Google’s latest Chrome update introduces on-device AI features under the Gemini brand, sparking confusion over data processing and privacy, as the local model operates differently from cloud-based services and raises resource and security concerns.
Chrome’s new on-device AI setting has exposed an awkward split inside Google’s browser strategy. On one side is Ask Gemini, an online service that can read the current tab and send its contents to Google’s infrastructure. On the other is Gemini Nano, a local model that Chrome stores on the computer and runs on the device itself for selected built-in features and web APIs. The result is a browser that uses the same brand name for two very different systems, while leaving many users unclear about where their data is actually processed.
That distinction matters because the local model is not a standalone chat assistant for users. It is a component that websites, extensions and Chrome itself can call through dedicated APIs for tasks such as summarisation, rewriting, proofreading and prompt-based generation. The official Chrome Developers documentation says these capabilities are designed to run without developers having to ship or manage their own model, while Google’s own guidance also sets device and storage requirements for the feature set.
The practical privacy question is simple: local inference is not the same thing as local application behaviour. Google says data used by the built-in model is not sent to its servers for the inference step, but the site that invokes the model still sees the input text and the output. It can then store, forward or analyse that content in the usual way. In other words, the model may stay on the computer, but the surrounding code does not become trustworthy by association.
That distinction has already led to confusion over the 4GB-plus file many users have found in Chrome’s profile directory. Articles from Android Authority, PCWorld and Malwarebytes all describe Chrome silently downloading Gemini Nano for features such as writing assistance and scam detection, with some users discovering that the model can reappear after deletion. The browser’s own controls now offer a clearer switch for on-device AI, but the broader complaint remains the same: the download is large, opaque and not always easy to manage.
According to Google’s developer documentation, the local model is meant to power browser functions as well as site-level APIs. That includes tools such as Summarizer and Prompt, which can be called from web pages when the model is available. The company says these requests are handled on the device, but the browser still decides whether the model is installed, whether it is downloadable and whether it is currently available for use.
Chrome’s own use of Gemini Nano is most visible in security work. Google has said the model helps identify pages that imitate technical support scams or pressure users into calling a number, paying money or installing software. In that workflow, the browser can analyse page content locally before, in some cases, sending a summary of suspicious signals to Google Safe Browsing. That is an important nuance: one stage may be local, but the full protection pipeline is not necessarily confined to the device.
The hardware and language limits also constrain what the model can do. Google’s documentation says Chrome chooses between model variants depending on the machine, and the browser may use either CPU or GPU. The local model is also available only in selected languages, which means that even where the feature is present, support is uneven. That makes the setup useful for short summaries, categorisation and drafting, but less dependable for long or sensitive material where a wrong answer would matter.
There is also a resource question. The model can use memory, CPU time, GPU capacity and battery life without asking permission each time a site calls it. Chrome does not currently offer a per-site consent prompt for Gemini Nano, even though a page can repeatedly invoke the API while it remains open. For administrators, Google does provide a policy to block local model downloads entirely, and the browser’s diagnostic pages expose version, storage path and event logs.
That administrative visibility does not remove the larger architectural issue. Google is shipping a browser that can update several gigabytes of model weights, run them locally, and use them in both user-facing and security-related features, yet the company still presents the experience through overlapping branding that obscures what is local and what is cloud-based. The Chrome distinction is therefore not about whether AI exists in the browser, but about who runs it, who pays for it and where the data goes afterwards.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





