Fortanix Confidential AI Protects Proprietary Model IP and Data for Secure AI Inference in Enterprise AI Factories.

Learn More

AI Inference

What is the SOC 2 requirement for AI inference?

SOC 2 doesn’t have specific technical requirements for AI inference as a distinct category. But it defines trust service criteria, and AI inference workloads should account for those criteria in the same way any other data processing service would. 

When it comes to AI inference, you’ll find the trust service criteria of most importance to be Security (covering access controls and the like), Confidentiality for the protection of sensitive data over its entire lifecycle, and Availability for system uptime and performance. 

Take a token factory undergoing a SOC 2 AI compliance audit. The auditor is there to see if the controls put in place to satisfy those criteria are soundly designed; a Type II report will go further and tell you if they were effective over the course of the audit period. In essence, SOC 2 is about holding an organization to what it says it does with data and verifying that its controls live up to that description. But don’t expect cryptographic evidence from a SOC 2 audit that your data was shielded at the hardware level during processing. For that reason, the best way to handle compliance is to have the token factory operator’s SOC 2 Type II certification backed by confidential computing infrastructure for hardware-level protection, which is something the SOC 2 can point to as a control that has been put in place.

Fortanix-logo

4.6

star-ratingsgartner-logo

As of January 2026

SOCISOPCI DSS CompliantFIPSGartner Logo

US

Europe

India

Singapore

4500 Great America Parkway, Ste. 270
Santa Clara, CA 95054

+1 408-214 - 4760|info@fortanix.com

High Tech Campus 5,
5656 AE Eindhoven, The Netherlands

+31850608282

UrbanVault 460,First Floor,C S TOWERS,17th Cross Rd, 4th Sector,HSR Layout, Bengaluru,Karnataka 560102

+91 080-41749241

T30 Cecil St. #19-08 Prudential Tower,Singapore 049712