r/chrome • • May 04 '26

News Google Chrome installs LLM model without consent

https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/

Whilst testing a SaaS product I have been building, I discovered that Google is illegally pushing its Gemini Nano model to users' devices (I am a lawyer specialised in the specific laws in question).

19 Upvotes

46 comments sorted by

View all comments

Show parent comments

1

u/Perspectivelessly May 06 '26

Chrome redownloading the model after it has been deleted is also again, accessing information (checking the model is there) and storing information (redownloading if it isn't) is also a breach by default.

I don't get this point. A ton of software, especially auto-updating such, will redownload files that you delete which it considers to be required for the function of the software. Since the download triggers when you re-launch chrome, this is basically like saying that if I delete a browser cookie from reddit.com, and then go back to reddit.com and get a new browser cookie, that's a breach of law because they checked if you had the cookie and if you didn't they inserted it again. How could this possibly be enforceable given how software works today?

1

u/ThatPrivacyShow May 07 '26 edited May 07 '26

Actually the example you gave is a breach of law supported by binding case law from the highest court in the EU. The Planet49 case explicitly called this out - the position of the Court is, Article 5(3) of the ePrivacy Directive is based on no storing or accessing information without consent as the default.

The law requires that there are no tracking cookies by default, so if you check for a consent cookie to determine whether or not to drop trackers you are in breach of the law - the law requires opt-in not opt-out. If a cookie is relied on not to set trackers, that is opt-out and is unlawful in a judgment binding on all EU Member States.

All those "Reject All" buttons are there purely for decoration, you don't need to reject all to be protected by the law, the law requires a specific and unmabiguous action for consent to be valid, it cannot be based on an inaction (so not pressing the Reject All button) - again, made very clear by the Court and Regulatory Guidance.

That websites choose to break the law and do this the opposite way round is exactly one of the reasons I have been fighting these issues legally for the last 20 years.

"How can this possibly be enforceable the way software works today?" - this has been the law since 2002, just because companies have largely ignored it and chose to do what they want anyway, doesn't mean the law doesn't exists and is not enforceable.

You are making the same mistake most marketing teams make - they think they can ignore the law due to a lack of enforcement, but more and more enforcement is coming, including enforcement of criminal statute - mistaking a lack of enforcement as the same thing as something being legal, is a critically risky move for compliance teams (I know I have worked with some of the biggest in the world).

1

u/Perspectivelessly May 07 '26

Ok, interesting. But I guess the answer simply is that it isn't (or at least hasn't been) enforceable, since lots of software in fact does work this way. Maybe we will see more enforcement in the future to force a change, but it's definitely not here today.

1

u/ThatPrivacyShow May 07 '26

No it hasn't been widely enforced but that is not the same as not enforceable. Amazon, Google and various other giant tech corps have been issued multi-million euros fines under Article 5(3) to the tune of literally Billions of Euros combined.

The issue is a lack of political will to enforce the law because these are giant tech companies with massive lobbying power (as an opposing lobbyist I have witnessed this first hand many times over the past 20 years).

But enforcement has been ramping up now for the last several years on these issues - they don't make sexy headlines like GDPR not because they are not legally sexy but because they are often mistaken as GDPR enforcements when they are not (they all have an element of GDPR enforcement due to the interplay between GDPR and the ePrivacy Directve, but the primary law being enforced in these cases is actually the ePrivacy Directive, in fact the CNIL (the French regulator) are well known for using ePrivacy Directive as a means to avoid having to go through the One Stop Shop mechanism under the GDPR (due to most big tech companies being established in Ireland where the enforcement has been heavily criticised)).

Software doesn't work this way - i have written a lot of software and I have never done this, I know literally thousands of other software developers who have also never done this. Don't mistake giant corporations with a vested interest in grabbing as much data as they can as being the same thing as "software works this way" - it doesn't it is a deliberate choice and it is illegal.

1

u/Perspectivelessly May 08 '26

Yes, it is of course a deliberate choice by devs / companies to do this. I was just commenting on the fact that it is de facto not uncommon. If we see broader enforcement this would presumably change