Own your keys: passkeys, your own AI and real decentralisation

Centralised databases are honeypots. Passkeys move the key back to you — and combined with client-side encryption and permissioned AI, they make a genuinely user-owned model possible.

"Decentralisation" has been stretched to mean many things. For personal data, the useful definition is simple: who holds the keys? If a company holds the keys to your data, it's centralised, however many servers it runs on. If you hold them, it's yours.

The problem with the old model

For most of the internet's history, the default architecture has been:

  • you create a password — a secret shared with the service;
  • the service stores your data on its servers, encrypted (if at all) with keys it controls;
  • other apps get access through broad permissions that rarely expire.

Every one of those choices concentrates power — and risk — in the middle. A single breach of a central database can expose millions of people at once, which is why these databases are such attractive targets. The economics are stark: IBM's 2026 Cost of a Data Breach report puts the global average cost of a breach at a record $4.99 million. (We dig into the numbers in why personal data is vulnerable.)

Step one: passkeys decentralise identity

Passkeys quietly change the first of those choices. Instead of a shared secret stored by the service, you hold a private key on your own device and the service holds only a public key. There's no central pile of passwords to steal. Authentication moves from "something the server knows about you" to "something only you have".

With five billion passkeys now in use, according to the FIDO Alliance, this is no longer a niche idea. It's how a large share of the world already signs in. (More in Passkeys went mainstream.)

Step two: encrypt before it leaves your device

The second step is to apply the same principle to the data itself. With client-side (end-to-end) encryption, your files are encrypted on your device before they're uploaded, using keys that never reach the server. The service stores ciphertext it cannot read. This is often called a zero-knowledge design: the provider can host your data without being able to see it — or hand it over in readable form.

Link the encryption keys to your passkey and the two steps connect: the key that proves who you are is also the root of the key that unlocks your data.

Step three: give AI permission, not possession

The third step is the one that's new. AI agents will need context to work for us. In the old model, you'd give an app sweeping access and hope for the best. In a user-owned model:

  • the AI gets a scoped grant — only the slice of data a task needs;
  • the grant expires automatically;
  • every access is logged where you can see it;
  • you can revoke it instantly.

The AI works for you, using data you've unlocked for it, for a limited time. That's what we mean by decentralisation with AI power: the intelligence can come from any provider, but the keys, the data and the permissions stay with you.

What it isn't

It's worth being precise. This isn't a blockchain, and it doesn't mean your data lives only on your phone. Encrypted data can still be stored in the cloud for reliability; passkeys commonly sync through Apple, Google or Microsoft keychains. The decentralisation is about control and readability — who can decrypt, who can grant access — not about where the bytes physically sit.

The direction of travel

Identity is already moving to user-held keys. Encryption is moving to the client. AI is moving to agents that act on our behalf. Put together, they point to a future where the default is that you own your keys, your data and your AI's permissions.

That's the architecture we're building AI Memory Vault on. See how the pieces fit together in Inside AI Memory Vault.

Frequently asked questions

Do passkeys make the internet decentralised?

They decentralise authentication: instead of a shared password stored by every service, you hold a private key and services hold only public keys, so there is no central pile of secrets to steal.

What is zero-knowledge encryption?

A design where data is encrypted on your device with keys the provider never has, so the provider can store your data without being able to read it.

Sources

  1. IBM — Cost of a Data Breach Report 2026 (key findings via eSecurity Planet)
  2. FIDO Alliance — Five Billion Passkeys: World Passkey Day 2026
  3. FIDO Alliance — Five billion passkeys: a milestone, not a finish line
  4. NIST — Syncable authenticators (glossary / SP 800-63)

Figures are as reported by the sources above at the time of writing; survey data from vendors is indicative. AI Memory Vault is in private beta — product details describe how it is designed.

Follow Hushkey:

AI Memory Vault

Give your AI a memory you own.

Private, encrypted, passkey-protected — with permissioned access for your AI agents. Join the private beta waitlist.

No spam. One email when your invite is ready.

Keep reading

Inside AI Memory Vault: how the architecture differs from the last generation

Passkey-derived keys, on-device AES-256-GCM encryption, zero-knowledge storage and permissioned AI agents. How AI Memory Vault is built, and why the future needs it.

Your personal data is scattered — and that’s the security problem

Record breach costs, AI-assisted attacks and data spread across dozens of apps. What the 2026 IBM and Verizon reports tell us, and what a safer home for personal data looks like.