Google has open-sourced HEIR, a compiler toolchain designed to let developers run existing AI models on encrypted data without a server ever seeing what it is processing. The project, whose name stands for Homomorphic Encryption Intermediate Representation, is built on MLIR, the same compiler infrastructure Google and others use for machine-learning frameworks, and the company says it aims to become a standard compiler for fully homomorphic encryption, or FHE.
Fully homomorphic encryption is a decades-old cryptographic technique that allows computation directly on ciphertext, producing an encrypted result that decrypts to the same answer as if the computation had run on the original data. In practice it has been notoriously difficult to use: writing an FHE-compatible program has typically required specialized cryptography expertise well outside most application developers' skill sets. HEIR is meant to close that gap. Developers write a program in Python and annotate which variables are secret; the toolchain compiles the rest, targeting backends including OpenFHE and Lattigo for the BGV, BFV and CKKS encryption schemes, with additional support for the CGGI scheme through tfhe-rs and Jaxite.
Why It Matters for "Private AI"
Google frames the release as part of a broader effort described in a Google Security blog post to make privacy-preserving inference practical rather than purely theoretical. The pitch is that a server hosting an AI model — say, one generating recommendations or processing a query — could run inference on a user's encrypted input and return an encrypted output, without the operator or an attacker who breaches the server ever seeing the underlying data in the clear. Google says it has also been working with hardware-accelerator makers, including Belfort, Niobium, Cornami and Optalysys, to speed up the computationally expensive process of running FHE workloads.
The toolchain is installable through the google/heir GitHub repository via the pip-installable heir_py package, alongside command-line and library interfaces for developers who want more direct control over the compilation pipeline. Google positions the current release as a step toward what it calls a "one-click" path to encrypted inference in production systems, though the company's own materials acknowledge FHE workloads still carry significant performance overhead compared with unencrypted computation.
The release fits a pattern of large technology companies publishing cryptography tooling as open infrastructure rather than proprietary products, a strategy that has previously helped standardize technologies from transport encryption to differential privacy libraries. Whether HEIR becomes a genuine industry default will depend on adoption by other cloud providers and independent developers, who can now inspect, modify and contribute to the compiler's source directly on GitHub.