«Google Chrome silently installs a 4 GB AI model on your device without consent. At a billion-device scale the climate costs are insane.»
Tak wyglądałyby sygnały, gdyby moduł coś wykrył. Poniższe przykłady są zmyślone — służą tylko do pokazania, jak działa ochrona.
Podaj kod BLIK z aplikacji, żebyśmy mogli odblokować Twoją wygraną.
Prośba o kod BLIK = wypłata gotówki dla oszusta.
Masz tylko 24 godziny — po tym czasie konto zostanie permanentnie zablokowane.
Sztuczna pilność wymusza działanie bez zastanowienia.
Kliknij w link: https://pkobp-bank.pl/odblokuj
Domena «pkobp-bank.pl» udaje prawdziwy «pkobp.pl».
Co tu jest nie tak 8
M.in. „silently registering”, „without asking”, „trust boundaries” — wartościowanie zamiast neutralnego opisu.
«MY»: Użytkownicy, konsumenci, planeta, analitycy prywatności… · «ONI»: Google, Big Tech, korporacje AI - opisane przez działania…. Taki podział włącza plemienność zamiast myślenia.
Mówi: «Google Chrome instaluje bez zgody użytkowników 4 GB model AI, łamiąc przepisy o…». A sugeruje: «Wielkie firmy technologiczne systematycznie lekceważą prawa użytkowników i środowisko…».
Artykuł przedstawia wyłącznie perspektywę krytyczną wobec Google i Anthropic, bez żadnego komentarza ani stanowiska firm. Brak próby uzyskania odpowiedzi od Google lub przedstawienia potencjalnych uzasadnień technicznych dla opisywanych działań.
Statystyki wskazują 34 zdania z chwytami (loaded_language, framing, anchoring, appeal_to_authority). Język emocjonalny ('reaching into users' machines', 'unilaterally deciding', 'climate bill paid by the entire planet') wzmacnia przekaz perswazyjny.
Autor przedstawia swoją interpretację prawną jako jednoznaczny 'direct breach' bez zaznaczenia, że to opinia wymagająca rozstrzygnięcia sądowego. Obliczenia środowiskowe podane z dużą pewnością mimo wielu założeń i szacunków w metodologii.
Brak oficjalnej odpowiedzi Google wyjaśniającej, czy pobieranie modelu… · Artykuł nie przedstawia danych, jak wiele urządzeń faktycznie otrzymało… (+3 więcej)
Ten tekst chce reakcji natychmiast. Nie musisz — wróć do niego za godzinę.
«Reach across vendor trust boundaries.»
Twój mózg po przeczytaniu pierwszych 7 słów tytułu już zdecydował, jaką emocję ma czuć przy reszcie tekstu — to mechanizm pierwszego wrażenia, kiedyś służący do oceny obcego: wróg czy przyjaciel.
Co zrobić: Spróbuj przeformułować to samo zdanie zupełnie innymi słowami i sprawdź, czy ocena się zmienia.
Rozkład treści
Klasyfikacja typu treści
Multi-label — artykuł może łączyć cechy kilku gatunków. Pokazujemy najsilniej wykryte, posortowane malejąco po dopasowaniu.
Tekst zawiera pogłębioną analizę z odwołaniami do regulacji GDPR, dyrektyw UE, badań naukowych i danych liczbowych dotyczących wpływu na klimat.
Artykuł zawiera liczne osobiste oceny autora, interpretacje i werdykty prawne ("direct breach", "unilaterally deciding") bez wyraźnego oznaczenia jako komentarz czy opinia.
Tekst krytykuje praktyki dużych korporacji technologicznych w kontekście regulacji EU i CCPA, oceniając ich zgodność z prawem i etyczne implikacje.
Artykuł zawiera pogłębiony opis konkretnego zjawiska (instalacja modelu AI) z sekwencją odkryć autora i procedury odtworzenia obserwacji.
Tekst jest wyraźnie autorski, zawiera osobiste odkrycia i refleksje autora o negatywnych konsekwencjach technologicznych bez pretensji do całkowitej neutralności.
Artykuł opisuje świeże odkrycie (Google Chrome pobiera model AI bez zgody), ale dominują oceny i analiza autora zamiast standardowej struktury newsowej.
Tekst ujawnia szczegóły techniczne (nazwy plików, ścieżki, procedury) działań Google i Anthropic, potencjalnie mobilizując przeciwko tym firmom.
Rozkład artykułów w polskich mediach
Nagłówek vs. treść
Ocena 4/5. Im więcej żółtych kwadratów, tym lepiej nagłówek odpowiada treści.
Sygnał stylu AI heurystyka, nie detektor
Tekst wykazuje cechy pisarstwa ludzkiego eksperta z branży: osobisty ton ('I wrote', 'I discovered'), specjalistyczny żargon techniczny, wyraźny głos autorski i styl publicystyki advocacy. Struktura jest bardziej organiczna niż schematyczna.
- Osobiste zwroty i narracja pierwszoosobowa ('in my professional opinion')
- Specjalistyczna terminologia techniczno-prawna bez wyjaśnień dla laików
- Nieregularna struktura z długimi akapitami analitycznymi
- Emocjonalny, zaangażowany język typowy dla advocacy
- Konkretne szczegóły techniczne (nazwy plików, ścieżki) zamiast ogólników
Struktura narracji
Jak zbudowany jest kościec tego artykułu — niezależnie od poszczególnych zdań.
Google Chrome instaluje bez zgody użytkowników 4 GB model AI, łamiąc przepisy o prywatności i powodując ogromne szkody klimatyczne na skalę globalną.
Wielkie firmy technologiczne systematycznie lekceważą prawa użytkowników i środowisko naturalne w pogoni za wdrożeniem swoich technologii AI, traktując urządzenia klientów jako własność i ignorując zasady zgody.
Autor przedstawia techniczne dowody instalacji pliku weights.bin, następnie przechodzi do analizy prawnej wskazującej na naruszenie GDPR i ePrivacy Directive. Kluczowym elementem jest kalkulacja kosztów środowiskowych, gdzie autor przelicza 4 GB na skalę miliardów urządzeń, pokazując emisję 6-60 tysięcy ton CO2. Uzasadnienie opiera się na połączeniu faktów technicznych, ekspertyzy prawnej autora i obliczeń wpływu klimatycznego.
Autor konsekwentnie używa języka inwazji i naruszenia wobec firm ('reaching into machines', 'cross vendor trust boundaries'), podczas gdy użytkownicy są opisani w stronie biernej jako ci, którym coś się dzieje. Asymetria wzmocniona przez contrast: gigantyczna skala Google (miliardy urządzeń) vs. bezsilność jednostki (nie można nawet trwale usunąć pliku). Język prawny i techniczny buduje autorytet 'nas' przeciw bezprawiu 'ich'.
Język wartościujący
Słowa, które obok znaczenia niosą ocenę emocjonalną — i ich neutralne odpowiedniki.
