Don’t Fence In What Is Designed to Move
June 25, 2026
Nadella Named the Reverse Information Paradox. He Missed Its Cause.
July 16, 2026

AITech Interview with Paolo Campoli, Senior Vice President, DataKrypto

by AI TechPark June 30, 2026

Confidential AI, encryption in use, and enterprise trust reshaping how data is secured during AI inference and model execution.

What made you realize standard encryption would not be enough for generative AI?

It was not one specific breach. It was a pattern, and I recognized it immediately.

I spent 26 years at Cisco, so I have seen this movie before. First, the industry realized that data in transit had to be protected. That is how HTTPS and TLS became standard. Then we went through the same transition with data at rest across storage, databases, and backups.

Now AI is forcing the third step. During inference, some of the most sensitive assets in the enterprise, prompts, proprietary context, model logic, can still be exposed while they are being processed.

So for me the missing layer is very clear. It is not only protected execution. It is encryption in use, the ability to run inference without sensitive data reverting to clear text at runtime.

The moment I saw enterprises sending confidential business information into AI systems without that level of protection, it was obvious to me that this was the next gap the industry had to close.

What are the core tenets of Confidential AI?

I believe Confidential AI starts from a precise principle: encryption has to extend into inference itself.

There is too much confusion in the market. Many people describe Confidential AI as AI running inside an attested Enclave or Trusted Execution Environment. That certainly improves security, but it is not the same as encrypted inference. If data is still decrypted during processing, even inside a secure enclave, the exposure has been reduced, not removed.

My view is that real Confidential AI means “encryption in use”. Inference should happen without sensitive data or model assets reverting to clear text at runtime.

That matters because enterprises need to protect two things at once. First, their own data, prompts, context, business logic. Second, the Model itself, its weights, its tuning, its intellectual property. Be that subsumed in an LLM, SLM or Machine Learning model.

This is why I see Confidential AI as such an important next step. It moves protection closer to the data and models themselves, not only to the infrastructure around them.

What makes an AI system truly trusted, not just functional?

A functional AI gives you an answer. A trusted AI gives you an answer, and confidence in how that answer was produced.

That is the real distinction.

In many consumer use cases, people accept limited visibility into what happens behind the scenes. In enterprise environments, especially in banking, healthcare, telecom, or critical infrastructure, that is not enough.

If I am putting sensitive data into an AI system, I want three things: quality in the output, assurance on how the data is handled, and confidence that the execution environment itself has not been compromised.

But I would add one more point. Trust is not solved simply by saying the workload ran inside an enclave. If data still becomes clear text during inference, then the core confidentiality problem is not fully solved.

Today, many systems address output quality. Trusted AI has to go further than that.

What vulnerabilities appear when enterprises use external AI models without a privacy-first architecture?

The first issue is exposure during inference. Data may be protected in storage and in transit, but while it is being processed it can still be exposed in ways many enterprises underestimate.

And this is exactly where there is often confusion. Some architectures are described as confidential because they use protected execution or attested enclaves. That can reduce risk, yes. But if data is still decrypted at inference time, then sensitive information still exists in clear text during execution. That is a very different standard from encrypted inference.

The second issue is control. Many organizations still depend too heavily on contractual commitments instead of technical enforcement. That may be acceptable for low-risk use cases, but not for sensitive workloads.

The third is jurisdiction and compliance. If you operate internationally, you have to know where data is processed, under which legal framework, and who may compel access to it.

And then there is a strategic dimension that boards often underestimate. If an enterprise keeps feeding valuable internal logic into an external platform, pricing models, operating playbooks, deal structures, strategic reasoning, the cumulative value of those interactions becomes significant. Even if no single prompt is deliberately extracted, the accumulation of institutional intelligence on a third-party platform extends trust much further than most boards would accept in any other mission-critical setting.

So in the end, this is not only a security question. It is also a question of control, governance, and long-term competitive exposure.

What still prevents AI from being dependable in mission-critical environments?

I would simplify it into three barriers.

The first is trust. In mission-critical environments, whether telecom, energy, healthcare, or transport, useful output is not enough. Operators need assurance that the model, the runtime, and the inference chain have not been altered or exposed.

The second is isolation. Most AI infrastructure today is shared, especially at the GPU level. That makes sense economically, but it also raises understandable concerns around predictability, separation, and cross-tenant risk.

The third is auditability. Regulators increasingly want evidence, not only policy statements. Organizations need to demonstrate how sensitive data is handled during execution, not just before and after.

And here I would be very clear: attestation is valuable, but attestation alone is not enough if sensitive data still appears in clear text during inference. For mission-critical AI, the bar has to be higher.

Until those three points improve, trust, isolation, and auditability, AI will remain harder to deploy in mission-critical environments than many people assume.

How can Confidential AI make AI more affordable for mid-market enterprises?

This is where the MSP model becomes very important.

Many people assume stronger security automatically means higher cost. In practice, that is not always true. For mid-market companies, it can be exactly the opposite if Confidential AI is delivered through Managed Service Providers.

Most medium enterprises are not going to build their own AI stack. They do not want the capital expense of buying GPUs, the operational burden of MLOps, or the need to manage security, compliance, model operations, and infrastructure economics all at once.

So in reality they need a trusted delivery partner. That is where MSP economics become powerful.

If a Managed Service Provider can offer AI on shared infrastructure, with strong confidentiality at inference level, it can serve multiple customers with the economics of multi-tenancy while still giving each customer meaningful protection for its data and model assets. The provider absorbs the complexity, key management, platform operations, compliance controls, and service levels, then spreads that cost across many customers.

