Product Updates Google DeepMind Blog

Advancing Private AI Compute with secure, server-side memory

GooglePrivate AI Computesecure enclavesprivacy

Google says AI is becoming more capable and intuitive — remembering what matters, understanding context, and acting on a user's direction — and that privacy and trust are core to making that possible as assistants provide more continuous help across devices. The update addresses a longstanding dilemma: how to give an assistant long-term continuity across devices while upholding the strict privacy standards typically limited to on-device processing. On-device processing has historically been the privacy gold standard, but frontier AI models often need far more compute than any single device can provide, so bringing advanced AI to personal assistants requires tapping cloud power without weakening data protection. Google previously introduced Private AI Compute to process complex tasks in hardware-isolated cloud enclaves, but that technology — like similar industry solutions — was strictly stateless, wiping all context the moment a task ended. Workarounds such as having AI save lists of personal facts and preferences are not enough to support the rich, continuous experiences users expect.

The new capability adds a persistent memory layer that functions like a secure digital vault in the cloud. Information needed to assist the user is sealed in dedicated, encrypted storage, while the cryptographic keys required to unlock it are held exclusively on the user's personal devices — making the data inaccessible to anyone else, including Google. When a model needs to access information, an authenticated, end-to-end encrypted channel connects the device to a protected, isolated cloud environment. That secure enclave temporarily decrypts the data in isolated memory to handle the request, saves any new context, and immediately re-encrypts it — keeping information private as if it never left the device.

The architecture combines three elements: hardware-enforced secure enclaves, encrypted channels, and per-user databases shielded by device-derived encryption keys. Together, Google says, these ensure data stays fully private and under the user's control, resolving the tension between cloud-scale AI capability and on-device-grade privacy for continuous, cross-device personal assistance.

Read original →

← Back to home