- «registering without user notice»
- «auto-registering»
Emphasizes secretive action to imply impropriety
- «without user consent»
- «non-consensually»
Emphasizes lack of consent to frame action negatively
- «vendor separation»
- «cross-product installation»
Loaded term suggesting violation of security principles
- «is automatically reinstalled»
- «reinstalls»
Anthropomorphic language ('itself') frames software as autonomous agent
- «a similar pattern»
- «comparable behavior»
Suggests equivalence to strengthen comparison
- «installing»
- «writing to»
- «downloading to»
Anthropomorphic, invasive metaphor suggests forceful intrusion
- «without explicit user consent»
- «non-consensually»
Emphasizes absence of consent to frame negatively
- «is located in»
- «is stored in»
Anthropomorphic language renders technical fact as living entity
- «did not prompt»
- «obtained no consent»
Emphasizes absence of consent as violation of autonomy
- «is not displayed»
- «is not visible to users»
Emphasizes concealment; implies hiding from users
- «environmental cost»
- «CO2 emissions»
Economic/debt metaphor frames environmental impact as financial obligation or wrongdoing
- «results in atmospheric CO2 emissions»
- «generates emissions»
Frames impact as burden on all humanity to emphasize moral weight
- «deciding independently»
- «deciding without user input»
Emphasizes unilateral power; suggests tyrannical or autocratic decision-making
- «distribute to»
- «push to»
Militaristic/authoritarian connotation amplifies perception of scale and force
- «potential breach»
- «alleged breach»
- «possible breach»
Absolute language ('direct') forecloses nuance in legal interpretation
- «contains a directory»
- «includes a directory»
Anthropomorphic language renders technical path as passive object awaiting discovery
- «was installed without consent»
- «was automatically installed»
Passive framing ('appeared') and 'no consent' both emphasize user powerlessness
- «automatically installs on machines meeting requirements»
- «deploys to eligible devices»
Militaristic/commercial metaphor frames user device as passive target rather than tool
- «pattern of deletion and reinstallation»
- «automatic reinstallation after deletion»
Repetitive structure emphasizes futility and user powerlessness
- «unavailable to typical users»
- «not accessible to individual users»
Emphasizes exclusion and powerlessness of ordinary users
- «is installed»
- «is created»
Anthropomorphic; suggests descent/arrival beyond user control
- «might characterize»
- «could argue»
Speculative attribution of bad faith motive to preemptively delegitimize anticipated counter-arguments
- «objective evidence source»
- «independent verification method»
Legal/judicial metaphor invokes credibility and impartiality to frame technical evidence
- «the evidence»
- «the record»
Legal/courtroom metaphor positions OS logs as testimony
- «were installed»
- «appeared in»
Anthropomorphic; suggests uncontrolled descent or arrival
- «along with»
- «grouped with»
Suggests intentional deception or obfuscation by treating fundamentally different updates identically
- «absent explicit user authorization»
- «installed without prior user action»
Evaluative framing that presupposes lack of authorization rather than neutrally stating absence of explicit user action
- «aggressive pace of rollout»
- «rapid feature integration»
- «accelerated deployment»
Metaphorical term implying hostile intent where neutral descriptor would be 'rapid rollout' or 'expansion'
- «the installation pattern»
- «this deployment»
- «this occurrence»
Presupposes that the described installation pattern constitutes singular unified problematic 'behaviour' rather than multiple potentially distinct deployment events
- «design pattern»
- «interface pattern»
- «default behavior pattern»
Technical term from UX ethics, but carries inherent negative valuation implying deception
- «bundling»
- «co-installation»
- «included installation»
Loaded term presupposing coercion; neutrally could be 'inclusion' or 'bundling'
- «integrated into»
- «extended to»
- «added to»
Phrasing suggests intrusion; 'integrated into' or 'added to' would be more neutral
- «downloads»
- «installs»
- «creates»
'Writes' metaphorically suggests secretive action; 'downloads' or 'installs' is more neutral
- «distinct consent requirements»
- «separate authorization scope»
Neologism that frames the issue through a specific lens of consent violation
- «no user action required»
- «automatic installation»
- «without user interaction»
Emphasizes automation through contrast with manual action, implying problematic secretiveness
- «automatically re-downloads»
- «re-downloads without notification»
- «programmatically restores»
'Silently' implies secretive action; 'automatically re-download' or 'will re-download without notification' is more neutral
- «typical user»
- «average user»
- «non-technical user»
Undefined category that implies a standard against which Chrome's documentation fails; excludes expert users
- «occupies»
- «is stored»
- «remains installed»
Colloquial phrasing that implies useless, burdensome presence; more neutral: 'occupies' or 'is stored'
- «more descriptive naming»
- «user-facing naming»
- «clearer naming»
Presupposes that one naming is objectively 'accurate' while current naming is not; both are naming choices with different trade-offs
- «used internal technical naming»
- «did not provide user-facing labels»
- «employed abbreviated naming»
Presupposes deliberate intent to hide rather than other explanations; 'used internal naming' or 'did not provide user-facing labels' is more neutral
- «independent»
- «separated»
- «operates regardless»
Technical term that neutrally describes architectural separation, but in this context implies undesirable autonomy
- «automatic download»
- «background download»
- «unnotified download»
Loaded term implying secretive action; 'automatic download' or 'background download' is more neutral
- «technical users»
- «system administrators»
- «users who search documentation»
Qualifier that implies only motivated power users discover the documentation, excluding regular users
- «typical user»
- «non-expert user»
- «average user»
Undefined category that presupposes homogeneous user behavior
- «initiates»
- «begins»
- «starts deploying»
Anthropomorphizes Chrome's automated process as deliberate decision-making with intent
- «Chrome restores the model on the next update cycle»
- «the model is reinstalled automatically»
- «the deletion is not persistent across updates»
Rhetorical framing that casts Chrome's behavior as disrespectful; neutral: 'Chrome restores the model on next update' without value judgment
- «does not make retroactive»
- «does not address»
- «does not resolve»
Presupposes that past installations require legitimation and that future consent would be insufficient remedy
- «may affect user trust»
- «could impact the relationship»
- «raises trust concerns»
Abstract harm framing that invokes emotional concern; more neutral: 'trust may be affected' or 'relationship impact'
- «has environmental implications»
- «contributes to energy usage»
- «has climate impact»
Poetic metaphor that evokes environmental harm; actual environmental impact claim requires data
- «This raises significant legal concerns»
- «The following is legally notable»
- «This point warrants legal attention»
Emotional appeal designed to create shock and urgency; presupposes that following information warrants dramatic reaction
- «prominent location»
- «highly visible area»
- «primary UI element»
Real estate metaphor emphasizes prominence in way that presupposes intentional placement to deceive
- «a user who sees»
- «most users would infer»
- «users may assume»
Legal standard invoked to presuppose correctness of specific inference about UI interpretation
- «might infer»
- «could reasonably conclude»
- «may assume»
Presupposes inference is obvious when it requires specific prior knowledge about on-device models and their location
- «incorrect»
- «inaccurate»
- «contradicted by actual implementation»
Absolute negation is more emphatic than 'incorrect' and implies user culpability for failed inference
- «are not prominently displayed»
- «are difficult to find»
Implies Chrome's design is intentionally obscure
- «functions alongside»
- «operates in parallel with»
Imputes deliberate concealment strategy without direct evidence
- «obscures»
- «fails to clarify»
Assumes intentional deception rather than ambiguity or poor UI
- «in clear disclosure»
- «with adequate notice»
Imposes a specific standard without legal specification
- «contrary to»
- «inconsistent with»
Hyperbolic framing of design choice
- «may not comply with»
- «potentially violates»
Softened accusation; suggests impropriety without direct claim
- «are significant»
- «warrant attention»
Defensive rhetorical move that discourages scrutiny of severity claim
- «was minimal»
- «was substantially lower»
Subjective evaluation presented as fact
- «significant environmental footprint»
- «measurable impact»
Emotional framing ('alarming') before data presentation activates concern
- «the mid-point»
- «one reasonable estimate»
Preemptively deflects criticism by asserting reasonableness
- «still very large»
- «still significant»
Vague but emotionally amplifying descriptor
- «unreasonably large»
- «implausible»
Suggests all three estimates are realistic without proving any
- «bytes users selected»
- «bytes users chose to download»
Sugeruje że każdy inny byte to narzucony download, który użytkownik nie chciał.
- «consumed»
- «used»
- «spent»
Metafora sugerująca marnotrawstwo i bezsensowność działania.
- «unsolicited download»
- «automatic download»
Podkreśla brak zgody użytkownika.
- «is insufficient»
- «does not address the concern»
Informalnie odrzuca argument bez szczegółowego obalenia.
- «not prominently disclosed»
- «difficult to find»
Sugeruje celowe ukrywanie informacji przed typowym użytkownikiem.
- «overrides user preference»
- «ignores user settings»
Przypisuje aplikacji paternalistyczną postawę, sugerując złą wolę.
- «distribution channel»
- «platform»
Metafora sugerująca instrumentalizację maszyny użytkownika, wojskowy/techniczny ton.
- «control»
- «ownership»
Odwołanie się do autorytetu prawa, dramatyzuje kwestię autonomii.
- «wider regulatory risk»
- «broader user impact»
Sugeruje zagrożenie bez konkretnych liczb; dramatyzuje skalę.
