Android On-Device AI Gets a Security Bump With "Next-Gen" Enclaves
Google announced in a blog post a new feature to keep local AI isolated from the rest of your device, based around virtual machines and hardware isolation, which they're calling "AI seal."
AI personal assistants require lots of data in order to work, but this access can make them a valuable target for hackers. Your entire personal user knowledge graph can include sensitive emails, messages, calendar, events, contacts, and other interactions that could reveal a lot about you.
Android already sandboxes this data by default. No app can access your contacts, pictures, files, etc., without asking you first, and apps can't access the data from other apps without mutual consent first. AI assistants essentially need to centralize all this data into one place in order to work, making their stored knowledge graph an attractive target for hackers.
The new AI seal architecture attempts to strengthen protection of this data using the Android Virtualization Framework (AVF) and the protected Kernel Virtual Machine (pKVM) hypervisor.
On-device AI seal enables a hardware-isolated, centrally managed secure vault (utilizing protected VM) that decouples sensitive AI workloads from the host operating system—designed so that even in the event of a full host OS compromise, personal data remains cryptographically isolated and protected from unauthorized access.

The pKVM hypervisor is certified to SESIP Assurance Level 5 (AVA_VAN.5), the highest vulnerability testing tier available under ISO 15408.
AI seal provides multi-tenant capabilities that, according to Google, will allow multiple AI services to share a single, secure vault without compromising isolation.
The vaults don't expose raw data, instead implementing strict internal access controls. For example, an AI assistant can ask the database to summarize your schedule entirely from within the vault. Only the final result will be exposed outside the isolated environment.
Google says the industry is already shipping implementations of AI seal: MetiaTek's Dimensity 9600 Pro and Qualcomm's Snapdragon chipsets will support the architecture via AVF, and they are working with device manufacturers.
In the future, Google wants to put the entire on-device AI into the vault, so an AI assistant can operate fully within the isolated environment without ever touching the host memory.
The end goal is establishing a secure, open standard for on-device AI enclaves.
Google's own Pixels have made headlines with Gemini allowing attackers to bypass the Android lock screen in some cases.
Community Discussion