01 / The mechanism and its boundary
What is being described
A trusted execution environment (TEE) is an execution area that the processor protects, so that software outside it, including the host operating system and hypervisor, cannot read the data inside or alter its code and data S-1600 S-1604.
The Confidential Computing Consortium lists data confidentiality, data integrity and code integrity as the core attributes of a TEE, and code confidentiality and attestability as optional S-1604. Isolation and remote attestation are separate properties. The TEE protects a workload, and attestation, the validation of a hardware-signed report of what was loaded, lets a remote party check it S-1604. The consortium defines confidential computing as computation in a hardware-based, attested TEE, so it requires both S-1604. A TEE can cover a whole confidential virtual machine and extend to accelerators S-1604. PAL*M, for example, pairs Intel TDX confidential VMs with NVIDIA H100 GPUs to attest properties of generative models S-0012. In AI verification, TEEs underpin TEE remote attestation for AI workloads and confidential multi-party verification, such as running safety benchmarks while keeping both the model and the test data confidential S-0009. A 2026 MIRI Technical Governance Team post notes that whoever holds the hardware's attestation key can produce valid reports, and that microarchitectural side channels and physical attacks such as bus interposition remain concerns S-0014.
Connections in the research map
Related research
Sources and provenance
- S-1600 / Tier A
NIST Computer Security Resource Center (CSRC) Glossary ↗
National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center
Supports: NIST definition of TEE as an area or enclave protected by a system processor
Locator: term: trusted_execution_environment (NISTIR 8320)
Version and catalogue details - S-1604 / Tier B
Common Terminology for Confidential Computing ↗
Confidential Computing Consortium · 2022 · Confidential Computing Consortium
Supports: confidential computing defined as computation in a hardware-based, attested TEE; core TEE attributes (data confidentiality, data integrity, code integrity); optional attributes including code confidentiality and attestability; attestation as validation of a hardware-signed report of TCB measurements; confidential VMs protected from the hypervisor and host OS
Locator: definitions; TEE attributes; attestation; confidential VMs
Version and catalogue details - S-0012 / Tier B
PAL*M: Property Attestation for Large Generative Models ↗
P. Chantasantitam, A. I. Caulfield, V. Duddu, L. J. Gunn, N. Asokan · 2026 · arXiv
Supports: property attestation using confidential VMs with Intel TDX and NVIDIA H100 GPUs
Locator: abstract
Version and catalogue details - S-0009 / Tier B
Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments ↗
C. Schnabl, D. Hugenroth, B. Marino, A. R. Beresford · 2025 · ICML 2025 Workshop on Technical AI Governance
Supports: TEE-based verifiable benchmarks keeping model and test data confidential
Locator: abstract
Version and catalogue details - S-0014 / Tier C
On TEEs for Privacy-Preserving Monitoring in AI Governance ↗
Gloria Z · 2026 · MIRI Technical Governance Team
Supports: attestation-key holder can produce valid reports; microarchitectural side channels and physical attacks such as bus interposition as limitations
Locator: Limitations
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review