Skip to content Skip to footer

Building Trust in the Age of Machines: Dr. Chen Feng on Confidential AI, TEE Tech and the Real-World Future of Autonomous Agents

Feng recently joined co-hosts Megan Nilsson and Lisa Loud on the Spilling the TEE podcast to explain why confidential computing, Trusted Execution Environments (TEEs), and Web3 incentives could be the cornerstones of a safer, AI-powered world.

In the crowded conversation around AI, few voices are as grounded, and as visionary, as Chen Feng. An associate professor at the University of British Columbia and Head of Research at Autonomys, Feng is a rare breed: an academic who speaks the language of builders and a builder who sees clearly where the future is headed. That future, he believes, is private, decentralized, and governed by intelligent agents who work for us, not the other way around.

Castles, not silos: why TEEs matter

Feng opens with a metaphor: TEEs are castles. They’re secure, hardened zones within untrusted territory, safe spaces for code and data to run with privacy and integrity, even when the surrounding system can’t be trusted.

“If you want to understand TEEs,” Feng says, “ask what problem they solve. It’s about running software on someone else’s computer, with guarantees.”

In other words: in a decentralized future, where compute resources are scattered across the globe, TEEs offer a way to compute safely on hostile ground.

Compared to other privacy tech like multi-party computation (MPC), homomorphic encryption (FHE), or zero-knowledge proofs (ZKPs), TEEs offer real-world performance now.

“If we wait for some of the cryptographic approaches to catch up,” he notes wryly, “we may need to wait until the end of the century.”

That performance isn’t just theoretical. TEEs can reduce the privacy overhead to as little as 5%, Feng explains. In GPU-heavy AI workloads, that tradeoff is not only acceptable, it’s optimal.

Why Autonomys chose TEEs

Autonomys’ decision to integrate TEE technology into its infrastructure is both practical and philosophical. TEEs provide what Web3 needs: trust without centralization. But they also offer something AI urgently needs: confidentiality.

Modern AI requires vast amounts of personal data, sensitive model architectures, and secure inference. Without privacy, AI can’t be trusted. Without trust, it can’t scale. TEEs, Feng says, are the most mature answer today.

Yet he’s quick to note TEEs aren’t perfect. Side-channel attacks, hardware dependencies, and limited memory remain challenges. But the academic community is hard at work. Open-source TEE hardware is emerging, and hybrid models that combine TEEs with MPC or ZKPs are already in research and in some cases, production. “It’s not about picking one solution,” he says. “It’s about combining them.”

The rise of AI agents, and why privacy must come first

Looking ahead, Feng sees a new breed of blockchain user: AI agents. Billions of them. Performing tasks, negotiating deals, interacting with humans and each other. But AI agents need privacy too.

“If AI agents are users,” Feng says, “they deserve confidentiality.”

But scaling privacy to billions of agents is a major challenge. TEEs, paired with powerful GPUs like NVIDIA’s H100, offer a path forward. Autonomys is already building decentralized coordination tools to help networks handle that scale.

He also proposes a novel solution: assign TEEs to app operators, not directly to each agent. “It’s about managing privacy at the infrastructure layer. That way we don’t overwhelm the system.”

This model, he believes, will not only scale, it will unlock fair compensation, a vital feature of decentralized AI.

“If I share my data, I take a risk. That risk should be rewarded. That’s the promise of Web3.”

The healthcare test case: AI doctors

To demonstrate what’s possible, Feng shares a real-world pilot project: decentralized AI doctors. In British Columbia, where 20% of residents don’t have access to a family doctor, AI can fill the gap. “We’re not replacing doctors. We’re showing what’s technically feasible.”

With patient data kept confidential via TEEs and models stored on-chain, users get access, privacy, and affordability. “It’s a pilot,” Feng cautions, “but it shows the way forward. Prove the tech first. Then fight the regulation.”

The bigger vision: decentralized AI as a safety net for humanity

Perhaps the most arresting part of the conversation is Feng’s closing thought: decentralized AI may be our best shot at safe superintelligence.

“If only two or three companies control artificial superintelligence, that’s dangerous,” he says. “We need decentralized alternatives. And we need to attract the best developers to build them.”

That shift is already happening. Open-source AI models are closing the gap with proprietary giants. Compensation mechanisms in Web3 make it possible for talented researchers to thrive outside corporate labs. And TEEs provide the trust layer to make it all secure.

“We still have time,” Feng says, “but not much. The window is open.”

Homework for humanity

Chen Feng ends like a professor—because he is one—he offers homework: read the research, think big, and act now.

“We can build a better AI future. One that’s private, decentralized, and fair. But only if we start today.”