Google DeepMind lays out planned server-side memory for Private AI Compute
Google DeepMind outlined a planned memory layer for Private AI Compute that would retain context across devices using encrypted storage, device-derived keys and isolated cloud enclaves.
Google DeepMind detailed a planned server-side memory layer for Private AI Compute that would retain context over time and across devices. The proposal would move the platform beyond its current stateless model, in which Google says context is wiped when a task ends, and give it continuity between sessions.
Google says that shift could let an AI assistant resume conversations or retrieve relevant context across a user’s devices. Google has not announced a rollout date, supported products, regions or account eligibility for the memory feature.
In Google’s proposed architecture, persistent context would sit in dedicated encrypted storage, separated into per-user databases and protected with device-derived key material. When a model needs that information, the device would establish an authenticated, end-to-end encrypted connection to an isolated cloud environment, or secure enclave. The enclave would temporarily decrypt the data for processing, add new context and then encrypt the updated information again.
Google says the keys needed to unlock the stored information would remain exclusively on a user’s devices. The company says that would make the data inaccessible to others, including Google, and keep it as private as on-device processing. Those privacy and security assurances are claims about the planned design. The available research did not establish that a production memory service currently matches the architecture or independently verify the guarantees across deployments.
The memory plan builds on Private AI Compute, which Google introduced in November 2025 for sensitive AI work that requires cloud models. Google said that platform uses remote attestation, encryption and hardware-secured isolation to connect devices to protected cloud environments. The proposed memory layer would add cross-device continuity to that model, contrasting with Google’s on-device AI processing, which keeps computation on individual devices.
For the memory update, Google said it is publishing a tamper-resistant public record of server software and the results of an independent cybersecurity audit. It also said devices will be able to confirm that server software is authentic and unaltered before sending personal data. A public Trail of Bits repository entry identifies a September 2026 assessment of Google’s secure server-side memory. The announcement does not specify retention periods, deletion controls or user-facing consent settings.
More news

xAI launches Team Bots for shared workflows

AWS adds xAI’s Grok 4.7 to Amazon Bedrock

OpenAI adds $5 million and up to $5 million in credits to Lenfest AI program
