Google Research says it has deployed a new federated-learning system in Gboard that moves training computation from users’ devices to server-side secure enclaves. The system is already being used for English and Japanese next-word prediction, with the aim of making training faster while strengthening privacy guarantees.
Watch Desk analysis
What happened
In the system Google describes, devices encrypt training examples before uploading them. A public transparency log records which server workloads are authorised to process the data, and a key-management system releases decryption keys only to workloads matching those policies. Training runs inside Trusted Execution Environments, or TEEs, and releases differentially private model weights rather than raw training examples.
Google says the approach has enabled faster training and improved accuracy for the Gboard models. The company also says its new setup can support stronger privacy guarantees or smaller noise multipliers by optimising when devices participate. Its research post describes the design and deployment.
Why it matters
Federated learning is meant to train models without gathering everyone’s raw data in one place. But Google acknowledges that earlier systems did not let outside observers verify that server-side code never logged or inspected uploaded data. Its new approach aims to make the authorised processing logic visible and auditable, while shifting the compute burden away from phones.
That shift could make larger federated-learning workloads practical, not just reduce training time for keyboard predictions. It also changes the privacy question: users and auditors can inspect which workloads are authorised, but the protections still depend on the TEE hardware and its limits.
Our read
This is a substantial infrastructure advance with a concrete live use, rather than a privacy promise left hovering in a slide deck. The transparency log and restricted key release are the useful parts to scrutinise: they give outsiders something specific to check. But “verifiable” is not the same as invulnerable. Google itself flags side-channel limitations and says stronger protections will depend on future TEE hardware and continuing research.
What to watch
- Whether independent auditors can meaningfully verify the logged policies and deployed workloads.
- How the system’s privacy and accuracy compare with earlier federated-learning deployments.
- Whether Google expands the approach to larger models or other workloads.
- How TEE hardware and side-channel research address the limitations Google identifies.
Discussion spark: Should privacy-critical AI training rely on secure hardware, or should it be required to work without trusting the hardware at all?
Sources and evidence
- Toward provably private learning from federated data (2 October 2026, 14:57 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.