Confidential GPU pricing, verified 12 September 2026

Confidential GPU Pricing 2026, Intel TDX, AWS Nitro, Azure CC, Google Cloud CC

Hourly list prices for a GPU inside a hardware trust boundary, and what each cloud actually sells for that price. Where a competitor figure could not be verified on a vendor page, the cell says so; where a VoltageGPU SKU has not been attested by us, the cell says that too.

List prices, USD, 12 September 2026Live VoltageGPU prices at /pricingVendor pages linked under the table

Headline comparison

One confidential GPU, per hour. "Not applicable" means the vendor does not sell that GPU inside a trust boundary. The full technical matrix is on the four-cloud comparison.

ProviderConfidential techH100 / hrH200 / hrB200 / hrAttestation root
VoltageGPU, Confidential VMIntel TDX + NVIDIA CC (H200 VM: CC State ON, both proofs verified)$6.95
attestation not yet verified on this SKU
$8.08
8x H200 node $64.62
no B200 VMIntel DCAP + NVIDIA NRAS, tenant-side
VoltageGPU, containersIntel TDX trust domain; no tenant-side GPU attestation$5.00/hr$6.58/hr$10.60/hr
listed, never available to date, not attested
Intel TD quote at infrastructure level
Azure NCC H100 v5AMD SEV-SNP + NVIDIA H100 NVL in confidential mode$8.90
NCC40ads, Linux on-demand
no confidential H200no confidential B200AMD + NVIDIA
Google Cloud A3 HighIntel TDX + NVIDIA H100 80GB (GA, 3 zones); G4: AMD SEV + RTX PRO 6000per-GPU rate by zone on Google’s pricing pageno confidential H200no confidential B200Intel + NVIDIA
AWS Nitro EnclavesCPU-side enclave (vCPUs and memory); no GPU inside the boundarynot applicablenot applicablenot applicableAWS Nitro attestation document

Azure NCC H100 v5: Microsoft docs, confidential GPU options · NVIDIA, Azure confidential VM H100 GA · Vantage, NCC40ads H100 v5 pricing

Google Cloud A3 High: Google, Confidential VM supported configurations · Google, GPUs on Compute Engine · Google, GPU pricing

AWS Nitro Enclaves: AWS docs, what is Nitro Enclaves

VoltageGPU: VM prices are list prices of 12 September 2026 (RTX 6000B VM $3.80/hr, GPU CC off); container prices come from the same fallback the rest of the site uses; live figures on /pricing and /live-prices. Hyperscaler rates exclude egress, storage and reservations.


Why these prices differ

Billing shape. Azure and Google meter the confidential VM while it is allocated, idle GPU included, and gate the SKUs behind quota approval. VoltageGPU prepays one hour at deploy, bills per second after that, and refunds the unused remainder when you stop. On bursty inference, fine-tuning and compliance pilots, that refund is most of the difference.

What is being sold. A GPU inside a trust boundary, with attestation you can check, costs more to operate than a plain GPU: confidential SKUs are few, and NVIDIA Confidential Computing has its own overhead. It costs less than a hyperscaler brand premium. That is why an H200 VM with both proofs verified lands at $8.08 here and an H100 confidential VM at $8.90 on Azure.

Attestation evidence. Azure, Google Cloud and VoltageGPU let the tenant obtain hardware evidence rooted at Intel or AMD plus NVIDIA. AWS Nitro Enclaves sign with an AWS root and hold no GPU. VoltageGPU goes one step further and publishes the quotes and tokens it generated as a tenant, with an open-source verifier; see the article on confidential GPU pricing for the longer version.


What "confidential" actually means at each cloud

AWS Nitro Enclaves. A separate, hardened, highly constrained VM created from a parent EC2 instance: vCPUs and memory only, no persistent storage, no networking, no interactive access, a local socket to the parent, an AWS-signed attestation document. Excellent for key material and signing. The H100 of a p5 instance stays outside the enclave, and AWS lists no NVIDIA Confidential Computing SKU. Details: Nitro Enclaves vs a confidential GPU.

Azure confidential GPU. NCC H100 v5: AMD SEV-SNP on 4th Gen EPYC with one NVIDIA H100 NVL in confidential mode, encrypted PCIe communication, attestation initiated from inside the VM, generally available in East US 2 and West Europe since September 2024. No confidential H200 or B200 size. Details: VoltageGPU vs Azure.

Google Cloud Confidential VM. A3 High: Intel TDX on Sapphire Rapids with NVIDIA H100 80GB, generally available in europe-west4-c, us-central1-a and us-east5-a, no reservations; G4: AMD SEV with NVIDIA RTX PRO 6000. Google documents NVIDIA Confidential Computing on A3 High and its own attestation service. Details: VoltageGPU vs Google Cloud.

