Video: Building trust in the age of Sovereign AI | Duration: 3612s | Summary: Building trust in the age of Sovereign AI | Chapters: Welcome and Introductions (37.44s), Speaker Introductions (135.085s), Customer AI Concerns (197.445s), Sovereign AI (259.1s), Hybrid Cloud Control (410.59s), Technical Requirements (537.545s), Implementation Complexity Challenges (769.78s), Confidential Computing (925.805s), Adoption and Momentum (1370.85s), Flexible Secure Deployment (1622.89s), Platform Integration (1898.4651s), Implementation Roadmap (2098.5698s), Q&A and Closing (2434.395s), Closing Remarks (2740.035s)
Transcript for "Building trust in the age of Sovereign AI":
Hello, and welcome. And thank you for joining us today. This session is brought to you by BizClick in collaboration with Red Hat and Intel, and it's great to have you with us. Today, we're focusing on a topic that is quickly moving up the agenda for organizations across all industries, How to build trust in an age of sovereign AI. I'm Ella Wilkinson, director of BizClick Studio, and your host for today. What makes this such an important conversation right now is that AI is reaching a real turning point. Organizations are moving beyond experimentation and starting to embed AI into core operations across different environments and often different regions. So the challenge is not just about adopting AI. It is about doing it in a way that maintains control, resilience, and trust. So joining me today are two experts who bring deep experience across AI, security, and infrastructure. First, a leader in confidential computing and secure AI working across enterprise, government, and cloud environments. Paul O'Neil, senior director of security center of excellence at Intel. And from Red Hat's CTO organization focused on bridging customer needs with engineering and driving forward innovative architectures. Axel SaaS, principal chief architect, a member of the EMEA field CTO team at Red Hat. So it's great to have you both with us. And before we jump into our discussion today, I would like to throw to both of you to give me a very quick introduction on who you are. So, Paul, let's start with you. Thanks, Ella. And, good morning, good afternoon, good evening to everybody. Thanks for tuning in. My name is Paul O'Neil. I work at Intel focusing on confidence computing and security strategy, which are very relevant to the topic today. My role is really about helping organizations, you know, build trust into digital infrastructure as we move into the world of AI and increasingly sovereign, requirements. So I'm delighted to be here today with our partners, Red Hat, to talk about how we're gonna make all that real. Fantastic. And we are delighted to have you with us as well, Paul. So let me throw to your partners, Red Hat. So Axel? Yes. As you said, a chief architect, our job is not only to to connect customers to also to understand what their business use cases are. And I'm focusing on confidential computing also as part of us. Brilliant. And just before we jump into our main discussion today, I always start with a little kickoff question, and that is, when you look at AI adoption today, what is the one shift or challenge that really stands out to you? I think customers when I talk to customers, they are all aware that this needs to be integrated in their business processes, but they are worrying about how can they perform, how can they run this in a performant matter in their environments. So that's the question is, how do we do this? How do we use this from my point of view? Brilliant. And, Paul, the same question to you. I think Axel probably got most of it. I think the one thing we hear a lot is how am I gonna get ROI from the investment I made on my AI infrastructure? How do I get through all of the regulations and and things that are coming that give me that are stopping me from getting access to data, etcetera, etcetera. So that ROI conversation is one that we hear a lot of as well on top of the things that that Axel just articulated. Fabulous. I I think we're in for a great discussion today. So I'm excited to kick us off with our first discussion point, which is the rise of SovereignAI and why it matters so much. So we're hearing the term SovereignAI being thrown around more and more. Paul, why does sovereignty matter so much right now? And, actually, first, let's start with just a definition of Sovereign AI versus the standard AI. Yeah. I think, you know, when people talk about Sovereign AI, they're really talking about control. They're talking about trust. They're talking about assurance in a world where AI is generally becoming foundational to everything. At its core, sovereign AI means that organizations, whether that's a government, a health care provider, or a financial institution, retain control over their data, their models, and the infrastructure that those models would run on. Now not just in a policy sense, but in a way that can actually be verified. And that's a very important theme that we'll talk through this webinar today. What's driving this now is really a combination of forces coming together at once. Right? First of all, AI has really changed the stakes. We've reached that tipping point. We're no longer just protecting stored data. We're protecting models, prompts, and real time decision making. And so models can be incredibly valuable. That's highly sensitive intellectual property. And in many cases, it can be national or maybe even citizen level data. Right? Secondly, regulation