Monday Aug 17

Google Runs AI On Encrypted Data

17AUG
STILL SEALEDSEALEDANSWER OUT

The privacy trade-off in AI just moved. Google open-sourced HEIR, a compiler that converts trained models to run on encrypted inputs, so the server never sees your data. Fraud detection and recommendations already work.

Jeremy Kun announced it on the developers blog Aug 14. HEIR compiles machine learning workloads to fully homomorphic encryption, the 'holy grail' technique where computation happens without ever decrypting.

FHE has been a lab curiosity since 2009 because it was millions of times too slow. Hardware acceleration and compiler advances have cut that to practical latency for real inference tasks.

Why a product leader should care: banks, health systems, and government have been the hardest AI segment to crack, all blocked on data exposure. If inference stops requiring plaintext, that entire market opens.

full brief & sources

⚡ Why this matters

  • Privacy vs capability has been a forced trade in AI. This work says you might get both: cloud-scale models on data the cloud cannot read.
  • Regulated industries are the last untapped AI budget. Banks and hospitals blocked deployments on data exposure grounds. That objection weakens.
  • It is open source. Not a Google Cloud lock-in feature, a toolchain anyone can build on.

🔍 What happened

  • Google expanded its fully homomorphic encryption offering on the developers blog (Jeremy Kun, Aug 14), open-sourcing a compiler path that turns trained models into FHE-executable programs.
  • The pitch: send encrypted inputs, get encrypted outputs, the server never holds plaintext. Working examples include fraud scoring and recommendation inference.
  • Press coverage followed on Aug 15. The code and docs live at heir.dev and GitHub.

💬 Smart takes

  • Cryptographers' consensus: real progress, but FHE overhead still rules out large LLMs. This is for compact models today.
  • Security folks note the timing: enterprises are pushing back hard on sending sensitive data to AI APIs.
  • The strategic read: Google planting the standard early, the way it did with Kubernetes.

🧭 Where this goes

  1. Likelyprivacy-preserving inference becomes a checkbox in enterprise AI RFPs within a year.
  2. PossibleApple or Microsoft answer with their own encrypted-inference stacks.
  3. Wild CardFHE-grade privacy becomes a regulatory requirement for health and finance AI in the EU.

🥄 The Spoon Take

File this under quiet announcements that age well. Nobody's stock moved. But 'the server never sees your data' is the sentence every regulated-industry deal has been waiting for. Small models first, sure. The Kubernetes lesson applies: whoever open-sources the standard tends to own the category a decade later.

🤔 Pushback

FHE remains orders of magnitude slower than plaintext inference. LLM-scale workloads are nowhere near practical.