Private AI Compute: how it works, architecture and real-world uses

Last update: November 19th 2025
  • Hybrid architecture: local execution with enclaves and jump to sealed cloud (TIE over TPUs) with remote attestation.
  • Verifiable privacy: data used only for each task, end-to-end encryption, IP relay with blind tokens, and external audits.
  • Real-world experiences in Pixel: Magic Cue, Multilingual Recorder, Circle to Search, translations and more, with user control.

Private AI Compute Architecture

Artificial intelligence has become an integral part of our daily lives, but with it have come concerns about privacy: every suggestion, every summary, and every smart notification relies on personal data. In this context, Google presents Private AI Compute as a game-changer , an approach designed to leverage powerful models without having to open the floodgates to our data.

First, let's clarify: Private AI Compute (PAC) isn't a typical app or service . It's a technical framework that redefines where and how certain AI tasks are executed within the Pixel ecosystem and, progressively, on more devices. Whenever the hardware allows, the functions run locally; if more processing power is needed, the computation is moved to a secure cloud. The goal is to ensure equivalent privacy safeguards are applied both on the mobile device and in the cloud.

What is Private AI Compute and why is it arriving now?

Google's proposal aims to square the circle between performance and confidentiality: processing what's necessary for each task without exposing identifiable information . When the device has the capacity, the model runs on the device itself; otherwise, the work is delegated to a secure cloud with hardware controls and encryption.

This approach addresses an uncomfortable reality: today, most popular AIs run on servers, where user data can be temporarily stored or even used for training if not disabled. PAC aims to offer comparable benefits to local processing—lower latency and greater control—but with the power of Gemini in complex scenarios.

Google assures users that the information sent to PAC is used only for the action you request —for example, summarizing a note or translating a conversation—and is deleted after completion. Furthermore, the user retains control over which functions can rely on the private cloud and which cannot, with explicit switches and permissions within the system.

The result points to mobile phones and computers that perform as if they had an "invisible coprocessor" in the cloud: more speed when needed and verifiable privacy as an essential condition . And this isn't an isolated gesture: there's a clear trend in the sector to strengthen protection without sacrificing cutting-edge AI.

How Private AI Compute Works

Technical architecture: from device to sealed cloud

For tasks that fit on a mobile device, Google has built an isolated execution environment. We're talking about Titanium Intelligence Enclaves on the device: protected spaces separated from the operating system and other apps. There, data is encrypted both in transit and at rest and validated with remote attestation to confirm that the software and hardware are as expected and haven't been tampered with, so that no one—not even Google—can snoop on what's happening inside.

  Real-time search in web applications: search engines, AI, and UX

Meanwhile, models optimized for local use, such as the Gemini Nano , provide context and quick answers without leaving the device. For features like Circle to Search or some Recorder summaries, the phone acts as its own private AI that learns from usage but doesn't expose that knowledge.

When the task requires more computation, the private cloud comes into play. In this step, everything runs within hardware enclaves on Google's infrastructure, specifically Titanium Intelligence Enclaves (TIEs) on custom TPUs . Before allowing data transmission, the system performs remote certification/attestation to ensure the enclave is clean, running the correct binary, and that the environment complies with security policies.

Google summarizes the architecture in three pillars that, in addition to security, reinforce public trust:

  • Cryptographic isolation: processing is done in verified enclaves; operators cannot access the data in plain text.
  • Explicit permissionsThe user decides which functions can use PAC; nothing is released without consent.
  • Technical transparencyDocumentation, audits, and implementation details to avoid "black boxes".

In addition to the above, PAC incorporates further layers. A control service—known internally as Borg Prime —validates attestation proofs before authorizing any sensitive computation. To dissociate requests from identities, the system uses an IP blinding relay that routes requests through third parties such as Cloudflare and Fastly and employs blind tokens (Blind RSA) . This makes it difficult to link specific content to a specific user, even from within the infrastructure itself.

Transmission and temporary storage are protected by end-to-end encryption; and, once the task is complete, the data is discarded . All of this is supported by measures published by the company: the Secure AI Framework , the AI ​​Principles , and the Google Privacy Principles , which establish a common standard for operational security.

To build trust, Google is committed to providing detailed technical documentation , allowing external audits, and publishing parts of the system's code for researchers to review. The message is clear: privacy here is not just a promise, but something that can be verified and audited.

