Google DeepMind unveils encrypted, device-keyed server-side memory for Private AI Compute
Google DeepMind has detailed persistent, cross-device server-side memory for Private AI Compute, encrypted with keys held only on users' devices and processed inside secure enclaves, keeping data inaccessible to Google.
Google DeepMind has announced an update to its Private AI Compute architecture introducing persistent, server-side memory, designed to let Gemini-powered AI assistants retain long-term context across sessions and devices without compromising on-device privacy standards. Until now, the platform has been stateless: it processes sensitive data in a hardware-isolated cloud environment and discards all context when a task ends. Under the new design, assistance data would be stored encrypted, with decryption keys held only on the user's devices. When a request is made, a hardware-enforced secure enclave temporarily decrypts the data over an authenticated end-to-end channel, processes it, and re-encrypts it, keeping the data inaccessible to Google. The two reports differ on deployment status: Google DeepMind's own announcement (2026-09-23) presents the system as an introduced architecture update, while Help Net Security (2026-09-24) characterizes it as planned, noting cross-device scenarios are described as future possibilities rather than current features. To support verifiability, Google published an updated technical brief, a tamper-proof record of its server software, and independent audit results, and says devices can verify the server software before sending personal data.
- Announced by Google DeepMind on 2026-09-23, with coverage by Help Net Security on 2026-09-24.
- Private AI Compute has previously been stateless, erasing all context when each task ends.
- The new memory would store assistance data server-side, encrypted with decryption keys held only on users' devices.
- A hardware-enforced secure enclave temporarily decrypts data over an authenticated end-to-end channel, processes the request, then re-encrypts it.
- Google says the design keeps user data encrypted and inaccessible to Google itself.
- Google released an updated technical brief, a tamper-proof record of server software, and independent audit results.
- Devices can verify the server software before sending personal data.
- Sources disagree on maturity: DeepMind frames the system as introduced, while Help Net Security describes cross-device scenarios as future possibilities, not current features.
Coverage timelineoldest first · each row is one article
- · 3d agoAdvancing Private AI Compute with secure, server-side memory
Google DeepMind· 45
Google DeepMind introduces persistent, private server-side memory for its Private AI Compute architecture using secure enclaves and device-held keys.
- · 2d agoGoogle plans to give Private AI Compute a memory that follows users across devices
Help Net Security· 48
Google plans encrypted, device-keyed server-side memory so Private AI Compute assistants retain context across devices.