How Karambit.AI and Microsoft Bring Software Authenticity to 14 Billion Files Per Month
June 25, 2026Right-Sizing Intelligence: Building a Multimodal Model Portfolio for Healthcare and Life Sciences
June 25, 2026
This blog provides an update on that momentum: how Azure Confidential Computing (ACC) is expanding across infrastructure, services, hardware-rooted security, and operational maturity, and why that matters for customers with increasing requirements for control, assurance, privacy, and compliance. As digital sovereignty and regulated workload needs continue to grow, ACC is becoming an increasingly important part of how Azure helps customers move sensitive workloads to the cloud with hardware-backed protections designed to help protect data in use.
The opportunity for ACC is especially clear in scenarios where customers are balancing innovation with heightened requirements for control, assurance, and compliance. That includes sovereign cloud strategies, national and regional regulatory obligations, privacy-sensitive AI scenarios, and workloads where reducing exposure to privileged infrastructure layers is increasingly important.
Momentum over the last year
- September 2025: Microsoft announced general availability of AMD SEV-SNP DCasv6 and ECasv6 confidential VMs based on 4th Generation AMD EPYC processors.
- November 2025: At Ignite 2025, Microsoft highlighted continued momentum for Azure Intel TDX confidential VMs, alongside hardware-rooted advances such as ABCD and TDISP to strengthen protected device and I/O paths for sensitive workloads.
- February 2026: Microsoft launched general availability of AMD SEV-SNP DCasv6 and ECasv6 confidential VMs in Azure Government, extending sovereign cloud capabilities.
- February 2026: Microsoft announced general availability of Azure Intel TDX confidential VMs across the DCesv6, DCedsv6, ECesv6, and ECedsv6 series.
- September 2025: Microsoft announced Azure Confidential Computing support for Azure Database for PostgreSQL, extending confidential computing capabilities into a managed database service.
- May 2026: Microsoft announced general availability of Azure Integrated HSM (AIH), strengthening hardware-backed key protection for sensitive and regulated workloads.
- June 2026: Microsoft announced preview of multiparty analytics with Azure Confidential Clean Rooms.
- June 2026: At Microsoft Build 2026, Microsoft showcased Confidential Live Migration for Intel TDX confidential VMs.
- June 2026: Microsoft announced that DCasv6 and ECasv6 confidential VMs are now available in 57 regions worldwide, significantly expanding the global footprint for confidential workloads.
- June 2026: Microsoft Signing Transparency (MST) general availability which complements ACC by extending verifiable trust into the software supply chain, enabling customers to independently validate the integrity and provenance of software artifacts alongside hardware-rooted protections for data in use.
Taken individually, each announcement is a product update. Taken together, they show Confidential Computing (CC) maturing across VM breadth, digital sovereignty and regulated cloud relevance, AI-oriented confidential computing, operational capabilities that make the platform more practical for real-world deployment, and a growing set of Azure services adopting CC patterns beyond infrastructure alone. The June 2026 expansion of AMD-based DCasv6 and ECasv6 confidential VMs to 57 regions is especially important because it brings low-latency deployment closer to where customers operate, supports data residency and sovereignty requirements, improves multi-region resiliency planning, and can reduce cross-region data movement costs for sensitive workloads.
Why ACC matters
Azure Confidential Computing (ACC) is Azure’s portfolio across confidential virtual machines, containers, GPUs, attestation, and related services. Its purpose is to let customers run selected workloads inside trusted execution environments so that sensitive data can remain protected during processing and workload integrity can be measured and verified.
That makes Azure Confidential Computing (ACC) particularly relevant for customers with digital sovereignty requirements, regulated data environments, and privacy-sensitive AI use cases. It extends the Azure security model beyond encryption at rest and in transit by helping protect data in memory while it is actively being processed within supported confidential computing environments.
Confidential Computing is a powerful technical control, but it is not a substitute for the broader set of governance, access control, auditability, and key management measures that regulated customers often require. It is one of the most important building blocks in a larger trust architecture.
Security rooted in hardware
What differentiates ACC is that its security foundation starts in hardware. The core isolation boundary is provided by hardware-based trusted execution environments (TEEs), rather than relying only on software controls in the hypervisor or operating system. That matters because sensitive workloads are actually running inside attested TEEs, which gives customers a stronger basis for helping protect data and code during execution and for verifying the integrity of the environment before releasing secrets or processing sensitive data.
