Google announced AISeal on October 7, 2026, as an Android architecture for personalized on-device AI. Google says its foundational rollout milestone is hardware-isolated storage for personal context, while running AI models inside the protected environment and giving it direct access to a phone’s neural processing unit remain future plans.
How Google says AISeal is designed to work
AISeal is built on Android Virtualization Framework (AVF) and the protected Kernel Virtual Machine (pKVM), which Google describes as the basis for a hardware-isolated protected virtual machine. The design is intended to separate sensitive workloads from Android’s host operating system.
Google describes the protected environment as a shared vault for databases, AI services and agents, with internal access controls separating its components. That is the architecture’s proposed structure; the capabilities Google identifies as rolling out today center on storage, not a complete in-vault AI workflow.
Personal-context storage is the stated rollout milestone
Google says AISeal is rolling out across Android with protected databases that store and index personal context in encrypted local storage. AppSearch is the reference database implementation. Google also says the architecture can support other databases, including an original equipment manufacturer’s proprietary store.
That storage milestone is distinct from having a model use personal context to generate an answer inside the protected environment. Google describes foundation-model inference through future AICore integrations, along with agents operating in the vault, as future work.
Chipset support and the planned roadmap
Google reports that MediaTek announced AISeal support on the Dimensity 9600 Pro. Google also says Qualcomm Snapdragon chipsets will support the architecture through AVF. These are chipset-level statements; Google’s announcement does not identify specific retail phones in connection with them.
The roadmap also includes direct, private assignment of an on-chip NPU to the protected environment. Google plans an encrypted hybrid-inference extension connecting on-device protected virtual machines with original equipment manufacturers’ confidential-cloud servers.
What Google’s certification statement covers
Google says its foundational open-source pKVM implementation, delivered through Generic Kernel Image (GKI), is certified to SESIP Assurance Level 5 (AVA_VAN.5) under ISO 15408. The statement concerns that pKVM implementation.