Disclosure: TechSifted has no affiliate relationship with Google, Anthropic, or OpenAI. This is editorial news coverage.
Google published a blog post this week describing a planned upgrade to its Private AI Compute platform: persistent, encrypted memory that recalls context across all your devices, with cryptographic keys held on your device and nowhere else. Google says this means the company itself cannot access your stored data.
That’s a stronger privacy claim than any other major AI assistant makes today. It’s also a claim that only means something if the implementation is sound, and the feature does not exist yet.
What Private AI Compute Memory Is
Private AI Compute is Google’s existing privacy architecture for AI requests. It routes AI processing through isolated cloud environments called secure enclaves, where data is processed in a protected space separate from the rest of Google’s infrastructure.
Until now, that system was strictly stateless. Every session started from zero. No context carried over from one task to the next. Google says the new server-side memory layer changes that. (Google DeepMind blog)
The use case Google describes: you review assembly instructions through smart glasses, then pick up the same project on your laptop, and the AI assistant already knows where you left off. Or you start a complex conversation on mobile and continue it on the web without re-explaining the context.
How the Encryption Works
The architecture Google describes is technically specific. When your device needs to send data to the compute environment, it opens an authenticated, end-to-end encrypted channel to the secure enclave in the cloud. The enclave temporarily decrypts your data in isolated memory to handle the request, saves any updated context, then re-encrypts it immediately.
The key architecture is where Google makes the distinctive claim. The system uses Key Encryption Keys (KEK) and Data Encryption Keys (DEK). Google says these keys are held exclusively on your personal devices. The company says this means the data is inaccessible to anyone else, including Google itself.
Google also says devices can verify the authenticity of the enclave software before sending any personal data. Tamper-proof software records are published publicly. An independent audit by what Google calls “a leading cybersecurity firm” validated the design, and a technical whitepaper has been released for review by the privacy community.
What Is Confirmed and What Is Not
Nothing here is available yet. Help Net Security, which covered the announcement September 24, noted that the examples Google describes are presented as potential capabilities, not as currently available features, and no rollout date has been announced. (Help Net Security)
Keep that separation clear. The architecture is described. The feature is not shipped.
How ChatGPT, Claude, and Gemini Handle Memory Today
The contrast with the rest of the category is worth understanding, because this is ultimately what Google is positioning against.
ChatGPT stores saved memories and chat history, tied to your account. That data can be used to improve the model.
Claude from Anthropic rolled out persistent memory to all users in 2026. The system stores facts across conversations and syncs across web, desktop, and mobile. Anthropic takes a notable approach on sensitive data: health, race, ethnicity, religion, politics, and gender identity are excluded from memory storage by default, and certain categories, including government IDs, criminal history, and immigration status, are never stored regardless of settings. (Anthropic’s memory overview)
Standard Gemini memory stores data on Google’s servers. Google’s Personal Intelligence integration means Gemini can draw on your Gmail, Photos, YouTube history, and Search activity. Human reviewers may access conversations, and data can be used to improve Google’s AI. Standard Gemini memory and Private AI Compute Memory are separate systems. Do not conflate them.
The announced Private AI Compute Memory would be architecturally distinct from standard Gemini memory. If it ships as described, the key difference is simple: the company running the servers says it cannot read what those servers hold.
What Privacy-Minded Users Should Watch For
Scope matters. Private AI Compute covers what goes into the AI compute environment. Standard Gemini activity, your Google account data, and everything routed outside that protected environment continues to flow through Google’s standard infrastructure. This feature addresses one part of the data picture, not all of it.
Architecture and implementation are different things. A sound design can develop gaps when it ships across millions of users on varied hardware with varied software states. The MCP security issue OX Security disclosed earlier this year is a useful reference point: the protocol was working as designed, and the security gap still existed. The architecture described here is credible. That is necessary but not sufficient.
The underlying question this feature addresses is real: how do you give an AI assistant useful memory across your devices without handing all of it to the company behind the assistant? Google’s proposed answer is more architecturally specific than anything the other major platforms have committed to in public. Whether the shipped product matches the described architecture is a question that only gets answered once there is a shipped product.
Users who want tools that manage their personal data exposure today can start with the best personal data removal services roundup while the Private AI Compute rollout timeline remains open.