on geopolitics are accelerating the need for control generally. Right? So across Europe and globally, we're seeing far stricter requirements around data residency, privacy, and operational independence. Organizations have been asked not just where their data sits, but who can access it and under what conditions, and how is that enforced. And third, I think there's a growing recognition that, traditional security models just aren't enough anymore. You know, the perimeter based approaches that we've sort of all grown up with assume trust in the infrastructure. But in a cloud first AI driven world, that assumption just doesn't stack up anymore. And that leads to the sort of key shift. We're moving from trust by policy to trust by verification. And that's why Sovereign AI is becoming a priority now because organizations need to prove, not just claim, that their AI systems are secure, that they're compliant, and under their control. So, ultimately, sovereign AI is not about restricting innovation. It's about enabling its safety so organizations can adopt AI at scale with a sort of confidence, across public, private, and hybrid environments. And in our increasingly digital world, I guess, we're opening ourselves up to vulnerability that sovereign AI is the only thing that can bridge that gap. So sorry. Yeah. That that's absolutely correct. And those vulnerabilities, you know, are coming because people wanna access, you know, to more datasets. And as I said, those privacy elements are coming into play, and that links directly back into, you know, how do I build, an infrastructure that's gonna drive ROI based on data that I really can't get to. So, Axel, then how are organizations interpreting sovereignty in practice? Is it mainly about regulation, or does it actually go beyond that? I think when I talk to my customers, their main focus currently is to get everything back into their control. So most of them trying to avoid the cloud now and go back on premise. But that, there's a problem with that because they are then losing the advantages of the cloud, like consumption based pricing, like access to new and better CPUs, and dynamically adding infrastructure and, components into their environment. And that takes away the advantage. They don't have access to the advantage of the cloud anymore. So they want to, make this happen that they can use both, on premise and, off premise in a sense of a hybrid cloud environment. And, but re regulations is not the only one. It's like Paul already said. Resilience is also they they won't like to be able to, supply an infrastructure which runs all the time and is not hindered by anything from the outside. So this also then adds the need to also use the cloud. But then it also again, if we look into AI, this SEM AI is a new topic, companies want to, want to, run-in their environment, and we now need to be able to also integrate AI into a sovereign environment. And that's what is company what companies are looking for. And it's about using AI smarter than so not allowing the AI to kinda take over? Yes. Exactly. Yes. So, Paul, how do concerns around privacy, security, and compliance translate into concrete technical requirements? Yeah. I think that's a a great follow-up to what Axel just said there. I mean, you know, the concept of the cloud and the concept of cloud economics and moving fast, etcetera. This is where SovereignAI sort of moves from concept into something quite concrete. Right? You know, when when I talk to customers about privacy, security, and compliance in the context of AI, they're not abstract concerns anymore. They translate directly into specific sort of technical requirements across the stack. And when I was thinking about this area, I think I'd kinda group them into maybe four areas. The first is sort of, data protection, right, especially data in use. And we will come on and talk a little bit more more about that later. It it's no longer enough to just encrypt data at rest or in transit. With with AI, the most sensitive moment is when data is being processed, when models are training or doing inference. So so the requirement becomes, how do I ensure that that data remains protected even while it's being computed on? And that's where we see the need for hardware enforced isolation and encryption during execution. The second, which I think is incredibly important, and a lot of people are not really thinking about this yet, is verifiable trust. In a sovereign model, you just can't assume that the platform is secure. You need to prove it. Right? So this drives requirements around attestation, you know, the capability of being able to cryptographically verify the integrity of the hardware that you're running on. The firmware, the workload before I don't think sensitive is allowed to run or any keys are released, and that becomes the foundation for policy enforcement. And I think the third is control and policy enforcement generally. So a lot of organizations are gonna need to define or they are defining who can access data, where work workloads can run and under what condition. Because as Axel said, you can't it's not about running a workload specifically somewhere. You've gotta be able to run workloads everywhere, whatever suits the job at the time. So, technically, that means integrating identity, attestation, key management, etcetera. So that access to sensitive data or models is almost dynamically granted based on verified trust signals, not sort of static credentials. Right? And