WWDC26 gave Siri a new name, a dedicated app, and a privacy story that now includes Google's data centers. Apple still says your data is not stored and is not available to Apple or to anyone else. It also confirmed that the largest cloud model, AFM 3 Cloud Pro, runs on Nvidia hardware in Google Cloud, inside a new edition of Private Cloud Compute built for third-party machines. Those two sentences can both be true. They are not the same as "it stays on my Mac."

AFM 3 Core, or Core Advanced on newer hardware. The request never leaves the enclosure. Core Advanced needs an M3 or later Mac with at least 12GB of memory. The Neo and every 8GB Mac stay on the smaller local model.
AFM 3 Cloud and ADM 3 Cloud still run on Apple silicon in Apple data centers. Apple says the content of the request is not stored, and that only limited technical metadata such as size and duration is kept.
AFM 3 Cloud Pro is the one on Nvidia GPUs in Google Cloud. Apple signs the software, keeps an append-only ledger of the hardware, and uses Nvidia Confidential Computing, Intel TDX, and Google Titan chips so neither Apple nor Google can read the prompt.
You do not pick the path by hand. A router on the device chooses, which is why the hardware gate and the privacy ledger both matter.
What Apple is not doing with Google
After the keynote, Craig Federighi spent a technical session drawing a hard line. Apple is not shipping the Gemini app. It is not using the models Google gives its own customers. It is not using Google Search as the knowledge base. Only Cloud Pro is described as comparable in quality to Google's frontier models, and only Cloud Pro sits on Nvidia in Google's buildings.
That distinction is easy to flatten into "Siri is Gemini now." It is also easy to flatten the other way, into "nothing changed." The useful version is narrower. Apple built its own models, asked Google for frontier-quality help on the largest one, and extended Private Cloud Compute onto someone else's floor for the first time. Federighi said the amount of Google Assistant in the stack is none. Believe the architecture, not the slogan either camp wants.
What a Mac user can still inspect
On a shipping Apple Intelligence Mac, System Settings, Privacy and Security, Apple Intelligence Report shows recent Private Cloud Compute traffic. Apple has published PCC server binaries for inspection and invited independent researchers. The Google Cloud edition adds a cryptographically verifiable ledger of hardware in the fleet, and Macs are supposed to refuse servers that are not on it and not signed by Apple.
The uncomfortable clause is timing. Apple said PCC on Google Cloud would ramp toward the complete set of protections through the summer preview. If you are on the Golden Gate public beta, treat the most complex Siri AI turns as a preview of policy, not as the finished ledger. I would not put a client transcript, a medical PDF, or a folder of unpublished photos through Cloud Pro until that ramp is over and the report on your Mac looks the way Apple described in June.
Geography is a separate gate. Apple says Mac and Apple Vision Pro users in the EU can use Siri AI when the language is supported. iPhone, iPad, and Apple Watch in the EU do not get it at launch because of the Digital Markets Act. China is waiting on regulatory approval. English is the first language, later this year, as a beta. The Siri app syncs conversation history through iCloud using end-to-end encryption. Pinning a chat does not upload it in the clear.
On-device is still a hardware purchase. AFM 3 Core Advanced, the local model that unlocks Siri's pace and expressivity controls and better dictation, wants M3 or later and 12GB. An M1 Air, an M2 Air, and the MacBook Neo can run Golden Gate and still send more work to the cloud because the larger local model does not fit. That is a product decision, not a privacy bug, and it is why the 8GB question is now an Intelligence question too.
When I would refuse the cloud path
Siri AI that can see the screen, search Mail, and act in Messages is useful because it is personal. Personal is exactly why the routing chart matters. I am willing to let Apple's PCC draft a reply or summarize a public web page. I am not willing to let a preview-period Cloud Pro path see a recording I have not decided to share. For that class of work I still want a tool that cannot call a data center even if I ask badly.
That is why Droppy's Voice Transcribe exists as a separate product choice. It runs Whisper or Parakeet on the Mac, writes the text beside the file, and lets you decide how long the audio stays. It is not Siri. It will not search your mail or rewrite a Safari tab. It also will not surprise you with a Google Cloud hop. Use each tool for the job it can actually promise.
Apple's privacy page for Apple Intelligence, last updated before this architecture landed, still talks about limited technical metadata and no training on your private data. Read the June technical explanation beside it, not instead of it. If Apple ships a clearer Intelligence Report that names Core, Cloud, and Cloud Pro per request, that is the setting I want on every Mac that turns Siri AI on. Until then, assume the router is doing what Apple described, and keep the files you cannot lose on a path that never asks.