- «contradicts»
- «conflicts with»
Metafora sugerująca celowe osłabienie, sabotaż.
- «user consent»
- «explicit permission»
Konceptualizuje zgodę jako fundamentalną wartość, dramatyzuje jej znaczenie.
- «subject to the same legal requirements»
- «governed by the same regulations»
Sugeruje że Google/Anthropic mogą chcieć się wymigać spod prawa.
- «carbon footprint»
- «environmental impact»
Dramatyzuje skalę szkody; używa słowa 'harm' które ma moralną wagę.
- «comply with regulations»
- «respect user preferences»
Idiom sugerujący rozumienie życzenia publiczności; ramowanie jako kwestia smutku, nie prawa.
- «are consistent with»
- «align with»
Sugeruje że bez działania, stanowiska są hipokryzją; ironiczny, deprecjonujący ton.
- «observed in recent cases»
- «reported in some instances»
Sugeruje trend nasilania się praktyk; używa ad populum (wszyscy coś robią).
- «should regulations apply equally»
- «how should regulators enforce»
Retoryczne pytanie sugerujące że są zwolnione; zawiera implikaturę oskarżenia.
Wykryte chwyty erystyczne i techniki perswazyjne
Audyt źródeł
Kogo artykuł cytuje, kogo nie — i czy podane źródła można zweryfikować.
S1–S5 z poziomem zaufania. Cytowana jako podstawa prawna do twierdzenia o naruszeniu Art. 5(3) przez instalację bez zgody
Cytowane jako podstawa dla zarzutów naruszenia zasad zgodności z prawem, uczciwości i przejrzystości oraz ochrony danych przez projekt
Cytowana jako podstawa do stwierdzenia, że szkoda środowiskowa powinna być zgłaszalna
Użyte jako źródło danych o udziale Chrome w rynku przeglądarek (62.85%)
Użyte jako dodatkowe źródło danych o udziale Chrome w rynku
Użyte do oszacowania liczby użytkowników Chrome (2 miliardy)
Cytowana jako dodatkowa podstawa prawna dla naruszeń prywatności
Własna metodologia autora do obliczania wpływu środowiskowego, kod źródłowy
Badanie naukowe z 2018 o wpływie środowiskowym reklamy online, użyte do obliczeń emisji CO2
Dane o intensywności emisji gazów cieplarnianych przy produkcji energii elektrycznej
Użyte do porównania zużycia energii (średnie zużycie energii przez gospodarstwo domowe ~2700 kWh/rok)
Dane o średnich emisjach CO2 z nowych samochodów osobowych, użyte do porównania
Artykuł formułuje poważne oskarżenia wobec Google (naruszenie GDPR, ePrivacy, szkoda środowiskowa) bez uzyskania stanowiska firmy ani wyjaśnienia, czy instalacja modelu AI była błędem, celowym działaniem, czy miała podstawę w warunkach użytkowania
Autor sam ocenia legalność działań Google odwołując się do swojej opinii zawodowej, brak niezależnej weryfikacji prawnej przez eksperta niezwiązanego ze sprawą
Obliczenia emisji CO2 opierają się głównie na własnej metodologii autora (WebSentinel), brak weryfikacji przez niezależnego eksperta lub organizację zajmującą się audytem środowiskowym technologii
Artykuł opiera szacunki na danych z firm trzecich (StatCounter, DemandSage), a nie na oficjalnych danych Google o tym, na ilu urządzeniach faktycznie zainstalowano model Gemini Nano
Brak głosu eksperta technicznego, który mógłby wyjaśnić przyczyny techniczne instalacji modelu, czy było to zamierzone zachowanie, błąd w aktualizacji, czy element funkcjonalności wymagającej opt-in
Brakujące perspektywy
Analiza zdanie po zdaniu
«Two weeks ago I wrote about Anthropic silently registering a Native Messaging bridge in seven Chromium-based browsers on every machine where Claude Desktop was installed [1].»
FAKT«The pattern was: install on user launch of product A, write configuration into the user's installs of products B, C, D, E, F, G, H without asking.»
FAKT«Reach across vendor trust boundaries.»
OPINIA«No consent dialog.»
FAKT«No opt-out UI.»
FAKT«Re-installs itself if the user removes it manually, every time Claude Desktop is launched.»
FAKT«This week I discovered the same pattern, executed by Google.»
FAKT«Google Chrome is reaching into users' machines and writing a 4 GB on-device AI model file to disk without asking.»
FAKT«The file is named weights.bin.»
FAKT«It lives in OptGuideOnDeviceModel.»
FAKT«It is the weights for Gemini Nano, Google's on-device LLM.»
FAKT«Chrome did not ask.»
FAKT«Chrome does not surface it.»
FAKT«If the user deletes it, Chrome re-downloads it.»
FAKT«The legal analysis is the same one I gave for the Anthropic case.»
FAKT«The environmental analysis is new.»
FAKT«At Chrome's scale, the climate bill for one model push, paid in atmospheric CO2 by the entire planet, is between six thousand and sixty thousand tonnes of CO2-equivalent emissions, depending on how many devices receive the push.»
FAKT«That is the environmental cost of one company unilaterally deciding that two billion peoples' default browser will mass-distribute a 4 GB binary they did not request.»
OPINIA«This is, in my professional opinion, a direct breach of Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive) [2], a breach of the Article 5(1) GDPR principles of lawfulness, fairness, and transparency [3], a breach of Article 25 GDPR's data-protection-by-design obligation [3], and an environmental harm of a magnitude that would be a notifiable event under the Corporate Sustainability Reporting Directive (CSRD) for any in-scope undertaking [4].»
OPINIA«What is on the disk and how it got there»
NEUTRALNE«On any machine that has Chrome installed, in the user profile, sits a directory whose name is OptGuideOnDeviceModel.»
FAKT«Inside it is a file called weights.bin.»
FAKT«The file is approximately 4 GB.»
FAKT«It is the weights file for Gemini Nano.»
FAKT«Chrome uses it to power features Google has marketed under names like "Help me write", on-device scam detection, and other AI-assisted browser functions.»
FAKT«The file appeared with no consent prompt.»
FAKT«There is no checkbox in Chrome Settings labelled "download a 4 GB AI model".»
FAKT«The download triggers when Chrome's AI features are active, and those features are active by default in recent Chrome versions.»
FAKT«On any machine that meets the hardware requirements, Chrome treats the user's hardware as a delivery target and writes the model.»
FAKT«The cycle of deletion and re-download has been documented across multiple independent reports on Windows installations [5][6][7][8] - the user deletes, Chrome re-downloads, the user deletes again, Chrome re-downloads again.»
FAKT«The only ways to make the deletion stick are to disable Chrome's AI features through chrome://flags or enterprise policy tooling that home users do not generally have, or to uninstall Chrome entirely [5].»
FAKT«On macOS the file lands as mode 600 owned by the user (so it is deletable in principle) but Chrome holds the install state in Local State after the bytes are written, and as soon as the variations server next tells Chrome the profile is eligible, the download fires again - the architecture is the same, only the file permissions differ.»
FAKT«How I verified this on a freshly created Apple Silicon profile»
NEUTRALNE«Most of the existing reporting on this behaviour is from Windows users who noticed their disk filling up - useful, but Google could (and probably will) try to characterise those reports as anecdotes from non-representative configurations.»
OPINIA«So I went looking for a clean witness on a different platform.»
NEUTRALNE«The witness I found is macOS itself.»
NEUTRALNE«The kernel keeps a filesystem event log called .fseventsd - it records every file create, modify and delete at the OS level, independent of any application logging.»
FAKT«Chrome cannot edit it, Google cannot remotely reach it, and the page files that record the events survive the deletion of the files they reference.»
FAKT«I created a Chrome user-data directory on 23 April 2026 to run an automated audit (one of the WebSentinel 100-site privacy sweeps).»
FAKT«The audit driver is fully Chrome DevTools Protocol - it loads a page, dwells for five minutes with no input, captures events, closes Chrome between sites - and the profile had received zero keyboard or mouse input from a human at any point in its existence.»
FAKT«Every "AI mode" surface in Chrome was untouched - in fact every UI surface in Chrome was untouched, the audit driver only interacts with the document via CDP and the omnibox is never reached.»
