NEAR AI is expanding its confidential computing infrastructure with hardware-isolated environments designed for AI agents, multimodal inference and sensitive workloads. Requests to supported confidential models run inside Trusted Execution Environments built with Intel TDX and NVIDIA Confidential Computing, preventing the host operating system, GPU operator and NEAR AI itself from accessing plaintext prompts during processing under the platform’s stated security model.
According to the official NEAR AI announcement, the stack includes IronClaw, a secure agent runtime, alongside a Confidential GPU Marketplace and multimodal inference covering text, images and voice. The architecture is intended to replace operator-policy assurances with hardware-backed evidence that developers can independently inspect before sending sensitive workloads.
Hardware Attestation Verifies the Execution Environment
NEAR AI Cloud places supported open-weight models inside Intel TDX confidential virtual machines paired with NVIDIA GPUs running in confidential-computing mode. Incoming encrypted connections terminate inside the protected environment, where prompts are decrypted for inference and encrypted again before leaving. Sensitive data becomes readable inside the enclave for computation but remains inaccessible to infrastructure outside that trusted boundary.
Developers can request an attestation report without creating an account or supplying an API key. The report contains Intel and NVIDIA evidence, identifies the loaded model and can incorporate a fresh user-generated nonce to prevent reuse of an older report. Attestation proves which verified hardware and software environment handled the workload, rather than mathematically proving that every internal model operation or resulting answer was correct. Intel and NVIDIA provide independent verification paths for the underlying evidence.
That distinction matters for autonomous agents. IronClaw runs inside encrypted TEEs while separating credentials from model reasoning, storing secrets in an encrypted vault and sandboxing tools through WebAssembly containers. The security model is designed to prevent infrastructure operators from reading credentials or agent data while the system browses, calls APIs or executes other authorized actions.
Confidential Infrastructure Moves Into Production Use
The infrastructure is already operating beyond a technical demonstration. NEAR AI launched its Confidential GPU Marketplace and multimodal confidential inference in February, followed by integrations with services including Venice, Corbits and SayGm. These deployments show the TEE stack being exposed through production-facing AI services rather than remaining an experimental roadmap item.
NEAR AI also provides an OpenAI-compatible API, allowing existing applications to route workloads into confidential inference with relatively limited integration changes. The company previously reported approximately 5% to 10% additional latency for its confidential stack and capacity of up to 100 requests per second per tenant, although those are NEAR AI’s own infrastructure benchmarks and should not be generalized across every model, workload or hardware configuration.
The platform further strengthened its verification model in August by integrating Intel Trust Authority, adding an attestation verifier independent of NEAR AI itself. That development reduces reliance on the operator’s own verification path, although the system still ultimately depends on trusted hardware, firmware and Intel and NVIDIA attestation roots. Confidential computing therefore changes the trust boundary rather than eliminating trust entirely.
The next measurable milestone will be sustained third-party use under sensitive production workloads. Uptime, latency, throughput, attestation reliability and adoption by enterprises running agents with private credentials will determine whether confidential GPU infrastructure can compete operationally with conventional cloud services. For now, NEAR AI has established a live hardware-backed stack that lets developers verify where supported inference runs before submitting sensitive data, while keeping claims about computational correctness separate from what attestation itself can prove.
Natalie Pierce tracks the parts of crypto that move fast and rarely wait for everyone to catch up. From South Africa, she covers DeFi, AI crypto, hacks, airdrops, sentiment and emerging narratives, especially when user behavior and protocol risk start to overlap.
Her reporting is built for messy sectors. Natalie looks at incentives, reactions, security concerns, social momentum and early signs of traction without pretending every new trend is already proven. Her voice is clear and accessible, but careful enough for areas where excitement can outrun the facts very quickly.
