Apple Intelligence is designed to process as much information as possible directly on your iPhone, iPad, Mac, Apple Watch, and other supported devices. But some AI requests need more computing power than a device can provide. When that happens, Apple Intelligence can use Private Cloud Compute, or PCC, to process more complex requests in the cloud.
Private Cloud Compute is Apple’s system for running powerful AI models while extending the privacy protections of its devices into the cloud. It uses Apple silicon-based servers, a specially designed operating system, encryption, hardware security, and publicly verifiable software to process personal AI requests without storing the data or making it accessible to Apple.
What Is Private Cloud Compute?
Private Cloud Compute is a cloud-based intelligence system built specifically for Apple Intelligence. It allows Apple to use larger server-based AI models for requests that are too demanding to run entirely on a user’s device.
The important part is how Apple designed the cloud environment. Instead of treating PCC like a conventional cloud AI service, Apple built it around the idea that personal data should only be available for as long as it takes to fulfill a request.
Apple says data processed by PCC is not stored or made accessible to Apple. It is used only to fulfill the user’s request, after which the result is securely returned to the device and the processed data is removed.
Why Does Apple Need Private Cloud Compute?
On-device processing is a major part of Apple’s approach to AI privacy. If an Apple Intelligence request can be completed on the iPhone, iPad, or Mac, it can be processed locally without sending the relevant information to a server.
However, larger AI models require significantly more computing resources. Some requests can involve complex reasoning, larger amounts of information, or AI capabilities that are better suited to a server-class model.
Private Cloud Compute gives Apple Intelligence access to that additional computing power without simply sending personal information to a conventional cloud AI service.
The system effectively creates two paths for Apple Intelligence: process a request on the device when possible, or use PCC when additional computational capacity is required.
How Does Private Cloud Compute Work?
When you make an Apple Intelligence request, the system first determines whether it can be handled on the device.
If the request requires more computing power, Apple Intelligence can send the relevant information to Private Cloud Compute. The device encrypts the request so that it can be processed by validated PCC servers.
The request is processed by a server-based AI model, and the result is securely returned to the user’s device. Apple says the data used during processing is not retained after the request is completed.
This means PCC is not intended to work like a conventional cloud service that keeps a database of user AI requests. Its architecture is built around temporary processing instead.
Can Apple See Your Private Cloud Compute Requests?
No, according to Apple’s stated PCC privacy architecture, the personal data being processed by Private Cloud Compute is not accessible to Apple.
This is one of the most important differences between PCC and a typical cloud AI service. Apple says even staff with administrative access to the production service cannot access the personal data being processed.
The protection is not based only on an internal policy telling employees not to look at user requests. Apple designed the infrastructure so that privileged access cannot simply be used to bypass the system’s privacy protections.
Does Private Cloud Compute Store Your Data?
Apple says Private Cloud Compute does not retain the personal data used to fulfill an AI request.
The information is processed only for the purpose of completing the request. Once the response has been returned, the data is removed rather than kept for later use.
PCC was designed around what Apple calls stateless computation. The goal is for personal data to leave no persistent record inside the Private Cloud Compute environment.
Apple’s security documentation also describes protections against data remaining on storage after a server reboot, including cryptographic handling of storage keys.
What Makes Private Cloud Compute Different From Regular Cloud AI?
A conventional cloud AI service can involve many different layers of infrastructure, including servers, load balancers, logging systems, monitoring tools, administrators, and debugging systems.
Each additional component can potentially create another place where sensitive information might be exposed.
Apple designed PCC to reduce these risks by limiting which components can access request data and by removing several traditional administration mechanisms. For example, PCC nodes do not include remote shell or interactive debugging tools, and the system does not use a general-purpose logging mechanism for user data.
Instead, PCC uses restricted and specifically designed systems for operational metrics and management.
Private Cloud Compute Uses Apple Silicon
Private Cloud Compute runs on custom server hardware based on Apple silicon.
The servers use security technologies that are also central to Apple’s devices, including Secure Enclave and Secure Boot. The hardware provides a root of trust for the system, while the software environment is based on hardened foundations from Apple’s operating systems.
Apple also uses code signing, sandboxing, memory-safety protections, and other security technologies to restrict what can run on PCC servers.
This is important because PCC is not simply a standard cloud server running an AI model. Apple built the hardware and software environment specifically around its privacy requirements.
How Does Apple Prevent Unauthorized Software From Running?
A major part of PCC’s security model is ensuring that a server is running the software Apple expects it to run.
Secure Boot and code signing help ensure that only authorized software can execute on a PCC node. The Secure Enclave also protects important cryptographic keys used by the system.
Apple takes this a step further with cryptographic attestation. Before an Apple device sends a request, it can verify that the PCC server is running an authorized software configuration.