FAKT«By 29 April the profile contained 4 GB of OptGuideOnDeviceModel weights - and I knew it because a routine du -sh of the audit-profile directory caught it during a cleanup pass.»
FAKT«I went back to .fseventsd to ask exactly when those 4 GB landed.»
NEUTRALNE«macOS gave me the answer, byte-precise, in three sequential page files:»
FAKT«24 April 2026, 16:38:54 CEST (14:38:54 UTC) - Chrome creates the OptGuideOnDeviceModel directory in the audit profile (page file 0000000003f7f339).»
FAKT«24 April 2026, 16:47:22 CEST (14:47:22 UTC) - three concurrent unpacker subprocesses spawn temporary directories in /private/var/folders/.../com.google.Chrome.chrome_chrome_Unpacker_BeginUnzipping.*/ .»
FAKT«One of them (5xzqPo) writes weights.bin, manifest.json, _metadata/verified_contents.json and on_device_model_execution_config.pb.»
FAKT«The second writes a Certificate Revocation List update.»
FAKT«The third writes a browser preload-data update.»
FAKT«Chrome batched a security update, a preload refresh and a 4 GB AI model into the same idle window, as if they were equivalent (page file 00000000040c8855).»
OPINIA«24 April 2026, 16:53:22 CEST (14:53:22 UTC) - the unpacked weights.bin is moved to its final location at OptGuideOnDeviceModel/2025.8.8.1141/weights.bin along with adapter_cache.bin, encoder_cache.bin, _metadata/verified_contents.json and the execution config.»
FAKT«Concurrently four additional model targets (numbered 40, 49, 51 and 59 in Chrome's optimization-guide enum) register fresh entries in optimization_guide_model_store - these are the smaller text-safety and prompt-routing models that pair with the LLM.»
FAKT«None of these targets existed in the profile before this moment (page file 00000000040d0f9c).»
FAKT«Total install time, from directory creation to final move: 14 minutes and 28 seconds.»
FAKT«Total human action against the profile during that window: none.»
FAKT«The GoogleUpdater logs record the on-device-model control component (appid {44fc7fe2-65ce-487c-93f4-edee46eeaaab}) being downloaded from http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/%7B44fc7fe2-65ce-487c-93f4-edee46eeaaab%7D/... - a 7 MB compressed control file that arrived on 20 April 2026, three days before the audit profile in question was created.»
FAKT«That is the upstream control plane: it is profile-independent, it is launched automatically by a LaunchAgent that fires every hour, and the URL is plain HTTP (the integrity is verified by the CRX-3 signature inside the package, not by transport security).»
FAKT«The control component gives Chrome the manifest pointing at the actual weights, and Chrome's in-process OnDeviceModelComponentInstaller - a separate code path from GoogleUpdater - then fetches the multi-GB weights direct from Google's CDN.»
FAKT«So we now have a four-way evidence chain - macOS kernel filesystem events, Chrome's own per-profile state, Chrome's runtime feature flags, and Google's component-updater logs - all four agreeing on the same conduct, and the conduct is: a 4 GB AI model arrived on this user's disk without consent, without notice, on a profile that received zero human input, in a window of 14 minutes and 28 seconds, on a Tuesday afternoon.»
FAKT«Reports of the OptGuideOnDeviceModel directory and the weights.bin file have been circulating in community forums for over a year - what is new in 2026 is the scale and the verifiability.»
FAKT«Chrome's market share has held above 64% globally [9][10], Chrome's user base is between 3.45 billion and 3.83 billion individuals worldwide depending on which 2026 estimate you trust [9][11], and Google has been rolling Gemini features into Chrome with increasing aggression.»
FAKT«The behaviour is no longer affecting a minority of power users on a minority of platforms - it is affecting hundreds of millions of devices, on every desktop OS Chrome ships against.»
FAKT«The same dark-pattern playbook.»
OPINIA«I am repeating my categorisation from the Claude Desktop article [1] because the patterns are identical and that is the point.»
NEUTRALNE«Forced bundling across trust boundaries.»
OPINIA«Anthropic installed Claude Desktop, then wrote into Brave, Edge, Arc, Vivaldi, Opera, and Chromium.»
FAKT«Google installs Chrome, then writes a 4 GB AI model under the user's profile directory without authorisation.»
FAKT«The binary is not Chrome.»
FAKT«It is a separately-trained machine-learning model, with a separate purpose, a separate data-protection profile, and a separate consent footprint.»
FAKT«No dialogue at first launch.»
FAKT«No checkbox in Settings.»
FAKT«The model is downloaded; the user finds out about it months later when their disk fills up [5][6][7].»
FAKT«Adding the file took zero clicks.»
FAKT«Removing it requires (a) discovering the file exists, (b) understanding what it is, (c) navigating into a hidden user profile path, (d) deleting it (and on Windows, also clearing the read-only attribute first), and (e) accepting that Chrome will silently re-download it on next eligible window unless the user also navigates chrome://flags, enterprise policy, or platform-specific configuration tooling to disable the underlying Chrome AI feature [5].»
FAKT«None of those steps is documented in the place a normal user looks - none of them is even hinted at in default Chrome.»
OPINIA«The Nano model exists on the user's disk so that Chrome features that use it can run instantly when the user invokes them.»
FAKT«The user has not invoked any of those features.»
FAKT«The model still sits there, taking 4 GB.»
OPINIA«OptGuideOnDeviceModel is internal Chrome jargon for "OptimizationGuide on-device model storage".»
FAKT«A user looking at their disk usage, even one who knows roughly what they are looking at, would not match OptGuideOnDeviceModel/weights.bin to "Gemini Nano LLM weights".»
OPINIA«Accurate naming would be GeminiNanoLLM/weights.bin.»
OPINIA«Google chose to obfuscate the name.»
OPINIA«A user who has not opened Chrome's AI features still gets the model.»
FAKT«A user who has opened them once and decided they were not interested still gets the model.»
FAKT«The file's presence is decoupled from the user's actual use of any feature it powers.»
FAKT«Google's user-facing documentation about Chrome's AI features does not, with the prominence proportionate to a 4 GB silent download, tell the user that the cost of the feature being available is a 4 GB file appearing on their device.»
OPINIA«The behaviour is documented in places a curious admin will find.»
OPINIA«It is not documented in the place a regular user looks before installing Chrome or before Chrome decides to begin pushing the model.»
OPINIA«Delete the file, Chrome re-creates it.»
FAKT«The user's deletion is treated as a transient state to be corrected, not as a directive to be respected.»
OPINIA«Same as Claude Desktop.»
NEUTRALNE«If Google in future starts asking users "would you like Chrome to download a 4 GB AI model", that prompt does not retro-actively legitimise the silent installs that have already happened on hundreds of millions of devices.»
OPINIA«The damage to the trust relationship is done.»
OPINIA«The bytes have moved.»
NEUTRALNE«The atmosphere has been written to.»
OPINIA«This is not test build behaviour.»
FAKT«It is Chrome stable.»
FAKT«Here is the part that should make every privacy lawyer in the audience put their coffee down.»
PERSWAZJA«When Chrome 147 launches against an eligible profile, the omnibox - the address bar at the top of the window, the most visible piece of real estate in the entire browser - renders an "AI Mode" pill to the right of the URL field.»
FAKT«A reasonable user, seeing "AI Mode" sitting in their browser's most prominent UI element in 2026, with the well-publicised existence of on-device LLMs in Chrome and a 4 GB Gemini Nano binary already silently installed on their disk, is going to draw what feels like an obvious inference - that the visible AI Mode is using the on-device model, that their queries stay on the device, that the local model is what powers the local-looking surface.»
OPINIA«Every part of that inference is wrong.»
OPINIA«The AI Mode pill in the Chrome 147 omnibox is a cloud-backed Search Generative Experience surface - every query the user types into it is sent over the network to Google's servers for processing by Google's hosted models.»
FAKT«It is skipping because the user is not given a moment to choose between local-only and cloud-backed AI surfaces - both are switched on by the same upstream rollout, with no per-feature consent.»
