A Close Reading of OpenAI's Private Safety Processing

At DevDay on September 29, OpenAI announced Private Intelligence. The headline version is easy to repeat: frontier models, confidential computing underneath, and your data stays private, even during inference. The documents tell a more careful story. Private Intelligence is two things, and they are at very different stages: Zero Data Retention with Private Safety Processing (PSP). This is rolling out to eligible API customers, and OpenAI published a 36-page technical white paper describing it. Private Inference. This is a preview “coming this fall.” OpenAI hasn’t published the hardware, the trust boundary, or how a customer would verify it. I’ve spent most of my career on attestation and key release, first in payments and then in confidential computing. The first item is the more interesting piece of engineering, and very few people are writing about it. The second is the bigger bet. This post is my reading of both, based only on what OpenAI and others have published as of early October 2026. ...

October 1, 2026 · 13 min · Pawan Khandavilli

When Private AI Needs to Remember

An assistant processes a conversation inside a trusted execution environment (TEE). The response comes back, the session ends, and the environment disappears. That is a useful model for private inference. It is a poor model for an assistant that is supposed to remember what you said tomorrow. That gap has been on my mind after reading three recent designs: Google’s plan for secure server-side memory, Meta’s Private Processing architecture for AI glasses, and Amazon’s Bee Private Compute paper. Each starts with a different product. All three have to deal with the same fact: a personal assistant needs context that lasts longer than one inference request. ...

September 24, 2026 · 8 min · Pawan Khandavilli

Trust Is the Next Bottleneck: Why the Agentic Economy Needs Confidential Computing

I’m giving a talk at Confidential Computing Summit 2026 in San Francisco on Tuesday. The title is “Trust Is the Next Bottleneck.” This essay is the argument behind the slides. The short version: we are building an economy of autonomous AI agents on a trust foundation designed for humans clicking buttons. That foundation is cracking. The fix isn’t better software — it’s hardware. The gap between authorization and execution OAuth tokens, API keys, and IAM roles answer one question: who authorized this action? ...

June 20, 2026 · 6 min · Pawan Khandavilli

From 'Trust Us' to 'Verify Us': Anthropic, Confidential Inference, and the Next Trust Problem

Jason Clinton’s OC3 2026 talk on confidential computing and scaling laws pushed me to finally write about Anthropic’s Confidential Inference Systems paper, a joint publication with Irregular (formerly Pattern Labs), released June 2025. It’s one of the cleaner public treatments of what it actually means to make AI trust verifiable rather than asserted. It also points directly at a gap the industry hasn’t begun to close: trust in agentic systems. This post unpacks the paper’s core contributions, where its claims need qualification, and where I think the conversation has to go next: from confidential inference to attested agent identity. ...

April 27, 2026 · 11 min · Pawan Khandavilli

What WhatsApp's Trail of Bits Audit Teaches Us About Real TEE Security

In January, I wrote about WhatsApp’s Private Processing as a milestone for confidential computing: the first time TEEs were deployed at truly global scale to protect AI inference for billions of users. That post was about the architecture. This one is about what happened when someone tried to break it. Trail of Bits just published its pre-launch security audit of WhatsApp’s Private Processing system. They found 28 issues, including 8 high-severity findings. Meta fixed the critical issues before launch. ...

April 10, 2026 · 7 min · Pawan Khandavilli