Google adds encrypted, persistent cross-device memory to Private AI Compute
On Sept 23, 2026 Google DeepMind described an update to Google's Private AI Compute platform. Cloud AI can now keep long-term, cross-device memory for a user in per-user encrypted storage whose keys stay only on the user's own devices, so that, Google says, the data is "inaccessible to anyone else, even Google". Data is decrypted only briefly inside hardware-isolated secure enclaves. Google also published a tamper-proof public record of its server software and the results of an independent security audit.
Key facts
- Until now Private AI Compute (and similar industry systems) was 'stateless', wiping all context when a task ended; the new layer adds persistent memory
- Design: an end-to-end encrypted channel from device to an attested enclave; the enclave temporarily decrypts data in isolated memory, saves new context and re-encrypts it; per-user databases are protected by device-derived keys
- Transparency: updated technical whitepaper, a tamper-proof public record (log) of server software that devices can verify before sending data, and an independent audit by 'a leading cybersecurity firm' (not named in the post)
- Example uses: continuing on a laptop what was seen through smart glasses; resuming conversations across mobile and web
- Co-developed by Google DeepMind with Platforms & Devices, Core and Cloud teams
What happened
Google extended Private AI Compute, its secure-enclave cloud platform for processing personal data with Gemini, so that it can remember. A user's context is stored in a per-user encrypted "vault" in the cloud. The keys stay on the user's devices, and data is decrypted only inside attested, hardware-isolated enclaves while a request is handled. Google says this solves a long-standing trade-off: frontier models need cloud compute, but strong privacy has usually meant on-device processing, and cloud enclaves could not keep state between requests.
Why it matters
Personal agents that remember users across phones, laptops and glasses need long-term memory. Google is betting that cryptographic guarantees, rather than policy promises, will make users willing to let the cloud hold that memory. Other enclave-based systems in the industry (such as Apple's Private Cloud Compute) are stateless, so this adds persistence. It also comes as Gemini replaces Google Assistant on Android.
Changelog
- 2026-09-30: created (official-blog audit)
Related events
- Gemini fully replaces Google Assistant on Android; Gemini gets 'Call for Me', and Gems become skills ★★★
Sources (1)
id: 2026-09-23-google-private-ai-compute-memory · updated 2026-09-30 · open in the interactive timeline