
23 Sep 2026
DeepMind adds private server-side memory to Private AI Compute
Google DeepMind detailed how Private AI Compute will gain persistent, cross-device AI memory with on-device privacy standards — encrypted cloud storage unlocked only by keys held on the user’s devices, plus a public software attestation record and an independent security audit.
SOFTWARE desk — cloud AI that remembers you usually means trust the company with your history; DeepMind is pitching the opposite design: memory in the cloud, keys only on your phone, so a personal assistant can span glasses-to-laptop without handing Google a readable diary.
What the post says was missing. An assistant that remembers you needs personal context, and the post says that context has to stay private as the help becomes continuous across devices. On-device processing has been the strict privacy standard, because the data stays on the hardware you hold. The post says the newest models often need more computing power than any one device can provide. Private AI Compute was the earlier design for that gap: complex tasks run in hardware-isolated cloud enclaves. An enclave, here, is a locked room in the cloud. The machine around it is not supposed to see the work inside. Until now, the post says, that technology, and similar systems elsewhere in the industry, was strictly stateless. Stateless means the context was wiped when the task ended. Saving a list of personal facts and preferences, the post says, is not enough for the continuous help people expect.
The new model, in the post’s words. A persistent memory layer will function like a secure digital vault in the cloud. The information needed to assist you is sealed in dedicated encrypted storage. The cryptographic keys that unlock it are held exclusively on your personal devices. A key, here, is the secret that opens the encrypted file. If that secret stays on your devices, the cloud can hold the locked box without holding the way in. Google says that arrangement makes the data inaccessible to anyone else, including Google. Those sentences are the post’s. This desk did not inspect a key store.
How a request moves, still the post. When a model needs information to assist you, an authenticated, end-to-end encrypted channel connects the device to a protected, isolated environment in the cloud. Authenticated means the two ends prove who they are. End-to-end encrypted means the path between them is scrambled so the middle cannot read it. That space, which the post calls a secure enclave, temporarily decrypts the data in isolated memory, handles the request, saves any new context, and encrypts it again. The post says the design combines hardware-enforced secure enclaves, encrypted channels, and per-user databases shielded by device-derived encryption keys. Per-user means each person’s vault is separate. Device-derived means the key comes from that person’s own devices. The post says the data stays fully private and under the user’s control. Will, and designed, stay the verbs.
The picture the post uses, not a product this desk tried. It asks the reader to imagine pulling up assembly instructions on a laptop that they previously viewed through smart glasses, or resuming a complex conversation between a phone and the web. Private AI Compute is designed to make that kind of help possible, with the pieces it needs to remember locked away. Smart glasses, a laptop, a phone, and the web are the post’s examples. They are not a ship list, and they are not a claim that a named glasses product gained this memory today.
What the post offers as something a reader can check. It says trust starts with transparency. Alongside an updated technical whitepaper, it is publishing a tamper-proof public record of the server software. Devices running Private AI Compute will be able to verify that the software is authentic and unaltered before sending personal data. That check is what engineers call attestation: the device asks the server to prove which program is running. The post also says it is sharing an update on the technical methods, including the results of an independent audit by a leading cybersecurity firm. The blog page does not print the firm’s name. It invites readers to review the updated Private AI Compute Technical Brief, the system architecture, the security proofs, and the verification protocols.
Who built it, only the acknowledgement. The research was co-developed by Google DeepMind, Platforms & Devices, Core, and Cloud. The post thanks Four Flynn, Jay Yagnik, and David Kleidermacher for executive sponsorship. The page prints the name Four Flynn. Sponsorship is a credit line. It is not a measured result.
What the linked technical brief adds, and where its clock is still ahead. The brief is “Google Private AI Compute: Enabled with Secure Server-Side Memory,” dated September 2026, from Google Platforms and Devices, Google DeepMind, Google Core, and Google Cloud. The file this desk read is the PDF linked from the blog. It describes a secure, persistent, isolated storage layer for long-term context, cross-device context, and user preferences. It says user data processed by Private AI Compute is not available to anyone other than the user, including Google. It says outside auditors validated the design for the first release and for this memory update, and it points to a 2025 report and a 2026 report. It says a client checks a cryptographic key before sending data, and that network requests can be inspected in Network Logs on supported Pixel and Android devices. Its “What’s next” section still lists a fuller check on the phone as future work: moving from Google-asserted compliance toward devices that independently validate the server’s evidence before sending sensitive data. It also lists a public software log co-signed by independent third parties as a direction, not as a finished public notary. Future releases, and further capabilities that will run on this infrastructure, are the brief’s own ahead-tense. There is no consumer on-sale date in that section. The component names in the paper stay in the source note.
