As artificial intelligence moves deeper into enterprise and government operations, one challenge is becoming impossible to ignore: trust. From healthcare records and financial transactions to classified government information, organisations increasingly want to harness AI without exposing their most sensitive data to security, privacy or compliance risks.
That challenge is driving growing interest in confidential AI, a new approach that combines advanced cryptography, confidential computing and emerging post-quantum security techniques to protect data throughout the AI lifecycle.
The topic has gained fresh attention following OPAQUE’s recent acquisition of cryptographic AI technologies developed by Abu Dhabi’s Technology Innovation Institute (TII), marking a significant milestone for the UAE’s deep-tech ecosystem and its ambitions to become a creator of globally adopted technologies.
Born from UC Berkeley’s RISELab, OPAQUE solves the core challenge blocking AI adoption at scale: concerns about data leaks and compliance violations. the company provides verifiable privacy and governance for AI so organisations can safely run models, agents, and workflows on their most sensitive data. TII is the dedicated applied research pillar of Abu Dhabi’s Advanced Technology Research Council (ATRC). It’s also a pioneering global research and development centre that focuses on applied research and new-age technology capabilities.
The transaction is about more than a single commercial deal. It highlights a broader shift in how countries are thinking about AI infrastructure, data sovereignty and cybersecurity in an era where autonomous AI agents are becoming increasingly capable and quantum computing is beginning to reshape long-term security planning.
In an interview with Gulf Business, Victor Mateu, chief researcher at TII’s Cryptography Research Center, explains why traditional cybersecurity tools are no longer enough for the age of AI, how organisations are preparing for post-quantum threats, and what the global adoption of Abu Dhabi-developed technology says about the UAE’s growing role in shaping the future of trusted AI.
What problem in today’s AI ecosystem does this acquisition solve that existing cybersecurity or encryption tools have not been able to address?
Existing cybersecurity tools were largely designed for traditional software systems, where access controls and encryption protect data at rest or in transit. AI introduces a different challenge, because models and agents need to actively process sensitive data to generate value.
Once that data is exposed to the AI runtime, traditional protections are often no longer sufficient. What this acquisition brings together is the ability to secure the full AI lifecycle, from training and fine-tuning to inference and AI agents, using cryptographic techniques such as fully homomorphic encryption, multi-party computation, and post-quantum cryptography. It allows organisations to use highly sensitive data without exposing it to model operators, cloud providers, or unauthorised systems. That is particularly important as enterprises move AI from experimentation into production environments.
OPAQUE says this technology enables AI to work securely with highly sensitive and regulated data, what industries do you expect will adopt this first, healthcare, finance, government, defence, or others?
The first wave of adoption will likely come from highly regulated sectors where the sensitivity of the data is already a strategic and compliance issue. Healthcare, financial services, insurance, government, and defense are natural early adopters because they operate under strict regulatory and sovereignty requirements.
Organisations in such sectors want to benefit from AI while maintaining control over patient records, financial transactions, classified information, or citizen data. We also expect strong interest from sovereign AI programmes, where countries want assurance that data remains within national jurisdictions and that policies governing AI workloads can be cryptographically verified.
Post-quantum security is becoming a bigger conversation globally, but how immediate is this threat for businesses today? Are companies already preparing for a quantum future?
The post-quantum threat is no longer theoretical. There is already widespread concern around what is commonly called “harvest now, decrypt later,” where external actors collect encrypted data today with the intention of decrypting it once sufficiently powerful quantum computers become available.
For sectors handling long-lived sensitive data such as governments, healthcare systems, financial institutions, critical infrastructure, that risk horizon is very relevant now. We are already seeing organisations begin planning migrations to post-quantum cryptography, particularly in areas where data confidentiality must be preserved for many years. The transition cannot happen overnight, which is why preparation is starting today.
Abu Dhabi has been investing heavily in AI, semiconductors, and advanced technologies. How important is this deal in positioning the UAE as a developer, not just a consumer, of advanced AI infrastructure?
This deal is significant for TII and for the UAE because it demonstrates that the UAE is producing foundational technologies that international companies, including US companies like OPAQUE, are adopting at scale.
The technologies acquired by OPAQUE were developed in Abu Dhabi through advanced applied research and are now being integrated into a global Confidential AI platform serving enterprise and sovereign customers worldwide. That is an important signal for the UAE’s technology ecosystem. It shows that the country can contribute original innovation in strategically important domains such as AI security, cryptography, and sovereign infrastructure.
Many companies want to deploy AI tools but remain concerned about privacy and compliance risks. How does this technology help address those concerns?
One of the biggest barriers to enterprise AI adoption is the fear that sensitive data could leak, be misused, or fall outside regulatory requirements. This technology addresses those concerns by embedding privacy and governance directly into the AI execution environment itself. Through hardware-backed attestation and advanced cryptography, organisations can verify where workloads ran and whether data remained protected throughout the process. That creates a stronger level of assurance for compliance teams and regulators, particularly in environments governed by frameworks such as GDPR, ISO standards, or emerging AI regulations.
Large global players such as Microsoft, Google, and Amazon Web Services are also investing in secure AI infrastructure. What differentiates OPAQUE’s offering?
Large cloud providers are investing heavily in secure AI infrastructure, but OPAQUE’s differentiation comes from the completeness of the platform and the combination of technologies now integrated through this acquisition. The partnership combines confidential training, confidential inference, AI agent governance, fully homomorphic encryption, and post-quantum protections into a unified ‘Confidential AI’ stack. It also focuses heavily on verifiable enforcement, where security guarantees are rooted in hardware attestation and cryptographic proof rather than relying solely on vendor trust. This is particularly important for sovereign AI and regulated environments where organisations require independently verifiable assurances.
Does this acquisition signal a broader trend where research institutions like Technology Innovation Institute are becoming more active in commercialising homegrown technologies?
This acquisition reflects a broader maturation of the research ecosystem in the UAE. At TII, the objective has always been to develop technologies that can transition from research into real-world deployment. Different technologies require different commercialisation paths.
In some cases, venture building is appropriate through our sister subsidiary VentureOne. In others, licensing or strategic acquisition partnerships make more sense. This transaction shows that advanced research
developed locally can achieve global commercial relevance. It also validates the broader strategy of investing in deep technology domains where long-term scientific capability translates into economic and strategic value.
What are the next milestones following this acquisition, whether that’s product rollout, partnerships, or expansion into new markets?
The immediate next step is the integration of these technologies into OPAQUE’s core Confidential AI platform for deployment globally, including in both the US and UAE markets. We expect continued expansion into regulated industries and sovereign AI programs where secure AI adoption is becoming a strategic priority.
From a technical perspective, the focus will be on scaling confidential AI capabilities across training, fine-tuning, inference, and agentic workflows while strengthening post-quantum deployments and the required migrations.
Read: Women in AI is a strategic advantage for UAE, says TII’s Dr Najwa Aaraj