Copy article

Google Chrome just installed local AI on users' PCs without asking. One billion devices means 60,000 tonnes of CO2 just from the download

ended 18. May 2026

Google Chrome is silently downloading a 4 GB AI model onto computers without asking users and if they delete it without making configuration changes, it auto-downloads itself again.

Security researcher Alexander Hanff has documented Chrome quietly installing Google's Gemini Nano AI model onto users' devices with no consent prompt, no notification, and no obvious way to stop it. Snopes confirmed the file on multiple staff machines. 

With the number of security risks operating systems and software faces, users are advised to apply updates quickly to secure their machines. Updates now come thick and fast and the user may lack the time or skill to investigate the precise nature of the updates.

Hanff calculated that pushing 4 GB to even 30% of Chrome's user base would consume 240 gigawatt-hours of energy and generate up to 60,000 tonnes of CO2, just from the downloads, before anyone's browser uses the model. 

That is the annual electricity consumption of 72,000 UK households, spent distributing software nobody asked for. He argues the practice likely breaches the EU's ePrivacy Directive and GDPR transparency requirements.

Google says the model has been available since 2024, powers security features like scam detection, and that users can now disable it in Chrome settings. Hanff says that toggle didn't exist when the downloads started. Google also says it will not download the software on machines that are low on disk space.

We'd like your views:

  • If a browser can silently install 4 GB of AI, and use your RAM, disk space and electricity to run,  without asking how do you feel about companies who are doing this? 
  • Google said it added an opt-out a year after the silent installs started. Does that count as consent or a panicked cleanup?
  • Up to 60,000 tonnes of CO2 could have been released to distribute software nobody requested. When does an AI rollout become an environmental event needing an impact assessment?
  • Is this the moment you switch browsers? Which one and why?

2 responses from the Newspage community

Copy all

Star Quote
Copy

On-device scam detection is genuinely useful and nobody's arguing against that. The problem is that Google decided the way to deliver it was to commandeer 4 GB of your hard drive, your bandwidth, syphen off some more RAM for software that already grabs a large chunk of local compute, and amps up your electricity bill without a conversation.

A useful feature delivered without consent isn't a gift. Your device is not part of Google's deployment infrastructure, available whenever their product roadmap says so.

If any other company quietly installed 4 GB of software on your machine and re-downloaded it when you deleted it, you'd call it what it is: a low blow for user trust.
Copy

The discussion around Gemini Nano is less about one AI model and more about how software companies handle disclosure, consent and accountability as AI becomes embedded into everyday products.

Most users reasonably expect browser updates to deliver security patches or performance improvements. They are less likely to expect additional local AI functionality with implications for storage, bandwidth, memory usage and energy consumption. That gap between user expectation and deployment practice is where the governance questions begin to emerge.

Google says Gemini Nano supports security and scam detection features and that users can disable the functionality in settings. The broader challenge for the industry is whether future AI rollouts should involve clearer upfront disclosure, easier consent choices and more transparent reporting around environmental impact before deployment becomes standard practice.