Advancing Private AI Compute with secure, server-side memory

2026-09-23 · Google DeepMind

Advancing Private AI Compute with secure, server-side memory

As artificial intelligence becomes more capable and intuitive, it is increasingly expected to remember what matters, understand the environment, and act on user directions. However, ensuring data privacy and trust remains a core challenge as AI systems evolve to provide continuous assistance across multiple devices. The Google Private AI Compute Team has shared a technical update on introducing private, server-side memory to its Private AI Compute platform, resolving a longstanding dilemma in modern AI.

Bringing On-Device Privacy to Cloud-Scale Memory

Historically, local on-device processing has been the gold standard for privacy. Yet, frontier AI models often demand far more computing power than a single device can offer. While Google's previously introduced Private AI Compute platform allowed complex tasks to be processed in hardware-isolated cloud enclaves, the technology was strictly "stateless," wiping all context once a task ended. Simple workarounds, like saving lists of personal facts, are insufficient for the rich, continuous experiences users expect.

To address this, the new persistent memory layer functions like a secure digital vault in the cloud. The architecture relies on several key mechanisms:

  • Dedicated Encrypted Storage: Information needed to assist the user is sealed within dedicated, encrypted storage in the cloud.
  • Device-Side Cryptographic Keys: The cryptographic keys required to unlock this data are held exclusively on the user's personal devices, ensuring the data is inaccessible to anyone else, including Google.
  • Secure Enclave Processing: When an AI model needs information, an authenticated, end-to-end encrypted channel connects the device to a protected, isolated cloud environment. This "secure enclave" temporarily decrypts the data in isolated memory to handle the request, saves any new context, and immediately re-encrypts it.

By combining hardware-enforced secure enclaves, encrypted channels, and per-user databases shielded by device-derived encryption keys, the architecture ensures data remains fully private and under user control, as if it never left the device.

Building Trust and Looking Ahead

Private AI Compute is designed to enable seamless cross-device assistance. Examples include pulling up assembly instructions on a laptop that were previously viewed through smart glasses, or resuming complex conversations between mobile and web platforms. However, user trust in the system's privacy is crucial.

Building this trust starts with transparency. To achieve this, Google is taking several steps:

  • Tamper-Proof Public Record: Alongside an updated technical whitepaper, Google is publishing a tamper-proof public record of its server software. Devices will be able to verify that the software is authentic and unaltered before sending any personal data.
  • Independent Audit: Google is providing an update on its technical methods, including the results of an independent audit conducted by a leading cybersecurity firm.
  • Community Verification: By sharing these resources, Google invites the broader privacy community to verify the protections of Private AI Compute.

This research, co-developed by Google DeepMind, Platforms & Devices, Core, and Cloud teams, demonstrates how deeply personal assistance can be private by design. The community is invited to review the updated Private AI Compute Technical Brief, system architecture, security proofs, and verification protocols.

Source