Lightning
Your AI Assistant Shouldn't Trust You: Building Verifiable AI Systems with Gemini and Confidential Computing
Large Language Models are increasingly being used to analyse confidential enterprise documents, but most AI applications still assume the infrastructure and even the developer can be trusted with sensitive data. In this session, I'll demonstrate how to build a verifiable AI system using Gemini, Google Cloud Confidential Space, Cloud KMS, Workload Identity Federation, and the Model Context Protocol (MCP). Instead of focusing on another Retrieval-Augmented Generation (RAG) chatbot, we'll build an AI assistant that proves why its answers should be trusted. The demo shows how confidential documents remain encrypted until a cryptographically attested Confidential Space workload is verified, preventing even the application developer from accessing the plaintext. Every response is grounded in retrieved evidence, accompanied by citations, checked for unsupported claims, and recorded in a tamper-evident audit trail. I'll also demonstrate how MCP can connect the assistant to GitHub so it can compare governance policies against implementation and identify potential gaps. Attendees will leave with practical patterns for building trustworthy AI applications using Gemini and Google Cloud services, including confidential computing, secure identity, evidence-backed retrieval, and verifiable AI workflows that can be adapted to enterprise systems.




