibility to operate on their own terms, backed by sovereignty they can demonstrate, not just declare."

For VAST, the launch also reflects a bet that model weights will become an increasingly important class of corporate assets. That applies both to base models created by specialist developers and fine-tuned models built by enterprises for internal use.

Jeff Denworth, Co-Founder, VAST Data, said the value of model weights was rising quickly as AI adoption spread. "Model weights are fast becoming the most valuable intellectual property in the world. Base weights define the value of frontier models, while fine-tuned weights will increasingly represent the proprietary intelligence of AI-driven enterprises," Denworth said. "As the stakes get higher, so does the need to secure enterprise data so customers can apply the most intelligent AI models against it. Today, VAST Data, in partnership with NVIDIA, is moving the industry forward with a comprehensive approach to verifying previously untrusted computing environments and unlocking the ability to run any model against any data, anywhere."

NVIDIA said the partnership is intended to give enterprises a security framework for AI deployments that combine internal data with advanced models. "Enterprise data is essential to accurate, usable AI, and keeping business data confidential is critical to protecting IP in the age of agents. VAST Data's integration of NVIDIA Confidential Computing delivers protection for both enterprises and model builders, providing security, identity, permissions, governance and compliance as a foundation of the agent architecture," said Justin Boitano, Vice President, Enterprise AI, NVIDIA.