In June 2026, Apple announced something that would have seemed unthinkable two years earlier: Apple Intelligence requests will now also run on Google servers with NVIDIA chips. What is supposed to make that possible is, of all things, the technology Apple introduced in 2024 to build cloud AI fundamentally differently from the rest of the industry: Private Cloud Compute, or PCC. Time to take a closer look - what it is, how it works, and whether the promise holds up.
What Private Cloud Compute is
Apple's long-standing position was simple: AI runs on the device, period. Photo analysis, text recognition, dictation - all local, nothing leaves the iPhone. Generative AI breaks that approach. Large language models need more compute and memory than a phone can deliver, no matter how good the Neural Engine gets.
The industry's standard answer is: send it to the cloud, where the provider sees everything. Requests get logged, sampled and read by employees, and sometimes used for training. Apple's answer from June 2024 is Private Cloud Compute: its own servers that extend the iPhone's security architecture into the cloud. Simple requests still stay on the device; only what cannot be computed there goes to PCC.
How it works
Apple defines five requirements that the system is meant to enforce technically - not by policy, but by architecture:
- Stateless computation: User data is used only to answer the request and deleted afterwards. No logs, no training, no leftovers.
- Enforceable guarantees: The promises must not depend on operational pledges; they have to be technically enforced.
- No privileged runtime access: There is no admin shell and no debug interface that would let Apple staff bypass the protections - not even for troubleshooting.
- Non-targetability: An attacker cannot single out a specific user. Requests pass through a third-party relay that hides the IP address before they reach a random PCC node.
- Verifiable transparency: Security researchers can verify that the software Apple claims to run is actually running.
The last point is the real trick. Every production server image is recorded in a public, append-only transparency log. Before the iPhone sends a request, it demands cryptographic proof from the server (an attestation signed by the server's Secure Enclave) of which software is running - and refuses to communicate if the image is not in the log. Apple therefore cannot quietly roll out a backdoored version without it being detectable in principle. The servers themselves are Apple Silicon machines with Secure Boot and a hardened operating system, and each request is end-to-end encrypted to the specific node.
Verifiable instead of merely promised
In October 2024, Apple followed up: a detailed security guide, a virtual research environment that lets anyone rebuild and inspect a PCC node on an Apple Silicon Mac, and the source code of key components on GitHub. Anyone who finds a way to remotely access request data can earn up to 1,000,000 US dollars in bug bounty. That is not proof of security, but it is a far stronger signal than the privacy policy of your average chatbot provider.
The 2026 twist: PCC on someone else's hardware
With the new Siri generation and the Gemini-based Apple Foundation Models, Apple's own server fleet is no longer enough. The most demanding tasks - agentic tool use, complex reasoning - will now run on Google Cloud with NVIDIA GPUs. Apple stresses that all five requirements remain in place. Technically, though, the foundation changes: instead of Apple's own Apple Silicon servers, it is now NVIDIA Confidential Computing, Intel CPUs with TDX, and Google's Titan chip. Apple says it does not rely solely on the vendors' confidential computing promises but requires at least two independent roots of trust for critical components.
Still, this step genuinely stretches the model. In 2024 the argument was: we control every screw, from the chip to the operating system. In 2026 it is: we control the cryptography and the software; the hardware belongs to someone else. That can work - but it asks for a bigger leap of faith.
Good or bad?
The honest answer: far better than anything comparable, but not a blank check.
On the plus side stands a system that leaves conventional cloud AI far behind. With a typical chatbot provider, what protects you is a privacy policy - paper. With PCC, what protects you is architecture: no storage, no employee access, publicly auditable server software, and the device enforces all of it cryptographically before a single byte is sent. Cryptography professor Matthew Green, not usually an Apple flatterer, assessed the system in 2024 roughly like this: building trustworthy computers is the hardest problem in computer security, and PCC is pretty much the best that an excellent team with a very large budget could make of it.
On the minus side are three points. First, the trust anchor remains Apple itself: Apple builds the hardware, holds the keys, and operates the transparency log. The log makes covert manipulation risky and detectable, but not impossible - it is a very strong promise, not a mathematical guarantee like end-to-end encryption. Second, researchers at TU Darmstadt found gaps in exactly this spot in an analysis for WiSec 2026: the published binaries cannot be reproducibly built and contain no symbols - so you cannot conclusively verify that the published source code matches what actually runs. Third, and this was Green's core worry all along: PCC normalizes personal data leaving the device at all. The system, not you, decides which request stays local and which goes to the cloud - there is no "on-device only" switch, only turning off Apple Intelligence entirely.
Conclusion
Private Cloud Compute is the industry's most serious attempt to build cloud AI with verifiable privacy - and it sets a bar that OpenAI, Google and others will have to be measured against. If you use Apple Intelligence, PCC leaves you orders of magnitude better off than any ordinary AI service. Just take the system for what it is: a technically well-secured promise from Apple, not a law of nature. The expansion to Google hardware shows that this promise is currently being scaled up considerably - and with every additional company involved, the surface you have to trust grows. If that is too much for you, Apple's own original logic still applies: the most private AI request is the one that never leaves the device. Why everyone is rushing to the cloud anyway is something I covered in my post on the AI app flood with no winners.
Sources
- Apple Security Research: Private Cloud Compute: A new frontier for AI privacy in the cloud - announcement and architecture, June 2024
- Apple Security Research: Security research on Private Cloud Compute - research environment, source code, bug bounty up to 1 million USD, October 2024
- Apple Security Research: Expanding Private Cloud Compute - expansion to Google Cloud and NVIDIA, June 2026
- Apple: Private Cloud Compute Security Guide - technical documentation
- MacRumors: Apple's Private AI Will Run on Google's Servers - context on the Google partnership
- Dittmar et al. (WiSec 2026): Unlocking Apple's Private Cloud Compute - independent security analysis, including the lack of reproducible builds
- Matthew Green: Thread on Private Cloud Compute - the cryptographer's assessment, June 2024