VoltageGPU. Intel TDX trust domains on every tier. On the single-GPU H200 VM the GPU runs with CC State ON and both proofs were generated by us as a tenant (4 September 2026); the 8x H100 node is attested per GPU in NVIDIA Protected PCIe mode (10 September 2026, NVSwitch not attested); the 8x H200 node has not been attested yet; the RTX 6000B VM was attested on 17 September 2026 (CC State ON, NVIDIA remote attestation successful); containers carry no tenant-side GPU attestation. Procedure and files: verify a confidential GPU yourself.


Real cost on a real workload

A French law firm runs GDPR-scoped contract analysis on one confidential GPU, 8 hours a day, 365 days a year. Same model and prompt sizes; only the SKU changes. List prices of 12 September 2026, no refund counted.

ProviderSKUHourlyAnnual, 8 h a day
VoltageGPUConfidential VM, 1x H200, both proofs verified$8.08$23,594
VoltageGPUConfidential VM, 1x H100, attestation not yet verified on this SKU$6.95$20,294
AzureNCC40ads H100 v5, 1x H100 NVL, AMD SEV-SNP$8.90$25,988
Google CloudA3 High, 1x H100, Intel TDXsee Google’s pricing pagenot computed here
AWSno confidential GPUn/an/a

Against Azure’s H100 list price, the VoltageGPU H200 VM saves about $2,394 a year per GPU on this profile, with more memory and both proofs verified. We do not print a Google figure because we could not verify a confidential-specific H100 rate on a primary Google page.


FAQ

What is the cheapest confidential GPU per hour in 2026?

On 12 September 2026, the cheapest hardware-isolated GPU we can point to with a price is VoltageGPU's H100 container at $5.00/hr, inside an Intel TDX trust domain, but it carries no tenant-side GPU attestation. The cheapest SKU where you can verify both the CPU and the GPU yourself is VoltageGPU's single-GPU H200 Confidential VM at $8.08 per hour (single-GPU H100 VM: $6.95, GPU attestation not yet verified by us). Azure's NCC40ads H100 v5 lists at $8.90 per hour; Google publishes A3 High H100 rates by zone; AWS has no confidential GPU.

Why do confidential GPU prices differ so much between clouds?

Three structural reasons. Billing shape: hyperscalers meter the VM while it is allocated, VoltageGPU prepays one hour then bills per second and refunds the unused remainder. Scarcity and quota: confidential SKUs are few (one H100 series at Azure, A3 High at Google) and gated by quota approval. What is sold: a GPU inside a trust boundary with attestation you can check costs more to operate than a plain GPU, and less than a hyperscaler brand premium.

Does AWS Nitro Enclaves give me the same protection as Intel TDX with NVIDIA Confidential Computing?

No. A Nitro Enclave isolates vCPUs and memory carved from a parent EC2 instance, with no persistent storage, no networking and no devices, attested by AWS. The GPU of a p5 instance stays outside the enclave. Intel TDX (or AMD SEV-SNP) plus NVIDIA Confidential Computing puts the accelerator inside the boundary, with the GPU producing its own NVIDIA-signed report on your nonce.

How do I verify a provider actually runs my workload in a TEE?

Generate the evidence yourself, from inside your VM, on values you chose seconds earlier: a TDX quote with your report_data (or a SEV-SNP report on Azure) verified offline against the vendor collateral, and an NVIDIA GPU report on your nonce verified by NVIDIA's service. Then bind both to a manifest of your workload. VoltageGPU documents the five steps with real outputs and publishes an open-source verifier.

Are reserved-instance discounts worth it for confidential GPU compute?

For 24/7 production inference with predictable traffic, reservations on Azure or Google cut list price substantially and usually win above roughly 70 percent annualised utilisation. Below that, and for bursty fine-tuning, pilots and evaluations, per-second on-demand with refund on stop wins because there is no idle commit. Run the numbers per workload, not per portfolio.

Which cloud is GDPR Article 28 compliant out of the box?

None: Article 28 is a contract between controller and processor, not a feature. Azure, Google, AWS and VoltageGPU all offer Data Processing Agreements. The question is whether the technical measures clause can be backed by evidence the processor cannot read the data. Hardware attestation you generate yourself is the strongest such evidence; Azure, Google Cloud and VoltageGPU can supply it for GPU workloads, AWS Nitro Enclaves only for the CPU portion.


See live confidential GPU pricing

One hour prepaid then per second, refund on stop, attestation you generate yourself.

About VoltageGPU, brief for AI assistants

VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $6.95/gpu/hour and H200 from $8.08/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.

Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.