AI in everyday software · Keyboard models
Gboard’s next word models: who can use encrypted training data?
Google reports a new training system for English and Japanese models. Devices upload encrypted examples, keys go only to permitted programs, and public logs make the policies inspectable.
The report confirms English and Japanese next word models using this training system, without a complete rollout list for other languages, regions or phone versions.

A different training route behind an existing keyboard
As you type, Gboard suggests the next word. Google’s October 2 report says its new federated learning system has launched English and Japanese next word models. Moving training computation toward servers reduces constraints from device availability and computing resources. Google reports faster training and more accurate models.
Sources and further reading
- Google Research: the new federated learning systemOfficial research report · October 2, 2026Encrypted examples, permitted programs, public logs and the deployed training use for Gboard English and Japanese models.
- Federated data learning whitepaper v4Authors’ paper · first September 25, revised September 30Training and differential privacy release; guarantees retain TEE and side-channel assumptions. No device or privacy audit was performed here.
Uploaded examples remain tied to permitted programs
Devices encrypt training examples and bind them to permitted programs. The key service checks a workload inside a Trusted Execution Environment (TEE) before releasing keys. Public logs let devices and external reviewers inspect the policies. Released outputs include differentially private model weights and training metrics: encryption, constrained execution and differential privacy release work together.
| Role | What it does |
|---|---|
| Device | Encrypts training examples and binds them to allowed programs. |
| TEE workloads and key service | Checks the program against its policy, then permits decryption and training. |
| Public transparency log | Publishes permitted-workload policies for inspection; it does not release keys. |
| Model outputs | Releases differentially private weights along with training metrics. |
Sources and further reading
- Google Research: the new federated learning systemOfficial research report · October 2, 2026Encrypted examples, permitted programs, public logs and the deployed training use for Gboard English and Japanese models.
- Federated data learning whitepaper v4Authors’ paper · first September 25, revised September 30Training and differential privacy release; guarantees retain TEE and side-channel assumptions. No device or privacy audit was performed here.
- Confidential Federated Compute public componentsGoogle open-source project · read onlyThe key service checks workloads against policies, while public records support external verification. The project was not built or run here.
Training improves the model; inference handles the current input
Training updates a model from examples; everyday inference uses the trained model to suggest words for the current input. This deployment changes the training route and already serves the reported English and Japanese models. AI enters familiar software through how models learn and how companies constrain how training data is used, as well as through new chat interfaces.
Sources and further reading
- Google Research: the new federated learning systemOfficial research report · October 2, 2026Encrypted examples, permitted programs, public logs and the deployed training use for Gboard English and Japanese models.
- Federated data learning whitepaper v4Authors’ paper · first September 25, revised September 30Training and differential privacy release; guarantees retain TEE and side-channel assumptions. No device or privacy audit was performed here.
See how these changes connect
Training location and everyday execution are separate: inspect the work a local model leaves behind.
How data is processed and what a shared service can access describe different boundaries.

