Mesh Request a demo
Pillar: Confidential AI

Confidential AI: training and using a model without exposing your data

In brief

Confidential AI (or privacy-preserving AI) refers to the set of methods that make it possible to train or use an AI model without exposing the sensitive data it processes. The goal: benefit from AI on valuable, personal or strategic data, without copying, transferring or making it readable to a third party. Confidential federated learning (Mesh's approach) is one of its most advanced forms for collaboration between organizations.

The Mesh principle: the model travels, your data stays home.

Before / after: without Mesh data leaks, with Mesh it stays encrypted and local
On this page

What is confidential AI?

Confidential AI brings together the techniques that make an AI model work on data that stays protected at every step: during training, during inference (use), or both.

It's a response to a tension that has become central: the most useful data for training an AI are often the most sensitive: medical records, banking transactions, industrial data, personal data. Exposing them to train a model is forbidden, risky or commercially unacceptable. Confidential AI removes this blocker: you can learn from this data without having to see it.

It is also called privacy-preserving AI and, more broadly, privacy-enhancing technologies (PET) applied to machine learning.

Why confidential AI? The problem it solves

Without confidential AI, an organization that wants to train a good model runs into three walls:

  1. The regulatory wall. GDPR, medical confidentiality, banking secrecy, DORA, sector regulations: centralizing sensitive data to train on it is often illegal or heavily regulated.
  2. The competitive wall. Two companies in the same sector would gain from jointly training a better model, but neither wants to hand its data to the other. The sharing never happens, and the shared model does not exist.
  3. The scarcity wall. A single actor doesn't always have enough labeled data, or observes only part of reality (a limited sensor fleet, a single market). Its model has a structural blind spot it can't fill alone.

Confidential AI knocks down all three walls at once: it enables collaboration without exposure. That's the heart of Mesh's proposition: collective intelligence, everyone's confidentiality.

How can you train an AI without exposing your data? The main techniques

There is no single "confidential AI," but a toolbox you combine according to the need. The main building blocks:

1. Federated learning

Each actor trains the model locally, on its data, and shares only the learned parameters. Data are never centralized. It is Mesh's founding block. → see Federated learning: definition and how it works.

2. End-to-end transport encryption

The model parameters that travel are end-to-end encrypted, so that no intermediary (network, relay, host) can read them. Mesh uses standard primitives (RSA-OAEP 2048-bit + AES-GCM 256-bit, via WebCrypto): it is not a simulation, it is real encryption.

3. Differential privacy

You add calibrated mathematical noise to the model updates, to prevent tracing back to an individual from the shared parameters. It's a dial: more noise = more protection, but slightly less accuracy. To be used and presented with its limits (a formal privacy budget must be computed and tracked).

4. Confidential computing (trusted execution environment, TEE)

Computation runs inside the processor's trusted execution environment (Intel SGX, AMD SEV…), so that even the machine's operator does not see the data gathered there. A complementary approach to federated learning (it centralizes the computation while protecting it, whereas federated centralizes nothing). At Mesh, the word enclave means one thing, and it is an option: the place where the models are federated. The Mesh enclave never receives data, it receives model updates, and the operator cannot see an individual member's contribution there.

5. Secure aggregation

A cryptographic protocol that lets the coordinator compute the sum of the updates without seeing any individual contribution. It is the countermeasure to the main limitation of basic federated learning.

What Mesh does today. real scope Mesh combines (1) federated learning + (2) end-to-end encryption, real and functional, and offers (3) differential privacy as an option. Secure aggregation (5) and hardware integration (4) are available as an option.

Confidential AI and data sovereignty

Confidential AI is a direct lever of data sovereignty: since the data never leave their holder's infrastructure, the holder keeps legal and physical control end to end. For a European organization subject to the GDPR, or for an actor that refuses to entrust its data to a third-party cloud or a competitor, this is decisive: you get the value of a collectively trained model without ceding control of your most sensitive asset. → dedicated page: Data sovereignty: training an AI without losing control of your data.

Confidential AI and the GDPR

Confidential AI, and federated learning in particular, helps with GDPR compliance by natively applying data minimization (no copy, no transfer, no centralization). It does not guarantee it automatically: compliance depends on the concrete deployment and is assessed, case by case, with a lawyer. → details on Federated learning and the GDPR.

How Mesh implements confidential AI

Mesh is a confidential federated learning platform. Several organizations (including competitors) train a shared AI model without any data ever leaving home. Three ways into the collective:

FAQ: Confidential AI

What is confidential AI?

It's the set of methods that make it possible to train or use an AI without exposing the sensitive data it processes: the data stay protected and, with federated learning, are never centralized.

What's the difference between confidential AI and federated learning?

Federated learning is one of the techniques of confidential AI, the one that avoids centralizing the data. Confidential AI is the umbrella term, which also includes differential privacy, encryption, the processor's trusted execution environment (TEE) and secure aggregation.

Can you train an AI without exposing your data?

Yes. By combining federated learning (training stays local) and end-to-end encryption of the exchanged parameters, you train a shared model without any raw data ever leaving its holder.

Is confidential AI compatible with the GDPR?

It helps with compliance by minimizing the exposure of personal data, but final compliance depends on the deployment and must be validated legally, case by case.

Does Mesh compute on encrypted data (homomorphic encryption)?

No. Mesh relies on federated learning (data stays local) and end-to-end transport encryption. Computation happens in the clear, at each actor, on its own data, not on someone else's encrypted data.

Let's see it on your data

An interactive demonstration is available on request: we'll give you access.

contact (at) meshuniverse.fr