That changes the model completely. A medium enterprise no longer has to choose between building an expensive dedicated environment or taking uncomfortable risk on a generic shared platform. It can consume trusted AI as a managed service.

For me, this is one of the most practical reasons Confidential AI matters. It is not only about stronger protection. It is also about making serious AI economically accessible beyond the very largest enterprises.

Why is privacy directly linked to the long-term reliability of AI services?

The connection is very direct. If users do not trust the system, the quality of the data going into it starts to deteriorate.

That is what always happens. People hold back information, sanitize inputs, obfuscate or stop using the service altogether. In healthcare, that means incomplete symptoms. In financial services, incomplete client context or partial fraud detection. In enterprise environments, it means people avoid putting real problems into the system.

When input quality declines, output quality declines with it.

And if users believe their data may still be exposed during execution, even inside a supposedly protected environment, that trust problem becomes even more serious. So privacy is not only about policy language. It is also about whether the architecture truly protects data at the moment it matters most, during inference.

So privacy is not only a compliance topic, or an ethical one. It is also a reliability topic. If users do not trust the system with their data, they will not give the system what it needs to perform well.

What cost drivers typically spiral when AI infrastructure is not optimized?

The first surprise for many companies is the token bill.

As enterprises move from basic chatbot use cases into more agentic models, where AI chains multiple calls, retrieves information, reasons across several steps, and iterates, token consumption rises very quickly. On the surface the workflow may look simple. Underneath, the compute cost can become significant.

That is where many organizations experience real billing shock. They move from pilot to production and suddenly discover that scale is much more expensive than expected.

At that point, they typically want more cost control. They start looking at open-weight models, fine-tuning with their data set in order to avoid submitting very long context for every prompt, and managed or self-hosted inference so they can better understand cost, performance, and operational behavior.

And that is exactly where cost strategy and security strategy start to come together. Once you are running valuable models and sensitive workloads in a more controlled environment, you need to protect both without forcing inference back into a clear-text model that recreates the same exposure problem.

Beyond the token bill itself, there are secondary cost drivers that grow when confidentiality is not solved at the infrastructure level: GPU underutilization because workloads cannot be consolidated across security tiers, redundant environments built purely for compliance isolation, and operational overhead from managing parallel stacks for different risk profiles. All of these are symptoms of the same root problem.

Why does data provenance matter across the AI lifecycle?

Data provenance is fundamental because it determines the chain of custody.

You need to know where data came from, whether you are entitled to use it, whether it has been altered, which model version processed it, and under what conditions an output was generated.

That matters at every stage. At training time, provenance helps reduce contamination risk and compliance exposure. At inference time, it helps confirm that the right model, data, and environment are involved. At output time, it gives you an auditable record.

AI systems evolve constantly. Models change, data changes, configurations change, and regulation becomes more demanding. Without provenance, reliability becomes difficult to prove and even harder to defend.

And in my view, provenance becomes stronger when protection is attached not only to the environment, but also to the data and model during execution itself. That is another reason why encryption in use matters so much.

How will confidentiality reshape the global AI race over the next decade?

I believe confidentiality will become one of the major dividing lines in the next phase of AI competition.

Until now, the market has rewarded scale, more compute, larger models, faster rollout. But as AI moves into regulated sectors, sovereign use cases, and critical infrastructure, the rules of the game change.

It is no longer only about who has the biggest infrastructure. It becomes who can offer AI in a way that customers, regulators, and governments are prepared to trust.

And here again, precision matters. The market will not be satisfied with vague claims around secure processing or protected execution. The real question will be whether sensitive data and model assets remain protected during inference itself, without reverting to clear text at runtime.

That creates a real opportunity for telecom operators, sovereign cloud providers, and managed service providers that already have established trust with enterprise and public-sector customers.

They may not own the largest model or the biggest GPU footprint. But if they can provide confidentiality, control, and assurance at the level of execution itself, they can be extremely well positioned in the market.

There is also a geopolitical dimension. The countries and regions that build confidentiality frameworks earliest, both in regulation and in technical infrastructure, will define the terms of the next era of AI competition. Europe, the Middle East, and Asia-Pacific all have the opportunity to compete not by replicating hyperscaler compute scale, but by building the trust architecture that makes AI deployable in the sectors where it matters most.

In the next decade, confidentiality will not be a nice-to-have. It will increasingly become a condition for access to the most valuable AI markets.

Paolo Campoli

Senior Vice President, DataKrypto

Paolo Campoli is SVP and Chief Growth Officer of DataKrypto, helping lead global growth strategy, focusing on scaling enterprise-grade Confidential AI deployments across regulated industries through collaboration with AI platform providers, Cyber Security and OEM Partners, Systems Integrators, and Managed Service Providers.  Campoli holds a Doctorate in Electronics and Telecommunications from the Polytechnic University of Milan and has advised global technology providers and infrastructure operators on secure digital transformation initiatives.   A former Cisco executive, Campoli served as the company’s Global Head of the Service Provider Segment, where he led go-to-market strategy and supported large-scale transformation initiatives with carriers, hyperscalers, and cloud providers worldwide. He also held roles including CTO of the Service Provider Segment in EMEAR, helping shape next-generation network architecture and innovation strategies. His experience leading global infrastructure and ecosystem strategy positions him to help DataKrypto scale Confidential AI from innovation to enterprise-critical infrastructure.