then the fourth, I think, is often overlooked, which is sort of operational sovereignty. This is pretty critical. It's not just about securing a single workload. It's about doing that at scale across environments. As Axel said, multiple different types of environments. So the I think the requirement becomes, can I deploy and manage these trusted workloads consistently across the public cloud or the hyperscalers, private cloud, or on prem or some other local cloud? And that drives the need for platform level integration with some things like Kubernetes, with container run times, enterprise orchestration layers. And when you bring those together, you start to see a pattern. Right? Privacy drives confidentiality during execution. Security drives attestation and isolation. I think compliance drives auditability and policy control. And then sovereignty overall demands that all of that works consistently across environments. So the shift we're seeing is, from a technical perspective, is that organizations are no longer satisfied with security features in isolation. They need end to end trust architecture or protection, verification, I guess, and control that are built into the platform itself. And that's what enables Sovereign AI in practice, turning those high level concerns into enforceable, verifiable technical guarantees. And that's the work that we're doing with Red Hat today. And I guess we then have issues arising when organizations deploy these strategies. So, Axel, from your experience, where do organizations tend to actually underestimate the complexity strategies into action? I think they don't see all the dimensions to, to moving an application from a to b. So as a private story, we we try to, look at this from, in the team of the team chief architects, and there were so many aspects of moving an application from a to b that at some point, this needs to be a a project, a service project to find out where the complexity is and how do we to cope with this, especially when you look at data sovereignty. So, when you move your application from a cloud a to cloud b or back on premise, you still need to look at how is what data do the applications use, and how can I make this accessible from another, cloud or another source? And that that is a lot more complicated than most of the companies, see this. And, at some point, what you need to do is to create a a strategy to look at your, applications to see what data does an application need, what is an easiest way to move it from a to b, to give them the road map on how to move data when they want to move, their applications around. They need a data strategy, how to place data, where to access this, and so on. And if you look at, like Paul said, if you look at the hybrid cloud environment, this makes it even more complicated because you are not sure where where those, where where that data is then found. If you can trust the environment that no one has changed that data, and then we come back again to trust in moving an application from a to b. And exactly that is is a core essence of confidential computing to establish a trust within the environment where you move to and where you are coming from. So just basically like building a house. Laying the foundations first, making sure it's nice and solid before you put the walls up. Mhmm. Exactly. Yeah. In fact, that's how we designed one of the images, I think, Axel. Right? A a roof across solid foundations. Right? And, maybe we can put a link to, some of, that material in the webinar, at the end of it. Absolutely. I think that'll be really interesting for our audience. So let's move on to discussion two, which is both of your area of expertise, and that is confidential computing and protecting the data that's actually in use. So, Paul, for SovereignAI, it looks like confidential computing is a key part of the conversation. So can you walk us through how it protects data, not just at rest or in transit, but while it's actively being used, and why this is relevant to soft computing? Sure. Yeah. Yep. We we definitely think it's relevant. But, but good good question, and we should really get into what confidence computing is. So it's definitely worth introducing it now because it's becoming, as you said, a foundational technology for Sovereign AI. Confidential computing is really about protecting data, not just when it's stored on a transit, as you said, but when it's being actively processed. And that closes, you know, a gap that's been there for quite a while. That memory that data is vulnerable when it's being processed. Traditionally, once data is loaded into memory for computations, it's exposed to the system. And now being exposed to the system means it's exposed to the operating system. It's exposed to the hypervisor. It's exposed to potentially privileged users, cloud administrators, for example. Confidential computing is now, a default technology in all of the main, hyperscalers, for example. Right? So in a sovereign AI context, that's the real concern. You know, Axel mentioned the word trust a few times there. You you need to guarantee that your data models and AI workflows remain under your control at all time. Ergo, you need to have trust in the people who are providing you the infrastructure. So confidential computing does it closes that gap. It brings you that control, and it brings you that trust. How does it work? It uses hardware based trusted execution environments. The company I work for does pretty good hardware. Right? And in most