FAKT«And it is hindering because turning AI Mode off does not also remove the on-device install, and removing the on-device install does not turn AI Mode off - the two are separately controlled, and discovering both controls requires knowing about both chrome://flags and chrome://settings/ai, neither of which is obvious in default Chrome.»
FAKT«So: not just a non-consented install, but a non-consented install that doubles as cover for a parallel cloud-backed surface that misrepresents to the user where their typing is being processed.»
OPINIA«Both layers compound the consent problem.»
OPINIA«Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive) prohibits the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user, without the user's prior, freely-given, specific, informed, and unambiguous consent, except where strictly necessary for the provision of an information-society service explicitly requested by the user [2].»
FAKT«The 4 GB Gemini Nano weights file is information stored in the user's terminal equipment.»
FAKT«The user did not consent.»
FAKT«The user has not requested any service that strictly requires a 4 GB on-device LLM.»
OPINIA«Chrome is functional without the file.»
FAKT«The Article 5(3) breach is direct.»
OPINIA«Article 5(1) GDPR requires processing of personal data to be lawful, fair, and transparent to the data subject [3].»
FAKT«Where the user's hardware is profiled to determine eligibility for the model push, where the install events are logged on Google's servers, and where the on-device features the model powers process user prompts (whether or not those prompts leave the device), the lawfulness, fairness, and transparency of all of that processing depend on the user being told, in plain language, what is happening.»
OPINIA«They are not.»
FAKT«Article 25 GDPR requires the controller to implement appropriate technical and organisational measures to ensure that, by default, only personal data that are necessary for each specific purpose are processed [3].»
FAKT«Pre-staging a 4 GB AI model on a user's disk, against a contingency that the user might in future invoke an AI feature, is the architectural opposite of by-default minimisation and the profiling of the device to determine whether or not to push the model is not different to the profiling used to track you online and as such that profile contains personal data and if the AI model is used, will process personal data, so the GDPR arguments are in scope and valid.»
OPINIA«Under the UK GDPR and the Privacy and Electronic Communications Regulations 2003, the analysis is the same.»
FAKT«Under the California Consumer Privacy Act, the absence of a notice-at-collection covering this specific category of pre-staged software puts Google's CCPA notice posture in question [12].»
OPINIA«Then there are the criminal-law violations under various national computer-misuse statutes - which again cannot be overstated.»
OPINIA«The Anthropic case I wrote about was a desktop application installing a 350-byte JSON manifest in seven directories.»
FAKT«The bandwidth and energy cost of that, summed across all Claude Desktop users, was negligible.»
OPINIA«The Chrome case is different.»
FAKT«Chrome is pushing a 4 GB binary across hundreds of millions of devices.»
FAKT«That has a measurable, quantifiable, and frankly alarming environmental footprint.»
OPINIA«I am calculating this using the same methodology our WebSentinel audit platform applies to website environmental analysis [13]:»
NEUTRALNE«Energy intensity of network data transfer: 0.06 kWh per GB, the mid-band of Pärssinen et al. (2018) "Environmental impact assessment of online advertising", Science of The Total Environment [14].»
FAKT«The paper reports a 0.04-0.10 kWh/GB range depending on the share of fixed-line vs mobile transfer and inclusion of end-user device energy.»
FAKT«0.06 is a defensible mid-point.»
OPINIA«Grid emissions factor: 0.25 kg CO2e per kWh, the EEA / IEA composite EU-27 electricity-supply factor for 2024 reporting [15].»
FAKT«Globally the figure varies from ~0.10 kg/kWh on mostly-renewable grids to over 0.70 kg/kWh on coal-heavy grids; 0.25 is mid-band for a global push and is the figure WebSentinel uses by default.»
FAKT«Per-device cost of one Nano push»
NEUTRALNE«Bandwidth: 4 GB»
FAKT«Energy: 4 × 0.06 = 0.24 kWh per device per push»
FAKT«CO2: 0.24 × 0.25 = 0.06 kg CO2e per device per push»
FAKT«That is per device, per push.»
NEUTRALNE«A single download of the model.»
FAKT«It does not include re-downloads triggered by the user trying and failing to delete the file.»
FAKT«It does not include subsequent updates to the model.»
FAKT«It does not include the on-device inference energy when the model is actually used.»
FAKT«It is just the one-time delivery cost to one device.»
NEUTRALNE«Google does not publish how many devices receive the Nano push.»
FAKT«The eligibility criteria gating the push (a hardware "performance class" that Chrome computes from CPU class, GPU class, system RAM and available VRAM - typically ~16 GB unified memory or better on Apple Silicon, ~16 GB RAM and a discrete or integrated GPU with sufficient VRAM on Windows and Linux) carve out the very low end of the consumer install base, but the qualifying population is still enormous.»
FAKT«I will use three illustrative deployment bands so the reader can pick whichever they consider closest to reality.»
NEUTRALNE«None of these bands is implausibly large for a feature that ships in default-on Chrome.»
OPINIA«Devices receiving the push»
NEUTRALNE«Total bytes pushed»
NEUTRALNE«Total energy»
NEUTRALNE«Total CO2e»
NEUTRALNE«100 million (low band: ~3% of Chrome users)»
FAKT«400 petabytes»
FAKT«24 GWh»
FAKT«6,000 tonnes CO2e»
FAKT«500 million (mid band: ~15% of Chrome users)»
FAKT«2 exabytes»
FAKT«120 GWh»
FAKT«30,000 tonnes CO2e»
FAKT«1 billion (high band: ~30% of Chrome users)»
FAKT«4 exabytes»
FAKT«240 GWh»
FAKT«60,000 tonnes CO2e»
FAKT«To compare those numbers to what an ESG report could compare to:»
NEUTRALNE«24 GWh (low band) is roughly the annual electricity consumption of about 7,000 average UK households [16].»
FAKT«120 GWh (mid band) is roughly the annual electricity consumption of about 36,000 average UK households, or the annual output of a 14 MW wind turbine running at typical UK capacity factor.»
FAKT«240 GWh (high band) is roughly the annual electricity consumption of about 72,000 average UK households, or the annual output of about 28 MW of installed wind capacity.»
FAKT«6,000 tonnes CO2e (low band) is roughly the annual emissions of 1,300 average passenger cars in the EU [17].»
FAKT«30,000 tonnes CO2e (mid band) is roughly the annual emissions of 6,500 cars, or one return flight from London to Sydney for about 8,000 passengers in economy.»
FAKT«None of that infrastructure exists for free.»
FAKT«Every byte Chrome pushes is a byte that competes with bytes the user actually wanted.»
OPINIA«For users on capped mobile data plans, particularly in regions where smartphone-as-only-internet is dominant (much of Africa, much of South and Southeast Asia, most of Latin America), 4 GB of unrequested download is on the order of a month's data allowance, vapourised by Chrome on the user's behalf.»
FAKT«Google has not, to my knowledge, published any analysis of the welfare impact of this on the populations whose internet access is metered.»
FAKT«Keep in mind that mobile data plans (4G and 5G) are used by many households who do not have access to fiber, cable or adsl and are used for desktop devices as well as mobile - so the argument that Google won't push this to mobile devices (although I have not found anything official to support that argument anyway) will not fly.»
OPINIA«Ask.»
NEUTRALNE«First time Chrome is about to download the Nano model, pop a dialogue.»
NEUTRALNE«"Chrome would like to download a 4 GB AI model file to your device to power the following features.»
NEUTRALNE«Allow, or skip and decide later."»
NEUTRALNE«Two buttons.»
NEUTRALNE«Done.»
NEUTRALNE«Pull, not push.»
OPINIA«Trigger the download as a downstream consequence of the user invoking an AI feature for the first time.»
NEUTRALNE«Let the feature itself be the consent event.»
OPINIA«Do not pre-stage on a contingency.»
OPINIA«Surface it.»
OPINIA«In chrome://settings/, list the AI model files Chrome has downloaded, their size, the features they power, and a "Remove and stop downloading" button per model.»
NEUTRALNE«Make removal persistent, not a transient state Chrome corrects on next launch.»
OPINIA«Document it.»
