Google designs persistent Private AI Compute memory around device-held keys
Google has documented a stateful extension to Private AI Compute that stores per-user AI memory as encrypted cloud data while a user device retains the key material needed to unlock it. The design uses attested enclaves, an open-source Oak memory server and a public binary ledger, but Google has not announced broad availability, and a 2026 Trail of Bits review left two findings unresolved.