Sovereign AI Inference Inside Confidential-Compute Enclaves.
Operator-held attestation keys exclude the cloud vendor from the trust path. 24 claims.
A sovereign AI inference workload runs inside a confidential-compute enclave on cloud infrastructure while excluding the cloud vendor from the trust path. The attestation key signing the enclave-launch quote, the wrapping key sealing the model weights, and the signing key authenticating each inference output are all held in an operator-controlled hardware identity element whose silicon root is independently procurable from the cloud vendor's supply chain. An attestation-chain validator refuses any quote whose root certificate authority resolves into the cloud vendor's identity. The composition produces a sovereign inference primitive in which the cloud vendor supplies only silicon, electricity, and bandwidth. Filed 4 May 2026 as GB2610418.2.