TEEs are emerging as a trust layer for AI, enabling sensitive data to be processed in secure enclaves while blockchain records provide verifiable attestations of model use, bridging gaps in confidentiality and accountability.
A core challenge in decentralized AI is the reliance on offchain computation within deterministic onchain systems. TEEs address this by providing verifiable proofs of execution, reducing trust assumptions, and enabling offchain compute to integrate more securely with blockchain-based frameworks.
Enterprises and institutions can collaborate on AI model training without exposing raw data. TEEs keep inputs and model weights encrypted during computation, while blockchains coordinate contributions and log model updates to ensure fairness and compliance.
Although TEEs can secure data, models, and execution, they cannot solve deeper challenges such as model opacity, bias, or hallucinations, which require complementary safeguards beyond hardware isolation.
Primer
Trusted Execution Environments (TEEs) have become a critical building block for securing sensitive computation. By creating hardware-isolated enclaves, TEEs allow data and models to remain protected even while in use, guarding against leakage or tampering at the infrastructure level. When combined with blockchains, TEEs extend these guarantees by producing cryptographic attestations that can be recorded onchain, offering both confidentiality and verifiability.
This convergence is especially relevant for artificial intelligence (AI). AI models today face deep trust challenges: organizations must balance the need to use sensitive datasets, safeguard proprietary models, and demonstrate compliance in increasingly regulated environments. TEEs provide the secure container for training, inference, and deployment, while blockchains supply the transparent record of what occurred inside those containers. Together, they enable AI systems that are private enough to protect critical data and transparent enough to be trusted across organizational boundaries.
For a deeper introduction to TEEs, their evolution, and their role across computation networks, custody, interoperability, and DeFi, see the previous report.
Despite rapid adoption across industries, today’s AI stack faces a widening trust gap. The core challenges stem from three issues: opaque models, unverified outputs, and data leakage. Each undermines reliability, accountability, and safe deployment at scale.
Opaque Models
Modern AI systems, particularly deep neural networks, are often described as “black box” models. Users can see inputs and outputs, but the internal processes remain hidden. Even developers of advanced systems such as OpenAI’s ChatGPT or Meta’s Llama cannot fully explain how conclusions are reached. This opacity makes it difficult to audit decisions and obscures hidden flaws.
Healthcare illustrates the problem clearly. During the COVID-19 pandemic, AI models trained on chest X-rays achieved high accuracy in testing but failed in real-world use. Researchers found the models were relying on irrelevant features such as annotations, rather than medical signals. Known as the “Clever Hans effect,” this showed how models can appear accurate while learning the wrong correlations, creating significant risks in mission-critical settings.
Unverified Models
AI systems today require users to trust that outputs are generated by the claimed model and that the model has not been tampered with. In practice, enterprises and regulators have no way to confirm whether an inference came from an approved model version, or whether it was altered, downgraded, or replaced. Because providers control the model weights, infrastructure, and execution stack, users remain dependent on opaque assurances rather than cryptographic evidence. This unverifiable provenance problem creates structural risk, particularly in regulated domains where accountability demands proof of model integrity.
Unverified Outputs
Even when models are authentic, their outputs cannot always be trusted at face value. The most visible case is AI hallucination, where models generate fabricated but convincing information. In July 2025, more than 50 global cases surfaced of lawyers submitting fake citations generated by AI into court filings. These incidents reveal how professionals can be misled into treating AI outputs as authoritative, with serious legal and reputational consequences.
The problem extends across sectors. From healthcare to customer service, fabricated outputs erode trust because users cannot reliably distinguish accurate responses from false ones. Without safeguards, organizations face rising risks of over-reliance on unverifiable AI content.
Data Leakage
AI systems remain vulnerable to data leakage, exposing both enterprise data and individual privacy. In 2023, Microsoft researchers inadvertently exposed 38 terabytes of sensitive internal data through a misconfigured Azure storage URL. That same year, OpenAI experienced a bug that briefly revealed user chat histories and payment details.