of our Xeon data center range, we have these secure isolated regions of memory, where data remains encrypted and is only decrypted inside that protective boundary for processing. Everything outside of that boundary, including the infrastructure, itself only sees encrypted data. Now to make that more concrete, our main, product in this area is is a product called Intel Trust Domain Extensions or Intel TDX as it's known in the market, and that ships on all of our Xeon products that you'll find in, all the cloud providers around the world. And TDX enables what we call confidential virtual machines, where an entire virtual machine is isolated and protected in hardware. The cloud provider that owns the machine or the hypervisor, system level software can't act that access that memory or the state of that workload. So whether you're running in a public cloud or on a shared on prem environment or, as Axel said, a hybrid environment, You can ensure that your data remains confidential, that you're processing, that your AI models are protected as effectively intellectual property, and your inputs and outputs, prompts, and results are secured end to end. Imagine, inferencing, for example. But protection enough isn't alone, and that's where this technology becomes, I think, especially relevant for sovereignty. TDX, like other confidential computing technologies, also supports a thing called attestation, And that attestation gives you the ability to cryptographically verify that your workload is running in a genuine trusted environment before any sensitive data is used. So you can validate that it's the expected hardware platform, that you that you expected, that the software stack hasn't been altered, and that it's operating within the conditions that effectively you've defined. And then only then do you release keys or allow access to sensitive data to to happen. And that's the key shift. You move from trusting the environment to verifying it and enforcing policy based on that verification. And when you apply this to AI, it becomes even more critical. AI pipelines are generally distributed. You know, data ingestion, model execution, inference often involve multiple environments and accelerators. So technologies like TDX can provide that trusted foundation at the compute layer, and that trust can then be extended across the broader AI stack. So we tie it back to Sovereign AI. It enforces data sovereignty by protecting data in use. It enables control by binding access to verified conditions, and it delivers assurance by providing cryptographic proof that policies are being upheld. So in simple terms, you know, confidential computing and technologies like Intel, TDX allow organizations to run AI anywhere, including shared infrastructure without losing control, confidentiality, or trust. A bit of a long winded, answer, Ella. Sorry. But it's important to glue all that together as a technology stack and apply it back to sovereignty. Absolutely. And I think, you know, it will bring a lot of peace of mind because it's it's just triple locking that data and making sure it's protected. So let's focus on that AI in confidential computing. So, Axel, how does confidential computing extend to AI workloads, especially when g GPUs are involved? Mhmm. So when when I look at the customer needs, I see that about 90% of a AI work is inferencing. There is some more, modeling done, but inferencing is or training done. The inferencing is the most important, thing. And when we look at the cloud, it becomes more apparent that companies have difficulties accessing GPUs or getting them at all. And the cloud then can provide this, the the resources dynamically for them to use when they have, for example, an event going, and they need that, inferencing in that to accomplish that event or to perform with that event. And the availability of those those GPUs in the cloud is is much easier because it's consumption based pricing and availability. They can get a GPU. And if they don't need it anymore, they can release it again and don't have to pay for this anymore. And this then adds, the advantage of using the cloud. But when we then come back, confidentiality is a a major requirement for this because they don't want to share data with other customers of that cloud provider. They want it to be able to run their models and add, for example, reg or data to the models when they are inferencing. And that for example, we see this in a in a use case, in a partner interacting use case when you have two different partners who want to interact, but neither of them wants to exchange information. They don't they and one doesn't want to exchange the model or make get the other partner access rights to the model. Or and then the other partner will maybe shares, the reg data, but they don't want the, the partner a to be able to access them. And those use cases then interact and need to be addressed with a in a secure manner, and this is done with so there's confidential computing and, specifically, with confidential containers, which enables customers to to, start a specific container in confidential mode. Mhmm. So in terms of uptake then on this, Paul, where where are you seeing the strongest momentum today? Are organizations already moving on this, or is is it still very early for most? Well, we're definitely past the theory stage, Ella, I would say. You know, as as as I mentioned earlier on, all of the major hyperscalers, you know, Microsoft, Google, Alibaba, what, you know, ByteDance, Baidu, whatever, are