Google's AI will remember you across every device and says it can't see what it knows

Private AI Compute is getting a persistent memory layer. Google says the keys stay on your phone, not in its data centres.

AI2Day NewsdeskEditor: Lee Brown4 min read
Photoreal editorial shot of a modern server rack with a single glowing translucent vault door embedded in it, cool blue and steel colour palette, subtle green k
Share

Key points

  • Google DeepMind announced on 23 September 2026 that its Private AI Compute platform will add persistent, cross-device memory that even Google cannot read.
  • The memory sits in encrypted cloud storage, but the keys that unlock it live only on your personal devices.
  • Cloud AI enclaves were previously stateless, meaning they wiped all context the moment a task ended.
  • Google is publishing a tamper-proof public record of its server software alongside results from an independent cybersecurity audit.
  • Outside privacy researchers have been invited to verify the protections.

Google wants its assistant to remember you across your phone, laptop and smart glasses. It also wants to promise, in writing, that it cannot read what it remembers about you.

That's the pitch behind an update to Private AI Compute, the company's platform for running heavy AI tasks in the cloud with the same privacy guarantees as your own device. The change, announced by Google DeepMind on 23 September 2026, adds a persistent memory layer so the assistant can carry context from one device to another.

Here's how it works in plain terms. Your personal context sits in encrypted cloud storage. The cryptographic keys, the digital codes that open that storage, live only on your devices. When the AI needs to check something, your phone opens an encrypted channel to a sealed area in the cloud called a secure enclave, a slice of a server walled off by the chip itself. The data is briefly decrypted inside that enclave, the task runs, new context is saved, and everything is locked again.

Google's claim is blunt: the information is inaccessible to anyone else, not even Google.

Why does this matter for ordinary users?

Because memory has been the awkward gap in personal AI. Assistants either forget you between sessions, or they remember by parking your preferences on a company server that staff and subpoenas can potentially reach. Google is trying to give you the first option without the second.

The example the company uses: pulling up assembly instructions on your laptop that you'd previously viewed through smart glasses, or picking up a long conversation that started on mobile and continuing it on the web. Saving a short list of user facts was the usual workaround before this, and it never really covered rich, continuous help.

Should you take the privacy claim on faith?

No, and Google isn't asking you to. Alongside an updated technical whitepaper, the company is publishing a tamper-proof public record of the server software running Private AI Compute. Your device can check that the cloud code matches the published version before it sends any personal data over.

An independent cybersecurity firm has audited the setup. Google says it's also inviting outside privacy researchers to examine the design.

That's a stronger transparency posture than most cloud AI services offer today. It isn't a guarantee. Hardware enclaves have been broken by academic researchers before, and "we cannot see your data" claims tend to get tested hard once regulators and reporters go looking. This announcement lands just a week after we reported that a bug during a security test gave Gemini access to private systems it was never meant to touch, which is worth keeping in mind when evaluating any Google privacy claim right now.

How this fits the wider privacy story

Privacy has quietly become the biggest running theme on this beat. All 51 of AI2Day's privacy-tagged stories have run since 13 July 2026. The mood in most of them is defensive: clothes designed to confuse cameras, a Firefox assistant that forgets every prompt, unease about Meta's Muse remembering everything about you.

Google is trying to flip that script. The argument is that memory and privacy aren't opposites if you engineer the keys correctly.

My honest read: the architecture is genuinely more thoughtful than the marketing usually is, and the public software log is the part sceptics should actually check. Watch for two things next. Whether independent researchers confirm the enclave does what the whitepaper says. And whether this memory ends up switched on by default in Gemini, because a privacy feature only matters at the scale of the people who actually use it.

© 2026 AI2Day