Skip to main content
Live
Main content

Nvidia Blackwell GPUs land inside Apple's Private Cloud Compute on Google Cloud

Apple is extending its server-side Apple Intelligence stack onto Nvidia Confidential Computing running on Google Cloud infrastructure.

Jaeden Schafer
Editor in Chief · · 4 min read
Nvidia logo

Nvidia Blackwell GPUs with Confidential Computing are now running confidential inference inside Apple's Private Cloud Compute, and that stack is moving off Apple's own data centers and onto Google Cloud. The arrangement, disclosed June 9, 2026 during Apple's WWDC, threads three of the most consequential names in AI infrastructure — Nvidia, Apple, and Google — into a single server-side pipeline for Apple Intelligence.

The Blackwell GPUs will support server-side inference for Apple Foundation Models, which Apple and Google are custom-building using the technologies behind the Gemini family. In other words, when an iPhone, iPad, or Mac kicks a request up to the cloud, that request can now land on Nvidia silicon sitting inside Google's data centers, executing models co-developed by Google, under a security envelope designed by Apple.

This is a striking departure from Apple's historical posture. Private Cloud Compute was introduced as Apple's answer to the trust problem of cloud AI: hardware Apple designed, operated in Apple-controlled facilities, with verifiable attestation that user data could not be retained or inspected. Extending that perimeter to Google Cloud and Nvidia GPUs means Apple has decided the cryptographic guarantees of Confidential Computing are strong enough to substitute for physical control of the room.

Key facts

  • 01Nvidia Blackwell GPUs with Confidential Computing now power server-side inference inside Apple's Private Cloud Compute.
  • 02Private Cloud Compute is expanding beyond Apple's own data centers to run on Google Cloud.
  • 03Apple Foundation Models are being custom-built by Apple and Google using technology from the Gemini family.
  • 04The arrangement was disclosed alongside Apple's WWDC announcements on June 9, 2026.
  • 05Nvidia CEO Jensen Huang is scheduled to deliver a GTC Taipei keynote on June 1 at 11 a.m. Taipei Time.

Nvidia frames Confidential Computing as a hardware-rooted trust layer for accelerated AI workloads. The technology isolates workloads inside trusted execution environments on the GPU, encrypts communication paths between components, and supports remote attestation so the calling software can verify the platform's security state before releasing sensitive data. The pitch is that none of those guarantees require giving up GPU performance for inference or training.

As AI experiences combine on-device and cloud-based processing for their tasks, there's a need for high-performance, server-side inference while maintaining strong privacy and security guarantees.
Avinash Ahuja, Nvidia

For Apple, the appeal is operational. Building out enough M-series server capacity to handle global Apple Intelligence demand is a multi-year exercise. Renting Blackwell capacity on Google Cloud, with Confidential Computing as the privacy backstop, lets Apple scale Apple Intelligence features without waiting for its own silicon roadmap. It also explains why Apple was willing to lean on Google for the underlying foundation model work in the first place: if you are already co-developing the model with Google, running it on Google's infrastructure is a smaller leap.

The security model is the entire point of the announcement. Nvidia's Avinash Ahuja, writing on the company blog, argues that Confidential Computing closes the gap between on-device privacy and cloud-scale inference, with attestation guarantees meant to satisfy users who would otherwise refuse to let their data leave the device. Whether that argument holds up under scrutiny from regulators, security researchers, and Apple's own privacy-conscious user base is the open question.

For end users, NVIDIA Confidential Computing means that no one, not even the system's builders, can look at their data, chats or conversations.
Avinash Ahuja, Nvidia

For Nvidia, this is a credibility win for Confidential Computing as a product category. Apple does not put its name on infrastructure casually, and a public reference customer of this profile makes it materially easier for Nvidia to sell the same capability to banks, healthcare systems, and governments that have so far hesitated to run sensitive inference workloads on shared GPU infrastructure. The Confidential Computing pitch — hardware-rooted trust, encrypted data paths, remote attestation, no performance penalty — now ships with Apple's implicit endorsement.

For Google Cloud, the win is volume. Hosting Apple Intelligence inference traffic, even a portion of it, is a meaningful workload, and it positions Google Cloud as a viable home for privacy-sensitive AI even when the customer is a direct competitor in the consumer device market. The detail that Apple Foundation Models are being custom-built by Apple and Google using Gemini-family technology also strengthens Google's narrative that its model stack is the one other hyperscalers' customers want to license.

Related · from this week
Apple trained a custom China AI model with Alibaba, Reuters reports
Jaeden Schafer · 4 min read →

The risks are real. Confidential Computing is only as strong as the attestation chain and the absence of side-channel vulnerabilities in the GPU itself, and the security research community has historically found ways to chip away at trusted execution environments on every platform that has shipped one. A single credible compromise of the Blackwell Confidential Computing path would land squarely on Apple's privacy brand, not just Nvidia's, which is precisely why Apple's willingness to extend Private Cloud Compute onto third-party infrastructure is the news.

The deeper signal is that the AI infrastructure market is consolidating around a small number of trust-and-performance bundles. Apple has effectively concluded that running Apple Intelligence at the scale users now expect requires Nvidia GPUs and hyperscaler capacity, and that the way to preserve its privacy positioning is to bolt cryptographic attestation onto someone else's data center rather than build out its own. If that bet works, expect every other consumer-AI company with a privacy story to follow the same template — Nvidia Confidential Computing on a hyperscaler, dressed in the brand's own attestation language. If it doesn't, Apple will be the one explaining why.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Business

Apple trained a custom China AI model with Alibaba, Reuters reports
Business

Apple trained a custom China AI model with Alibaba, Reuters reports

The partnership would make Apple the first US company approved to offer a proprietary AI model in China, ahead of an Apple Intelligence rollout.

Jaeden Schafer4 min read
Apple wires Mac users in China into Alibaba's Qwen AI service
Business

Apple wires Mac users in China into Alibaba's Qwen AI service

Apple has cleared the way for Mac users in China to connect to Alibaba's Qwen models, its latest workaround for a regulatory wall that blocks its own AI stack.

Jaeden Schafer4 min read
Intel jumps 9% after Trump announces Apple chip design deal
Business

Intel jumps 9% after Trump announces Apple chip design deal

The president said on Truth Social that Apple will design and build chips with Intel in the U.S., extending a run that has lifted Intel 464% in 12 months.

Jaeden Schafer4 min read