OPINIA«Tell the user, plainly, in the Chrome description on the Microsoft Store, in the Chrome installer, on the Google Chrome download page, that Chrome will download additional model files of substantial size on supported hardware.»
OPINIA«Currently, this is essentially undocumented to a normal user.»
FAKT«Respect deletion.»
OPINIA«If the user deletes weights.bin, do not re-create it.»
OPINIA«If the user has a strong preference about what is on their disk, the application is not in a position to override that preference because the application thinks it knows better.»
OPINIA«Disclose at scale.»
OPINIA«Publish, in Google's annual ESG report, the aggregate bandwidth and carbon footprint of all AI-feature model pushes to user devices, broken down by region.»
OPINIA«Treat it as the Scope 3 Category 11 emission it is.»
OPINIA«Account for it.»
OPINIA«Notify retrospectively.»
OPINIA«Users who already received the model without consent should, on next Chrome launch, be told what happened, shown the file, and offered a one-click revoke + uninstall.»
OPINIA«This is the same retrospective-consent step Anthropic should also have taken.»
OPINIA«Both of these episodes, the Anthropic Claude Desktop manifest install I wrote about two weeks ago and the Google Chrome Gemini Nano push I am writing about today, share the same underlying decision.»
OPINIA«An engineering team at a large AI vendor decided that the user's machine is a deployment surface to be optimised for the vendor's product roadmap, not a personal device whose owner is the legal authority on what runs there.»
OPINIA«The Anthropic case put a pre-authorisation for browser automation on around three million Claude Desktop user devices [19].»
FAKT«The Google case puts 4 GB of AI weights on, by my mid-band estimate, around 500 million Chrome user devices, with proportionally larger ePrivacy, GDPR, and environmental exposure.»
OPINIA«Both companies have a public posture of caring about safety, ethics, and responsible AI.»
FAKT«Both companies, in the silent installation behaviours documented here, have undermined the foundational consent on which the legitimacy of any of those positions depends.»
OPINIA«The fact that the bytes are AI bytes does not exempt them from the law that governs every other byte that gets written to a user's device without permission.»
OPINIA«The fact that the bytes are "small" relative to the user's disk does not exempt the cumulative carbon footprint from being a real, measurable, ongoing harm to the climate.»
OPINIA«If Google's next Chrome update silently removes the unconsented installs and replaces the behaviour with an explicit opt-in, we will know the company can read the room.»
OPINIA«If it does not, we will know what the company's published positions on responsible AI and sustainability are actually worth.»
OPINIA«In light of what is increasingly becoming default behaviour, one has to ask a very simple question.»
NEUTRALNE«When will the Regulators and Public Prosecutors start to enforce the law which has been in place since 2002 - or are global tech corporations exempt from criminal and civil statutes?»
OPINIAKliknij zdanie oznaczone jako fakt lub perswazja, aby zobaczyć szczegółową analizę.
Google Chrome silently installs a 4 GB AI model on your device without consent. At a billion-device scale the climate costs are insane.
Two weeks ago I wrote about Anthropic silently registeringNACECHOWANE a Native Messaging bridge in seven Chromium-based browsers on every machine where Claude Desktop was installed [1].
The pattern was: install on user launch of product A, write configuration into the user's installs of products B, C, D, E, F, G, H without askingNACECHOWANE.
Reach across vendor trust boundariesNACECHOWANE.
No consent dialog.
No opt-out UI.
Re-installs itselfNACECHOWANE if the user removes it manually, every time Claude Desktop is launched.
This week I discovered the same patternNACECHOWANE, executed by Google.
Google Chrome is reaching intoNACECHOWANE users' machines and writing a 4 GB on-device AI model file to disk without askingNACECHOWANE.
The file is named weights.bin.
It lives inNACECHOWANE OptGuideOnDeviceModel.
It is the weights for Gemini Nano, Google's on-device LLM.
Chrome did not askNACECHOWANE.
Chrome does not surfaceNACECHOWANE it.
If the user deletes it, Chrome re-downloads it.
The legal analysis is the same one I gave for the Anthropic case.
The environmental analysis is new.
At Chrome's scale, the climate billNACECHOWANE for one model push, paid in atmospheric CO2 by the entire planetNACECHOWANE, is between six thousand and sixty thousand tonnes of CO2-equivalent emissions, depending on how many devices receive the push.
That is the environmental cost of one company unilaterally decidingNACECHOWANE that two billion peoples' default browser will mass-distributeNACECHOWANE a 4 GB binary they did not request.
This is, in my professional opinion, a direct breachNACECHOWANE of Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive) [2], a breach of the Article 5(1) GDPR principles of lawfulness, fairness, and transparency [3], a breach of Article 25 GDPR's data-protection-by-design obligation [3], and an environmental harm of a magnitude that would be a notifiable event under the Corporate Sustainability Reporting Directive (CSRD) for any in-scope undertaking [4].
What is on the disk and how it got there
On any machine that has Chrome installed, in the user profile, sits a directoryNACECHOWANE whose name is OptGuideOnDeviceModel.
Inside it is a file called weights.bin.
The file is approximately 4 GB.
It is the weights file for Gemini Nano.
Chrome uses it to power features Google has marketed under names like "Help me write", on-device scam detection, and other AI-assisted browser functions.
The file appeared with no consentNACECHOWANE prompt.
There is no checkbox in Chrome Settings labelled "download a 4 GB AI model".
The download triggers when Chrome's AI features are active, and those features are active by default in recent Chrome versions.
On any machine that meets the hardware requirements, Chrome treats the user's hardware as a delivery targetNACECHOWANE and writes the model.
The cycle of deletion and re-downloadNACECHOWANE has been documented across multiple independent reports on Windows installations [5][6][7][8] - the user deletes, Chrome re-downloads, the user deletes again, Chrome re-downloads again.
The only ways to make the deletion stick are to disable Chrome's AI features through chrome://flags or enterprise policy tooling that home users do not generally haveNACECHOWANE, or to uninstall Chrome entirely [5].
On macOS the file landsNACECHOWANE as mode 600 owned by the user (so it is deletable in principle) but Chrome holds the install state in Local State after the bytes are written, and as soon as the variations server next tells Chrome the profile is eligible, the download fires again - the architecture is the same, only the file permissions differ.
How I verified this on a freshly created Apple Silicon profile
Most of the existing reporting on this behaviour is from Windows users who noticed their disk filling up - useful, but Google could (and probably willNACECHOWANE) try to characterise those reports as anecdotes from non-representative configurations.
So I went looking for a clean witnessNACECHOWANE on a different platform.
The witnessNACECHOWANE I found is macOS itself.
The kernel keeps a filesystem event log called .fseventsd - it records every file create, modify and delete at the OS level, independent of any application logging.
Chrome cannot edit it, Google cannot remotely reach it, and the page files that record the events survive the deletion of the files they reference.
I created a Chrome user-data directory on 23 April 2026 to run an automated audit (one of the WebSentinel 100-site privacy sweeps).
The audit driver is fully Chrome DevTools Protocol - it loads a page, dwells for five minutes with no input, captures events, closes Chrome between sites - and the profile had received zero keyboard or mouse input from a human at any point in its existence.
Every "AI mode" surface in Chrome was untouched - in fact every UI surface in Chrome was untouched, the audit driver only interacts with the document via CDP and the omnibox is never reached.
By 29 April the profile contained 4 GB of OptGuideOnDeviceModel weights - and I knew it because a routine du -sh of the audit-profile directory caught it during a cleanup pass.
I went back to .fseventsd to ask exactly when those 4 GB landedNACECHOWANE.
macOS gave me the answer, byte-precise, in three sequential page files:
24 April 2026, 16:38:54 CEST (14:38:54 UTC) - Chrome creates the OptGuideOnDeviceModel directory in the audit profile (page file 0000000003f7f339).
24 April 2026, 16:47:22 CEST (14:47:22 UTC) - three concurrent unpacker subprocesses spawn temporary directories in /private/var/folders/.../com.google.Chrome.chrome_chrome_Unpacker_BeginUnzipping.*/ .
One of them (5xzqPo) writes weights.bin, manifest.json, _metadata/verified_contents.json and on_device_model_execution_config.pb.
