VMware Cloud Foundation

Protecting Data Where It’s Most Vulnerable: How Broadcom and Intel Are Making Confidential Computing Real

AI is only as trustworthy as the infrastructure it runs on. Organizations increasingly want to use AI with sensitive data, deploy workloads in regulated environments, and meet growing sovereignty requirements. Achieving those goals requires more than traditional security controls. It requires confidence that data, applications, and infrastructure can be trusted throughout the lifecycle of a workload.

Broadcom and Intel are helping organizations build that confidence through confidential computing capabilities integrated into VMware Cloud Foundation (VCF), creating a foundation for trusted AI, regulated workloads, and verifiable infrastructure security.

Why traditional security controls are no longer enough

Encrypting data at rest and in transit has become standard practice, and most enterprise security teams have those challenges well under control. The next challenge is protecting sensitive data while it is actively being processed. As organizations increasingly use AI to analyze proprietary information, customer data, and other business-critical assets, they need greater assurance that workloads remain protected during execution, not just while data is stored or transmitted. Confidential computing addresses this challenge, and it’s what Broadcom and Intel have been co-engineering into VMware Cloud Foundation across the 9.x release cycle.

The importance of protecting data in use has grown as AI adoption accelerates and regulatory expectations evolve. An inference workload processing financial records, patient data, or proprietary models remains exposed throughout execution. At the same time, organizations in highly regulated sectors such as financial services, healthcare, and government are increasingly being asked to demonstrate how sensitive data is protected while it is being processed, not simply how it is stored or moved.

The Security Foundation We Established jointly in VCF 9

Across VCF 9.0 and VCF 9.1, both Broadcom and Intel have been partnering to bring  confidential computing capabilities into VCF as a production-ready platform feature. Broadcom’s platform contributions included bringing confidential computing in as a generally available feature for the first time in VCF 9.1, supporting Intel TDX along with Quickboot support.  TPM 2.0 and vTPM integration established hardware roots of trust for every workload on the platform. Live Patching for TPM-enabled ESX hosts now applies security patches to up to 80% of CVEs with no VM evacuation, shrinking the window between vulnerability disclosure and a patched production host from weeks to hours. Continuous compliance enforcement keeps the security posture verifiable in real time rather than reconstructed before an audit.

Intel’s contribution starts at the lower layers of  VCF’s infrastructure stack and in the silicon itself. Intel Trust Domain Extensions (TDX), available on Intel Xeon 5 and newer processors, create hardware-isolated Trust Domains where individual VMs run with encrypted memory that the hypervisor cannot inspect. Intel QuickAssist Technology (QAT) accelerates cryptographic operations helping support  encrypted vMotion with minimal impact on CPU resources.

Intel is responsible for the silicon trust layer and Broadcom is responsible for the operational trust layer. Together they create an end-to-end chain of trust, backed by attestation, from the CPU through the hypervisor to the workload. The real value lies in the joint engineering and validation across the stack.  While TDX originates in silicon, delivering it as a production ready capability requires supported firmware, managed by VCF, to function as a platform feature customers can ship to production. Customers do not need to validate or troubleshoot the interaction between TDX firmware  and the ESX hypervisor themselves. That integration work has been done and validated jointly.

Delivering confidential computing at scale

Confidential VMs in VCF 9.1 run using the same operational model as standard VMs, with the same lifecycle management, compliance tooling, and processes. There’s no separate infrastructure footprint and no specialized expertise required to deploy a workload into a TEE. Organizations already running VCF on Intel Xeon 6 or Xeon 5 processors can enable confidential computing on existing  infrastructure.

For AI workloads, sensitive inference pipelines run inside hardware-isolated TEEs where data, models, and computations remain protected during execution . For security teams, hardware attestation reduces the compensating controls needed to satisfy auditors. For infrastructure teams, the operational model doesn’t change.

Looking ahead

As organizations deploy increasingly sensitive AI workloads and operate across more complex regulatory and sovereignty environments, trust in the execution environment is becoming as important as trust in the data itself. Confidential computing is evolving from a specialized security capability into a foundational layer for trusted AI, regulated workloads, and verifiable cloud infrastructure.

Broadcom and Intel continue to work together to simplify the adoption of confidential computing and bring hardware-rooted trust into mainstream enterprise operations. By combining Intel’s silicon-based security innovations with VMware Cloud Foundation’s operational capabilities, organizations can establish a verifiable chain of trust that extends from infrastructure to workload.

Getting started

Confidential Computing in VCF 9.1 is available today for organizations running sensitive AI, business-critical, or regulated workloads. Customers already running VMware Cloud Foundation from Intel Xeon 5 processors can evaluate Confidential Computing using existing infrastructure and operational processes. Broadcom account teams can help identify suitable workloads and provide access to joint Intel and Broadcom reference architectures and deployment guidance.


Discover more from VMware Cloud Foundation (VCF) Blog

Subscribe to get the latest posts sent to your email.