01 / The mechanism and its boundary
What is being described
NVIDIA describes itself as having "pioneered accelerated computing" S-3604. Its public material relevant to verification concerns its data-centre GPUs:
- Confidential-computing mode. NVIDIA documents a confidential-computing mode for its Hopper and Blackwell data-centre GPUs, in which the GPU is paired with a CPU trusted execution environment and attests its identity and firmware S-1200; see TEE remote attestation for AI workloads.
- H100 launch. NVIDIA engineers describe the feature's launch on the H100, with an on-die root of trust, a fused device identity key and SPDM attestation S-1201.
- Counters in confidential mode. NVIDIA disables performance counters in full confidential-computing mode, stating that they could provide an avenue for side-channel attacks S-1200; see On-chip telemetry from timing, memory and performance counters.
- Fleet telemetry. NVIDIA reports an opt-in, customer-installed fleet-management service that provides read-only GPU telemetry S-1413. Its Fleet Intelligence service uses a read-only, open-source agent that sends GPU power, performance, health and configuration data to an NVIDIA cloud service S-3180. The service supports attestation only on Blackwell and Vera Rubin GPUs S-3180. NVIDIA states that its GPUs "do not have hardware tracking technology, kill switches and backdoors" S-1413. See On-chip telemetry from timing, memory and performance counters.
- Location verification. Avellar and Grunewald report, citing Reuters, that NVIDIA has confirmed it is developing location verification that estimates a chip's location from communication delays with NVIDIA-run servers S-1402; see Chip location verification.
- Use by others. Tinfoil's documentation lists NVIDIA GPUs in confidential-computing mode as supported hardware for its enclaves S-1206; see Tinfoil model identity (Modelwrap).
Connections in the research map
Related research
Sources and provenance
- S-3604 / Tier B
About NVIDIA ↗
· 2026 · NVIDIA
Supports: self-description as pioneer of accelerated computing
Version and catalogue details - S-1200 / Tier B
NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper) ↗
NVIDIA · 2025 · NVIDIA documentation
Supports: confidential computing on Hopper and Blackwell GPUs; performance counters disabled in confidential-computing mode
Locator: pp. 6-18
Version and catalogue details - S-1201 / Tier C
Confidential Computing on NVIDIA H100 GPUs for Secure and Trustworthy AI ↗
E. Apsey, P. Rogers, M. O'Connor, R. Nertney · 2023 · NVIDIA Technical Blog
Supports: H100 confidential-computing launch: on-die root of trust, device identity key, SPDM attestation
Version and catalogue details - S-1206 / Tier B
A primer on secure enclaves ↗
Tinfoil · 2026 · Tinfoil documentation
Supports: NVIDIA GPUs in confidential-computing mode listed as supported hardware by Tinfoil
Version and catalogue details - S-1413 / Tier B
Opt-In NVIDIA Software Enables Data Center Fleet Management ↗
NVIDIA · 2025 · NVIDIA Blog
Supports: opt-in, customer-installed fleet-management service with read-only telemetry; statement on tracking, kill switches and backdoors (provider-reported)
Version and catalogue details - S-3180 / Tier B
Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and Optimization ↗
C. Shrauder, G. Frederick · 2026 · NVIDIA Technical Blog
Supports: Fleet Intelligence: open-source read-only agent, telemetry and attestation on Blackwell and Vera Rubin (provider-reported)
Version and catalogue details - S-1402 / Tier B
Near-Term Verification Methods for AI Chip Exports ↗
B. Avellar, E. Grunewald · 2026 · Institute for AI Policy and Strategy
Supports: NVIDIA reportedly developing delay-based location verification with NVIDIA-run servers (citing Reuters)
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review