Microsoft Patents a Method to Shield Sensitive Data While Running AI Models
When an AI model processes your medical records or financial data, every layer of that model touches something private. Microsoft has filed a patent for a system that figures out which layers of an AI need heavy security protection and automatically routes each one to the right piece of hardware.
How Microsoft splits an AI's brain by data sensitivity
A doctor's office runs an AI that reads patient scans. The AI has dozens of internal steps, and only some of them actually touch raw patient data. The rest work on patterns so abstract that the original information is unrecoverable.
Microsoft's system looks at each step inside an AI model and asks: does this step handle truly sensitive input, or has the data been transformed enough that it's safe to run on less-guarded hardware? It then splits the model into groups of steps, called partitions, and assigns each group to the right computing hardware based on its security needs.
The goal is efficiency without sacrificing protection. Instead of running everything through expensive, heavily guarded hardware, you only do that for the parts of the AI that actually need it. The less sensitive layers can run on faster or cheaper components, and the whole system is matched automatically rather than by hand.
… partitioning the neural network architecture into a partitioned neural network architecture that includes partitions comprising one or more layers of the neural network architecture based on the security requirements of each of the layers to be operated on selected hardware components from among the computing hardware components …
Translation: The system splits the AI model into pieces matched to the security level of each hardware part.
How the system maps layers and assigns security hardware
The system starts by building a map of the neural network, a diagram of every layer in the AI model, how they connect, and how data flows from one to the next. It notes which layers feed into which, and which layers depend on the output of earlier ones.
Next, it checks what computing hardware is available and sorts those components by their security domain (think of a security domain as a walled zone of hardware that has specific protections against snooping or tampering, enforced by physical chips, firmware, or both).
Then it applies rules to each layer to decide how sensitive that layer's work is:
- Layers close to the input that receive raw sensitive data get the highest security classification.
- Layers that produce abstract features (like edge patterns in an image or statistical signals) get a lower classification, because you can't reverse-engineer the original data from them.
- The layer type and its position relative to the input layer both factor into that judgment.
Finally, the system partitions the model, grouping consecutive layers with similar security needs together, and assigns each group to a hardware component whose security level matches or exceeds what that group requires. The AI then runs across these partitioned components simultaneously or in sequence.
Each partition includes a subset of the layers of the neural network architecture and each partition has different security requirements based on whether the layers in the partition are receiving sensitive input data or operating on data from which features of the sensitive input data can be reconstructed.
Translation: Different parts of the AI get different security based on how close they are to sensitive user data.
What this means for AI running on sensitive data
AI is moving into hospitals, banks, and government agencies, places where the data being processed is regulated and genuinely sensitive. Right now, the common answer is to run the entire AI inside a secure enclave, which is slow and expensive. Microsoft's approach, if it works as described, means only the parts of the model that need heavy protection get it, while the rest run normally. That could make privacy-preserving AI meaningfully faster and cheaper to deploy.
Claim 1 covers the whole pipeline: mapping the network, reading available hardware, classifying each layer's security needs, and partitioning accordingly. That's a broad functional claim. If granted, it could give Microsoft a foundational position over automated, hardware-aware security partitioning for AI models, covering a wide range of enterprise AI deployments.
Microsoft's 13th filing we've tracked since August in our on-device AI privacy watchlist follows work on catching data leaks and shrinking AI models.
Claim 1 is written broadly. It doesn't require a specific type of AI model, a specific hardware platform, or a specific security standard. It covers the general act of analyzing a neural network's layers, reading the hardware available, and splitting the model by security requirements. That breadth is the interesting thing here.
A claim this wide, if granted, could touch almost any system that automatically partitions an AI model for deployment across mixed-security hardware. That's a significant portion of where enterprise AI is heading, especially as companies try to run large models partly on-device and partly in the cloud.
Microsoft's interest in confidential computing shows up across its Azure infrastructure work, and this patent fits that thread. The practical question is whether prior art in trusted execution environments and model segmentation will narrow the claim during examination. The concept is sensible; the grant likelihood depends on how the examiner reads the existing landscape.
There are more where this came from
We read every patent application Big Tech publishes and send you the ones worth knowing. Plain English, free, every week.
The drawings
12 drawing sheets from US 2026/0300489 A1 · click any drawing to enlarge
Want this weekly breakdown for a company we don't cover? Patentlyze Pro →
Be the first to weigh in