Amazon's Ring unit said on August 26, 2026 that a scheme called TAKE will become the default encryption for customer video worldwide, with a phased rollout beginning in September and end-to-end encryption remaining an optional setting.
The announcement appeared on Amazon's corporate news site under the byline Amazon Staff. It carries no named spokesperson, no engineering detail beyond a handful of sentences, and no date for when the worldwide rollout completes. What it does carry is a change to the default state of every camera and doorbell Ring has in service.
TAKE stands for Throw Away the Key Encryption. According to Ring, the design is drawn from the privacy principles behind end-to-end encryption but built for a different problem: a household security product whose value depends on cloud processing that end-to-end encryption forecloses.
What changes at the key layer
Ring video was already encrypted in two states before the announcement. According to the company, footage is encrypted in transit to the cloud and encrypted at rest once stored there. Neither of those properties is new, and neither addresses the question TAKE is aimed at, which is who holds the key.
Under TAKE, according to Ring, videos are protected with unique, rotating encryption keys. A copy of those keys is held temporarily inside what the company describes as a secure enclave within the cloud, a sealed environment that releases the key to Ring only under conditions the announcement characterises as strict and limited. Ring receives access solely to run the intelligent features a customer has switched on, and then, in the company's phrasing, throws away and deletes the keys.
What remains after that step is the part Ring is selling. Only the account holder and any trusted Shared Users granted permission retain the keys, and they retain them on enrolled devices: a phone, a tablet, a computer. The cloud copy is gone. The named example of an intelligent feature that survives the arrangement is Smart Alerts.
The company frames the arrangement through an analogy about house keys, arguing that a lock manufacturer does not keep a copy, that a spare might go to a trusted relative, and that a tradesperson gets one only for the duration of a job. The analogy carries the intended point about custody. It does not describe rotation intervals, enclave attestation, or the duration of "temporarily," none of which appear anywhere in the announcement.
The gap between the claim and the disclosure
Two statements in the announcement sit in tension, and the announcement does not reconcile them. The first is that the keys are held in the cloud enclave and released to Ring under limited conditions. The second is that only the customer retains the keys. Both are true at different points in the sequence, but the announcement moves between them without marking the transition, and a reader could reasonably come away believing that Ring never has key access at all.
The unstated variables matter more than the analogy. The announcement does not name the enclave technology or the silicon behind it. It does not state how frequently keys rotate, how long a copy persists inside the enclave, what the "strict, limited conditions" governing release actually are, or whether any third party can attest that the deletion step executes as described. It does not say what happens to key custody when a law enforcement request arrives, a question that has followed Ring since its Neighbors partnerships drew congressional attention. Ring points to a white paper on the upgrade and to its privacy page for further detail; the announcement itself contains none of it.
There is also a calendar ambiguity. The rollout is described as beginning "in September" with no year attached, and the announcement was published in August 2026, so September 2026 is the reasonable inference. No completion date is given for the phased worldwide deployment. A default that is announced and a default that is in force are different things, and the announcement supplies only the first.
E2EE stays, with its trade-offs unchanged
Ring introduced video end-to-end encryption in 2021, describing itself at the time as the first major smart home security provider to offer it. That option survives TAKE and remains available on a per-device basis, switchable at any time from the Ring app.
The reason E2EE never became the default is stated plainly. According to Ring, when E2EE is enabled only enrolled devices ever hold the encryption keys, and because access is limited by design, Shared Users and cloud-based features are unavailable. Live view, playback and video sharing continue to function. Everything that requires the cloud to look at a frame does not.
That is the trade that TAKE is engineered around. The company is not claiming that TAKE equals E2EE. It is claiming that TAKE preserves the feature set while removing Ring's persistent key custody, which is a narrower and more testable proposition than the marketing language around it suggests.
The direction of travel across the wider platform market has not been uniform. Meta confirmed that end-to-end encryption for Instagram direct messages would stop functioning after May 8, 2026, retiring a capability rather than extending it. Signal threatened to withdraw from Germany over a proposal to scan content before encryption. Brazil's regulator, examining Discord, declined to treat encryption itself as a violation while holding that a provider whose architecture makes a control unworkable carries the burden of substituting an equivalent one. Ring is moving in the opposite direction from Meta and toward the position that regulator described.
Why an encryption default lands on an advertising beat
The announcement makes no reference to advertising, and nothing in it suggests Ring video has been used for ad targeting. The relevance runs through architecture rather than through any disclosed data flow.
Amazon reported advertising services revenue of 19.8 billion dollars for the second quarter of 2026, a 26% year-over-year increase and the company's strongest disclosed growth rate across six quarters. That business is built on first-party signal originating from surfaces Amazon owns. The company has been extending those surfaces steadily: four Echo devices with custom AZ3 silicon and the Omnisense sensor platform in September 2025, an Alexa+ push into Samsung televisions and BMW vehicles in January 2026, and the Ember television line with Omnisense ambient sensing in June 2026.
