Skip to content

What is homomorphic encryption? Computing on data without ever reading it

Processing numerical data without decrypting it seems impossible. It is mathematically feasible, and it could resolve the dilemma between AI and privacy.

Advertisement
The idea that seems impossible 🔐
Imagine handing a locked safe to someone, having them work on its contents without ever opening it, and getting the safe back with the result inside. Only you can open it. They did the work without ever seeing what they were working on. That's exactly what homomorphic encryption makes possible, and it's not magic but mathematics.

Google recently highlighted work in this area, and the topic deserves an explanation because it touches on the central dilemma of enterprise AI: how to use a remote service without entrusting it with your data.

The principle

Classic encryption protects data at rest or in transit. But to process it, you have to decrypt it. That's the moment when it's exposed, and it's that moment that becomes a problem when the processing happens on someone else's infrastructure.

Homomorphic encryption has a remarkable property: certain mathematical operations performed on encrypted data produce a result that, once decrypted, matches the result you would have obtained on the plaintext data.

In other words, you can add two encrypted numbers without knowing what they are, and get the encryption of their sum. By combining additions and multiplications, you can theoretically compute anything.

What it would solve for AI

The use case is obvious and substantial. A company wants to analyse medical records, legal documents or financial data with a powerful model hosted elsewhere. Today, it has the choice between sending its data in plaintext to the provider, or giving up.

That's what pushes many organisations towards local hosting, with the hardware constraints that entails. Homomorphic encryption would offer a third path: using a remote service that never sees anything.

The limitation that blocks everything: cost ⏱️
This technique has been known for a long time, and if it isn't deployed everywhere, it's because it's extraordinarily expensive in computational terms. Depending on the schemes and operations, the overhead compared to plaintext computation can reach several orders of magnitude. Applying that to a model that already performs billions of operations per request yields something that is impractical today. Progress is real and fast, but we're talking about a technology approaching use on targeted operations, not a solution available for running an entire model.

What's realistic in the short term

Rather than encrypting the entire process, promising approaches target specific steps.

Encrypted search. Querying a database without the server knowing what you're looking for or what it returned to you. This applies directly to RAG systems.

Statistical aggregation. Computing averages or trends across data from multiple organisations without any of them seeing the others' data.

Targeted sensitive operations. A specific operation on a critical piece of data, rather than a full pipeline.

What to take away

Homomorphic encryption is one of those technologies whose promise is so strong that it has regularly been presented as imminent for fifteen years. Caution is therefore warranted on timelines.

But the direction matters. Most current debates about AI and privacy rest on a trade-off: either you hand over your data, or you forgo the power. A technology that removed that trade-off wouldn't make the question moot; it would shift it to more favourable ground.

In the meantime, the only guarantee that's actually available remains the simplest one: what doesn't leave your premises can't be read. It's less mathematically elegant, and it works today.

Advertisement