Google Builds a More Verifiable Privacy Layer for Gboard Training

Google Research announced a new federated learning system on October 4, 2026, built on Trusted Execution Environments, or TEEs. The system gives Gboard externally verifiable central differential privacy guarantees, which Google’s research team claims is a first for federated learning.
The change addresses a trust gap that has followed federated learning since Google introduced it in 2017. Earlier systems allowed training without collecting raw data in one central place, but outsiders could not verify that data was never logged or inspected. Google’s new design makes the server-side work attestable, giving outside observers a way to check the rules governing the training process.
Closing the gap between privacy claims and proof
Federated learning trains models with data held across devices, but privacy depends on more than keeping that data distributed. The training system must also prevent data from being recorded or examined during processing. Google says its new system uses TEEs to protect that work while creating externally verifiable guarantees for central differential privacy.
Earlier systems used Secure Aggregation to add cryptographic protection. That approach still did not work with state-of-the-art central differential privacy algorithms such as matrix factorization DP-FTRL. The new design moves client gradient computation to the server and makes the server logic attestable, allowing the system to use those privacy methods within the TEE-based setup.
The system coordinates four core components: data upload, KMS and policy verification, workload execution, and fault-tolerant recovery. KMS, or Key Management System, uses the RAFT consensus protocol. TensorFlow Federated handles workload orchestration, connecting the training process with the other parts of the system.
Access policies are published to Rekor, Sigstore’s public transparency log. Those policies directly describe the Python training program, so the rules are not hidden in a separate explanation. The system can also sideload serialized logic at runtime inside the TEEs, which protects proprietary model architectures while allowing the training workload to run.
Gboard tests the system in real model training
Gboard used the system to launch English and Japanese next-word prediction models. Google says the models delivered stronger privacy guarantees and improved accuracy, bringing the new design into a product that relies on language prediction.
One stated training example involved an English model trained for 5000 rounds with cohorts of 6500 devices. The system collects all uploads before server-side training begins, which allows Google to choose an optimal participation schedule and tune differential privacy parameters.
That order of operations also changes how the training workload can be organized. Training now runs in parallel across machines, with the available TEE resources setting the limit. Google reports substantially faster compute times, but it does not publish a single speedup figure.
The result is a federated learning system that combines secure hardware, public policy records, privacy algorithms, and fault-tolerant execution. Its main shift is not only where computation happens, but also how the system can prove that its privacy rules were followed.
For Gboard, the system supports English and Japanese next-word prediction models with stronger privacy guarantees and improved accuracy. For federated learning, Google’s announcement points toward a model in which privacy protections can be checked from outside the training environment instead of accepted on trust alone.