The second writes a Certificate Revocation List update.
The third writes a browser preload-data update.
Chrome batched a security update, a preload refresh and a 4 GB AI model into the same idle window, as if they were equivalentNACECHOWANE (page file 00000000040c8855).
24 April 2026, 16:53:22 CEST (14:53:22 UTC) - the unpacked weights.bin is moved to its final location at OptGuideOnDeviceModel/2025.8.8.1141/weights.bin along with adapter_cache.bin, encoder_cache.bin, _metadata/verified_contents.json and the execution config.
Concurrently four additional model targets (numbered 40, 49, 51 and 59 in Chrome's optimization-guide enum) register fresh entries in optimization_guide_model_store - these are the smaller text-safety and prompt-routing models that pair with the LLM.
None of these targets existed in the profile before this moment (page file 00000000040d0f9c).
Total install time, from directory creation to final move: 14 minutes and 28 seconds.
Total human action against the profile during that window: none.
The GoogleUpdater logs record the on-device-model control component (appid {44fc7fe2-65ce-487c-93f4-edee46eeaaab}) being downloaded from http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/%7B44fc7fe2-65ce-487c-93f4-edee46eeaaab%7D/... - a 7 MB compressed control file that arrived on 20 April 2026, three days before the audit profile in question was created.
That is the upstream control plane: it is profile-independent, it is launched automatically by a LaunchAgent that fires every hour, and the URL is plain HTTP (the integrity is verified by the CRX-3 signature inside the package, not by transport security).
The control component gives Chrome the manifest pointing at the actual weights, and Chrome's in-process OnDeviceModelComponentInstaller - a separate code path from GoogleUpdater - then fetches the multi-GB weights direct from Google's CDN.
So we now have a four-way evidence chain - macOS kernel filesystem events, Chrome's own per-profile state, Chrome's runtime feature flags, and Google's component-updater logs - all four agreeing on the same conduct, and the conduct is: a 4 GB AI model arrived on this user's disk without consent, without noticeNACECHOWANE, on a profile that received zero human input, in a window of 14 minutes and 28 seconds, on a Tuesday afternoon.
Reports of the OptGuideOnDeviceModel directory and the weights.bin file have been circulating in community forums for over a year - what is new in 2026 is the scale and the verifiability.
Chrome's market share has held above 64% globally [9][10], Chrome's user base is between 3.45 billion and 3.83 billion individuals worldwide depending on which 2026 estimate you trust [9][11], and Google has been rolling Gemini features into Chrome with increasing aggressionNACECHOWANE.
The behaviourNACECHOWANE is no longer affecting a minority of power users on a minority of platforms - it is affecting hundreds of millions of devices, on every desktop OS Chrome ships against.
The same dark-patternNACECHOWANE playbook.
I am repeating my categorisation from the Claude Desktop article [1] because the patterns are identical and that is the point.
Forced bundlingNACECHOWANE across trust boundaries.
Anthropic installed Claude Desktop, then wrote intoNACECHOWANE Brave, Edge, Arc, Vivaldi, Opera, and Chromium.
Google installs Chrome, then writes a 4 GB AI modelNACECHOWANE under the user's profile directory without authorisation.
The binary is not Chrome.
It is a separately-trained machine-learning model, with a separate purpose, a separate data-protection profile, and a separate consent footprintNACECHOWANE.
No dialogue at first launch.
No checkbox in Settings.
The model is downloaded; the user finds out about it months later when their disk fills up [5][6][7].
Adding the file took zero clicksNACECHOWANE.
Removing it requires (a) discovering the file exists, (b) understanding what it is, (c) navigating into a hidden user profile path, (d) deleting it (and on Windows, also clearing the read-only attribute first), and (e) accepting that Chrome will silently re-downloadNACECHOWANE it on next eligible window unless the user also navigates chrome://flags, enterprise policy, or platform-specific configuration tooling to disable the underlying Chrome AI feature [5].
None of those steps is documented in the place a normal userNACECHOWANE looks - none of them is even hinted at in default Chrome.
The Nano model exists on the user's disk so that Chrome features that use it can run instantly when the user invokes them.
The user has not invoked any of those features.
The model still sits thereNACECHOWANE, taking 4 GB.
OptGuideOnDeviceModel is internal Chrome jargon for "OptimizationGuide on-device model storage".
A user looking at their disk usage, even one who knows roughly what they are looking at, would not match OptGuideOnDeviceModel/weights.bin to "Gemini Nano LLM weights".
Accurate namingNACECHOWANE would be GeminiNanoLLM/weights.bin.
Google chose to obfuscateNACECHOWANE the name.
A user who has not opened Chrome's AI features still gets the model.
A user who has opened them once and decided they were not interested still gets the model.
The file's presence is decoupledNACECHOWANE from the user's actual use of any feature it powers.
Google's user-facing documentation about Chrome's AI features does not, with the prominence proportionate to a 4 GB silent downloadNACECHOWANE, tell the user that the cost of the feature being available is a 4 GB file appearing on their device.
The behaviour is documented in places a curious adminNACECHOWANE will find.
It is not documented in the place a regular userNACECHOWANE looks before installing Chrome or before Chrome decides to begin pushingNACECHOWANE the model.
Delete the file, Chrome re-creates it.
The user's deletion is treated as a transient state to be corrected, not as a directive to be respectedNACECHOWANE.
Same as Claude Desktop.
If Google in future starts asking users "would you like Chrome to download a 4 GB AI model", that prompt does not retro-actively legitimiseNACECHOWANE the silent installs that have already happened on hundreds of millions of devices.
The damage to the trust relationshipNACECHOWANE is done.
The bytes have moved.
The atmosphere has been written toNACECHOWANE.
This is not test build behaviour.
It is Chrome stable.
Here is the part that should make every privacy lawyer in the audience put their coffee downNACECHOWANE.
When Chrome 147 launches against an eligible profile, the omnibox - the address bar at the top of the window, the most visible piece of real estateNACECHOWANE in the entire browser - renders an "AI Mode" pill to the right of the URL field.
A reasonable userNACECHOWANE, seeing "AI Mode" sitting in their browser's most prominent UI element in 2026, with the well-publicised existence of on-device LLMs in Chrome and a 4 GB Gemini Nano binary already silently installed on their disk, is going to draw what feels like an obvious inferenceNACECHOWANE - that the visible AI Mode is using the on-device model, that their queries stay on the device, that the local model is what powers the local-looking surface.
Every part of that inference is wrongNACECHOWANE.
The AI Mode pill in the Chrome 147 omnibox is a cloud-backed Search Generative Experience surface - every query the user types into it is sent over the network to Google's servers for processing by Google's hosted models.
It is skipping because the user is not given a moment to choose between local-only and cloud-backed AI surfaces - both are switched on by the same upstream rollout, with no per-feature consent.
And it is hindering because turning AI Mode off does not also remove the on-device install, and removing the on-device install does not turn AI Mode off - the two are separately controlled, and discovering both controls requires knowing about both chrome://flags and chrome://settings/ai, neither of which is obviousNACECHOWANE in default Chrome.
So: not just a non-consented install, but a non-consented install that doubles as coverNACECHOWANE for a parallel cloud-backed surface that misrepresents to the userNACECHOWANE where their typing is being processed.
Both layers compound the consent problem.
Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive) prohibits the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user, without the user's prior, freely-given, specific, informed, and unambiguous consent, except where strictly necessary for the provision of an information-society service explicitly requested by the user [2].
The 4 GB Gemini Nano weights file is information stored in the user's terminal equipment.
The user did not consent.
The user has not requested any service that strictly requires a 4 GB on-device LLM.
Chrome is functional without the file.
The Article 5(3) breach is direct.
Article 5(1) GDPR requires processing of personal data to be lawful, fair, and transparent to the data subject [3].
Where the user's hardware is profiled to determine eligibility for the model push, where the install events are logged on Google's servers, and where the on-device features the model powers process user prompts (whether or not those prompts leave the device), the lawfulness, fairness, and transparency of all of that processing depend on the user being told, in plain languageNACECHOWANE, what is happening.
They are not.
