Growing up in country Australia, backyard cricket wasn’t just a thing, it was everything. This version of cricket had its own anthem (Greg Champion’s I Made a Hundred in the Backyard at Mum’s) and a strict universal code. The most important rule was ‘six and out’: hit the ball over the fence, into the neighbour’s yard, or through a window, and you were out. No ifs, no buts, no appeals to the umpire. It was the quintessential egalitarianism of Australian kids.
I’ve been thinking about that rule while researching this piece. I’ve spent much of my career in edtech and remain as much a critic as a fan. My inner critic always looks for where claims don’t stack up, or where something fails the bloke-in-a-pub test. What follows has failed spectacularly.
The Browser We All Use Without Thinking
Google Chrome dominates the way most of us access the internet. It was launched in 2008, and today it accounts for roughly half the Australian browser market on all devices, and considerably more on desktop computers.1 Its dominance shapes the entire web, something that was made painfully clear to me when I tried to book a flight on Jetstar Australia. Every time I attempted to pay, it failed. After several frustrating calls to their customer support centre, we established that the problem was my browser (Firefox). “Our system only works if you use Chrome,” I was told. I pointed out that this meant a significant chunk of Australian internet users couldn’t book on Jetstar. “That’s correct, sir, and I hope you have a happy day”. Then the line went dead.
That exchange stuck in my mental flypaper. And then, about two weeks ago, I found the other piece it connected to.
The 4GB Guest That Didn’t Ask to Come In
In early May 2026, a Swedish privacy researcher and computer scientist named Alexander Hanff published an investigation into something he had found sitting on his computer without his knowledge.2 Google’s Chrome browser had been quietly installing a large AI software package, roughly 4GB, or about the size of a feature film, onto users’ machines without asking. No notification, no consent, no warning. And if you found it and deleted it, Chrome simply downloaded it again the next time you opened your browser.
The software in question is called Gemini Nano, Google’s on-device artificial intelligence model. Google says it powers useful background features like scam detection and writing assistance. That may be true, but the way it was delivered, silently, at scale, to hundreds of millions of devices, is the problem.
Here is where it gets more troubling. Chrome’s browser now displays a prominent “AI Mode” button that any reasonable person would assume is powered by this software sitting on their computer. It isn’t. Every query typed into it is sent over the internet to Google’s own servers for processing.3 So users are carrying the storage and bandwidth cost of a large piece of software they never asked for, while the AI feature they can actually see is sending their queries to Google anyway.
When asked to respond, Google confirmed the software’s existence and pointed to a setting, buried in the browser’s technical options, that allows users to turn it off.4 The option to remove it, in other words, arrived only after the behaviour was publicly exposed.
Anthropic Is Doing Something Similar
When I first read about this, I assumed Anthropic, the company behind Claude, which I pay for, was on the right side of the boundary (to use a cricket metaphor). That assumption was wrong.
Two weeks before the Google story broke, the same researcher published a second investigation, this time about Anthropic’s Claude desktop application.5 When you install Claude on a Mac, it quietly installs hidden configuration files into multiple web browsers on your computer, including browsers you haven’t installed yet, and including browsers Anthropic’s own documentation says it doesn’t support. The purpose of these files is to pre-authorise Claude to interact with your browser in ways that go well beyond what a desktop chat application should be doing: reading web pages, filling in forms, capturing your screen.
Anthropic has not publicly responded to these findings, and as of writing has not fixed the behaviour.
“Spyware” is a loaded word, and some security analysts stop short of applying it here. The more careful description is that both Google and Anthropic have crossed a fundamental line: one app should not modify or reach into another app, especially a browser, without asking. The behaviour is invisible by default, difficult to remove, and arguably illegal under European privacy law. All of that is true regardless of what label you put on it.
The Law That Is Being Ignored
European privacy law, or more specifically the General Data Protection Regulation (GDPR) and the ePrivacy Directive, requires explicit consent before any software installs itself on your device, unless it is strictly necessary for the service to function. Hanff argues, persuasively, that neither Gemini Nano nor Claude’s browser files clear that bar: Chrome works perfectly well without a 4GB AI model, and Claude works perfectly well as a desktop chat application without reaching into your browsers.
