Many times we’re talking about AI the wrong way.
Most of the public conversation still revolves around capability: how intelligent models are becoming, how quickly they’re improving, how many jobs they might automate, how close we are to AGI.
Inside organisations, that’s not usually the real discussion anymore. The real discussion is much quieter. It sounds more like this:
“Can we actually trust this enough to use it properly?”
Because the truth is, most enterprises already have access to powerful AI. That part arrived faster than many people expected.
What’s slowing adoption now isn’t raw capability. It’s uncertainty.
Uncertainty about:
- privacy
- governance
- regulation
- intellectual property
- data exposure
- accountability
- control
The numbers bear this out. Around 40% of organisations have already experienced an AI-related privacy incident, reinforcing the idea that AI governance is quickly becoming an operational issue rather than a theoretical one. At the same time, Gartner projects the Privacy-Enhancing Technologies market to exceed $25 billion by 2030, up from $2.8 billion in 2025 – a signal that the market itself is repricing the value of trust.
This is where one of the most important technology conversations of the next decade begins: Privacy-Enhancing Technologies.
Not exactly the sexiest name in tech, admittedly, but possibly one of the most important.
The Contradiction at the Centre of AI
AI becomes more useful the more context it has. That’s the entire game.
The better the data:
- the smarter the outputs
- the more accurate the predictions
- the more useful the automation
- the more valuable the system becomes
However, there’s an obvious problem hiding inside that model. The most valuable data organisations possess is usually the data they’re least comfortable exposing.
- Customer records
- Legal files
- Healthcare information
- Financial transactions
- Internal strategy documents
- Sensitive operational intelligence
In other words, the data AI needs most is often the data organisations are most afraid to share. That creates a tension most companies still haven’t fully resolved – because modern AI ecosystems aren’t neatly self-contained anymore.
They’re connected: cloud platforms, third-party models, copilots, APIs, external tooling, distributed teams, shared environments.
The old “protect the perimeter” security model starts looking increasingly fragile in that world. And I think many organisations know it.
The EU AI Act, fully in force from August 2026, makes this tension a compliance reality — mandating risk assessments, human oversight, and traceability for high-risk AI systems. Organisations that haven’t embedded governance into their architecture aren’t just taking a strategic risk. They’re taking a regulatory one.
We’re Entering the Era of “Conditional Trust”
For many years, most technology adoption operated on a kind of implicit trust. Not necessarily because organisations fully understood how platforms handled data, algorithms, or decision-making, but because the value exchange felt worthwhile. Convenience often outweighed transparency.
That era is ending. AI is simply too invasive operationally to rely on implicit trust alone.
- When employees are pasting strategic documents into AI systems
- When AI is embedded into healthcare workflows
- When governments are using machine learning for public services
- When copilots are integrated into financial and legal processes
…privacy stops being a compliance issue and starts becoming a strategic issue.
As Quaylogic’s Data Culture in the Age of AI research highlights, trust is the currency of AI adoption. If employees don’t trust the data, they override it. If customers don’t trust AI decisions, they disengage. If regulators don’t trust governance, they intervene. The constraint on AI value isn’t computational sophistication, it’s cultural maturity and architectural trust.
That’s why Privacy-Enhancing Technologies matter so much – because they represent a shift away from:
“Trust us with your data.”
toward:
“The system is designed to minimise exposure in the first place.”
What PETs Actually Are and Why They Matter Now
Despite the slightly academic name, the idea behind PETs is actually very simple: finding ways to use data without unnecessarily exposing it. Different technologies approach that challenge differently.
- Federated learning allows AI models to train across distributed datasets without centralising the raw information itself. A compelling real-world example: the MELLODDY project enabled 10 pharmaceutical firms to collaboratively train a shared drug discovery model while each company’s proprietary data never left its own environment.
- Differential privacy helps protect individual identities while still allowing meaningful analysis at scale. Apple already deploys it across hundreds of millions of iOS devices — demonstrating that privacy-preserving analytics can operate at enterprise and consumer scale simultaneously.
- Homomorphic encryption, one of the more fascinating developments in the space, makes it possible to perform computations on encrypted data without first decrypting it.
- Secure multi-party computation (MPC) creates ways for organisations to collaborate analytically without revealing their underlying datasets to one another.
- Confidential computing could become one of the most important foundations for trusted AI. Instead of exposing sensitive data during processing, confidential computing protects data even while it’s actively being used helping organisations scale AI while strengthening governance, privacy, and control.

Figure: Privacy-Enhancing Technologies Key Components
What’s significant is the market trajectory. Over 60% of large enterprises are expected to have integrated at least one PET solution by the end of 2025, with Gartner predicting that figure rises to 60% of large enterprises deploying PETs in production by 2028. These technologies are moving from research and pilot into core enterprise infrastructure.