Article 25 GDPR requires the controller to implement appropriate technical and organisational measures to ensure that, by default, only personal data that are necessary for each specific purpose are processed [3].
Pre-staging a 4 GB AI model on a user's disk, against a contingency that the user might in future invoke an AI feature, is the architectural oppositeNACECHOWANE of by-default minimisation and the profiling of the device to determine whether or not to push the model is not different to the profiling used to track you online and as such that profile contains personal data and if the AI model is used, will process personal data, so the GDPR arguments are in scope and valid.
Under the UK GDPR and the Privacy and Electronic Communications Regulations 2003, the analysis is the same.
Under the California Consumer Privacy Act, the absence of a notice-at-collection covering this specific category of pre-staged software puts Google's CCPA notice posture in question [12].
Then there are the criminal-law violations under various national computer-misuse statutes - which again cannot be overstatedNACECHOWANE.
The Anthropic case I wrote about was a desktop application installing a 350-byte JSON manifest in seven directories.
The bandwidth and energy cost of that, summed across all Claude Desktop users, was negligibleNACECHOWANE.
The Chrome case is different.
Chrome is pushing a 4 GB binary across hundreds of millions of devices.
That has a measurable, quantifiable, and frankly alarming environmental footprintNACECHOWANE.
I am calculating this using the same methodology our WebSentinel audit platform applies to website environmental analysis [13]:
Energy intensity of network data transfer: 0.06 kWh per GB, the mid-band of Pärssinen et al. (2018) "Environmental impact assessment of online advertising", Science of The Total Environment [14].
The paper reports a 0.04-0.10 kWh/GB range depending on the share of fixed-line vs mobile transfer and inclusion of end-user device energy.
0.06 is a defensible mid-pointNACECHOWANE.
Grid emissions factor: 0.25 kg CO2e per kWh, the EEA / IEA composite EU-27 electricity-supply factor for 2024 reporting [15].
Globally the figure varies from ~0.10 kg/kWh on mostly-renewable grids to over 0.70 kg/kWh on coal-heavy grids; 0.25 is mid-band for a global push and is the figure WebSentinel uses by default.
Per-device cost of one Nano push
Bandwidth: 4 GB
Energy: 4 × 0.06 = 0.24 kWh per device per push
CO2: 0.24 × 0.25 = 0.06 kg CO2e per device per push
That is per device, per push.
A single download of the model.
It does not include re-downloads triggered by the user trying and failing to delete the file.
It does not include subsequent updates to the model.
It does not include the on-device inference energy when the model is actually used.
It is just the one-time delivery cost to one device.
Google does not publish how many devices receive the Nano push.
The eligibility criteria gating the push (a hardware "performance class" that Chrome computes from CPU class, GPU class, system RAM and available VRAM - typically ~16 GB unified memory or better on Apple Silicon, ~16 GB RAM and a discrete or integrated GPU with sufficient VRAM on Windows and Linux) carve out the very low end of the consumer install base, but the qualifying population is still enormousNACECHOWANE.
I will use three illustrative deployment bands so the reader can pick whichever they consider closest to reality.
None of these bands is implausibly largeNACECHOWANE for a feature that ships in default-on Chrome.
Devices receiving the push
Total bytes pushed
Total energy
Total CO2e
100 million (low band: ~3% of Chrome users)
400 petabytes
24 GWh
6,000 tonnes CO2e
500 million (mid band: ~15% of Chrome users)
2 exabytes
120 GWh
30,000 tonnes CO2e
1 billion (high band: ~30% of Chrome users)
4 exabytes
240 GWh
60,000 tonnes CO2e
To compare those numbers to what an ESG report could compare to:
24 GWh (low band) is roughly the annual electricity consumption of about 7,000 average UK households [16].
120 GWh (mid band) is roughly the annual electricity consumption of about 36,000 average UK households, or the annual output of a 14 MW wind turbine running at typical UK capacity factor.
240 GWh (high band) is roughly the annual electricity consumption of about 72,000 average UK households, or the annual output of about 28 MW of installed wind capacity.
6,000 tonnes CO2e (low band) is roughly the annual emissions of 1,300 average passenger cars in the EU [17].
30,000 tonnes CO2e (mid band) is roughly the annual emissions of 6,500 cars, or one return flight from London to Sydney for about 8,000 passengers in economy.
None of that infrastructure exists for free.
Every byte Chrome pushes is a byte that competes with bytes the user actually wantedNACECHOWANE.
For users on capped mobile data plans, particularly in regions where smartphone-as-only-internet is dominant (much of Africa, much of South and Southeast Asia, most of Latin America), 4 GB of unrequested downloadNACECHOWANE is on the order of a month's data allowance, vapourisedNACECHOWANE by Chrome on the user's behalf.
Google has not, to my knowledge, published any analysis of the welfare impact of this on the populations whose internet access is metered.
Keep in mind that mobile data plans (4G and 5G) are used by many households who do not have access to fiber, cable or adsl and are used for desktop devices as well as mobile - so the argument that Google won't push this to mobile devices (although I have not found anything official to support that argument anyway) will not flyNACECHOWANE.
Ask.
First time Chrome is about to download the Nano model, pop a dialogue.
"Chrome would like to download a 4 GB AI model file to your device to power the following features.
Allow, or skip and decide later."
Two buttons.
Done.
Pull, not push.
Trigger the download as a downstream consequence of the user invoking an AI feature for the first time.
Let the feature itself be the consent event.
Do not pre-stage on a contingency.
Surface it.
In chrome://settings/, list the AI model files Chrome has downloaded, their size, the features they power, and a "Remove and stop downloading" button per model.
Make removal persistent, not a transient state Chrome corrects on next launch.
Document it.
Tell the user, plainly, in the Chrome description on the Microsoft Store, in the Chrome installer, on the Google Chrome download page, that Chrome will download additional model files of substantial size on supported hardware.
Currently, this is essentially undocumented to a normal userNACECHOWANE.
Respect deletion.
If the user deletes weights.bin, do not re-create it.
If the user has a strong preference about what is on their disk, the application is not in a position to override that preference because the application thinks it knows betterNACECHOWANE.
Disclose at scale.
Publish, in Google's annual ESG report, the aggregate bandwidth and carbon footprint of all AI-feature model pushes to user devices, broken down by region.
Treat it as the Scope 3 Category 11 emission it is.
Account for it.
Notify retrospectively.
Users who already received the model without consent should, on next Chrome launch, be told what happened, shown the file, and offered a one-click revoke + uninstall.
This is the same retrospective-consent step Anthropic should also have taken.
Both of these episodes, the Anthropic Claude Desktop manifest install I wrote about two weeks ago and the Google Chrome Gemini Nano push I am writing about today, share the same underlying decision.
An engineering team at a large AI vendor decided that the user's machine is a deployment surfaceNACECHOWANE to be optimised for the vendor's product roadmap, not a personal device whose owner is the legal authorityNACECHOWANE on what runs there.
The Anthropic case put a pre-authorisation for browser automation on around three million Claude Desktop user devices [19].
The Google case puts 4 GB of AI weights on, by my mid-band estimate, around 500 million Chrome user devices, with proportionally larger ePrivacy, GDPR, and environmental exposure.
Both companies have a public posture of caring about safety, ethics, and responsible AI.
Both companies, in the silent installation behaviours documented here, have underminedNACECHOWANE the foundational consentNACECHOWANE on which the legitimacy of any of those positions depends.
The fact that the bytes are AI bytes does not exempt them from the lawNACECHOWANE that governs every other byte that gets written to a user's device without permission.
The fact that the bytes are "small" relative to the user's disk does not exempt the cumulative carbon footprint from being a real, measurable, ongoing harm to the climateNACECHOWANE.
If Google's next Chrome update silently removes the unconsented installs and replaces the behaviour with an explicit opt-in, we will know the company can read the roomNACECHOWANE.
If it does not, we will know what the company's published positions on responsible AI and sustainability are actually worthNACECHOWANE.
In light of what is increasingly becoming default behaviourNACECHOWANE, one has to ask a very simple question.
When will the Regulators and Public Prosecutors start to enforce the law which has been in place since 2002 - or are global tech corporations exemptNACECHOWANE from criminal and civil statutes?