Google DeepMind has announced a technical update to its Private AI Compute architecture, introducing a persistent, server-side memory layer designed to enable continuous AI assistance across multiple devices while maintaining strict privacy standards.
PLUS ULTRAProduct LaunchesGoogle DeepMind
Google DeepMind introduces persistent server-side memory for Private AI Compute
PLUS ULTRA by Amenoyomi
Under this new architecture, AI models can access a secure digital vault in the cloud. This memory layer uses end-to-end encrypted channels to connect a user's device to a "secure enclave"—an isolated environment in the cloud. Data is temporarily decrypted within this isolated memory to handle requests and is immediately re-encrypted afterward. To ensure privacy, the cryptographic keys required to unlock the data are held exclusively on the user's personal device, making the information inaccessible even to Google.
This update addresses the limitations of current "stateless" cloud processing, where context is wiped as soon as a task ends. By providing a persistent memory layer, the architecture aims to support seamless AI experiences, such as resuming a complex conversation started on a mobile device on a laptop.
To support transparency, Google is publishing a tamper-proof public record of its server software, allowing devices to verify that the software is authentic before transmitting personal data. The company has also released an updated technical whitepaper and results from an independent cybersecurity audit to allow the privacy community to verify these protections.
PLUS ULTRAby Amenoyomi
Previous cloud AI processing was strictly "stateless," meaning the system wiped all context immediately after a task ended. While this approach protected privacy, it prevented an AI assistant from maintaining long-term continuity or remembering preferences across different devices.
To resolve this, the updated architecture introduces a persistent memory layer that functions as a secure digital vault. When the AI needs to access information, it uses a "secure enclave"—a hardware-isolated environment in the cloud. The data is decrypted only temporarily within this isolated memory to handle the specific request and is immediately re-encrypted afterward, ensuring the information remains protected as if it never left the user's device.
The privacy of this vault is maintained by shifting key management to the user. The cryptographic keys required to unlock and decrypt the stored data are held exclusively on the user's personal devices. Because Google does not possess these keys, the provider cannot access the contents of the encrypted storage.
To ensure the system operates as designed, Google provides a tamper-proof public record of the server software. This allows the user's device to verify that the cloud software is authentic and unaltered before any personal data is transmitted, moving the basis of privacy from trust in the provider to technical verification.
Sources
- Advancing Private AI Compute with secure, server-side memory (Google DeepMind Blog, 2026-09-23)