On the enterprise side, Samsung employees pasted proprietary source code and meeting notes into ChatGPT, inadvertently disclosing trade secrets and prompting a company-wide ban on generative AI tools. On the consumer side, ordinary users risk exposing personal identifiers, health information, and financial records through interactions with AI systems that may retain or mishandle inputs.
These cases show that both infrastructure flaws and human error can lead to irreversible information loss. The consequences include regulatory penalties, legal disputes, and weakened customer confidence, making confidentiality a critical barrier to large-scale AI adoption.
Where TEE meets AI
The combination of TEEs and blockchain technology provides a complementary framework for closing the trust gap in AI. TEEs protect data and models during computation, while blockchains create permanent, transparent records of what occurred inside those protected environments.
A core benefit of this integration is stronger protection against data leakage. TEEs ensure that sensitive data never leaves the secure enclave in plaintext. Training datasets, proprietary model weights, and user inputs remain encrypted even while in use, preventing malicious access or accidental exposure. By anchoring TEE attestations on a blockchain, organizations can prove that their models handled sensitive data without ever revealing the underlying information.
Multi-party collaboration is another area where TEEs and blockchains work in tandem. AI development increasingly requires diverse datasets from multiple organizations, but sharing raw data is often impossible due to privacy, competition, or regulatory barriers. TEEs allow each participant to contribute data to a training process without exposing it, while the blockchain coordinates collaboration by recording contributions, logging model updates, and ensuring fair aggregation of results. In healthcare, for example, hospitals could build more accurate diagnostic models by training across patient data from different regions. Each hospital would retain control of its records, but the blockchain would keep a transparent ledger of contributions and model improvements, ensuring that trust is maintained throughout the process. The same approach applies to enterprises that are cautious about contributing data to large language model (LLM) training. Today, providers such as OpenAI explicitly state that enterprise data is not used for training unless organizations opt in. With TEEs, enterprises could contribute sensitive data to LLM training in a way that guarantees confidentiality: their inputs would remain encrypted in secure enclaves, model updates would be verifiably isolated, and blockchain records would provide proof of how and when data was used. This creates a path for regulated industries to participate in improving LLMs without sacrificing data privacy or regulatory compliance.
The combination also enhances the verifiability of AI outputs. TEEs provide cryptographic attestations that confirm the hardware is operating as a secure enclave and has not been tampered with. These attestations, once anchored on a blockchain, become permanent and can be audited by anyone. This creates a tamper-proof record that proves. Consider a financial advisory system where users must trust that recommendations are generated by an approved model rather than a malicious copy. By combining remote attestations with reproducible builds of public application images (and, ideally, open-source model weights), the blockchain can store proofs of each model run, enabling users and regulators to independently confirm authenticity without accessing the sensitive details inside the enclave.
Beyond these core benefits, blockchain integration opens additional possibilities. DAOs, for example, can be used to manage AI model deployment and updates, with TEEs ensuring that governance rules are executed securely. While not an all-encompassing solution for the trust gap, these mechanisms add a participatory layer of oversight that complements the guarantees of confidentiality, collaboration, and verifiability.
Early Proof Points
A growing number of projects are actively building with TEEs to make AI more secure, private, and verifiable. While still early, these efforts illustrate how confidential computing can be applied in high-stakes contexts such as healthcare, finance, and enterprise data management.
iExec has demonstrated the potential of TEEs and blockchain through a healthcare-focused proof of concept recognized in Intel’s AI Inference Software & Solutions Catalogue. The project explored how confidential AI could support epilepsy surgery evaluation, a process that requires collecting and analyzing massive volumes of electroencephalogram data. By using Intel’s Trusted Domain Extensions (TDX), iExec created enclaves where sensitive patient records could be analyzed privately, without being exposed to clinicians, cloud providers, or other third parties. At the same time, AI models themselves were encrypted and only decrypted inside the enclave, protecting intellectual property. Blockchain provided governance and auditability, recording which models were used, when they were applied, and under what conditions.
