bytevyte
bytevyte
Language

AISeal Brings a Hardware Vault to Android's On-Device AI Data

Google's AISeal vault rolls out on Android, storing AI personal context in hardware isolation, with NPU and cloud extensions still to come.

AISeal

Google has begun rolling out AISeal, a hardware-isolated vault that keeps the personal data feeding Android's on-device AI separate from the rest of the phone. The company detailed the architecture this week, describing a protected space that stores encrypted personal context, including messages, email and calendar information, outside the main operating system. The first release is about storage, not a complete assistant running inside the vault.

The design goal is narrow and specific: personal context should stay protected even if Android itself is compromised. AISeal leans on the Android Virtualization Framework (AVF) and the protected Kernel Virtual Machine, or pKVM, to wall off sensitive AI workloads from the host system.

Inside the AISeal Vault

AVF lets Android run isolated environments at the hardware level, so code inside the vault cannot reach the rest of the device and the rest of the device cannot reach in. Google built the vault as a multi-tenant protected environment, which means several AI services can share one space without weakening the isolation between them.

Protected databases inside the vault store and index personal context in encrypted local storage. Google says the current implementation uses AppSearch as an optimised reference for that job. Multi-tenancy matters on a phone because a separate secure enclave for every AI service would strain memory and battery; one shared vault keeps resource use in check while preserving separation.

Google reports the architecture is certified to SESIP Assurance Level 5 (AVA_VAN.5), a rating tied to ISO 15408 evaluation. That level describes how resistant the design is to a defined class of attacks. It is not a blanket promise about every feature built on top of the vault.

Storage and inference are separate today. AICore, Android's system service for running Gemini Nano, handles local inference and isolates each request. The vault protects where context lives; AICore handles what runs on it. Running models inside the protected boundary is the step Google has not taken yet.

Which Phones Get It

The vault depends on silicon that supports AVF. MediaTek confirmed support in its new Dimensity 9600 Pro, and Qualcomm has said its Snapdragon chips will carry it. The Dimensity 9600 Pro, built on a 2nm process, pairs an all-big-core CPU using Arm's C2 cores with two NPUs: the NPU 1090 for generative and agentic workloads and the Super Efficient NPU 2.0 for always-on tasks. It also brings LPDDR6 memory, UFS 5.0 storage, H.266 video decoding, a hardware root of trust and post-quantum protection.

MediaTek worked with Google on the security side, and the chip supports Google's AICore framework with the Gemini Nano model running on the phone. That pairing keeps responses low-latency while holding data on the device. Gemini Nano now runs on more than 140 million devices, which sets the scale of the personal context that AISeal is meant to guard.

That scale is where the practical picture narrows. Hardware isolation depends on AVF-capable chips, and so far those are flagship-class parts from MediaTek and Qualcomm. Buyers on budget or midrange Android phones may not get the same local protection, and AI features that need screen context or automation could be routed to Google's cloud servers rather than the vault. The gap sits in the silicon, not the software stack.

For those buyers, the effect is uneven. A midrange device can still deliver AI features, but the processing path may travel through Google's infrastructure, where the guarantees rest on encryption and key handling rather than on a chip-level boundary.

CapabilityWhat it doesStatus
Encrypted personal context storageHolds messages, email and calendar data in the vaultRolling out now
On-device inference in the vaultRuns models and agents inside the protected boundaryFuture work
Direct NPU assignmentGives the vault dedicated AI accelerationPlanned
Confidential cloud extensionsLinks the vault to Google servers for hybrid AIPlanned

The context being guarded is broad. Android's AI features draw on signals from Search, Gmail, Photos, Calendar and Gemini to produce recommendations, reminders and summaries. Moving that material into a hardware vault shrinks the surface a malicious app or a compromised operating system can reach.

AISeal is one of several privacy features arriving with Android 17. Another is Live Threat Detection, which watches for risky app behaviour. On Pixel hardware the vault is part of the same push toward treating AI data as a protected class of information.

What Comes Next

Google has outlined two additions to the design. Direct NPU hardware assignment would let models process data faster while staying inside the protected boundary. Confidential cloud extensions would connect the vault to Google's servers for hybrid AI tasks, carrying the same isolation model off the device.

Speed and control pull in opposite directions here. Cloud processing can call on larger models and more compute, while on-device inference keeps data local and cuts latency. Google's hybrid roadmap tries to hold onto the privacy guarantees of local processing while borrowing cloud capacity, which is why confidential cloud extensions sit on the same plan as direct NPU assignment.

Those pieces sit alongside a parallel effort. Google's Private AI Compute team published details of secure server-side memory in late September, an architecture that keeps encrypted personal data in cloud databases while holding the decryption keys on user devices. Read together, the two projects point in one direction: keeping keys and raw context under the user's control even when processing moves to a data centre.

Running models and autonomous agents inside the vault remains future work, according to Google. For now the vault holds context. It does not yet run the assistants that will use it.

Why this matters

The immediate change for Android users is that the data behind AI features gains a hardware boundary, but only on phones whose chips support it. That split means privacy increasingly tracks device price, a pattern buyers will weigh when comparing a flagship against a midrange phone. Google's roadmap of NPU assignment and confidential cloud extensions suggests the vault is meant to become the anchor for hybrid AI, where context moves between phone and data centre while the keys stay with the user.

Sources

Android's Next-Gen Enclave for On-Device AI

Advancing Private AI Compute with secure, server-side ...

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.