TIE Enclaves and TPUs

What features does it enable: real-world examples on Pixel

One of the first features to benefit from this approach is Magic Cue . This contextual assistant generates recommendations based on what's on your screen—email, calendar, maps, messages—and presents them precisely when needed. With PAC, these suggestions are calculated without exposing your content , relying on the local repository or the private cloud depending on the task.

  Ollama: all the information you need to use local AI on your computer

The Recorder app gains significant advantages with automatic summaries in multiple languages. Transcriptions—which can be highly sensitive—are processed with PAC's protection layer, ensuring they are only used in the specific summary you requested and are discarded upon completion. The user retains the final result, not a trail of data circulating on servers.

Google is also promoting features that were already iconic on Pixel, such as Circle to Search . Contextual recognition runs locally whenever possible, and if more advanced models are needed, they are used in the private cloud, keeping the privacy perimeter intact.

Other practical examples include real-time translations , more natural AI responses in conversations, and proactive decision-making assistance, where the system combines what it sees with your context to give you just the clue you need. Initially, the Pixel 10 will lead the way in these experiences.

The ecosystem also adds everyday useful features: smart notification summaries to reduce noise and focus on what's important; assisted editing with Gemini in Messages to rephrase texts with a better tone; advanced photo editing tools without external apps; and even a data-saving mode in Google Maps designed for long trips. Everything aligns with one idea: more help, less friction, with privacy as a design requirement.

AI features in Pixel

Controls, verifiable privacy, and independent audits

In PAC, the user remains in control: nothing is sent without permission . Android offers toggles to enable or disable features that rely on the private cloud and displays clear notifications when a task requires this. The philosophy is simple: you decide what your phone shares and under what conditions.

Google accompanies the platform with public and auditable information : technical guides, external reviews, and the publication of code for critical parts, so that independent researchers can examine how the system is built. It's not about faith, but about verifiable evidence.

In fact, the architecture has been reviewed by the cybersecurity firm NCC Group . Its public report concludes that the design offers robust protection against malicious intruders—including the risk from a rogue employee—and that it successfully brings the safeguards of on-premises computing closer to those of cloud execution. It also points out an unavoidable limitation: if Google, as an entire organization, were to decide to break the rules, it would control both the hardware and the attestation system. Even so, the auditor describes PAC as “ the best feasible model ” today for cloud privacy.

  Cloud vs USB drive: which is safer for your data?

The review identified some low-risk vulnerabilities, notably a potential timing-related side-channel vulnerability in the IP relay that, in theory, could help re-identify users under very specific conditions. Google argues that the "noise" of real-world traffic and mitigation measures make this impractical, and that the design will continue to be strengthened with patches and ongoing improvements.

A key benefit for user peace of mind is that PAC limits data usage to the specific task and deletes it upon completion . Furthermore, all communication is encrypted, both between your device and the server sites and within the server network itself, minimizing the attack surface both in transit and at rest.

Privacy and auditing in PAC

Ecosystem and comparisons: towards a more private AI

The Pixel 10 phones usher in deep integration of PAC, with substantial improvements to Magic Cue, instant translations, more accurate transcriptions, and smoother responses. Google has already announced that this architecture will be progressively expanded to other devices and services, combining local and cloud models for the most critical applications.

They're not alone on this path: Apple paved the way with Private Cloud Compute—Apple Intelligence's encrypted cloud—and manufacturers like OnePlus and OPPO have opted for Private Computing Cloud, hybrid platforms that distribute tasks between the device and encrypted environments. The trend is clear: powerful AI, yes; privacy, too.

Beyond competition, Google is seeking a tone aligned with European and American regulations: fewer black boxes and more technical transparency. Hence the emphasis on audits, remote attestation, and visible controls. In practice, PAC is both a technological evolution and a strategic move to demonstrate that it's possible to compete in AI without exploiting sensitive information.

The direction is clear: if we want assistants that understand context, summarize, translate, or make accurate recommendations, we need to balance capabilities and safeguards. With Private AI Compute, Google is trying to tip that scales toward a useful, immediate, and increasingly private AI , where the user has a say and the technology is accountable.

chip law 2.0
Related articles:
Chip Law 2.0: What's changing, why it's coming, and how it will be implemented in Europe