TL;DR: Amazon announced Throw Away the Key Encryption (TAKE) for Ring cameras on August 26, 2026, and says it is rolling out in phases starting in September as the new default for every Ring customer worldwide.[1][2] Under TAKE, Ring holds a copy of your video keys inside a cloud secure enclave for a 24-hour window so its cloud features can process your footage, then deletes that copy; your phone can hand the keys back whenever a feature needs older video.[2] That is better than the encryption-at-rest Ring uses today and it is not end-to-end encryption, which Ring still offers as an option and which its help page now labels "legacy".[3] The Electronic Frontier Foundation's verdict, published September 11: TAKE is "barely different from encryption at rest where the server holds the keys", and a company that holds keys at any point can be ordered to keep holding them.[4] If you want footage that Ring cannot read, the setting to turn on is still end-to-end encryption, and it still costs you most of the cloud features.
What Ring announced
Amazon's announcement frames TAKE as "a new industry standard for default encryption and control" and says it is "inspired by the privacy principles of E2EE (end-to-end encryption)" while "maintaining the full Ring experience and suite of features."[1] The mechanics, in Amazon's words: "A copy of the keys is temporarily held inside a secure enclave within the cloud", and Ring "can only receive access to power the intelligent features that you have active on your account, and then throws away and deletes the keys."[1]
The accompanying white paper is more specific. "TAKE implements a 24-hour key retention window. During this window, content encryption keys are managed within AWS Nitro Enclaves and made available to platform services only for the duration of feature processing."[2] And: "Ring permanently deletes its copy of your keys after 24 hours. If you later enable a feature that needs to process older videos, your Ring app can temporarily provide the keys to power that feature, and Ring deletes them again afterward."[2] The features that need this cloud access are the ones most people leave on: the white paper names "cloud-based Smart Alerts, Video Search, Smart Video Descriptions, and other cloud-based analysis."[2]
Today, before TAKE, Amazon says "Your Ring videos are already encrypted when they travel to the cloud and while they are stored at rest."[1] Encrypted at rest with the service holding the key is the arrangement most cloud services use, and it is the arrangement a subpoena reaches. TAKE narrows the window in which Ring holds a usable key; it does not close it.
Why this is not end-to-end encryption
Ring itself draws the line clearly. The white paper says the key-retention behaviour "exist[s] only under TAKE; under End-to-End Encryption, Ring's cloud never holds decryption keys".[2] Amazon's announcement says Ring was "the first major smart home security provider to offer video E2EE to customers" back in 2021, that "With E2EE enabled, only your enrolled devices ever have access to your encryption keys", and that E2EE "will remain in place today as an option."[1]
EFF's analysis, published September 11, puts the difference in operational terms. Because the cloud must decrypt footage to run smart features, "Ring gets access to footage stored in the cloud for 24 hours", and "keys are still released to services that can be modified." Its conclusion: "In practice, that makes the system as a whole barely different from encryption at rest where the server holds the keys." In EFF's reading the phone simply takes the role a hardware security module would play, handing the keys back to the server whenever they are needed.[4] EFF also credits Ring for not overclaiming: "TAKE is not end-to-end encryption, where Ring would never have access to the keys, and the company thankfully doesn't claim it as such."[4]
Two further points from EFF matter for anyone whose threat model includes a records request. First, the metadata the smart features generate does not go away when the key does. EFF points out that offering Video Search and Smart Video Descriptions to the owner means that even where "the footage can't be seen by Ring, descriptions are readily available to the company".[4] Ring told EFF that "As Ring continues to expand and further strengthen TAKE's protections, video descriptions will be included."[4] Second, EFF notes that "account recovery keys are stored in the camera itself by default", and sketches how a mass search of descriptions followed by seizure of specific cameras could reach the footage.[4] Ring's white paper does list a camera-based recovery method among the ways a customer can regain access to keys after losing a phone.[2]
What Ring says about legal requests, and what it did not answer
Ring's statement to EFF: "By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content. With TAKE, Ring will only preserve and provide encrypted video files in response to valid legal process. It has been and continues to be Ring's policy to object to overbroad legal requests."[4] The white paper adds that Ring has "updated our Law Enforcement Guidelines to reflect changes resulting from the TAKE architecture."[2]
The question EFF put and did not get answered is the one that separates this design from end-to-end encryption. In EFF's words: "Ring could receive an order that demands they save content encryption keys or unencrypted videos from memory to disk, which would mean they'd retain some level of access." EFF "specifically asked about the possibility of complying with law enforcement orders to modify existing practice to turn over or preserve unencrypted video, which appears to be technically possible, but the company did not address it."[4] On independent verification, Ring told EFF that "critical components of TAKE's infrastructure underwent independent security testing prior to launch. We are exploring options for further independent review."[4]
What to do with your own Ring cameras
If your concern is Ring, or anyone who can compel Ring, reading your footage, the setting that delivers that is still end-to-end encryption, and it is opt-in. Ring's help page, now titled "Using legacy video end-to-end encryption (E2EE)", describes it plainly: "Only your enrolled mobile device can enter this passphrase to view recordings from end-to-end-enabled devices. No one else, including Ring, can access your encrypted content."[3] The path in the app is Control Center, then Video Encryption, then End-to-End Encryption, and it requires iOS 17 or Android 9 or newer; the help page also lists several older cameras, including the first-generation Video Doorbell and Stick Up Cam, as not compatible.[3]
The cost is the feature list. The same page says that with E2EE enabled, Shared User access, video links, viewing on Ring.com, the Event Timeline, Video Search, Pre-Roll, Rich Notifications, Person Detection, Video Descriptions and Familiar Faces are among the functions that "will NOT be available" for enrolled devices, along with watching video on Echo Show or Fire TV.[3] One item on that list is worth a second look before you rely on either document: the help page lists 24/7 Video Recording as unavailable under E2EE, while the white paper says "Features that do not require Ring to process video, such as Live View, event playback, and 24/7 recording, keep working."[2][3] Ring's own documents disagree on that point; check the app after enrolling rather than assuming.
Two practical notes. Amazon says encryption can be managed "on a per-device basis," so a camera watching the street can stay on TAKE with smart alerts while a camera inside the home goes end-to-end.[1] And the help page warns that if you later unenroll from E2EE, "you will lose access to previously recorded encrypted videos".[3] Save the passphrase somewhere that survives a lost phone.
Where this leaves the default: every Ring customer who does nothing will move from encryption at rest, where Ring holds the key permanently, to TAKE, where Ring holds it for a day at a time and gets it back on demand. That is an improvement in the amount of footage available to Ring at any given moment. It is not a change in who can ultimately be made to hand footage over. The label Ring chose for the setting that does change that, "legacy," is the detail worth remembering.
References
- Amazon: Ring TAKE: How Throw Away the Key Encryption protects your videos (August 26, 2026)
- Ring: Throw Away the Key Encryption | End-to-End Encryption, white paper (PDF, August 26, 2026)
- Ring Help: Using legacy video end-to-end encryption (E2EE)
- Electronic Frontier Foundation: Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy (September 11, 2026)