Google adds encrypted cloud memory to Private AI Compute
New architecture lets AI assistants retain context across devices while keeping data inaccessible to Google itself through device-held encryption keys.

Google introduces persistent memory for cloud AI
Google is expanding its Private AI Compute platform with a new capability that addresses a fundamental tension in AI assistant design: how to maintain conversational continuity across devices without sacrificing the privacy protections typically reserved for on-device processing.
The company's Private AI Compute platform already processes sensitive data through Gemini models in hardware-isolated cloud environments. Until now, however, the system has been stateless—wiping all context when each task completes. Google determined that workarounds like maintaining simple lists of user preferences fall short of providing the contextual understanding required for genuinely continuous assistance.
How the encrypted memory system works
The new architecture introduces what Google calls a "secure digital vault in the cloud." Information needed for AI assistance will be stored in dedicated, encrypted storage within the cloud infrastructure. The critical security element: cryptographic keys required to decrypt this data will be held exclusively on users' devices, not on Google's servers.
When an AI model needs to access stored context, the system establishes an authenticated, end-to-end encrypted channel between the user's device and a secure cloud enclave. The enclave temporarily decrypts data in isolated memory, processes the request, saves any new context, then re-encrypts everything. The combination of hardware-enforced secure enclaves, encrypted channels, and per-user databases protected by device-derived encryption keys means Google itself cannot access the stored information.
Verification and transparency measures
Google has released an updated technical brief and published a tamper-proof public record of its server software, along with results from an independent audit. Devices using Private AI Compute will verify that the software is authentic and unaltered before transmitting personal data.
The company has invited the privacy community to review the platform's architecture, security proofs, and verification protocols. This open approach to scrutiny reflects the sensitivity of introducing persistent memory to cloud-based AI systems.
Potential applications
Google presents several scenarios to illustrate the technology's capabilities: pulling up assembly instructions on a laptop after viewing them through smart glasses, or resuming conversations seamlessly across mobile and web platforms. The company emphasizes these are examples of the architecture's potential rather than currently available product features.
Why it matters
This architecture represents a significant attempt to resolve the privacy-versus-capability tradeoff that has constrained cloud AI development. Most AI assistants either process data entirely on-device with limited computational power, or send data to the cloud where companies can technically access it. By keeping decryption keys exclusively on user devices, Google aims to deliver cloud-scale AI capabilities with on-device privacy guarantees—a combination that could reshape expectations for enterprise AI deployments where data sovereignty is paramount.
The details were first reported by Help Net Security, which covered Google's announcement and technical documentation release.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call