Models & Research

Google Research Moves Federated Learning Into TEEs: Gboard Now Trains With Externally Verifiable Differenti…

· October 4, 2026
Google Research Moves Federated Learning Into TEEs: Gboard Now Trains With Externally Verifiable Differenti…

What happened

Google Research shifted part of its federated learning process into trusted execution environments (TEEs) on servers. Instead of phones doing all gradient computations locally, some training now happens in these attested TEEs. Policies controlling access to the training environment are logged publicly via Sigstore’s Rekor, and binaries are built reproducibly for external verification. Gboard uses this setup today for next-word prediction in English and Japanese, adding an externally verifiable layer of central differential privacy to protect user data.

Why it matters

Federated learning is meant to keep users’ data private by training models on local devices, but verifying that privacy properties are actually maintained has been tricky. Moving gradient calculations to server-side TEEs creates a secure, verifiable enclave that enforces privacy guarantees more transparently. Public logging of access policies and reproducible binaries let outside parties audit that differential privacy protections are active. This moves privacy from a black box to a verifiable system, raising the bar for compliance and trust in AI training pipelines that use sensitive data.

For operators, this means models can improve using user data without exposing the data or relying on blind trust in providers. It also opens a path for regulators and privacy-conscious businesses to demand cryptographic proof that differential privacy is enforced in real time during training. This could tighten privacy regulations around AI models and data usage and squeeze out less transparent approaches.

What to watch next

Watch for Google to expand this TEE-based verifiable learning framework beyond Gboard and across more languages and products. Competitors in AI and device ecosystems may feel pressure to adopt similar mechanisms or risk losing user trust and regulatory approval. The adoption curve of TEEs plus public audits will reveal how scalable and practical this privacy-first approach is at global scale.

Additionally, keep an eye on Sigstore’s ecosystem growth as a transparency and provenance tool for AI components. Its role in logging access policy could become a standard for proving compliance. How regulators and privacy advocates respond to these cryptographic proof tools will also shape the future of AI data governance.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.