Google Chrome silently installs 4GB Gemini Nano AI model without user consent
Google Chrome has been found to silently download and install a 4GB AI model file (Gemini Nano) onto users' devices without their knowledge or consent. The file, named weights.bin, resides in the OptGuideOnDeviceModel directory within the Chrome user profile. The download occurs automatically when Chrome's AI features are active, which are enabled by default in recent versions. Users who delete the file find it re-downloaded by Chrome. The behavior was verified on macOS using kernel filesystem event logs, showing the model was installed on a freshly created profile that received no human input. The total install time was 14 minutes and 28 seconds. The author estimates the environmental cost of this push across hundreds of millions of devices at between 6,000 and 60,000 tonnes of CO2-equivalent emissions, depending on deployment scale. The article argues this violates the ePrivacy Directive, GDPR, and computer misuse laws, and criticizes Google for not providing an opt-in, not documenting the behavior, and for the AI Mode pill in Chrome 147 being cloud-backed rather than using the on-device model, misleading users about where their data is processed.
Key facts
- Chrome silently installs a 4GB Gemini Nano AI model file (weights.bin) without user consent.
- The file is stored in the OptGuideOnDeviceModel directory within the Chrome user profile.
- The download occurs automatically when Chrome's AI features are active, enabled by default.
- Deleting the file results in Chrome re-downloading it; only disabling AI features or uninstalling Chrome stops it.
- Verified on macOS using kernel filesystem event logs; install took 14 minutes 28 seconds on a profile with no human input.
- Estimated environmental cost: 6,000 to 60,000 tonnes CO2e for one-time push across hundreds of millions of devices.
- The AI Mode pill in Chrome 147 is cloud-backed, not using the on-device model, misleading users.
- Author claims violations of ePrivacy Directive, GDPR, and computer misuse laws.
Entities
Institutions
- Chrome
- Gemini Nano
- Anthropic
- Claude Desktop
- European Data Protection Board
- European Environment Agency
- Ofgem
- StatCounter
- Wikipedia
- DemandSage
- Pure Infotech
- WinAero
- AIBase
- WebSentinel
- That Privacy Guy
Locations
- European Union
- United Kingdom
- California
- Africa
- South Asia
- Southeast Asia
- Latin America