
NEW DELHI: In late April 2026, privacy researcher Alexander Hanff was running automated audits on a fresh Chrome profile when he noticed something unexpected. His device storage was shrinking without any notification or permission prompt. Chrome had downloaded a 4GB file called weights.bin and stored it deep inside his browser’s user data folder. When he deleted it, Chrome downloaded it again. What Hanff had stumbled onto was not a bug. It was a feature one that Google had quietly rolled out to hundreds of millions of devices worldwide.
The model is Gemini Nano, Google’s lightweight on-device AI. And as of Chrome versions 147 and 148, it is being installed on qualifying devices whether users want it or not.
What Is Actually Happening
The file ‘weights.bin’ sits inside a folder called ‘OptGuideOnDeviceModel’ in Chrome’s user data directory. On Windows the path is ‘%LOCALAPPDATA%\Google\Chrome\User Data\OptGuideOnDeviceModel’. On macOS and Linux the equivalent paths follow the same structure inside the Chrome profile folder. The download triggers automatically on devices with more than 22GB of free storage and over 4GB of GPU VRAM. Once installed, Gemini Nano powers three confirmed features inside Chrome a writing assistance tool, on-device scam detection and a summarisation API that websites can call directly.
Here is the detail that has privacy researchers most concerned. Chrome 147 displays an AI Mode pill prominently in the address bar a feature that a reasonable user would assume runs on the locally installed model. It does not rather every query typed into AI Mode is sent to Google’s cloud servers. The 4GB model sitting on your device has nothing to do with it. The on-device model runs only the buried features most users have never knowingly enabled.
Google has confirmed the behaviour, telling technology publications that Gemini Nano has been part of Chrome since 2024 and that since February 2026 a Settings toggle exists to disable it. What Google has not explained is why 800 words of terms of service buried in technical documentation counts as consent for a 4GB installation that reinstalls itself when deleted.
The Legal Question
Privacy researcher Hanff’s legal argument is specific. He contends that silently writing 4GB of AI model weights to a user’s device constitutes unauthorised storage of code on terminal equipment a violation of Article 5(3) of the EU’s ePrivacy Directive, which requires prior informed consent for storing information on user devices. He further argues the behaviour breaches GDPR Article 5(1) on transparency and Article 25 on data protection by design.
As of May 2026 no formal enforcement action has been issued. The Irish Data Protection Commission which is Google’s lead EU regulator has not published a ruling. But the legal risk analysis is being taken seriously in European policy circles and formal investigation is considered likely by privacy law commentators.
The Indian picture is more complicated. India’s Digital Personal Data Protection Act 2023 and its Rules notified in November 2025 are in force but core consent management obligations do not come into full effect until May 2027. MeitY has not issued a public statement on this specific issue. CERT-In has published no advisory , the Competition Commission of India, which has previously acted against Google on Android-related behaviour has not linked any existing proceedings to this pattern.
Under India’s Consumer Protection Act 2019, the silent installation of resource-intensive software without informed consent could theoretically be framed as an unfair trade practice particularly if it causes measurable financial loss. That argument has not yet been tested.
Why This Matters Differently in India
Chrome’s browser share in India stands above 85% across all devices with Chrome for Android alone accounting for over 80% of page views as of December 2025. With over one billion internet users in India, credible estimates place Indian Chrome users well above 800 million the largest concentration of Chrome users anywhere in the world.
The confirmed 4GB download affects desktop and laptop users on Windows, macOS, and Linux. Chrome for Android users are not currently known to be affected Android-side Gemini Nano runs on a separate, smaller model of approximately 1GB. India’s budget smartphone market still carries millions of devices with 64GB of total storage, where usable space after system and apps often falls below 20GB. A silent 4GB download is not trivial in that context.
On data costs, TRAI’s Q4 2025 figures show average mobile data pricing at approximately ₹7.87 per gigabyte. A 4GB silent download represents roughly ₹31 in data costs for a user on a metered connection modest individually, significant when multiplied across millions of users who were never asked.
No major Indian technology publication has yet published dedicated coverage of this issue as a standalone privacy story and no Indian consumer organisation has formally raised it. That gap is itself worth noting.
What You Can Do Right Now
To check if the model is on your device go to %LOCALAPPDATA%\Google\Chrome\User Data\OptGuideOnDeviceModel on Windows or the equivalent Chrome profile path on macOS and Linux and look for weights.bin. Simply deleting it will not work Chrome will download it again on the next restart.
To stop it permanently open Chrome Settings, navigate to the AI or Generative AI section, and toggle off the on-device AI option. Alternatively open chrome://flags, search for Optimization Guide On Device Model and related AI flags, disable them and relaunch Chrome. Both methods may be needed to prevent the model from reappearing after Chrome updates.
The Bigger Question
Google’s argument is that on-device AI improves privacy by processing certain tasks locally rather than sending data to the cloud. That argument has merit in principle and the problem is not the technology. The problem is the method a 4GB installation that happens silently, reinstalls when delete and is buried behind multiple menus that most users will never find.
Hanff’s estimate suggests that deploying this model across one billion devices generates approximately 60,000 metric tonnes of CO2 in bandwidth and storage-related emissions. That figure is researcher-derived and not an official measurement. But it adds a dimension to the debate that goes beyond individual privacy.
India’s regulatory framework is moving in the right direction. The DPDP Act’s consent obligations will be enforceable by May 2027. Whether that timeline is fast enough for a practice that is already on hundreds of millions of devices is a question Indian regulators have not yet answered.
