NEAR AI Expands Confidential Inference Into User-Owned Stack

Silhouette of a user connected to a shielded AI brain inside secure hardware, data streams flow into private, user-owned processing in calm tones.

NEAR is broadening the positioning of its artificial-intelligence infrastructure from private model execution toward what it calls “user-owned intelligence,” combining confidential inference with secure agents and verifiable execution. According to NEAR AI’s official platform overview, supported open-weight models run inside hardware-isolated environments using Intel TDX and NVIDIA confidential-computing infrastructure. The core privacy proposition is that prompts can be processed without exposing their plaintext to the infrastructure operator outside the trusted execution environment.

The broader “user-owned” framing does not replace confidential inference with a new protocol. Instead, it places private model execution inside a larger stack that includes IronClaw agents, attestation, cross-chain execution and user-controlled credentials. Confidential inference remains the technical foundation, while user-owned intelligence is the product thesis built around who controls data, execution and agent permissions. NEAR’s current site identifies Venice AI, Brave, Abound and the Government of Bermuda among organizations using parts of that infrastructure.

Confidential Inference Moves Into Production Integrations

Venice provides one of the clearest live examples. The AI platform integrated NEAR AI in March to offer private text and image inference in which prompts are decrypted only inside a TEE and returned with cryptographic evidence about the execution environment. The integration demonstrates production use of confidential inference rather than merely the availability of secure-compute infrastructure. NEAR’s architecture around that model was previously reflected in its deployment of confidential inference with hardware-backed attestations.

Brave uses a similar model more narrowly. Brave introduced NEAR AI-backed confidential DeepSeek inference inside Brave Nightly, its testing channel, allowing the browser to verify that execution occurred inside the expected NVIDIA confidential-computing environment. That is a genuine user-facing implementation, but it should not be described as universal deployment across Brave’s entire release user base. The distinction matters because experimental availability and broad production adoption are separate stages.

Abound extends the stack into financial automation. The Times of India Group-backed service is piloting IronClaw agents for cross-border financial workflows, including account monitoring and remittances triggered by user-defined conditions. Here, privacy is only one part of the system: credential isolation, bounded agent permissions and financial execution become equally important once the model can act rather than merely answer questions. That broader architecture mirrors NEAR’s expansion of AI agents around Intents and cross-chain execution.

The Government of Bermuda provides a different adoption signal. Bermuda has publicly confirmed NEAR Foundation support for AI-powered public services, while NEAR says the partnership begins with confidential infrastructure for handling sensitive government information. Government participation demonstrates institutional interest, but neither side has published enough workload or usage data to establish the scale of the deployment.

User-Owned AI Still Depends on Hardware Trust

NEAR AI recently added Intel Trust Authority as an independent verifier of its TDX attestation evidence. Instead of relying solely on the infrastructure operator to verify its own secure environment, the system can use a separate authority to validate whether the workload ran inside expected hardware. That reduces one trust dependency, but it does not eliminate the underlying trust boundary around processors, firmware, enclave implementations and attestation roots.

This distinction is central to confidential computing. Prompts are not encrypted in a way that prevents all decryption everywhere; they are decrypted inside the protected execution environment so the model can process them. The security claim is isolation from the surrounding host and operator, not that plaintext never exists inside hardware. That same boundary has become increasingly important as NEAR AI expands confidential model access across multiple execution paths, because not every externally routed model carries identical attestation guarantees.

NEAR’s adoption claims should therefore be read at the integration level. Venice has a live private-inference option, Brave is testing the technology through Nightly, Abound is deploying agents into cross-border financial workflows, and Bermuda has confirmed government collaboration. Those deployments show that NEAR AI has moved beyond research infrastructure, but they do not yet quantify sustained inference volume, recurring enterprise usage or the economic scale of the platform. The “user-owned intelligence” thesis is becoming more concrete; its durability will depend on whether those integrations develop into recurring workloads rather than remaining isolated implementations.

Find Us on Socials

Join Our
Newsletter

Subscribe to get latest crypto news!

Latest News

You may also like

The Chain Observer
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.