Apple is making privacy the centerpiece of its delayed AI push, telling WWDC 2026 attendees on June 9 that Apple Intelligence and the new Siri AI app collect dramatically less user data than rivals — even as the company quietly opens its Private Cloud Compute architecture to Google Cloud servers, Nvidia GPUs, Intel CPUs, and Google Titan chips. The pitch: queries run on-device where possible, and when they don't, Apple says your data won't be stored, will only be used to execute your request, and won't be accessible to Apple or anyone else.
The new Siri AI works across iPhone, iPad, Mac, Apple Watch, and Vision Pro, with a dedicated chatbot app, AI-powered camera and photo editing, and the start of an agentic layer that can act inside other apps. Conversation logs in the Siri AI app stay on-device and in end-to-end encrypted iCloud. None of that architecture is brand new — Private Cloud Compute shipped alongside the first Apple Intelligence release in 2024 — but two years on, the stakes around it have shifted.
Apple is behind almost every major competitor on AI capability, and yesterday's keynote did not close that gap. That makes the privacy story load-bearing. It is the differentiator Apple has chosen to lean on against Google Gemini, ChatGPT, and Claude, all of which lead on raw capability.
Key facts
- 01Apple's new cloud AI models are based on Google Gemini, with Private Cloud Compute now running on Google Cloud using Nvidia GPUs, Intel CPUs, and Google Titan chips.
- 02Private Cloud Compute was first announced in 2024 as Apple-silicon-only with a hardened supply chain; two years later, the perimeter has widened.
- 03Apple says it collects only limited metadata on Private Cloud Compute requests — size and duration — and no content or results.
- 04Gemini stores chat history for 18 months by default, configurable down to 72 hours; Claude retains de-identified data up to 5 years.
- 05The new Siri AI, Apple Intelligence features, and agentic capabilities span iPhone, iPad, Mac, Apple Watch, and Vision Pro.
The complication is the supply chain. When Private Cloud Compute launched in 2024, Apple emphasized that it ran exclusively on Apple silicon, with each server scanned and validated before joining the rack. The 2026 version runs partly on hardware Apple does not design or manufacture. To compensate, Apple says it now maintains a cryptographically verifiable, append-only ledger of all Google Cloud hardware used for Private Cloud Compute and retains complete control of the software. The claim is that the security and privacy properties are unchanged. Skeptics will note that a longer, more diverse supply chain mathematically introduces vulnerabilities that did not exist when one company controlled every layer.
Apple's new cloud AI models are themselves based on Google Gemini, a striking concession for a company that has spent a decade marketing vertical integration as the source of its product advantage. The trade-off is functional: by leasing Google's models and infrastructure, Apple gets to ship competitive AI in 2026 rather than 2028, while still controlling the privacy envelope around how those models are queried.
“Some appear to be racing forward, seemingly pursuing AI for the sake of AI, without clear regard for the people, all of us, that it's ultimately meant to serve”— Craig Federighi, Apple SVP of Software Engineering
Craig Federighi, Apple's SVP of software engineering, used the keynote to draw the contrast directly with rivals, saying Apple Intelligence has been designed with privacy in mind at every step.
The data-collection comparison is where Apple's pitch holds up best. Google's Private AI Compute, announced last year, is architecturally similar to Private Cloud Compute — The Verge called the two virtually identical at launch, down to the name. But Google uses it selectively, for features like Magic Cue and the Recorder app on Pixel phones, and has not said whether every Gemini query gets the same treatment. By default, Gemini collects prompts, uploaded files, recorded conversations, generated content, and metadata from connected apps and devices. Chat history is retained for 18 months, configurable down to 72 hours.
OpenAI's ChatGPT collects prompts, uploads, and location and device data, and uses chats as training data by default unless users opt out. Anthropic's Claude collects similar inputs, deletes audio recordings while keeping transcripts, defaults to using data for training, and retains de-identified data for up to 5 years. Apple's 2025 Apple Intelligence privacy policy says it collects only limited information on Private Cloud Compute requests — size and completion time — with no content of the request or its result, and says it does not use private data or user interactions to train its foundation models.
There is an awkward subtext to that last claim. Apple does not need to train on user data because Google already did, on its own users. The Gemini partnership is both the reason Apple can credibly offer functional AI in 2026 and the reason its privacy claim survives — it has outsourced the data-hungry part of model development to a company whose entire business model depends on collecting that data.
The risks are real and named. The expanded Private Cloud Compute is harder to audit than the Apple-silicon-only version. Apple is now dependent on Google for model weights and on Nvidia and Intel for chips, which means a security incident at any of those vendors becomes Apple's incident too. And Apple Intelligence remains feature-thin compared to ChatGPT and Gemini, which raises the question of whether privacy alone can carry the category for the install base.
Apple's bet is that for a meaningful slice of its users, default data minimization beats raw model capability — and that the supply-chain compromises required to ship in 2026 are invisible to anyone who isn't reading the privacy policy. That bet is defensible. Most consumers will not parse the difference between an on-device query and a Private Cloud Compute query routed through Google's data center, and they will not notice that Siri AI is partly Gemini under the hood. What they will notice is whether the features work, and whether Apple's privacy story holds the next time a researcher pokes at the new perimeter. If it does, Apple has a category position no rival can easily copy. If it doesn't, the entire AI pitch collapses into the one thing Apple cannot afford: a broken promise.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




