Google Chrome silently installs a 4 GB AI model on your device without consent

Google Chrome is automatically installing a 4 GB AI model (Gemini Nano) on user devices without consent, with no opt-out mechanism and automatic re-installation if deleted—creating significant compliance risks under GDPR, ePrivacy Directive, and CSRD, while generating substantial environmental costs at scale. This represents a pattern of silent vendor overreach across trust boundaries that IT organizations cannot easily control or prevent without enterprise policy intervention or disabling Chrome features entirely. For CIOs, this raises critical questions about software supply chain governance, regulatory exposure, and the need for stricter vendor accountability in enterprise environments.

Hacker News3 min read
Read full article
Google Chrome silently installs a 4 GB AI model on your device without consent
Google Chrome is automatically installing a 4 GB AI model (Gemini Nano) on user devices without consent, with no opt-out mechanism and automatic re-installation if deleted—creating significant compliance risks under GDPR, ePrivacy Directive, and CSRD, while generating substantial environmental costs at scale. This represents a pattern of silent vendor overreach across trust boundaries that IT organizations cannot easily control or prevent without enterprise policy intervention or disabling Chrome features entirely. For CIOs, this raises critical questions about software supply chain governance, regulatory exposure, and the need for stricter vendor accountability in enterprise environments.