Google has outlined a persistent server-side memory design for Private AI Compute that would let Gemini-based assistants retain user context across sessions and devices. Assistance-related data would reside in dedicated encrypted cloud storage, while the decryption keys remain exclusively on a user’s personal devices; the proposed capability is not yet generally available.
For requests requiring saved context, a user device would create an authenticated end-to-end encrypted connection to an isolated hardware-enforced secure enclave. The enclave would decrypt the data only in volatile memory, process the request, then re-encrypt updated context immediately. Google said device-derived per-user keys, software attestation, a public record of server software, and independent audits are intended to make the system verifiable and prevent Google or other parties from accessing users’ stored memory.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Google announced a planned server-side persistent-memory capability for Private AI Compute, designed to let Gemini-based assistants retain encrypted context across sessions and devices. The proposed architecture keeps decryption keys on users' devices and uses authenticated end-to-end encrypted connections to secure cloud enclaves for temporary in-memory processing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.