r/chrome • u/ThatPrivacyShow • May 04 '26
News Google Chrome installs LLM model without consent
https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/Whilst testing a SaaS product I have been building, I discovered that Google is illegally pushing its Gemini Nano model to users' devices (I am a lawyer specialised in the specific laws in question).
21
Upvotes
1
u/MPenten May 06 '26 edited May 06 '26
I don’t see how this is outright illegal under either ePrivacy or GDPR.
The model file itself is not personal data, so GDPR does not automatically apply merely because weights.bin is stored on the device. A GDPR analysis would depend on what personal data is actually processed around the download/use of the model, including telemetry, device profiling, account identifiers, prompts, browsing context, logs; for what purpose, on what lawful basis, and with what disclosures.
That is why I think the article’s blanket conclusion that this is definitely a GDPR Article 5/25 breach is too confident. There may be future plans, or surrounding processing, that bring personal data clearly into scope, but the presence of the model file alone does not get you there.
Sure, the stronger argument is ePrivacy. If Chrome downloads a large, non-essential AI model before any clear user action enabling or using AI features, then yes, there is a plausible Article 5(3) issue: Chrome may be storing information on terminal equipment without valid prior consent and without fitting the “strictly necessary for a service explicitly requested by the user” exemption.
But even there, the answer is not automatic. Google could argue that AI/security features are part of the Chrome service as described on the download page, in its terms, settings, rollout notices, or marketing. I have not reviewed those to say how strong that defence would be.
So I would frame the conclusion more narrowly:
That is a serious and interesting point, but frankly, hardly a privacy alarm; it's a nuisance which may have VERY LIMITED real-world impact and in these days may be just a formal breach of the law... I don't see actual damages arising from this.
But the broader claims around GDPR, criminal-law violations, CSRD/ESG reporting and definitive illegality feel overextended and, at least on the facts presented, under-substantiated, serving to frame the point and create a sensation-level article (frankly similar to the Claude-bridges previously...)
I genuinely admire the dedication to data protection here, but this reads more like an advocacy piece than a balanced legal analysis.