all using confidential VMs now based on Intel and others' technology. So there's real momentum. But I wouldn't say it's uniform yet. What we're seeing is sort of strong adoption in specific segments while others are still sort of in valuation. And the fastest movers tend to be organizations where data sensitivity and regulatory pressure are the highest. You know, the I think the theme that we've talked through this has been trust, and we've both Axel and I have mentioned data many times. So first, if we look at things like financial services, you know, banks and trading platforms are already using confidential computing for things like secure analytics, fraud detection, and increasingly AI driven decisioning, where both the data and the models are highly sensitive. In health care and life sciences, you know, here the driver is, of course, patient data. And as Axel said, collaboration on patient data is, you know, something that I think we all want as long as that data, our personal data, is secure. And confidential computing is enabling scenarios like federated learning and multiparty research where data can be used without being exposed. And if we're sharing data across the planet, you know, for things like research, that's a potentially big unlock. And third, I think, which is moving very fast is, public sector, and sovereign cloud providers, I'll say. So this is probably where the strongest strategic push is happening at the moment. There are a lot of governments that are actively investing in sovereign AI capabilities, you know, not just for compliance, but for, I would say, national resilience, and control over their own critical infrastructures. Right? And then we're seeing growing traction in AI native use cases. Axel mentioned already, you know, AI has really swung, toward everything towards confidential computing. You know, as organizations start deploying large models, they're realizing that the model itself is pretty valuable IP. Right? The prompts and the queries can be very sensitive. For example, how would a government, you know, use a chat GPT, for example, like that? You know, we need to build private inferencing. Right? And inferencing and that inferencing is is often happening in shared environments, whether it's on the cloud or whether it's on some local provider or within a government department where multiple departments or multiple people have access to data that maybe, you know, they're they're restricted from. So confidential AI is is quickly moving from a nice to have to something organizations are actively piloting. And from a platform perspective, we're also seeing strong momentum in the ecosystem. Confidential VMs, including, I guess, those based on technologies like Intel TDX, are now available across, you know, all the providers. But, Axel also mentioned, things like confidential containers. The ecosystem is growing and growing, and that's important because that also shows this is not just a niche capability. It's becoming operationally viable at scale. With that said, it's fair to say that we're still in the early to mid adoption phase overall. I think many many organizations are running proof of concepts. Many are testing specific workloads or targeting high value use cases first. But the barriers are less about belief now. It's more about organizations understanding the need and more about operating maturity, integration, and skills. And that's, I think, the genesis of the work that we're doing now with Red Hat is to get into that repeatable, scalable deployment and remove sort of day two complexities. So I think we're getting to the point now where we can drive Ubiquiti beyond the hyperscalers into enterprises, and other organizations. So, Axel, then with that big uptake across organizations, from a practical standpoint, how important is it to introduce these capabilities without adding operational overhead? The the job of an administrator is to currently, to very challenging. And when now this comes into play, they need to look out for more complex configurations. And and the goal should be that they are not doing any errors or permitting any errors when they do things like this. So the focus from our development is that we are creating something like an opinion and opinionated way to configure services like this to make it as easy for administrators to use this or to configure this as it is possible. Of course, there are extensions available for customers who need a more complex environment. But for the, the the normal administrator, this should be if they start it and they configure it, it should be secure. And that is one of the major, development directions we are taking at Red Hat. And, also, what is also is needed is that the developers themselves. So when you create an application, you should, as a developer, not focus on where it is running, but that it that it can run on an a on premise environment and also in a confidential environment in the cloud. So, also, development, make it available, make it possible for developers to use this without them needing to know where it is running. So both things are there to to, reduce the operational overhead for administrators, for developers to make it as easy and to reduce the amount of errors they can commit to make this as secure as it can be. So, right, let's shift into that implementation phase then. So how can organizations realistically deploy AI across public cloud, private cloud, and on premises while still maintaining control? When