Apple has begun running Private Cloud Compute outside its own data centers. The host is Google Cloud, and the compute runs on NVIDIA GPUs. It is a difficult balancing act: handing the heaviest Apple Intelligence workloads to someone else's hardware while keeping Apple's privacy commitments intact.

Private Cloud Compute leaves Apple's own servers

Private Cloud Compute (PCC) is the AI inference platform Apple introduced in 2024. It was designed to move work that on-device models cannot handle into the cloud while preserving the same level of security users get on an iPhone or a Mac. Until now, every PCC request ran on Apple silicon inside data centers Apple controlled.

That premise has changed. Alongside the next generation of Apple Intelligence, Apple says it is working with Google and NVIDIA to run part of PCC on Google Cloud systems. The workloads in scope are the demanding ones: agentic tool use and complex reasoning. This is the first time Apple has extended its PCC privacy requirements to third-party data centers.

Part of the reason lies in how the models themselves are now built. The next generation of Apple Foundation Models is built on technologies behind Google's Gemini family, and running inference on the same infrastructure where the models were built keeps both the implementation and the latency simpler. Apple's own Apple silicon PCC fleet continues to operate in parallel, so this is an expansion rather than a migration.

Three vendors' hardware stacked into one root of trust

What is new about PCC on Google Cloud is the implementation, not the requirements. Apple's five core PCC properties carry over unchanged: stateless computation, enforceable guarantees, no privileged runtime access, non-targetability, and verifiable transparency.

Supporting them is a stack of hardware features from three companies. On the GPU side, NVIDIA Confidential Computing isolates data inside a trusted execution environment while it is being processed. On the CPU side, Intel TDX plays the same role, and the root of trust is anchored by Google's Titan security chip. NVIDIA's contribution includes hardware-rooted trust that verifies workloads are running on genuine, untampered GPUs, encrypted communication paths between components, and remote attestation that checks the platform's security state before any sensitive data is released to it.

Apple went a step further, treating every component as part of the trusted computing base, from firmware through the host and guest OS stacks to application code. The company is explicit that it does not rely on confidential computing alone to stop attacks that abuse privileged access outside the confidential VM, including side-channel attacks.

Built on the assumption that rented hardware cannot be trusted

The implementation details make Apple's wariness about borrowed infrastructure obvious.

The first is a component-level ledger. Apple maintains its own cryptographically verifiable, append-only record of all Google Cloud hardware that forms part of the PCC fleet. The point is to track supply chain risk independently rather than leaning on Google's own attestation.

The second is a doubled root of trust. For any component that could be abused to exfiltrate user data, software attestation is rooted in at least two separate roots of trust from independent vendors. Compromising Intel, NVIDIA or Google alone is not enough to break the verification chain.

The inference stack reuses the architectural patterns Apple developed for Apple silicon. Initial network data parsing for each request happens in a dedicated process within its own namespace, shared inference software is recycled on a short time-to-live, and attested keys sit in a separate confidential VM isolated from external inputs. Wherever the hardware lives, Apple retains full control of the PCC software, and Apple devices will only trust PCC software that Apple has cryptographically approved.

Public verification stays, rollout runs through the summer

The transparency story is unchanged. All PCC binaries running on Google Cloud will be published for public inspection. Apple will provide research tooling and continue offering access to live PCC nodes in research mode through the Apple Security Bounty Program. The framework that lets outside researchers check Apple's claims is being carried onto someone else's hardware.

The rollout ramps gradually through the summer preview period, so the full set of protections will take time to land. Apple plans to share technical detail at the Confidential Computing Summit, with an updated PCC Security Guide and expanded research program documentation due later in the year. Financial terms, capacity commitments and the regions involved have not been disclosed.

Summary

Apple has extended Private Cloud Compute beyond its own data centers for the first time, working with Google and NVIDIA to run demanding Apple Intelligence workloads on Google Cloud. The design layers NVIDIA GPU confidential computing, Intel TDX and Google's Titan chip, then verifies the rented hardware through a component-level ledger and dual roots of trust. The privacy requirements are unchanged, and binary publication and researcher access remain in place. Whether Apple can keep the same promises on someone else's cloud is a question the verification period is about to answer.