Omnisense is the useful comparison. That platform processes sensor data locally on custom silicon rather than shipping raw video to servers, which is a hardware answer to the same question TAKE answers in cryptography: how much of what a home device observes ever becomes legible to the operator. Both approaches lower the ceiling on what signal can exist, and a signal that cannot exist cannot later be repurposed. For anyone modelling the long-run supply of household-level data inside Amazon's ecosystem, the ceiling is the number that matters, not the current use.
The counterweight is that TAKE explicitly preserves cloud feature processing. Ring is not removing its ability to analyse footage; it is removing its ability to retain the means of decrypting footage after analysis completes. Those are different commitments, and only the second is what TAKE describes.
There is also a competitive read. Device data does not necessarily stay inside the manufacturer's app. A proposed class action filed in the Northern District of California on August 20, 2026 against Oura, six days before the Ring announcement, contested advertised sleep staging figures for a device whose readings Amazon had already confirmed would surface inside Alexa+. Consumer hardware claims about data handling are now litigated as advertising claims, and a company that publishes a specific mechanism has published something a plaintiff can measure against.
Regulatory timing
The September start date sits close to a European deadline. Manufacturers must design connected products and associated services so that data is directly accessible to users by September 12, 2026 under the EU Data Act, a requirement the French authority CNIL confirmed in December 2025 guidance applies to any device communicating over public networks. Germany named the Bundesnetzagentur as its competent national authority for the regulation in May 2026, giving the obligation a domestic enforcement route.
The interaction between the Data Act and TAKE is not settled by either document. A regime built on user data access and a scheme built on making the manufacturer's copy of the decryption key disappear point in compatible directions on custody, and in less obvious directions on portability, since data a manufacturer cannot read is also data a manufacturer cannot easily hand over in a machine-readable format. Ring's announcement does not mention the Data Act. Whether the September timing is a response to it or a coincidence is not stated.
Amazon carries other European obligations that bear on device data. Amazon Advertising is separately designated under the Digital Markets Act, which bars gatekeepers from combining personal data across their own services or processing end-user data collected from third-party services for advertising without consent meeting the GDPR standard. Legitimate interest does not qualify. In the EEA, where the GDPR binds across all thirty states while gatekeeper obligations bind across the EU 27, an architecture that keeps a category of household video cryptographically out of reach removes a combination question before it can be asked.
Enclaves as the industry's shared answer
The secure enclave Ring describes is the same primitive that has become standard equipment in privacy-preserving advertising infrastructure over the past two years, which is why the announcement reads as familiar to an ad tech audience despite covering a consumer camera.
Google introduced Confidential Matching in September 2024, built on trusted execution environments, with Kamal Janardhan, Senior Director of Product Management for Measurement, describing it as isolating business information during processing so that nobody, Google included, can access the data being handled. The company extended confidential computing to Google tag gateway on Google Cloud by June 2026, and routed EEA signals through on-device processing, trusted execution environments and secure multi-party computation when it began processing IP addresses for ad measurement from August 3, 2026. Reddit and Mozilla-owned Anonym built a measurement layer on the same three components in April 2026. Meta moved Messenger's link-safety checks into a hardware-attested enclave running on AMD SEV-SNP.
The common structure is that protection becomes technical rather than contractual. A promise not to look is auditable only through governance; an architecture that prevents looking is auditable through attestation. That distinction is the whole argument, and it depends entirely on whether the attestation is published and independently verifiable. Ring's announcement does not indicate that it is.
Regulators have already tested the limits of similar claims. The Federal Trade Commission warned in November 2024 that data clean rooms are not a privacy guarantee, a caution the VAB omitted from its July 2026 buyer guidance on identity and clean room questions. The pattern holds here: enclave language sets an expectation that only documentation can discharge.
What the announcement leaves open
Several questions survive the publication. The rollout has no stated completion date, so the population covered by the new default at any given moment is unknown. The enclave has no named technology, no stated attestation mechanism, and no published retention window for the temporary key copy. The interaction with law enforcement requests is unaddressed. Adoption figures for the 2021 end-to-end encryption option, which would indicate how many customers ever wanted maximum control at the cost of Shared Users and cloud features, are absent.
For a publication covering how household data becomes commercial signal, the durable point is narrower than the announcement's framing. Ring has committed, in public and in specific mechanical terms, to deleting its copy of a decryption key after a defined processing step. That commitment is now on the record for a device fleet operated by a company running a 19.8 billion dollar quarterly advertising business. Whether the mechanism performs as described is a question the white paper may answer and the announcement does not.