we look at so there was something that it which was called a standard operating around years ago and still true now. But this, I think, needs to be extended into the cloud also. So at some point, to get this going in the public cloud, in a private cloud, and on prem means that you need a standardized environment to run all of this. So you do not miss out on any configuration options. And I would then call it standard cloud environment, a CE, maybe. I have no clue. But this then needs to be we need to focus on standardizing things. So wherever it runs, it is always the same. The the the same security profiles are taken into account. The same operational procedures are taken into account. If you move from a to b, you need to look out for networking, for logging, for storage, for all of that. This needs to be handled the same way if you move from a to e. So you need a common platform. And to install that common platform, you also need automation to install to configure it correctly. And this is only the basis to to set up the environment in all of those different platforms, but then you also need to look at security. And sometimes security cannot be automated in a way because it depends on the environment you're going to. And, this then means that you need to establish, as we have said several times now, verifiable trust. You need to trust the environment you're where you're going to, and only confidential computing can do this for you because the interaction of, a CPU, like, Paul said, an Intel CPU with TDX and an attestation service running on premise makes it possible that you verifiable, that you verify that the environment's actually running in confidential mode. So you need a flexible, secure deployment model. Is that correct? Yes. So, Paul, then, from the Intel side, how has your partnership with Red Hat supported with that flexible secure deployment model? Good question. I I think, from, from Intel's perspective, this is where, I guess, this is exactly where our partnership, with Red Hat becomes critical because the the technology that we're building on just isn't enough, right, to to really scale Sovereign AI. As Axel said, right, you you need to make it consumable. You need to make it repeatable. You need to make it operationally simple. And, effectively, that's the role that Red Hat plays. Right? Intel brings the hardware rooted trust foundation technologies like TDX and others that protect workloads at the compute layer, and provide attestation. Both on their own, these capabilities are are incredibly complex, and, you know, can be complex to deploy and integrate into real environments. You know, what Red Hat does, and I don't oversimplify it, is take that underlying capability and turn it into a platform experience, you know, a repeatable platform experience, like Axel just described. Right? And with platforms like Red Hat, OpenShift, and, you know, confidential containers, you know, confidential computing becomes something developers and operators can actually use without needing deep expertise on the underlying hardware. You know, the hardware should be there and, you know, being utilized without having to crawl down into it. So instead of asking, you know, how do I configure, you know, trusted execution environments, manage all the station flows, and handle secure key releases, you get a model where trusted workloads are deployed like any other container or VM. So, you know, you just pull that one down and that one. Security policies are integrated as the platform, like, within OpenShift. And life cycle management, again, is automated, and it's consistent. And this is where complexity really gets removed because Red Hat abstracts away, you know, a lot of that heavy lifting. Hardware discovery and enablement done. Runtime configuration for confidential workloads is done. Integration with Kubernetes orchestration, and most importantly, I think, attestation and secret management workflows. So, with components like the Red Hat build of trustee, for example, that attestation process, which again, to repeat for the audience, is central to sovereignty and trust, that attestation process becomes part of a standardized, I guess, policy driven workflow, not something every customer has to build themselves. And the result then is a much more flexible flexible deployment model. So, again, organizations can run the same trusted workloads, as Axel said, repeatable in the public cloud, on private infrastructure, or in a sovereign on prem environment, all with the consistent security and operational model. And I think that's really the key outcome of this partnership. Intel provides the rule of trust and protection, and Red Hat provides the platform that makes it usable at scale. And together, it allows organizations to move from isolated proof of concept to production ready sovereign AI deployments without the operational burden that would normally come with that level of security and also the ability to do that at scale. So that's the benefit, I think, with the Red Hat partnership for Intel. It's that pull through. So a big trusted name with a very easy trusted process. There you go. You nailed it. You nailed it. So, Axel, then how do you take sovereignty requirements and translate them into a practical architecture organizations can actually work with? So as I mentioned, we have that experiment within our team. So first of all, you need to find out how far are you in your endeavors to sovereignty. So, about a couple of weeks ago, we