Oasis has extended TEEs into DeFAI, most notably through Talos, an autonomous treasury protocol that showcases the capabilities of its Runtime Off-Chain Logic (ROFL) framework. Talos combines AI-driven decision-making with human governance to manage yield-bearing assets, continuously monitoring onchain data and market dynamics to optimize investment strategies. The system leverages several ROFL components, including TEE execution for compute integrity, decentralized key management to control private keys within secure enclaves, and transparent upgrades coordinated through a multi-sig setup and automated GitHub flow. Together, these elements provide a verifiable and resilient foundation, allowing Talos to progress toward greater AI autonomy while preserving transparency and auditability.
Phala has approached the TEE trust model itself, addressing one of the key weaknesses in current deployments: reliance on vendor-controlled attestation. Phala’s enterprise solution anchors TEEs to Ethereum, moving the root of trust from hardware manufacturers to smart contracts. In this model, enclave policy and lifecycle are enforced onchain, and secrets are released only when an enclave’s attestation matches pre-approved conditions. Every key issuance, rotation, or revocation is tied to an onchain event, creating a public, auditable record. For AI applications, this means LLM inference can be delivered with verifiable provenance, with each response tied to a specific model hash and enclave identity. Phala Cloud extends these guarantees into a developer-oriented Confidential AI platform, ensuring that models, prompts, and data remain private while still producing results that can be independently verified. It also enables cross-organization collaboration, as multiple parties can contribute encrypted data to shared enclaves under transparent policies enforced on Ethereum, unlocking joint analytics without exposing raw data. By externalizing trust to a public blockchain, Phala reduces reliance on a single vendor and establishes a zero-trust foundation for deploying secure and verifiable AI at scale.
Closing Summary
TEEs, when paired with blockchain, are beginning to reshape how AI systems can be deployed in sensitive and high-stakes environments. From iExec’s work on privacy-preserving healthcare analytics, to Oasis’s demonstration of autonomous and verifiable trading agents, to Phala’s effort to externalize enclave trust through Ethereum, the early proof points show that confidential computing is moving from concept to practical application. The common thread is the ability to protect sensitive data, enable secure multi-party collaboration, and generate verifiable records of model execution. These capabilities directly address some of the most pressing barriers to enterprise and regulated adoption of AI.
Yet TEEs are not a complete solution. They do not make opaque models interpretable, prevent algorithmic bias, or eliminate the risk of hallucinations. They are best understood as one layer within a broader trust architecture, working in combination with approaches such as explainable AI (XAI), bias detection, and advanced cryptographic techniques. In this role, TEEs provide secure execution and verifiable records that complement other safeguards to deliver more reliable AI systems.
The trajectory is clear: as TEEs mature and integrate with decentralized infrastructure, they will increasingly underpin AI systems that are both private enough to protect sensitive inputs and transparent enough to be trusted across organizational boundaries. The winners in this emerging ecosystem will be those who can balance these strengths with complementary safeguards, delivering AI that is not only powerful but also demonstrably secure and accountable.
This report was commissioned by iExec RLC, Oasis Protocol, and Phala Network. All content was produced independently by the author(s) and does not necessarily reflect the opinions of Messari, Inc. or the organization that requested the report. The commissioning organization may have input on the content of the report, but Messari maintains editorial control over the final report to retain data accuracy and objectivity. Author(s) may hold cryptocurrencies named in this report. This report is meant for informational purposes only. It is not meant to serve as investment advice. You should conduct your own research and consult an independent financial, tax, or legal advisor before making any investment decisions. Past performance of any asset is not indicative of future results. Please see our Terms of Service for more information.
No part of this report may be (a) copied, photocopied, duplicated in any form by any means or (b) redistributed without the prior written consent of Messari®.
Alice is a Research Analyst on the Protocol Services team. She previously worked as a Research Analyst at The Block and was an Investment Intern at Variant Fund. Alice graduated from Northwestern University, where she studied Economics.
Alice is a Research Analyst on the Protocol Services team. She previously worked as a Research Analyst at The Block and was an Investment Intern at Variant Fund. Alice graduated from Northwestern University, where she studied Economics.