Who the 2026 auditor is, and what that report counts. The 2026 link in the brief is Trail of Bits, “Google Private AI Compute, Secure Server-Side Memory Security Assessment,” cover date September 21, 2026, marked public. The 2025 link is NCC Group’s public report on Private AI Compute. Trail of Bits says Google hired it to build a threat model and review the code for the memory feature. A team of four consultants worked from June 4 to July 17, 2026, for five engineer-weeks. A fix review finished on August 7. The final report was delivered September 21. The review focuses on the memory addition. It says an earlier NCC review covered the rest of the system, including the hardened chip platform that serves the model, and that this review did not redo that work. It says it did not find a mechanism, in the code it reviewed, by which Google employees may access user data. It also says its findings do not let an outside attacker take the system over, but they weaken the transparency claims and the resistance to insider threats. Its count table: 2 high, of which 1 was marked resolved; 1 medium, resolved; 2 low, of which 1 was marked resolved; 5 informational, all resolved. One high finding and one low finding were still open on that table. It says the system, as built, does not provide a cryptographic guarantee that a deleted memory stays deleted. It says Google may change the system at any time without a prior outside review, and that a large share of the code is closed and not available for the public to read. It describes the feature as persistent context for agents that act for Android users. Android users is that report’s scope line. The blog’s examples also include a laptop, the web, and smart glasses. Do not collapse those lists. These lines are the report’s. This desk did not re-run the review. Google’s sentence that auditors validated the design is the brief’s. It is not a finding that every row in the Trail of Bits table is closed.
Plain English for the rest of the card. Private AI Compute is Google’s name for running a heavy assistant in a locked cloud room instead of only on the phone. Server-side memory means the history lives in that cloud, not only on one device. A secure enclave is the locked room. A key on the device is the secret that opens the vault. Stateless means the room forgets when the task ends. Attestation is the check that the server is running the program it claims. A public record of that program is the ledger the post says a device can consult. Pixel and Android Network Logs are the brief’s line about where a supported phone can show the network request. They are not a switch this desk flipped. Five engineer-weeks is Trail of Bits’s effort figure, the time the reviewers spent. It is not a count of bugs. September 23, 2026 is the blog’s date, with no hour on the page. September 21, 2026 is the audit report’s cover date.
PRIMARY here: Google DeepMind’s 23 Sep 2026 blog, “Advancing Private AI Compute with secure, server-side memory,” page date September 23, 2026, no hour on the page — Tier A PRIMARY, the lab’s own record. The Private AI Compute technical brief linked from that post is the paper the blog points to, not a second newsroom. Trail of Bits’s September 21, 2026 public assessment is the 2026 audit the brief links. NCC Group’s public report is the 2025 audit the brief links, not today’s announcement. The will-enable line, the stateless description, the vault and device-key sentences, the encrypted-channel and temporary-decrypt flow, the per-user and device-derived key lines, the glasses-to-laptop and phone-to-web examples, the public software record, the unnamed “leading cybersecurity firm,” the co-development credit, and the Four Flynn, Jay Yagnik, and David Kleidermacher sponsorship lines are the blog’s. The September 2026 brief title, the including-Google privacy sentence, the 2025 and 2026 report pointers, the Pixel and Android Network Logs line, the client key check, and the “what’s next” list (client-side verification still ahead, a co-signed transparency log still ahead, no consumer on-sale date) are the brief’s. The Trail of Bits cover date, the June 4 to July 17 window, the five engineer-weeks, the August 7 fix review, the September 21 delivery, the Android-users scope, the no-employee-access sentence in the reviewed code, the outside-attacker limit, the weakened transparency and insider-resistance sentence, the severity table (2 high with 1 resolved, 1 medium resolved, 2 low with 1 resolved, 5 informational all resolved), the missing cryptographic deletion guarantee, and the closed-source and change-without-prior-review limits are the report’s. NOT claimed: a consumer general-availability date, that every Google product has this memory turned on, that this desk held a device key or read a vault, that the blog names Trail of Bits or NCC Group, that every Trail of Bits finding is closed, that client-side cryptographic verification is finished, a named glasses product, a stock tip, or investment advice. Distinct from the already-filed amazon-seller-assistant-agentic, wisdomai-live-apps, zerodrift-anchor-3, and gemini-3-8-live.
RELATED
On 23 Sep 2026 Google DeepMind published a technical update on Private AI Compute. The record is the lab’s blog, “Advancing Private AI Compute with secure, server-side memory.” The page date is September 23, 2026. The section is Responsibility & Safety. The byline is the Google Private AI Compute Team. The page this desk read does not print an hour. The standfirst says it is a technical update on the Private AI Compute architecture, which will enable persistent, cross-device AI memory with on-device privacy standards. Will enable is the page’s tense. This is an architecture and capability announcement. It is not a date when every Google assistant turned memory on. This desk did not send a personal history through the system.
Sources
- Google DeepMind — Advancing Private AI Compute with secure, server-side memory
deepmind.google
- Google — Private AI Compute technical brief, secure server-side memory
services.google.com
- Trail of Bits — Private AI Compute secure server-side memory security assessment
github.com
- NCC Group — public report, Google Private AI Compute review (2025)
nccgroup.com