released a rapid sovereignty readiness assessment tool, which helps you. You get asked some questions, and then there comes an output where it says, in this area, you need to advance something, blah blah blah. So all of this is you where are you? That is the first question question you need to answer. And then after that, we'll have we have created, let's say, a phased approach to establish a hybrid cloud environment. And the first step of that is you need to make sure that the foundation is right. So OpenShift is a is a secure foundation, a platform, which you can use in on premise, in the private cloud, and in the public cloud. So that then, puts a wrapper around all operational procedures. So that makes it easier from for you as a consumer, as a customer, to move or as a company to move from a to b. That makes it much easier to have that generalized way. And if you then look at confidential computing, it is on top of the operational wrapper. It's an a a security wrapper, which allows you to set standards for security profiles in each of those environments and be sure that they are adhered to. Second one is then you need to automate and the installation and configuration. So you need to be sure that if you decide on a whim that you want to go from cloud a to cloud b or you are forced to do this because cloud a is not, providing services to you anymore, you need to automate the installation regardless of where you want to deploy this. So then you can just deploy your models. You deploy your application, your service into a new environment without any big, constraint on how to configure this. Then, as we said, you need to look as I said, you need to look at data. How do I get access to the data? And how do I establish those security policies with looking at zero trust. So you need to be sure that the environment you're going to is always in a operated in a secure way. And you then for that, you can use confidential computing in the different ways you would like to that they are available in the different use cases we supply. Mhmm. Fabulous. So, finally, just to round us off in this section, and I know, Axel, you mentioned earlier about building the foundations. But, Paul, if if you're an organization looking to move towards Sovereign AI, what are the first practical steps that you should take? I think that's a key question, Al. I think the good news is you don't have to solve everything at once to get started. Right? I think the most successful organizations we're working with are taking a phased, very pragmatic approach, and I think, Axel called out a lot of the cornerstones of that. But the first step, I think, for people to to take on board is identify your high value, high sensitivity workloads. Where is your most critical data? Where are you using AIs in a way AI, sorry, in a way that involves sensitive inputs, maybe proprietary models or regulated data? Start there because that's where Sovereign AI delivers immediate value. And then I would think the second step is to think about how you establish then that trusted foundation. Right? That means adopting confidential computing in whatever infrastructure that you're running on for that particular project or program. You know, technologies like TDX are there everywhere. They ensure your data is protected, as we said, not just at rest or in transit, but during execution. And that gives you the core capability of protecting data use. And then the third step, is to introduce that verification and policy control where attestation becomes critical in making sure that workloads only run-in environments that meet your security and sovereignty requirements and that access to data is tied to those verified conditions. And then the fourth step is really about scale and consistency. You know, you don't want this to be a one off solution. You want a platform approach here. So that first, second, and third step, know, organizations are doing this now, and soon we're gonna start seeing, you know, confidential AI at scale. And that's where working with platforms like Red Hat Overture become key because it removes a lot of that, what I call day two operational complexity, allows you to deploy trusted workloads consistently as we at least as we've said many times here across cloud on prem and hybrid environments. So we simplify it. You know, the journey really looks like this. Start with a critical use case, build on a trusted compute foundation, add that verification of control, step in, and then scale it through a platform. And I think the most important point to leave with is this. Right? You know, Sovereign AI doesn't require you to slow down innovation. It actually gives you the confidence to accelerate it safely. And because once you can protect, verify, and control how your AI is running, you're no longer choosing between innovation and compliance. You can achieve both. So you can effectively move from a compliance focus approach to something that drives towards value creation. And I think that's the stage that most companies wanna get to to turn things that was a compliance capability into something that creates real value for their organizations. Well, thank you very much, Paul. Thank you, Axel. That was a brilliant ending to that discussion. We do actually have a couple minutes left. So I'm gonna jump into our presubmitted q and a section. I like to call these quick fire questions. So I'm gonna throw you a question that we've been submitted, and if one of you can answer in a thirty second