Subscribe

The trick: Announced Not Shipped

Google says your AI's memory will live in its cloud, locked so tightly that even Google cannot read it.

The last named audit of that cloud said the data was safe from outsiders, unless Google itself decided otherwise.

Issue 2525 September 202614 receipts4 min

Google says a planned persistent memory layer for Private AI Compute will seal user data in encrypted storage with keys held on the user's devices, ensuring the data is inaccessible to anyone else, even Google.

Before you read on. Your call?

the post describes what Google will build, and Help Net Security reports the example uses are presented as potential, not currently available features. The design still has a secure enclave in Google's cloud temporarily decrypt the data to handle each request.

The twist

the one named independent audit in our record, NCC Group's 2025 review of Private AI Compute, concluded Google had robustly limited exposure to outsiders unless Google, as a whole organization, decides otherwise. The new post cites an audit by an unnamed firm; nothing in this record shows whether that review reached a different conclusion about Google itself.

2025year of NCC Group's audit of Private AI Compute
0memory features Google presents as currently available

There’s more to this story.

Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.

Start your free month →

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in

The trick has a name

We call it Announced Not Shipped: claimed, never released. You'll see it again. Learn to spot it →

Say this in tomorrow's meeting“Google says its new cloud AI memory will be unreadable even to Google. It is a plan, not a shipped feature, and the last named audit of the platform, NCC Group in 2025, said the protection holds unless Google as a whole decides otherwise.”

Receipts

  1. Supports deepmind.google: ensuring your data is inaccessible to anyone else, even Google
  2. Context deepmind.google: Today, we are sharing how we will bring private, server-side memory to our Private AI Compute platform.
  3. Context deepmind.google: temporarily decrypts your data in isolated memory to handle the request, saves any new context, and immediately encrypts it
  4. Context deepmind.google: In addition, we’re providing an update on our technical methods, including the results of an independent audit by a leading cybersecurity firm.
  5. Context deepmind.google: Until now, that technology — along with similar solutions across the industry — was strictly “stateless,” meaning it wiped all context the moment a task ended.
  6. Supports deepmind.google: per-user databases shielded by device-derived encryption keys, this architecture ensures your data stays fully private and under your control.
  7. Context deepmind.google: we’re publishing a tamper-proof public record of our server software.
  8. Context helpnetsecurity.com: Private AI Compute is Google’s cloud platform for processing sensitive data with Gemini models in a hardware-isolated environment.
  9. Supports helpnetsecurity.com: Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy protections normally associated with on-device processing.
  10. Context helpnetsecurity.com: The company presents these scenarios as examples of the architecture’s potential, not as currently available product features.
  11. Refutes theregister.com: An audit conducted by NCC Group concludes that Private AI Compute mostly keeps AI session data safe from everyone except Google.
  12. Refutes theregister.com: Although the overall system relies upon proprietary hardware and is centralized on Borg Prime, NCC Group considers that Google has robustly limited the risk of user data being exposed to unexpected processing or outsiders, unless Google, as a whole organization, decides to do so
  13. Context thehackernews.com: Users will benefit from a high level of protection from malicious insiders.
  14. Context thehackernews.com: NCC Group, which has conducted an external assessment of Private AI Compute between April and September 2025, said it was able to discover a timing-based side channel in the IP blinding relay component

Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.

Next letterOpenAI built a mental health test, had its own model grade it, and its own model came top. Answers written by licensed clinicians scored 38.5%. GPT-6 Astra scored 57.3%.

This story is a stable, citable object. If you can falsify a verdict, tell us. Corrections are loud here.