Google DeepMind published a technical update on September 23 describing persistent server-side memory for its Private AI Compute architecture.
The proposal addresses a tension between local processing and cloud model capacity. Local processing keeps data on a device, while larger models may require more computing resources than one device provides.
1,000+ Claude Prompts Top Professionals Actually Use at Work
Claude can be your analyst, editor, and strategist.
But most professionals are using it to fix grammar.
These 1,000+ Claude prompts take it from grammar tool to your most powerful AI work assistant.
Sign up for Superhuman AI and get:
1,000+ ready-to-use Claude prompts to get real work done in minutes — researched, tested, and used by professionals at Google, Microsoft, and NASA
Superhuman AI newsletter (4 min daily) so you keep learning new AI tools and skills to stay ahead in your career — the prompts are just the beginning
Google says the new memory layer stores information in dedicated encrypted storage. It says the cryptographic keys needed to use that information remain on the user’s personal devices.
When the model needs stored context, Google describes an authenticated end-to-end encrypted channel from the device to an isolated cloud environment. The environment temporarily decrypts data in protected memory, processes the request, and encrypts new context afterward.
The architecture uses hardware-enforced enclaves, encrypted channels, and databases separated by user. These components are presented as part of Google’s design, not as independent proof that the privacy goals are achieved in every deployment.
The update also describes a change in state. Earlier Private AI Compute processing was described as stateless, meaning that context was removed when a task ended. The new proposal retains selected context across tasks and devices.
Persistent state changes the security review. A one-time request becomes a longer data life cycle involving creation, retrieval, update, deletion, account recovery, and device replacement.
Built for Product Teams moving at AI Speed.
Your teams are moving fast, burning tokens, and shipping more than ever.
But more output doesn’t mean more impact.
Jira Product Discovery brings your ideas, customer insights, and business context together so product teams can weigh the evidence, make the tradeoffs, and decide what’s actually worth building. Then connect those decisions directly to delivery in Jira, so everyone knows what you’re building and why.
Jira Product Discovery. For better product decisions in the AI era.
Google says devices will be able to verify that the server software is authentic and unaltered before sending personal data. It also says the update includes a public software record and results from an independent audit.
An earlier public report from NCC Group describes a separate review of selected Private AI Compute components. NCC Group says Google engaged it beginning in spring 2025 for architecture, cryptography, attestation, relay, logging, configuration, and source code work.
The report says ten consultants delivered 100 person-days of work. Its first phase reviewed the architecture, while a second phase examined selected components and communication protections.
NCC Group identified a timing-based side channel in an IP-blinding relay that could expose a target user under particular conditions. It rated the exploitability low.
The report also identified denial-of-service risks involving certificate quotas and session resources. It described a protocol transcript limitation in the Oak Session Library with undetermined exploitability.
NCC Group’s review did not cover every part of the system. The report excluded the confidential computing platform based on AMD SEV-SNP and phone applications using Private AI Compute.
That scope matters when comparing the external review with Google’s September memory update. The review provides evidence about selected system components, but it does not independently validate the complete new memory architecture.
The review also states that the system is centralized on Google infrastructure and that Google retains organizational power over the platform. Hardware isolation can reduce access paths without removing the provider’s role in operating the service.
Google’s proposal keeps plaintext processing inside protected environments. Users still need information about retention periods, deletion behavior, recovery after device loss, and product coverage.
The announcement does not state a general rollout schedule for every product. It describes an architecture and supporting verification methods rather than a universal availability claim.
The September evidence supports a limited conclusion. Google has described a technical path for persistent AI memory using device-held keys and protected cloud processing.
The external review shows why that path needs continuing examination. Its findings concern selected components, while the new memory layer introduces additional questions about state, deletion, recovery, and long-term verification.
How 2M+ Professionals Stay Ahead on AI
What’s the secret to staying ahead of the curve in the world of AI? Information.
Luckily, you can join 2,000,000+ early adopters reading The Rundown AI — the free newsletter that makes you smarter on AI with just a 5-minute read per day.




