Google’s Chrome browser is facing fresh scrutiny after reports that it silently downloads and installs a roughly 4GB on-device AI model called Gemini Nano without first obtaining clear user consent. Privacy researcher Alexander Hanff said he uncovered the behavior during an audit, finding that the model was stored in a directory named OptGuideOnDeviceModel and deployed without obvious notification to users.
Behavior confirmed across major operating systems
The reported installation has been observed on multiple platforms, including Windows 11, macOS, and Ubuntu. Some users had previously noticed unexplained increases in storage usage, but the source was not immediately clear. The issue became more controversial because Chrome reportedly reinstalls the model automatically after deletion, raising questions about how much control users actually have over software components placed on their devices.
What Gemini Nano is used for
Gemini Nano is designed to support on-device AI features inside Chrome, including tools such as email assistance and scam detection. Running these features locally can reduce dependence on cloud processing for certain tasks. However, the report also notes that Gemini Nano is not part of Chrome’s “AI Mode”, which sends user queries to Google’s cloud infrastructure. In other words, the local model and cloud-based AI experience serve different functions.
EU privacy compliance now in focus
Hanff argues that the practice may conflict with European privacy law, pointing specifically to the ePrivacy Directive and GDPR standards around informed consent. The central concern is not only the model’s size, but whether a company should be allowed to place a large AI package on a user’s device without clear advance authorization and transparent disclosure.
Google has said that users can disable the model through Chrome settings, but it has not directly addressed why the initial installation did not require explicit consent. As more mainstream software products embed local AI capabilities, the incident highlights a broader tension between AI convenience and the need for transparency, user choice, and accountable data governance.

