
Google unveils AISeal, a vault for on-device AI data on Android
Google says the operating system would no longer see the emails and messages an assistant gathers; today the protection covers storage only.
On Oct. 7, Google described AISeal in its security blog, a design meant to keep the personal data an AI assistant uses on Android out of reach of the operating system itself. The post is signed by Irene Ang and Helen Jiang, of the Android Virtualization team.
A useful assistant needs emails, messages, calendar entries and contacts, and that pile makes it an attractive target. AISeal keeps that data in an "enclave," a virtual machine isolated inside the phone. Only the final answer comes out, not the raw data. Several AI services can share the same vault without seeing what the others store.
The technical base is pKVM, Android's hypervisor, the layer that keeps virtual machines separate. Google claims that even if the host system is fully compromised, the data would stay cryptographically isolated. Privacy Guides picked up the announcement on Oct. 9 and notes that pKVM earned SESIP Level 5 certification, the highest tier of vulnerability testing, which Google announced in August 2025.
What works today and what is missing
What is available is isolated storage for personal context, using AppSearch or each manufacturer's databases. Running the models inside the vault, adding autonomous agents and extending it to a confidential cloud appear as plans. MediaTek announced support on its Dimensity 9600 Pro chip, and Google says Qualcomm's Snapdragon chips will support it through the Android Virtualization Framework.
All of this comes from the company itself, and no one has tested the security claims independently. There is also no list of phones, Android version or timeline, and it is unclear whether it will reach Mexico.
Google or the manufacturers have yet to say which devices will get it first.