Timeline
- 2021: Ring introduces video end-to-end encryption, describing itself as the first major smart home security provider to offer it
- September 2024: Google introduces Confidential Matching built on trusted execution environments
- November 13, 2024: The Federal Trade Commission warns that data clean rooms carry complicated privacy implications despite marketing claims
- September 30, 2025: Amazon announces four Echo devices with AZ3 silicon and the Omnisense sensor platform, processing sensor data locally rather than sending raw video to servers
- December 22, 2025: CNIL issues guidance confirming the EU Data Act's connected product access requirementapplies to devices communicating over public networks
- January 2026: Amazon extends Alexa+ to Samsung televisions and BMW vehicles
- March 9, 2026: Meta publishes the engineering account of Messenger's enclave-based Advanced Browsing Protection
- April 2, 2026: Reddit and Anonym announce a measurement layer built on trusted execution environments, end-to-end encryption and differential privacy
- May 8, 2026: End-to-end encryption for Instagram direct messages stops functioning
- May 2026: Germany names the Bundesnetzagentur as competent authority for the European Data Act
- June 2026: Amazon rebrands its televisions as Ember and ships the Artline with Omnisense ambient sensing
- July 30, 2026: Amazon reports second-quarter advertising services revenue of 19.8 billion dollars, up 26%
- August 3, 2026: Google begins processing IP addresses for ad measurement across the EEA, the UK and Switzerland using enclave-based processing
- August 20, 2026: A proposed class action against Oura contests advertised sleep staging accuracy for a device whose data routes into Alexa+
- August 26, 2026: Ring announces TAKE as the forthcoming default encryption for all customers worldwide
- September 2026: Phased rollout of TAKE begins, per the announcement
- September 12, 2026: EU Data Act requirement takes effect for connected products to make data directly accessible to users
Related PPC Land coverage
- Europe's Data Act reshapes connected device rules for marketers - Sets out the September 12, 2026 design obligation for connected products and the CNIL guidance interpreting its scope.
- Germany's Data Act enforcer goes live, and marketers should pay attention - Documents the Bundesnetzagentur's designation and the domestic enforcement structure behind the Data Act timetable.
- Amazon announces four new Echo devices with custom silicon for Alexa+ - Details the Omnisense platform and the local-processing architecture that parallels TAKE's cryptographic approach.
- Amazon advertising gains 26% to $19.8 billion as sports inventory sells out - Establishes the commercial scale of the advertising business attached to Amazon's device fleet.
- Instagram is killing its end-to-end encrypted chats - here's what changes May 8 - The counter-example of a major platform retiring end-to-end encryption rather than extending default protection.
- Meta's Messenger gets a cryptographic shield nobody asked about - but everyone needed - Explains hardware-attested enclave processing in a consumer messaging product.
- Reddit and Anonym's data deal: no first-party data leaves, ever - Describes trusted execution environments as the basis for advertising measurement without raw data transfer.
- Google introduces Confidential Matching to enhance advertiser data - The 2024 launch that established enclave processing as standard advertising infrastructure.
- Google to bring IP-based ads to EEA publishers from August 3 - Shows privacy-enhancing technologies deployed as the compliance basis for a European signal expansion.
- Signal threatens to exit Germany over Chat Control vote - Background on the European policy pressure surrounding encryption architecture.
- Oura sued over 95% sleep staging accuracy claim in ads - Illustrates how connected-device claims are now contested as advertising representations.
- Six identity questions VAB says every ad buyer must ask their vendor - Covers clean room definitions and the regulatory caution buyer guidance tends to omit.
Summary
Who: Ring, the home security subsidiary Amazon acquired in 2018, publishing through Amazon's corporate news site under an Amazon Staff byline with no named spokesperson. The change affects all Ring camera and doorbell customers, including Shared Users granted access to an account's footage.
What: TAKE, short for Throw Away the Key Encryption, a scheme in which Ring video is protected by unique rotating keys, a copy of which is held temporarily in a cloud secure enclave, released to Ring only to run active intelligent features such as Smart Alerts, then deleted. Afterwards only the customer and any trusted Shared Users hold keys on enrolled devices. End-to-end encryption, first offered in 2021, remains available as an option on a per-device basis, with Shared Users and cloud features unavailable when it is enabled.
When: Announced August 26, 2026. Phased rollout begins in September, with no completion date stated. The start coincides with the EU Data Act's September 12, 2026 connected product design obligation.
Where: Worldwide once fully deployed, according to the announcement, with encryption settings managed per device inside the Ring app.
Why: According to Ring, the design delivers the full feature set while leaving customers holding the keys, addressing the trade-off that has kept end-to-end encryption an opt-in setting since 2021 because it disables Shared Users and cloud-based features.
Discussion