Apple’s whole marketing push is about privacy. It’s how it positions itself as the better option in a world full of other companies (Google included) offering you free services in exchange for access to your private data and information.
With the new Siri AI, however, there are some cracks starting to show. Here’s what’s documented, what’s promised, and how the gap between the two of those things might affect you.
What Apple actually announced
A $1 billion deal, a 1.2-trillion-parameter model, and a WWDC unveiling
Back in January 2026, Apple and Google confirmed a multi-year partnership that added Gemini as the AI engine behind a new Siri and any new Apple Intelligence features. It will reportedly have Apple paying Google around one billion dollars a year, which is separate from the existing Google on Safari search agreement.
Bloomberg (via MacRumors) notes that the Gemini model will be a 1.2 trillion parameter model, which is roughly eigh ttimes larger than Apple’s current cloud-based AI (which uses about 150 billion parameters). It uses what’s called a “mixture-of-experts” (MoE) architecture, which means only part of the model is active per query, and it was reportedly tuned for the types of summary and planning tasks Siri is meant to handle the most. That makes this a custom Apple version of Gemini’s underlying model, not the consumer-facing one you may use in your Chrome browser.
Apple unveiled the new Siri AI at it’s Worldwide Developers Conference (WWDC) this past June, saying it was the biggest Siri overhaul in 15 years. The company promised a standalone chat app, multimodal input, multistep commands, custom voices, and conversational history routed through iCloud.
The pitch for privacy, tier by tier
Three tiers, and one clear line where Apple’s infrastructure ends
There are three tiers that your queries will route through when you use the new Siri AI. Tier one will handle simple requests, like setting a cooking timer, turning on and off your lights, or similar. These route to Apple’s own models via the Neural Engine in your phone (you need to have an iPhone 15 Pro and up), and they’ll never leave your device.
The second tier gets involved when your query is more complex. These requests will head to Apple Silicon servers in what the company calls its Private Cloud Compute (PCC), getting stateless processing, no data retention, and no privileged runtime acces. Outside researchers can inspect this private cloud via an Apple-provided PCC Virtual Research Environment.
It’s the final tier where Google gets involved. The heaviest reasoning tasks will route to this new custom Gemini model, which runs on Google Cloud infrastructure that runs on Nvidia Blackwell B200 GPUs instead of Apple Silicon. Some reporting theorizes that the latter wasnt’ fast enough at scale for what the new Siri AI needed.
The routing all happens on its own — you won’t get to choose which tier your queries get answered by, as Apple uses a System Orchestrator to decide which tier gets which request, and it’s based on complexity, not a choice you make.
Here’s where the Google-shaped asterisk comes in
Scrubbed data, borrowed hardware, and different stories from different CEOs
Apple says it will strip any personally-identifiable or account-linked data before your query even reaches Gemini, which seems to imply that Google won’t see an Apple ID, your identity, or location history. That’s what Apple says, of course, as reported by outlets like AppleInsider, not from independent verification. The agreement also reportedly keeps Google from training future models on Siri interactions, which is a contractual protection, not a technical.
On the technical side, though, Apple is relying on Nvidia’s confidential computing feature on the Blackwell chips it’s relying on. They provide encrypted processing in a trusted execution environment with remote attestation to confirm the hardware hasn’t been tampered with. While that sounds like a good privacy move, Apple’s spent years saying “what happens on iPhone stays on iPhone,” With Private Cloud Compute to back that up. Now it’s handing part of its job to a third-party company and its hardware.
On a call with CNBC ahead of an earnings report this past January, Tim Cook said, “We’re not changing our privacy rules. We still have the same architecture that we announced before, which is on device plus Private Cloud Compute.”
Sundar Pichai, CEO of Alphabet and Google, described it a bit differently, characterizing the collaboration with Apple as its “preferred cloud provider … to develop the next generation of Apple Foundation Models, based on Gemini technology.”
As we know from various other Google privacy missteps, this could be a problem.
Regulators are skeptical
The DOJ and EU aren’t buying it
Google and Apple have already run afoul of the US Department of Justice (DOJ) for the companies’ Safari agreement, which apparently moved $20 billion from Google to Apple in 2022 alone. The DOJ’s solution explicitly restricts exclusive Gemini distribution deals, with some legal analysts arguing that this new Siri-Gemini agreement could go against.
Apple has confirmed that Siri AI will not be available in the EU on iPhone or iPad, while Mac, Apple Watch, and Vision Pro will in that area, because those platforms aren’t designated “core platform services” under the DMA. China is withheld for separate, unrelated regulatory reasons.
Apple’s reasoning is that the EU’s interoperability requirements will fource the ompany to give competing assistants direct access to user data and control over other apps. The European Comission disputed this framing, saying the DMA never blocked the launch, blaming Apple for the delay.
If Apple is so confident in its own privacy architecture, it shouldn’t have to withhold the tech from regulators or worry about other companies getting a hold of user data.
So, How Private Is the New Siri, Really?
The verifiable, on-the-record facts say that PCC is stateless and able to be inspected by independent entities. Google is contractually barred from training on Siri data, and personally identifiable information is removed before the data even reaches Gemini.
What’s not verifiable (yet) is how that data is removed before your queries go to the Gemini tier, how the Nvidia’s confidential computation actually works in production environments, or how well Google will abide by the contractual training ban. These aren’t independently auditable, so they fail the privacy test that Apple already set with Private Cloud Compute.
Your queries remain in Apple’s privacy garden as long as they’re simple to moderately complex requests, but anything judged as more complicate will send your queries to this new Gemini-based system, which depends on the two companies’ contracts and a third-company’s chips. That’s the final result here, so far: Siri is as private as all the technology above (and the legal requirements) can allow.