In Azure, that hardware-rooted model spans multiple technologies and product paths. Hardware TEEs provide the protected execution environment. Azure Boost helps move key virtualization and storage functions into purpose-built hardware and offload paths, reducing the attack surface on the host and improving performance isolation. Azure Integrated HSM (AIH) adds hardware-backed key protection and helps strengthen the cryptographic control plane for customers that need stronger assurance around key custody and use. Just as important, Azure brings these capabilities together across a broad ACC portfolio that includes confidential VMs, confidential containers, confidential GPUs, attestation, and related services, giving customers more consistent protection patterns across infrastructure, data, and AI scenarios.
Taken together, these elements matter because they show that Azure’s trust story is not built on a single feature. It is built from a hardware-rooted approach that combines protected execution, workload verification through attestation, platform isolation, and stronger control over sensitive cryptographic material. Azure’s approach is also aligned with the broader industry direction reflected in the Confidential Computing Consortium (CCC), where the broader industry organizations, including Microsoft, AMD, Intel, ARM and NVIDIA are all active participants. That alignment matters for customers that care about open industry definitions, ecosystem interoperability, and the long-term evolution of CC across platforms and workloads.
The underlying security model starts in hardware and then extends upward through confidential VMs, confidential containers, confidential GPUs, attestation, and related services.
AI and confidential inferencing
AI is also becoming an important part of the ACC story. Azure was the first cloud provider to bring confidential computing to NVIDIA H100 with NCC H100 v5 confidential VMs, and we are seeing growing interest from sovereign and regulated customers that want stronger protections for sensitive models, prompts, and inference data. We are also seeing small- to medium-sized models run inference on confidential CPU-based VMs, showing that confidential AI is not limited to GPU scenarios alone. Looking ahead, we will continue innovating with our hardware partners to expand confidential AI capabilities, including support for multi-GPU confidential computing.
Microsoft first-party adoption of ACC
One of the clearest signs of ACC’s importance is Microsoft’s own adoption of CC in first-party services. Inside Microsoft, we often talk about eating our own dogfood, or drinking our own champagne, by using the same platform capabilities we ask customers to trust. That also applies to ACC.
Microsoft has publicly discussed the adoption of confidential computing technologies across selected first-party services.
More broadly, Microsoft continues to evaluate and expand confidential computing technologies across selected services where stronger isolation and protection may be beneficial. That direction matters because these are among the most security-sensitive parts of the platform. ACC is becoming relevant not just for sovereign/regulated workloads, but for the services that underpin Azure cloud trust itself.
ACC and the control model behind digital sovereignty
For digital sovereignty and regulated workloads, CC matters most when it is combined with complementary controls. Those can include governed operator access, customer approval workflows where supported, stronger key control, regional oversight capabilities in specific offerings, and auditability measures that help customers understand how sensitive systems are operated. In that broader model, ACC can also help reduce certain circumstances in which cloud operator access to sensitive data may be needed by helping protect data in use within hardware-backed environments, while still fitting within a larger control framework rather than replacing it.
That broader framing is important because it reflects reality. ACC helps reduce trust assumptions for data in use, but regulated customers still evaluate a larger system of controls that includes governance, approvals, operational restrictions, key management, and service-specific support boundaries.
That is why ACC is increasingly relevant. It helps address one of the most complex challenges in cloud trust: how to protect sensitive data during execution. For customers pursuing digital sovereignty and regulated cloud adoption, that is a foundational capability.
Why this matters for sovereign and regulated industries
The value of ACC is becoming clearer as customers move more sensitive workloads to the cloud and to AI-enabled architectures. They are not only looking for infrastructure that performs well. They are also looking for infrastructure that can support stronger assurances for privacy, compliance, sovereignty, and operational control.
ACC gives Azure a stronger foundation for those scenarios by combining hardware-rooted protection with an expanding platform portfolio across compute, containers, GPUs, attestation, and key protection. That combination helps Azure support the needs of customers that want to move forward on cloud and AI adoption without giving up on the control requirements that matter most to them.
Looking ahead, this direction will matter even more as confidential AI workloads become a larger part of the market. For the sovereign and regulated segments targeted here, helping protect model weights, prompts, customer data, and inference or training data during processing will be increasingly important. ACC can help provide part of that foundation by extending hardware-rooted protection to the next generation of sensitive AI workloads. As Azure continues to expand ACC, the most important outcome is not simply more features. It is a stronger platform for digital sovereignty and regulated workloads.