Apple brings Private Cloud Compute to Google Cloud with NVIDIA
Apple will run some Apple Intelligence workloads on Google Cloud, taking Private Cloud Compute beyond its own data centers.
Apple will run some Apple Intelligence workloads on Google Cloud infrastructure for the first time, expanding its Private Cloud Compute system beyond Apple-operated data centers.
Apple said the deployment will support Apple Intelligence tasks such as agentic tool use and complex reasoning. The workloads will run on Google Cloud systems using NVIDIA GPUs.
NVIDIA said its Blackwell GPUs with Confidential Computing are being integrated into Private Cloud Compute's hardware security architecture on Google Cloud. The GPUs will support server-side inference for Apple Foundation Models built by Apple and Google using technologies behind Google's Gemini family of models.
Apple introduced Private Cloud Compute in 2024 as a system for handling AI requests that are too complex to run fully on-device. The system was designed to extend Apple's device-level privacy and security protections to cloud-based AI processing.
How the Google Cloud deployment works
The Google Cloud deployment uses NVIDIA Confidential Computing with NVIDIA GPUs, Intel CPUs with Trust Domain Extensions, and Google's Titan chip. NVIDIA Confidential Computing isolates AI workloads in trusted execution environments and supports hardware-based security checks before sensitive data is processed.
The technology also supports remote attestation, which allows software to verify the security state of the platform before sensitive data is sent to the server. NVIDIA said its approach includes hardware-rooted trust and encrypted communication paths between system components.
Apple said the same core requirements will apply to the Google Cloud version of Private Cloud Compute. These include stateless computation, enforceable guarantees, no privileged runtime access, non-targetability, and verifiable transparency.
The company said the deployment does not rely only on standard confidential computing protections. Apple said every component, from firmware and operating system layers to application code, is treated as part of the trusted computing base and subject to transparency and no-privileged-access requirements.
Apple also said it will maintain a cryptographically verifiable, append-only ledger of Google Cloud hardware used in the Private Cloud Compute fleet. The company said software attestation for components that could be used to extract user data is rooted in at least two independent vendor trust sources.
The Google Cloud implementation also uses several security patterns from the Apple silicon version of Private Cloud Compute. Apple said initial network data parsing for each request takes place in a dedicated process within its own namespace.
Shared inference software is recycled on a short time-to-live basis. Attested keys are also kept in a separate confidential virtual machine that is isolated from external inputs.
Apple said it will retain control over Private Cloud Compute software regardless of where the infrastructure is hosted. Apple devices will only trust software that has been cryptographically approved by Apple.
The Google Cloud deployment will be expanded during a summer preview period. Apple said the system will move toward the full set of protections during that period.
Security review and transparency
As with the Apple silicon version of Private Cloud Compute, Apple said it will publish all binaries for public inspection. The company also plans to provide research tools and access to live Private Cloud Compute nodes in research mode through the Apple Security Bounty Program.
Apple said more technical information about Private Cloud Compute on Google Cloud will be shared at the Confidential Computing Summit later this month. Updates to the Private Cloud Compute Security Guide and research program details are also planned for later this year.