Analyst(s): Brad Shimmin
Publication Date: September 23, 2026
VAST Data unveiled VAST DataEnclave, an attestation-verified runtime embedded within the VAST DataEngine built on NVIDIA Confidential Computing. The capability resolves the standoff between enterprise data privacy and proprietary model protection, enabling closed-weight models to run directly against sensitive datasets in client-controlled infrastructure. By treating model weights as first-class system resources alongside enterprise data, the announcement advances the VAST AI Operating System from a high-performance data plane into an integrated model and agent orchestration platform.
What is Covered in this Article
- The introduction of VAST DataEnclave, an attestation-backed runtime integrating NVIDIA Confidential Computing across Hopper, Blackwell, and Rubin GPU platforms.
- The architectural transition from treating AI models as external compute applications to managing them as native, governed data assets within the VAST AI Operating System.
- Cryptographic verify-before-decrypt attestation, hardware-isolated execution, and independent dual-party key management.
- Ecosystem collaboration spanning frontier model providers, sovereign cloud operators, and server OEMs, including Cisco and Supermicro.
- Strategic 12-to-24-month market outlook examining enterprise key management friction and competitive pressure on enterprise storage incumbents.
The News: On September 22, 2026, VAST Data announced VAST DataEnclave, a confidential AI execution capability embedded natively inside the VAST DataEngine. Developed in collaboration with NVIDIA, DataEnclave builds on NVIDIA Confidential Computing to provide hardware-isolated execution across Hopper, Blackwell, and forthcoming Rubin GPU platforms. The architecture encrypts host CPU memory, GPU accelerator memory, and NVLink interconnect fabrics, enforcing cryptographic attestation before releasing decryption keys to run inference or autonomous agent workloads.
The solution targets the historical standoff in regulated industries—such as banking, healthcare, and defense—where sensitive enterprise datasets cannot leave secure boundaries and commercial model creators refuse to expose proprietary weights. Backed by more than twenty launch partners, including Cohere, CrowdStrike, Deepgram, Cisco, and Supermicro, VAST DataEnclave is available immediately in preview, with general commercial availability scheduled for the first quarter of 2027.
VAST DataEnclave Unifies Proprietary Models and Sensitive Enterprise Data
Analyst Take: The introduction of VAST DataEnclave addresses a persistent architectural flaw in modern accelerated computing: encryption historically stopped where the accelerator began. Conventional infrastructure protects weights and records while stored on flash or moving across network fabrics, but assets are decrypted into plaintext once loaded into shared GPU memory. By combining silicon-level memory encryption with cryptographic attestation, VAST closes that physical exposure window. According to the Futurum 1H 2026 Data Intelligence, Analytics, and Infrastructure Decision Maker Survey, 50% of data leaders cite security features as their primary evaluation criterion when selecting data management and analytics platforms. DataEnclave operationalizes this requirement by removing the mutual operational deadlock between corporate data custodians and commercial model providers.
Elevating Models to Native Operating System Resources
The central innovation in this release is the expansion of VAST’s broader AI Operating System strategy. Enterprise architectures have long enforced an arbitrary division: storage layers manage passive data files, while compute clusters treat machine learning models as transient application binaries. VAST inverts this model by bringing model weights directly into the logical data tier as first-class system resources. The operating system manages base weights, fine-tuned adapters, embeddings, and context stores under a unified governance plane. This setup allows the OS scheduler to dynamically route analytical requests to the appropriate model based on data sensitivity, cost-per-token limits, and latency requirements.
This tight coupling between data and execution proves essential as enterprises deploy autonomous systems via VAST AgentEngine. Autonomous agents read reference data and write updates across enterprise records without human intervention. To operate safely, these agents require hardware-isolated sandboxes, distinct non-human identities, and deterministic guardrails. Because attestation telemetry, key exchanges, and execution lifecycles record directly to an immutable audit trail within the VAST DataBase, compliance teams gain complete visibility into agent decisions without exposing underlying model parameters.
Silicon Attestation Resolves the Sovereign AI Impasse
DataEnclave enforces dual-party cryptographic sovereignty through independent Key Management System (KMS) integrations. Enterprises retain custody of their data decryption keys, model providers retain authority over their proprietary weight keys, and the hardware-isolated runtime prevents infrastructure operators, hypervisors, or adjacent tenants from accessing either asset during computation. This verify-before-decrypt sequence allows sovereign cloud providers like BUZZ HPC and Nscale to host frontier models locally without compromising national data residency mandates.
Competitive Pressures on Enterprise Infrastructure Rivals
Over the next two years, Futurum expects hardware-attested execution runtimes to redefine enterprise AI infrastructure standards. Traditional storage incumbents such as Dell, NetApp, and Pure Storage have spent recent quarters adding vector indexing and high-bandwidth NFS protocols to legacy storage arrays. VAST is looking to move past standard storage primitives by controlling the confidential execution boundary where data directly interacts with accelerator silicon.
Enterprise adoption faces real-world hurdles. Coordinating multi-party KMS handshakes across hybrid and air-gapped environments can create operational complexity for SecOps teams. Furthermore, with general commercial availability slated for Q1 2027, VAST is giving cloud hyperscalers a multi-quarter window to fortify their own confidential computing wrappers. Only time will tell whether the work done here by VAST and NVIDIA will put Infrastructure vendors lacking silicon-level attestation mechanisms at risk of being relegated to commodity bulk storage tiers beneath execution fabrics. Still, one thing is clear: VAST Data is on the right path by treating model weights as first-class system resources alongside enterprise data.
What to Watch
- OEM Appliance Turnkey Delivery: How rapidly Cisco and Supermicro deliver pre-integrated, factory-validated confidential AI appliances to enterprise channels ahead of the Q1 2027 release.
- Model Provider Licensing Shifts: Whether frontier model labs shift commercial pricing structures from token-metered cloud APIs toward customer-hosted confidential runtime licenses.
- Hyperscaler Confidentiality Responses: The velocity with which major hyperscalers expand native confidential AI enclaves to defend against workload repatriation to private data centers.
- SecOps Key Management Usability: How smoothly enterprise security teams navigate dual-party KMS orchestration across disconnected or sovereign environments.
- Agent Sandbox Adoption: Production uptake of VAST AgentEngine sandboxes enforcing policy boundaries over autonomous agents executing write-back tasks.
See the complete press release for this announcement on the VAST Data website.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Read the full Futurum Group Disclosure.
Other Insights from Futurum
Elevate AI Agent Quality With Active, Intelligent Context
Cloudera and Mistral AI Deliver Sovereign Private Intelligence
Autonomy Over Analytics: The Read-Write Decree Rewiring Enterprise Data Platforms
Author Information
Brad Shimmin is Vice President and Practice Lead, Data Intelligence, Analytics, & Infrastructure at Futurum. He provides strategic direction and market analysis to help organizations maximize their investments in data and analytics. Currently, Brad is focused on helping companies establish an AI-first data strategy.
With over 30 years of experience in enterprise IT and emerging technologies, Brad is a distinguished thought leader specializing in data, analytics, artificial intelligence, and enterprise software development. Consulting with Fortune 100 vendors, Brad specializes in industry thought leadership, worldwide market analysis, client development, and strategic advisory services.
Brad earned his Bachelor of Arts from Utah State University, where he graduated Magna Cum Laude. Brad lives in Longmeadow, MA, with his beautiful wife and far too many LEGO sets.

