← All speakers

Bio, Work & Ideas

Mike Bursell

Conference affiliation: Super Protocol · 2025

Mike Bursell is executive director of the Confidential Computing Consortium, co-founder of the open-source Enarx project, and a cybersecurity architect focused on protecting sensitive data and AI models while they are being used. His work replaces vague assurances about cloud security with hardware isolation, inspectable software, and cryptographic evidence of how computation actually happens.

After working at Citrix and Intel, Bursell joined Red Hat’s Office of the CTO in 2016 and became its chief security architect. In late 2018, he and fellow Red Hat architect Nathaniel McCallum began developing Enarx, a framework for running applications inside hardware-protected environments across processor architectures. They subsequently co-founded Profian in 2021 to commercialize confidential-computing technology, with Bursell serving as chief executive; Enarx remained an independently governed Linux Foundation project.

Bursell became the consortium’s executive director in 2023, following earlier work on its governance, technical initiatives, and attestation. His 2026 industry outlook connects confidential computing’s expansion to protected CPUs and GPUs, AI adoption, regulation, digital sovereignty, and distributed trust. He has also advised Super Protocol on confidential AI infrastructure.

His book Trust in Computer Systems and the Cloud examines security through risk, human behavior, and distributed systems. On his Alice, Eve and Bob blog, he argues that architectures cannot eliminate trust entirely: processors, firmware, verification services, and software suppliers remain dependencies that must be identified and constrained.

  • Protecting data during computation. Encryption typically protects information in storage and transit, but training, fine-tuning, and inference expose it during processing. Bursell champions trusted execution environments that isolate sensitive workloads from host operating systems, hypervisors, and infrastructure operators.
  • Cryptographic attestation. Hardware-backed measurements and signed certificates establish whether specified software is running on genuine protected hardware. His work on practical attestation explores certificate hierarchies and trusted loaders that make those checks operationally scalable.
  • Open-source confidential computing. Enarx makes the execution framework inspectable instead of replacing one opaque dependency with another, while supporting hardware choice across vendors.
  • Confidential AI collaboration. In his AI Engineer World’s Fair session, Bursell describes how healthcare providers, model developers, and computing operators can collaborate without exposing clinical datasets, proprietary model weights, or sensitive inputs. Attested execution also strengthens model provenance by connecting inference outputs to verified training environments and datasets.

Read the topics behind these talks

1 conference talk

References