NEAR AI: User-Owned Agents and Private Compute
NEAR AI is the artificial intelligence arm of NEAR Protocol, building confidential inference infrastructure and agent tooling on the argument that AI running on someone else's servers, reading your data in plaintext, is a bad default. Its flagship products, NEAR AI Cloud and Private Chat, run models inside hardware enclaves so the operator cannot see the prompt, the output, or the user.
The founder of the blockchain co-wrote the paper that made large language models possible. That is unusual enough to be worth taking seriously.
The Company That Became a Blockchain and Came Back
Illia Polosukhin was one of eight authors on "Attention Is All You Need", the 2017 Google Research paper introducing the transformer architecture underneath GPT, Claude, Gemini, and effectively every frontier model in production. He left Google that year to start NEAR.ai with Alexander Skidanov, working on program synthesis: teaching machines to write code from plain-language descriptions.
Paying data contributors across dozens of countries broke on traditional banking rails. The founders went looking for a blockchain that could handle small international payments, found the developer experience unworkable, and built one instead. NEAR mainnet launched in April 2020, and for five years the AI thread sat dormant while the team solved sharding.
It came back in force in late 2025, when the project restructured its AI work under NEAR AI and shipped products aimed at a specific gap: nobody had built inference you could use without trusting the operator.
What NEAR AI Cloud Actually Runs
NEAR AI Cloud provides model inference inside trusted execution environments, using Intel TDX on the CPU side and NVIDIA confidential computing on the GPU side. The launch announcement for AI Cloud and Private Chat describes end-to-end encrypted deployments where the model provider cannot read what passes through.
Private Chat is the consumer-facing version: a chat interface where prompts and responses stay encrypted through the enclave and are never visible to NEAR or to the infrastructure operator. For anyone who has hesitated before pasting a contract, a medical question, or proprietary code into a hosted model, the value is obvious.
The same hardware approach powers Confidential Intents on the trading side, where a private shard backed by TEEs hides swap size, direction, and timing from the public chain. Confidential TVL crossed $30 million during Q2 2026 with 42% of near.com swap volume running privately by default, according to Nansen. One trust model, two products.
Worth stating plainly: TEE-based privacy is hardware trust rather than mathematical proof. Enclave side-channel attacks are an active research area, and the assurance you get is Intel's and NVIDIA's rather than a zero-knowledge circuit's. The trade buys speed and usability that ZK systems have struggled to match, and it is a trade rather than a free upgrade.
Why Agents Need an Account Model Like NEAR's
Autonomous software transacting on its own behalf breaks most blockchain account designs. An agent needs spending authority without holding the keys to everything you own, needs to pay fees in whatever asset it happens to have, and needs to settle across chains without a human approving each bridge step.
NEAR's account model handles the first case natively. Function-call access keys grant permission to interact with one specific contract up to a fixed gas allowance, and they can be revoked without touching the account, a property that also shapes how NEAR wallets handle session permissions for ordinary users. Delegating scoped authority to an agent is the same primitive applications already use.
The gas relayer handles the second: a third party can sponsor transaction fees, so an agent does not need a NEAR balance to act. And NEAR Intents handles the third, letting an agent state a desired outcome and have solvers execute it across 34 chains with atomic settlement.
Speed matters here too. The SPICE upgrade targets 200 millisecond blocks and confirmation near 0.4 seconds, which is the difference between agent-to-agent negotiation feeling instant and feeling like a batch job. That focus separates NEAR from general-purpose throughput races, and the architectural contrast is covered in more depth in NEAR against Solana.
What Is Live Versus What Is Roadmap
Separating shipped products from stated intentions is the whole exercise with AI narratives in crypto.
| Component | Status as of August 2026 |
|---|---|
| NEAR AI Cloud, confidential inference | Live since late 2025 |
| Private Chat | Live |
| Confidential Intents | Live, over $30 million TVL |
| Multimodal model support | Shipped through H1 2026 |
| Private portable memory | Research and roadmap |
| Decentralized confidential machine learning | Roadmap |
The live column is more substantial than most AI-adjacent crypto projects can show, and the revenue question stays open. Inference payments have to become real volume before any of this reaches the token, and the mechanism for that is the network's fee burn and Intents buyback, described in NEAR's tokenomics. Validators securing that traffic earn from the same issuance pool covered in the guide to staking NEAR.
Frequently Asked Questions
Is NEAR an AI project or a blockchain?
Both, and the sequence matters. NEAR started as an AI company in 2017, built a layer 1 blockchain to solve its own payments problem, and returned to AI in 2025 with infrastructure for confidential inference and agent settlement. On-chain activity today is still dominated by wallets, DeFi, and cross-chain swaps rather than AI workloads.
What is NEAR AI Cloud?
NEAR AI Cloud is a confidential inference service that runs models inside trusted execution environments, so prompts and outputs stay encrypted from the infrastructure operator. It uses Intel TDX and NVIDIA confidential computing, and it powers NEAR Private Chat, a consumer chat product built on the same guarantees.
Do AI agents on NEAR need to hold NEAR tokens?
No. NEAR's multichain gas relayer lets a third party sponsor transaction fees, so an agent can operate without a NEAR balance, and function-call access keys let it act within a scoped permission rather than holding full account control.
The Case for Owning the Model You Talk To
NEAR AI is a bet that privacy becomes a purchase criterion for AI rather than a preference. Enterprises handling regulated data, developers with proprietary code, and individuals who would rather their conversations not become training material are all constituencies that exist today and are currently served by promises in a terms of service document instead of by hardware guarantees.
Whether that bet reaches the token is a separate question from whether the technology works. The products are live and the trust model is coherent, and confidential inference has to attract paying workloads at scale before it changes NEAR's fundamentals, which is the same conditional sitting underneath most of NEAR's price outlook.
If you want exposure while that plays out, NEAR spot pairs hold a simple long, NEAR perpetual futures trade both sides of the narrative, and Crypto in a Minute covers the rest of the AI and infrastructure field.
