---
type: "post"
stable_id: "post:google-heir-compiles-models-to-run-on-encrypted-inputs"
slug: "google-heir-compiles-models-to-run-on-encrypted-inputs"
title: "Google HEIR Compiles Models to Run on Encrypted Inputs"
description: "Google presented HEIR, an open-source compiler toolchain that can convert pretrained models to operate on homomorphically encrypted inputs."
retrieval_nugget: "The mechanism changes the privacy trade-off: a server can compute on ciphertext and return an encrypted result without seeing the underlying input. The remaining constraint is cost and latency, and Google's examples are demonstrations rather than proof that every workload is production-ready."
published_at: "2026-08-14"
updated_at: "2026-08-15"
record_date: "2026-08-14"
date_kind: "discovered_at"
topics: ["security","open-source","architecture"]
entities: ["Google","HEIR"]
source_urls: ["https://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption"]
source_format: "article"
editorial_timing: {"lane":"regular_hourly","scheduled_at":"2026-08-21T09:00:00+03:00","real_news_delta":"owner-selected verified story"}
origin: {"basket_id":"5854f7b2-5954-4d2a-8997-81596a49da74","basket_revision":1,"target_kind":"story_cluster","target_id":"b444eb59-a567-4fb6-a6e3-3998e8ef770b","owner_selection":"34","route":"hermes"}
visual_decision: {"outcome":"generate_explanatory_diagram","status":"included","reason_code":"mechanism_or_flow","explanatory_value":"homomorphic encryption lets a server run a compiled model over ciphertext and return an encrypted result without seeing plaintext input","text_only_limitation":"The value is the cryptographic direction of data through encryption, remote computation, and local decryption; prose alone does not make the no-plaintext server boundary as immediate.","owner_reviewed":true,"reviewed_by":"owner-and-codex"}
schema_version: "newruntime-agent-readable-v0.2"
status: "published"
visuals: [{"role":"hero","src":"/images/drip/google-heir-compiles-models-to-run-on-encrypted-inputs/google-heir-compiles-models-to-run-on-encrypted-inputs.webp","alt":"New Runtime whiteboard diagram explaining google heir compiles models to run on encrypted inputs.","caption":"New Runtime synthesis from blog.google."}]
routes: {"html":"https://newruntime.com/posts/google-heir-compiles-models-to-run-on-encrypted-inputs/","markdown":"https://newruntime.com/posts/google-heir-compiles-models-to-run-on-encrypted-inputs.md","json":"https://newruntime.com/posts/google-heir-compiles-models-to-run-on-encrypted-inputs.json"}
---

# Google HEIR Compiles Models to Run on Encrypted Inputs

## Retrieval answer

The mechanism changes the privacy trade-off: a server can compute on ciphertext and return an encrypted result without seeing the underlying input. The remaining constraint is cost and latency, and Google's examples are demonstrations rather than proof that every workload is production-ready.

Google presented HEIR, an open-source compiler toolchain that can convert pretrained models to operate on homomorphically encrypted inputs.

New Runtime reading: The mechanism changes the privacy trade-off: a server can compute on ciphertext and return an encrypted result without seeing the underlying input. The remaining constraint is cost and latency, and Google's examples are demonstrations rather than proof that every workload is production-ready.

Evidence boundary: this item uses the listed public sources and keeps vendor, author, or reporter claims attributed. The queued page is an editorial synthesis, not an independent validation of every reported metric.