The device can compare the server’s software measurements against Apple’s publicly available record of PCC software releases. If the server does not meet those requirements, the device will not send the protected request to it.
What Is Private Cloud Compute’s Target Diffusion?
Apple also designed PCC to make it difficult for an attacker to deliberately target a particular user’s data.
The company calls this approach target diffusion. PCC’s routing infrastructure does not receive identifying information about the user that would allow it to deliberately steer that person’s request to a particular compromised server.
Requests can also pass through an Oblivious HTTP relay that hides the originating device’s IP address before the request reaches PCC infrastructure.
Apple further limits which PCC nodes can decrypt a particular request. This means that compromising one server would not automatically provide access to every request being processed by the entire system.
Can Security Researchers Verify Private Cloud Compute?
This is one of the most unusual parts of Apple’s approach to cloud AI.
Apple makes PCC software available for security research so independent researchers can inspect the software running on production servers. The company also publishes cryptographic measurements of PCC software in a public transparency log.
This gives researchers a way to compare the software Apple says is running with the software actually running on PCC infrastructure.
Apple has also created a Private Cloud Compute Virtual Research Environment that allows researchers to study PCC software on Macs with Apple silicon. Certain security-critical source code is available for inspection as well.
What Is The Apple Intelligence And PCC Report?
Apple has added a transparency feature that lets users see when Apple Intelligence requests are processed off-device.
On supported iPhone, iPad, and Mac devices, you can enable transparency logging for Apple Intelligence and Private Cloud Compute. The resulting report can show requests that were sent off the device and processed through PCC.
This provides users with more visibility into when Apple Intelligence is relying on cloud processing rather than handling a request entirely on the device.
Is Private Cloud Compute Only Used By Siri?
No. Private Cloud Compute is part of the underlying Apple Intelligence infrastructure rather than being a Siri-only feature.
Apple Intelligence can determine whether different requests need on-device processing or additional cloud computing. For example, Apple’s privacy documentation notes that some requests involving features such as Image Playground can use Private Cloud Compute when a server-based model is required.
The specific features that use PCC can change as Apple adds new Apple Intelligence capabilities and server-based models.
What Changed With Private Cloud Compute In 2026?
Private Cloud Compute originally launched as Apple’s way of extending its device security model into Apple’s own cloud infrastructure. In 2026, Apple expanded PCC beyond its own data centers.
Apple announced that it was working with Google and NVIDIA to run new Apple Intelligence workloads in Google Cloud while extending Apple’s PCC privacy commitments to third-party data centers. The move is part of Apple’s newer Apple Intelligence architecture and its third-generation Apple Foundation Models.
The important point is that using third-party data center infrastructure does not mean Apple is abandoning the PCC security model. Apple says the same privacy commitments are being extended to these environments.
Does Private Cloud Compute Use Apple’s AI Models?
Private Cloud Compute can run Apple’s server-based foundation models as part of Apple Intelligence.
Apple’s third-generation Apple Foundation Models include both on-device and server-based models. The server-based models run on Private Cloud Compute and are intended for more demanding AI experiences that require additional computing resources.
This allows Apple to combine smaller models running locally with more capable models running in PCC when a request requires them.
Does Private Cloud Compute Train Apple’s AI Models?
Private Cloud Compute is designed to process requests, not to build a personal profile from them.
Apple says private personal data and interactions are not used to train its foundation models unless a user explicitly chooses to help improve Apple Intelligence.
Apple also states that data processed through PCC is used to fulfill the request and is not retained by the PCC system.
Why Private Cloud Compute Matters For Apple Intelligence
The biggest challenge with private AI is balancing capability and privacy.
Running everything on a device provides strong control over personal data, but a phone or computer cannot always match the computing resources available in a data center. Sending everything to a conventional cloud service provides more computing power, but introduces a different set of privacy and security concerns.
Private Cloud Compute is Apple’s solution to that tradeoff.
It allows Apple Intelligence to use more powerful server-based models while applying many of the security principles Apple normally uses on its devices. The system combines custom Apple silicon, encryption, hardware-backed security, restricted administration, temporary data processing, cryptographic verification, and independent security research.
Private Cloud Compute Explained
In simple terms, Private Cloud Compute is the part of Apple Intelligence that handles AI requests when your device needs help from a more powerful server.
Your device first tries to process the request locally. If the request needs additional computing power, Apple Intelligence can send the relevant information to Private Cloud Compute.
The request is processed by a server-based model, the result is returned to your device, and Apple says the personal data used for the request is not stored or made accessible to Apple.
That makes PCC an important part of how Apple is trying to bring more capable AI features to its devices without treating personal information like ordinary cloud data.
(via Apple)