Apple’s Private Cloud Compute expansion and EU data sovereignty
Apple is expanding Private Cloud Compute to Google Cloud using NVIDIA Blackwell GPUs and Google Titan chips. This move tests whether Apple's technical safeguards can satisfy EU digital sovereignty requirements and mitigate risks from the US CLOUD Act.
Apple moved Private Cloud Compute (PCC) workloads to Google Cloud on June 8, 2026. This expansion uses NVIDIA Blackwell GPUs with Confidential Computing and Intel CPUs with TDX. Google provides the Titan chip to act as a hardware root of trust. This hardware trust chain combines silicon from four different companies. Apple uses this setup to run AFM 3 Cloud Pro, its most demanding model for complex reasoning and tool use. Apple’s decision to run AFM 3 Cloud Pro on Nvidia GPUs inside Google Cloud data centers marks the first time the company has moved its most intensive workloads to non-Apple hardware.
The expansion uses Google Titan.
Apple maintains control over the PCC software. Devices only trust software that Apple cryptographically approves. To mitigate supply chain attacks, Apple maintains a cryptographically verifiable, append-only ledger of all Google Cloud hardware in the PCC fleet. This prevents unauthorized access to user data during processing. PCC requirements include stateless computation, enforceable guarantees, no privileged runtime access, non-targetability, and verifiable transparency. These requirements ensure personal data leaves no trace in the PCC system. The AFM 3 model family includes AFM 3 Core and AFM 3 Core Advanced, which run on-device. Developers in the App Store Small Business Program with fewer than two million first-time downloads can use Apple Foundation Models on PCC at $0 cloud API cost. Apple targets latency below 100 milliseconds for 90% of users. For each request, initial network data parsing happens in a dedicated process within its own namespace, while shared inference software is recycled with a short time-to-live duration.
The digital sovereignty triad
The European Commission released the Tech Sovereignty Package on June 3, 2026. This package includes the Cloud and AI Development Act and a formal definition of digital sovereignty. The concept contains three parts: data control, legal control, and vendor nationality. Data control involves managing who processes data and where it stays. Legal control concerns the frameworks governing the infrastructure. Vendor nationality refers to where a company’s headquarters reside.
The CLOUD Act complicates this.
The US CLOUD Act allows American authorities to compel US companies to provide data regardless of where that data resides. This creates a direct conflict with the GDPR. Even if a provider stores data in a European data center, US law can force disclosure. This legal tension makes the sovereignty of US-based cloud providers a constant concern. The US Ambassador to the EU, Andrew Puzder, stated that attempts to limit the competitiveness of US entities in Europe represent a red line. You should know that even with local servers, jurisdictional risk remains high. The definition of sovereignty addresses the fear of kill switches and foreign interference. This concept follows a November 2025 Franco-German summit where leaders agreed to develop a common definition of a European digital service. The concept of data control also differs from data residency, which refers to storing information in a specific geographical location, and data localization, the requirement that data created in a specific location remains in that location.
Regulatory realities and compliance
European countries use different rules to manage these risks. Germany requires providers to meet the BSI Cloud Computing Compliance Criteria Catalogue (C5). This requires transparency regarding government requests and limits on data access. France uses SecNumCloud, which demands that service providers store and process data within the EU. French requirements also state that providers must be immune to requests from third-country public authorities.
| Feature | PCC Specification |
|---|---|
| Deployment | Google Cloud and Apple Silicon |
| Hardware | NVIDIA Blackwell, Intel TDX, Google Titan |
| Model Access | $0 for developers with < 2M downloads |
| Latency | < 100ms for 90% of users |
| Privacy Guarantee | Stateless computation |
The Schrems II ruling changed how companies view data transfers. Organizations must perform Transfer Impact Assessments to evaluate if a destination country’s laws allow government surveillance that conflicts with EU rights. In response to the Schrems II ruling, organizations must conduct Transfer Impact Assessments to evaluate if a destination country’s legal framework allows government surveillance that conflicts with European privacy rights. Apple attempts to satisfy these needs through stateless computation and verifiable transparency. This means PCC uses personal data only for the specific request and deletes it immediately. The model uses the personal user data it receives exclusively for the purpose of fulfilling the user’s request. Failing to comply with GDPR can result in fines of up to 4% of total global annual revenue.
Will the European Commission accept these technical safeguards as sufficient for sovereignty?
Apple’s expansion to Google Cloud makes the privacy claims of PCC a test of third-party hardware.