On a Windows 11 machine with Chrome 147 installed, this folder is worth checking:
%LOCALAPPDATA%\Google\Chrome\User Data\OptGuideOnDeviceModelMany users will find a 4GB file named weights.bin sitting there. It is Gemini Nano, the lightweight model Google has spent the past year distributing to hundreds of millions of Chrome desktops without a clear prompt, opt-in box or installation consent dialog.
The discovery came from Alexander Hanff, a computer scientist and lawyer, who traced the behavior through macOS kernel file-system logs and filed a complaint against Google under European privacy law.
A few details make the rollout harder to dismiss
First, the file is 4GB. Not 400MB, and not 40MB. At desktop Chrome scale, that means Google has pushed data measured in exabytes onto user storage over the course of a year.
Second, deleting it does not necessarily end the matter. If a user removes weights.bin manually, Chrome can download it again on the next launch. For a long stretch there was no ordinary opt-out control; full blocking was mainly available to enterprise administrators.
Third, Chrome 147 shows an AI Mode icon in the address bar. But that 4GB local model is not what powers AI Mode. Those queries still go to Google's servers.
Hanff's estimate is blunt: multiply 4GB by hundreds of millions, or even a billion, devices and the transfer alone reaches several exabytes, with associated emissions estimated at roughly 6,000 to 60,000 metric tons of carbon dioxide.
That turns distribution itself into a meaningful energy cost, before any user-facing AI feature has even run.
Google's response says more than it first appears to
Google says it has deployed Gemini Nano in Chrome since 2024 as a lightweight on-device model. The company frames it as support for important safety features such as scam detection and developer APIs, with data handled locally rather than sent to the cloud. Google also says the model may be removed automatically when a device is short on space, and that since February 2026 Chrome settings have included controls to disable and remove it.
That statement carries three implications. Google acknowledges the quiet download, but treats it as a default feature rather than a bug. It justifies the installation through security capabilities and developer APIs that most users never see directly. And the February 2026 control implies that before then, ordinary users had no clear switch to turn the model off.
Why the story surfaced only now
- Mid-2024: Google began silently distributing Gemini Nano through Chrome.
- Mid-2025: the model grew from earlier versions to around 4GB.
- February 2026: Google added a setting to remove the model.
- May 6, 2026: Hanff published his full investigation and the issue spread widely.
- May 11, 2026: EU privacy regulators had begun informal inquiries.
For roughly a year, Chrome users were part of this distribution experiment without being explicitly told what was being placed on their devices. The pattern became visible only because a researcher went digging through file-system logs.
A textbook warning for on-device AI
Google and Apple have both promoted on-device AI as safer and more private because models run locally instead of sending data away. That promise depends on trust.
Chrome's handling undermines that message. Users who thought they had not installed AI may have had 4GB of model weights on disk. Users told that on-device AI protects privacy may still reasonably object if they were never told the model existed. And the user control that should have been obvious arrived only in February 2026.
Apple has not had a comparable episode so far. Apple Intelligence installation has been presented with visible prompts, user confirmation and storage disclosures. The contrast gives the industry a live test of what consent for on-device AI should look like.
What is likely to happen next
In the short term, European regulators are likely to examine the case through a GDPR lens. Writing several gigabytes to a user's storage without explicit consent is not a small matter in that framework.
Chrome is also likely to change its interface. A future version could present a first-install prompt for Gemini Nano and disclose the approximate 4GB disk requirement.
The larger effect may reach beyond Google. If Chrome can silently install a local model, then Edge, Safari, Firefox and any browser with built-in AI will face the same consent question. Within a year, the industry's default policy for preinstalled on-device AI may need to be rewritten.
The final point is the most important: Hanff does not argue that on-device AI is the wrong direction. The problem is consent. Google's rollout shows that the easiest way to put AI into a product is still to avoid telling users exactly what changed.
Sources: Google Chrome Is Silently Downloading a 4GB Gemini Nano AI Model to User Devices Without Consent (gHacks); CocoLoop; [Update: Google Statement] Chrome has been secretly downloading a 4GB Gemini Nano model to your device (Android Headlines); Google Chrome silently installs a 4 GB AI model on your device without consent (That Privacy Guy)