Blog post

Apple Expands Private Cloud Compute to Google Cloud — A New Standard for Confidential Computing

Apple extends Private Cloud Compute to Google Cloud with NVIDIA GPUs, using three-layer hardware trust and a verifiable transparency ledger. A new benchmark for confidential computing at hyperscale.

Apple has always kept its cloud infrastructure on its own silicon — until now.

At WWDC 2026, Apple announced it is extending its Private Cloud Compute (PCC) infrastructure beyond its own data centres to run on Google Cloud, using NVIDIA GPUs. This is the first time Apple has trusted third-party infrastructure with Apple Intelligence workloads. The announcement, made jointly with Google and NVIDIA, represents a shift in how hyperscale cloud providers compete on privacy guarantees.

The Three-Layer Trust Model

The most interesting part of the announcement is not that Apple moved to the cloud — it is how they maintain trust on hardware they do not control.

The architecture stacks three hardware-level security technologies that work together. NVIDIA Confidential Computing runs on Blackwell GPUs to protect AI inference workloads. Intel CPUs provide Trust Domain Extensions (TDX) as the CPU-level root of trust. Google’s Titan security chip anchors the hardware identity chain at the platform level.

Apple retains full control over PCC software and maintains a cryptographically verifiable append-only ledger of every hardware component in the Google Cloud fleet. All PCC binaries are published for public security research through the Apple Security Bounty Program, allowing independent researchers to verify what is actually running.

Why This Matters for the Industry

Apple is effectively defining a blueprint for verifiable third-party cloud trust — and that matters beyond Apple’s own infrastructure.

Enterprises increasingly need AI-scale compute but cannot compromise on privacy, regulatory compliance, or data sovereignty. The conventional answer has been to run everything on-premises or accept a black-box cloud. Apple’s PCC model offers a third path: run on shared infrastructure, but with hardware-rooted guarantees that even the cloud provider cannot bypass.

The three-layer trust approach sets a new baseline. A single trusted execution environment (TEE) is useful, but it can be compromised if the CPU, GPU, or platform chip has a vulnerability. Layering all three makes a successful attack dramatically harder because an attacker must break through three independent hardware security boundaries simultaneously.

Broader Market Implications

Cloud providers are increasingly competing on confidential computing guarantees rather than raw price or availability zones. Google Cloud now has a marquee customer using PCC to validate its Titan security model. AWS has its own Nitro Enclaves, and Microsoft Azure offers confidential computing with Intel SGX and AMD SEV-SNP. The Apple partnership gives Google Cloud a reference implementation that demonstrates real-world confidential computing at hyperscale.

For NVIDIA, this is further validation of its Confidential Computing platform on Blackwell GPUs — an important growth vector beyond AI training.

What to Watch

The PCC expansion is ramping gradually through summer 2026 in a preview period. The full technical architecture will be detailed at the Confidential Computing Summit organised by the Linux Foundation.

The longer-term question is whether Apple’s model becomes the industry template for how sensitive workloads run on shared cloud infrastructure. If it does, the era of blindly trusting cloud providers to keep data safe may be ending — replaced by cryptographically verifiable trust built into the hardware itself.

Related What I Do

These What I Do pages are matched from the subject matter of this article, creating a cleaner path from educational content to implementation work.

Continue reading

Based on shared categories first, then the strongest overlap in tags.