Announced 7 Oct 2026 · Sources checked
What did Google announce, and when?
The dated announcement is the 7 October 2026 Google Security Blog post, titled “Android's Next-Gen Enclave for On-Device AI” on the page we opened. Authors listed are Irene Ang, product manager for Android Virtualization and AISeal, and Helen Jiang, a software engineer. We opened that page on 9 October.
Google’s product name on the page is Android on-device AI seal, “also known as AISeal.” It is presented as Android’s enclave architecture for personalized on-device AI experiences. The stack named underneath is the Android Virtualization Framework and the protected Kernel Virtual Machine hypervisor. The vault is described as a hardware-isolated, centrally managed secure environment that uses a protected virtual machine and decouples sensitive AI workloads from the host operating system.
The name is not brand-new on 7 October. A 12 May 2026 Android security post, which we also opened, already said Android 17 “introduces AISeal with pKVM” on top of Private Compute Core and Private AI Compute. The 7 October post is the dedicated architecture write-up: tenants, the storage milestone, silicon partners and the later inference path. That is a different artifact from last week’s ML Drift on-device GPU engine, which opens a shader runtime and does not describe this vault.
What sits inside the vault today?
Google frames the vault as multi-tenant so several AI services can share one protected environment. The three tenants on the page are a protected database, on-device inference and AI agents.
The database tenant is the one Google marks as current. The post says it “securely stores and indexes personal context in encrypted local storage.” On-device AI seal “currently uses AppSearch as an optimized reference implementation, while supporting any database—including an OEM's proprietary store.” That matches the later milestone line: hardware-isolated personal context storage, “actively rolling out across Android.”
The other two tenants are written as a design. On-device inference is “designed to execute foundation models locally via future integrations with AICore.” AI agents are “built to assistants that combine private context with local inference.” An example on the page is an assistant that queries the database and summarizes a schedule inside the vault, with outbound controls “designed to allow only the final, intended answer to cross back.” Those are Google’s architecture sentences, not a shipping assistant we saw.
How does Google say the isolation works?
The threat the post writes against is a full host-OS compromise. Application sandboxing and SELinux are acknowledged as existing Android controls. AISeal is presented as a further step: personal data should remain “cryptographically isolated” even if the host is taken. That is a design goal on Google’s page, not a result we reproduced.
Trust is said to rest on the protected KVM hypervisor, delivered through Android’s Generic Kernel Image. Google writes that this implementation is “certified to SESIP Assurance Level 5 (AVA_VAN.5), the industry's highest vulnerability testing tier under ISO 15408.” SESIP is a security evaluation scheme. Level 5 with AVA_VAN.5 is the grade Google cites, and the “highest tier” wording is Google’s.
A vault that keeps personal context off the host is a different control from restricting what an agent’s tools can touch. For the process-isolation side of agents, the useful prior on this site is still agent sandboxing: file and network limits reduce what a mistaken action can reach. They do not, by themselves, put the user’s mail and calendar graph inside a protected virtual machine.
Which chips are named, and which phones?
Google’s silicon paragraph names two vendors. “MediaTek recently announced support of the pKVM-backed On-device AI seal on MediaTek Dimensity 9600 Pro.” Separately, “Qualcomm’s Snapdragon chipsets will also support our architecture via AVF as we expand across the broader silicon ecosystem.” The first sentence is framed as a recent MediaTek announcement. The second is a future-support line in Google’s post. We did not open a Qualcomm page that repeats it.
We did open MediaTek’s Dimensity 9600 Pro product page on 9 October. Under “AI Privacy, Security & Quantum Attack Protection” it lists three bullets: a hardware root of trust, post-quantum cryptography, and “AISeal: Hypervisor isolation for proactive AI privacy (using pKVM).” That is a first-party silicon page that uses the AISeal name and pKVM. It does not name phones, a ship date or which assistant binaries run inside the vault.
No handset model, carrier or region appears on the 7 October post or on the MediaTek page we opened. A supported SoC is not the same claim as “this phone’s assistant runs inside AISeal.” That gap matters next to other on-device artifacts this week, including EmbeddingGemma 2, which is a downloadable embedding model rather than a vault.
What is still on the roadmap?
After the storage milestone, Google lists three later items: “in-vault inference and autonomous agents,” so model execution would not touch host memory; “direct NPU device assignment,” a private lane to the on-chip neural processor; and a “confidential cloud extension” for encrypted hybrid inference with an OEM’s confidential cloud. None of those three carries a date on the page we opened. The post calls the work “an open enclave standard for on-device AI.” That is Google’s framing. We did not find a standards-body page, API schedule or device matrix attached to that sentence.
What is not established?
We did not run AISeal, open a protected VM on a handset, or inspect AppSearch data inside a vault. We did not verify the SESIP Level 5 certification beyond Google’s sentence. We did not open Qualcomm documentation for Snapdragon support. We did not confirm which Android 17 builds have the storage milestone enabled.
The May 2026 mention and the October architecture post can both be true: a feature can be previewed in a security round-up and then described in a dedicated post months later. The 7 October page is the source for the tenant list, the storage milestone and the silicon names. It is not, on the text we opened, a launch of in-vault Gemini or of on-device agents.
This is an evidence review of pages opened on 9 October. It is not a first-hand Android 17 test and not a ranking of AISeal against other mobile enclaves or confidential-computing stacks.
Common questions
Is AISeal a new on-device model?
No. It is Google’s name for a pKVM-backed vault on Android. The 7 October post describes architecture and a storage milestone. It does not release a foundation model.
Does this mean the phone’s assistant already runs inside the vault?
Not on the pages we opened. Google says personal-context storage is rolling out now. Inference and agents are listed as later work, including future AICore integration.
Which phones have AISeal?
Neither Google’s 7 October post nor MediaTek’s Dimensity 9600 Pro page names a handset. MediaTek lists AISeal on that chip. Qualcomm support is a sentence in Google’s post.
What to remember
Use the 7 October Security Blog post for the vault design and the storage-first milestone. Use MediaTek’s Dimensity 9600 Pro page for the silicon line that names AISeal. Treat in-vault inference, agents, NPU assignment and confidential cloud as Google’s roadmap until a device or API page says they are shipping inside the enclave.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





