Google introduces AISeal vault for Android's on-device AI
The protected-VM design aims to isolate personal context used by AI assistants; moving model execution into the vault remains a future milestone.
A vault for an assistant’s personal context
Google introduced Android on-device AI seal, or AISeal, as a protected environment for personal information an AI assistant might use across apps. Its October 7 security post says the architecture uses Android’s Virtualization Framework and the protected KVM hypervisor to separate a secure vault from the main operating system. Google describes encrypted local storage for personal context, with internal controls intended to let components query that context without exposing the raw data to the host. The company says the design is meant to keep data isolated even if the main Android system is compromised. That is an architectural claim, not evidence from an independent attack test.
The rollout starts with storage
Google says hardware-isolated context storage is the current milestone being rolled out across Android. Model inference inside the protected virtual machine, autonomous agents, direct access to a device’s neural processor, and a confidential cloud extension are future goals. MediaTek has announced support on its Dimensity 9600 Pro, and Google says Qualcomm chipsets will also support the architecture. These partner plans do not mean every current Android device already has the full AISeal design. The distinction matters because keeping stored context isolated is narrower than protecting an entire AI workflow, including the model and its actions, inside the vault.