sound bite, that would be amazing. So our first one here is, what's actually holding organizations back from adopting confidential computing at scale today? It's from from my point of view, it's it's it's secure, the seesaw. So they are not sure that confidential computing is secure. And we need first, we need to establish that it is actually secure, and you can trust it. Not not we don't only need the trust in the environment we're going to. We need the trust in the CSOs and and the security departments to also trust us. Copy that. I'll take a different answer to that. I think, the technology is crossing to mainstream. I think, when Red Hat delivers open shift confidential containers, I think we'll see more people adopting, confidential computing. How about that, Axel? So our next question here is, what is the most overlooked risk when organizations start building sovereign AI strategies for the first time? Oh, Axel. I would still say the platform. We already I already touched this. It's it's, that they need to perform. That needs to perform, and they they need to be able to handle all the requests And a standardized platform to to deploy models is a a very important thing. Also, when we look at the GPU support, it's how can I run models in the cloud in a secure way? I I would give a very quick answer to this. I think the most overlooked risk is assuming sovereignty as something you can define in policy, but not enforcement one time. Great. Where the next question here is, where do you see the biggest tension today between innovation speed and the need for control governance and compliance? If we look at AI, that is a really dynamic area. Most people when you need to when you find out about a new component, a new server there, it's already six months. After that, it's already gone. So in that sense, the the environment changes a lot, and you need to change with it or get at least a understanding of what those new feature services mean and then be able to address the security problems there. Yeah. I think, you know, from my perspective, the biggest tension in AI development sorry. The biggest tension is in AI development itself. I think teams wanna move fast. They wanna use real data. They wanna iterate quickly and scale across environments. Government's struggling to keep up, especially when the data is sensitive, so organizations either slow everything down to stay compliant or or move fast and take on hidden risk. But the real friction point is data in use because that's where traditional controls just don't apply. So the shift we're seeing, you know, is towards controlling how data is used and not just where it sits, as we said. And that's how, you know, you remove the trade off between speed and control, I think. And that's the biggest tension. And finally here, I've got one more question. As AI systems become more distributed and regulated, what capability or mindset shift will be essential over the next twelve to twenty four months? Okay. I think the key shift I mean, I think the theme that we're we're bringing here today is trust. Right? And we're you know, we've shown how you can build on a trusted foundation right up through the platform. So for me, the key shift is moving from trust by assumption to trust by verification. Right? So, as AI becomes more distributed and regulated, again, it's no longer enough to rely on where something is running or who is operating it. I think the shift will be that organizations are gonna need the ability to prove in real time that their data, their models, their workloads are running in a trusted environment under the right policies. And that means embedding verification to the system itself through things like attestation and policy enforcement at runtime. We haven't even touched the, the shift to agentic AI. I mean, the things that we're doing now are gonna move, to, you know, five x, six x. So trust will have to become something that happens in real time. I would, pick up on Paul what Paul said a couple of, minutes ago on the ROI. I would think there is there will be a shift when model AI and AI itself has to prove that it's worth doing. Currently, they are in some of them are in the innovative play around phase, but at at some point, this needs to prove that it's actually a value for the company. Brilliant. Thank you both so much. There were some great, concise quick fire questions there. That does unfortunately bring us to the end of today's session. So a big thank you to both of you for sharing your perspectives. If there's one thing to take away from today, it's this. Sovereign AI isn't just about where your data sits. It's about how it's protected, controlled, and verified while it's being used. We're moving from a world of assumed trust to the one of provable trust. Confidential computing is a critical foundation for that shift, allowing organizations to run sensitive workloads across cloud, on prem, and hybrid environments without compromising on privacy, security, or control. And important importantly, this isn't theoretical anymore. With the joint work between Intel and Red Hat, we're seeing these capabilities become operational, scalable, and ready for the real world. So the opportunity now is clear. Start thinking about how you can build AI systems that are not just powerful, but trusted by design. The recording of this webinar will be available shortly, so you will be able to revisit the discussion and share it with your colleagues. Thanks again for joining us, and bye bye for now.