Technology

Apple AI Will Now Run on Google, NVIDIA Tech, But What Happens to Privacy Promise

By VioNews Staff• Jul 3, 2026
Apple AI Will Now Run on Google, NVIDIA Tech, But What Happens to Privacy Promise

Apple Hands Its AI Stack to Google and NVIDIA — Privacy Claims Now Face the Biggest Test Apple built its AI identity on one idea: your data stays yours. For two years, that promise shaped every announcement, every product pitch, and every competitive comparison the company made. Privacy was not a feature; it was the foundation. Then came WWDC 2026, and that foundation shifted in ways most users had not anticipated. At the conference, Apple confirmed that its most advanced AI workloads now run on Google Cloud infrastructure, powered by NVIDIA GPUs. The company also revealed a deep collaboration with Google to build the next generation of Apple Foundation Models, drawing on technology from Google's Gemini family. The scale of these partnerships marks the most significant architectural change Apple has made since Apple Intelligence first launched in 2024. The core question, however, remains uncomfortable and urgent: what exactly happens to the privacy promise now? The Architecture That Once Defined Everything When Apple Intelligence debuted in 2024, the company introduced Private Cloud Compute (PCC) as its answer to cloud-based AI concerns. PCC operated on Apple silicon servers, under Apple's own software, with strict rules. User data would only be processed for the duration of a request. Nothing would be stored. Apple itself could not access the information. Security researchers could verify the entire system independently. That level of openness was rare among technology companies. It gave users and privacy advocates a concrete reason to believe Apple was different from rivals who had long harvested user data to train AI models. PCC was not marketing language; it was a documented, inspectable system. What WWDC 2026 Actually Changed The partnership with Google runs deeper than a simple cloud-hosting arrangement. In January 2026, Apple and Google announced a multi-year collaboration under which the next generation of Apple Foundation Models would be built using Google's Gemini models and cloud technology. That is a fundamental change in where Apple's AI capabilities originate. Apple is now collaborating with Google and NVIDIA to run new Apple Intelligence workloads on Google Cloud, extending its PCC privacy commitments to third-party data centers for the first time. The phrase "for the first time" carries weight. Apple's 2024 architecture was entirely self-contained. The 2026 version is not. Amar Subramanya, Apple's vice president responsible for AI technologies, confirmed the company works with both Google and NVIDIA to extend Private Cloud Compute to NVIDIA GPUs running in Google's cloud infrastructure. This means the most demanding Apple Intelligence tasks — complex reasoning, agentic actions across apps, may no longer touch Apple-owned hardware at any point. What NVIDIA's Confidential Computing Actually Does Apple's architecture now incorporates NVIDIA Confidential Computing alongside its existing PCC framework. The two systems address different problems and should not be treated as interchangeable. Standard encryption protects data while stored and during transmission. Processing, however, has traditionally left data exposed. NVIDIA's Confidential Computing uses hardware-based Trusted Execution Environments to address this gap. The technology creates a protected execution environment that helps keep data secure even while it is actively being processed, preventing unauthorised access. PCC on Google Cloud incorporates NVIDIA Confidential Computing with NVIDIA GPUs, Intel CPUs with TDX, and Google's Titan chip. Apple and Google then built additional protections on top of that foundation covering firmware, host and guest operating system stacks, and application code to mitigate risks that confidential computing alone cannot address. In practical terms, Apple defines the privacy rules. NVIDIA helps secure the hardware environment where those rules are enforced. The two systems work together, not as substitutes for each other. The Five Core PCC Principles and Whether They Still Hold Apple states its five original PCC requirements remain unchanged: Stateless computation — data is not retained after a request completes Enforceable guarantees — privacy protections are technically imposed, not just promised No privileged runtime access — even Apple cannot reach user data during processing Non-targetability — requests cannot be routed to specific servers to surveil individuals Verifiable transparency — all software binaries are published for public inspection Regardless of where the infrastructure is hosted, Apple retains complete control over PCC software, and Apple devices will only trust PCC software that is cryptographically approved by Apple. That control over the software layer is significant. It means Google cannot alter the privacy behavior of the system without Apple's knowledge and approval. Scale Drove the Decision The partnership with Google and NVIDIA is not merely strategic, it is a response to an enormous demand problem. According to Counterpoint Research, Apple had cumulatively shipped more than 450 million Apple Intelligence-capable iPhones by the first quarter of 2026. Apple Intelligence features also extend to iPads, Macs, Apple Watch, and Vision Pro devices, expanding the potential user base further. New Siri AI capabilities — personal context understanding, cross-app actions, on-screen content awareness, and multi-device conversation continuity, require significantly more compute than earlier assistant features. Building and scaling that infrastructure entirely in-house, at the speed required, was not feasible. Google's cloud and NVIDIA's processors offered the capacity Apple needed. Where the Real Debate Lies Apple's public position is clear: privacy protections remain unchanged. The company argues that user requests processed through PCC are still protected, data is not stored after processing, and personal information remains inaccessible to Apple, Google, or any third party. The more honest debate is not about privacy alone — it is about control. In 2024, Apple owned every layer of the stack. In 2026, the company owns the privacy architecture and the rules, but not the physical hardware or the underlying AI models. That is a different proposition, even if the stated outcomes are identical. Apple maintains a cryptographically verifiable, append-only ledger of all Google Cloud hardware that is part of the PCC fleet, and for components that could be abused to exfiltrate user data if compromised, software attestation is rooted in at least two separate roots of trust from independent vendors. The technical safeguards are real. Whether they satisfy users who trusted Apple precisely for its independence is a separate question. Final Words Apple's decision to extend Private Cloud Compute onto Google and NVIDIA infrastructure is not a retreat from privacy. The architecture, the transparency commitments, and the verification mechanisms remain in place. What has changed is the ownership of the underlying layers and for many users, that distinction will matter more than any technical explanation Apple can provide. The company now faces a challenge that no security whitepaper can fully resolve. Trust, once built on the perception of total control, must now survive a more complex story. Apple controls what the AI does with data. Google and NVIDIA control the environment in which it operates. Whether that division of responsibility holds under scrutiny from researchers, regulators, and millions of users, will define Apple's AI reputation for the years ahead. The promise was made in simpler conditions. The test of that promise begins now.