What’s interesting is that these technologies don’t just strengthen security. They potentially change the economics of trust. The less exposure required between participants, the easier collaboration becomes — and in an AI-driven economy, that could become enormously important.
Privacy Is Moving Into the Architecture Itself
What’s interesting about technologies like federated learning, differential privacy, homomorphic encryption, and secure multi-party computation is that they challenge an old assumption in computing: that data has to be fully visible to be useful.
That assumption shaped the entire digital economy.
- Collect everything
- Centralise everything
- Store everything
- Analyse everything
Now AI is beginning to expose the weaknesses in that model. Particularly when organisations want to collaborate without surrendering sensitive information.
PETs change the equation. They create ways to:
- train models without pooling raw data
- analyse encrypted information
- collaborate without fully exposing inputs
- and reduce the amount of trust required between parties
That last point matters more than people realise because the future of AI probably isn’t one giant centralised intelligence. It’s interconnected systems operating across fragmented ecosystems, jurisdictions, and organisations. Those systems will only work if trust becomes scalable.
Governments Know This Too
A lot of governments are still trying to figure out what AI regulation should even look like. The EU AI Act formalises risk classification, human oversight and accountability. The 2026 Delhi Declaration reinforced the global commitment to human-centred, trustworthy AI. UK regulators (FCA, PRA) emphasise model risk and senior management accountability. The US CFPB requires explainable, non-discriminatory AI in credit decisions.
Underneath all the policy debates is the same underlying concern:
How do you unlock the economic value of AI without losing control of data, privacy, and societal trust?
That’s a much harder problem than building bigger models.
I suspect it’s why conversations around sovereign AI, confidential computing, and privacy-preserving architectures are accelerating so quickly. Eventually governments, enterprises, and citizens all arrive at the same conclusion:
AI cannot become foundational infrastructure if people fundamentally distrust how it handles information.
From Philosophy to Practice: Governance That Scales
The challenge most organisations face isn’t a lack of policy. It’s the gap between policy and operational reality. Governance frameworks that live in documents but don’t run in systems don’t protect anyone.
This is why Quaylogic has developed an approach to AI governance that embeds trust at every stage of the lifecycle not just at the point of review.
At Quaylogic, we have operationalised this philosophy into a five-stage Trust Continuum Framework:
- Design-Time Governance – Privacy, ethics and accountability embedded from the earliest architectural decisions, not retrofitted later.
- Continuous Monitoring – Ongoing oversight of model behaviour, data drift and emerging risks across the AI lifecycle.
- Human-in-the-Loop Escalation – Defined escalation pathways that keep human judgement at the centre of consequential decisions.
- Cross-Functional Ownership – Governance responsibility distributed across data, legal, technology and business functions — not siloed in IT.
- Policy-to-Implementation Traceability – A clear, auditable chain from regulatory obligation to operational control.
👉 Trust is not a gate at the end. It is a system of practices across the entire lifecycle.

Figure: AI Goverance that Scales
This framework matters because it reflects a fundamental shift in how governance needs to work in an AI-native environment. You cannot review your way to trusted AI at scale. You have to design it in.
The Companies That Win May Not Be the Loudest
Right now the AI market still rewards spectacle:
- Bigger models
- Faster products
- More automation
- More disruption
In the long term, I’m not convinced the winners will simply be the companies with the most powerful systems.
The winners will be the organisations that become trusted stewards of intelligence.
The ones that can say:
- your data is protected
- your information remains governed
- your AI interactions are auditable
- your privacy isn’t being casually traded for convenience
That becomes incredibly valuable in a world where AI is embedded everywhere. And eventually every organisation deploying AI faces the same question:
“How much trust are people expected to give us?”
Privacy-Enhancing Technologies are interesting because they reduce the need for blind trust altogether. In the AI era, that might become one of the most important competitive advantages of all.
Ready to build AI governance that scales?🚀
At Quaylogic, we help organisations design and embed AI governance from the inside out not as a compliance bolt-on, but as a strategic capability. Using our Trust Continuum Framework, we work with data and technology leaders to move from implicit trust to trust by design.
Explore our AI Governance solutions or speak to our team about assessing your organisation’s AI governance maturity.
About the Author
Geoff Smith, Partner, Innovation, Privacy & Trust, Quaylogic
Professor Geoff Smith has led commercially focused data privacy and empowerment functions for more than 30 years. He is a Visiting Professor at Loughborough University focusing on Digital Ethics and Trust Economies, and an ethical advisor on the UK Government National Digital Twin Programme.

