The trick: Announced Not Shipped
Google says your AI's memory will live in its cloud, locked so tightly that even Google cannot read it.
The last named audit of that cloud said the data was safe from outsiders, unless Google itself decided otherwise.
Google says a planned persistent memory layer for Private AI Compute will seal user data in encrypted storage with keys held on the user's devices, ensuring the data is inaccessible to anyone else, even Google.
Before you read on. Your call?
TRUE, BUT
2025 audit
the post describes what Google will build, and Help Net Security reports the example uses are presented as potential, not currently available features. The design still has a secure enclave in Google's cloud temporarily decrypt the data to handle each request.
The twist
the one named independent audit in our record, NCC Group's 2025 review of Private AI Compute, concluded Google had robustly limited exposure to outsiders unless Google, as a whole organization, decides otherwise. The new post cites an audit by an unnamed firm; nothing in this record shows whether that review reached a different conclusion about Google itself.
There’s more to this story.
Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.
Start your free month →First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in
Couldn't check your access. That's on us.
The trick has a name
We call it Announced Not Shipped: claimed, never released. You'll see it again. Learn to spot it →
Receipts
- Supports deepmind.google:
ensuring your data is inaccessible to anyone else, even Google
- Context deepmind.google:
Today, we are sharing how we will bring private, server-side memory to our Private AI Compute platform.
- Context deepmind.google:
temporarily decrypts your data in isolated memory to handle the request, saves any new context, and immediately encrypts it
- Context deepmind.google:
In addition, we’re providing an update on our technical methods, including the results of an independent audit by a leading cybersecurity firm.
- Context deepmind.google:
Until now, that technology — along with similar solutions across the industry — was strictly “stateless,” meaning it wiped all context the moment a task ended.
- Supports deepmind.google:
per-user databases shielded by device-derived encryption keys, this architecture ensures your data stays fully private and under your control.
- Context deepmind.google:
we’re publishing a tamper-proof public record of our server software.
- Context helpnetsecurity.com:
Private AI Compute is Google’s cloud platform for processing sensitive data with Gemini models in a hardware-isolated environment.
- Supports helpnetsecurity.com:
Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy protections normally associated with on-device processing.
- Context helpnetsecurity.com:
The company presents these scenarios as examples of the architecture’s potential, not as currently available product features.
- Refutes theregister.com:
An audit conducted by NCC Group concludes that Private AI Compute mostly keeps AI session data safe from everyone except Google.
- Refutes theregister.com:
Although the overall system relies upon proprietary hardware and is centralized on Borg Prime, NCC Group considers that Google has robustly limited the risk of user data being exposed to unexpected processing or outsiders, unless Google, as a whole organization, decides to do so
- Context thehackernews.com:
Users will benefit from a high level of protection from malicious insiders.
- Context thehackernews.com:
NCC Group, which has conducted an external assessment of Private AI Compute between April and September 2025, said it was able to discover a timing-based side channel in the IP blinding relay component
Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.