The relevant provisions are Articles 5(1) and 25 of the GDPR, and Article 5(3) of the ePrivacy Directive. These are not obscure technicalities but are the very core of European digital privacy law, and they apply to any company whose software reaches European users and that means both Google and Anthropic.
Google’s Relationship with Fines
None of this is new behaviour from Google. The company has paid fines and settlements across multiple jurisdictions for privacy violations for years, including a $392m settlement with 40 US states in 2022 over location tracking. A running tracker of tech company regulatory penalties, maintained by Proton, puts Google’s cumulative total at around $4.5bn through 2025.6
Those numbers sound significant. Against the scale of Google’s business, they are not. The company’s established approach is to contest every fine through multiple rounds of appeal, exhaust the legal process, and pay a reduced amount years later. The theoretical maximum penalty under GDPR is 4% of global annual turnover, a sum that could theoretically run into billions of $/£ etc, but this maximum penalty has never been applied in full. Regulators move slowly; Google moves fast, and appears to have concluded that the cost of compliance is higher than the cost of eventual fines. So far, that calculation has held true.
The Part That Should Worry Anyone Who Cares About Education
This is where I return to schools.
Google, Chrome, and Chromebooks are deeply embedded in education at every level, in the devices kids use, the browser on most of their devices, the search engine most use, and now the AI layer being built on top of all of it. That is not inherently a problem. It becomes one when the usage, content, and digital footprints of students, teachers, and schools are being vacuumed up without consent to train and refine the AI systems that Google is building its future on.
Google is making a significant strategic shift. Its AI Overview feature, which now appears above ordinary search results for most queries, is an open acknowledgement that the search model it has dominated for two decades is changing. People like me have largely stopped using Google search and switched to AI tools for more detailed, conversational answers. Google is responding. The data from billions of people who use Chrome is the raw material for that response. Whether children in schools, who have no real choice about which browser or which device their school provides, are part of that data pipeline, without anyone’s knowledge or consent, is a question that deserves a direct answer.
What strikes me as genuinely extraordinary is who has noticed and who has not. The activist groups who are making lots of noise campaigning against edtech have been completely silent on this. Not a word. Equally, I have not heard anything from a single education department or privacy commissioner like Australia’s Julie Inman Grant. A large piece of AI software being installed on the school-issued Chromebooks of kids around the world, without positive consent, in apparent breach of multiple privacy laws, seems precisely the sort of thing these groups and bureaucrats should have something to say about.
What Can Actually Be Done
As an adult who uses Firefox as my main browser and Claude for most of my search, I have at least some choices and some awareness of the trade-offs. Most people don’t and kids in schools have neither. They use what’s provided, on the terms their school accepted, which were set by companies whose primary interest is not their education or welfare. The technical workarounds that exist, and they do exist, require a level of knowledge and technical sophistication that the vast majority of users don’t have. More to the point, no child in a classroom should need to navigate browser configuration menus to protect their own data.
The question at the end of all this isn’t really technical. It is whether we are willing to accept that the price of access to these tools, for adults and children alike, is the silent, permanent surrender of our data to the global behemoths that built them. As adults, some of us at least make that choice with our eyes open but for kids in school, the choice is being made for them, by people who are not asking.
In my backyard cricket terms, that’s a ‘six and out’. The ball is over the fence and the question is whether anyone with the authority to call it is actually watching the game?
Footnotes
- Similarweb placed Chrome’s Australian all-device share at around 49% in September 2025; Cloudflare’s methodology put the desktop-only figure at around 57% in the same period. Sources: https://www.similarweb.com/browsers/australia/ and https://ppc.land/chrome-reaches-66-3-market-share-as-safari-grows-to-15-1-in-q3-2025/ ↩
- Alexander Hanff, “Google Chrome Silently Installs a 4GB AI Model on Your Device without Consent,” That Privacy Guy, 4 May 2026: https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/ ↩
- Jess Weatherbed, “Chrome’s AI Features May Be Hogging 4GB of Your Computer Storage,” The Verge, 6 May 2026: https://www.theverge.com/tech/924933/google-chrome-4gb-gemini-nano-ai-features ↩
- Google statement to Gizmodo, reproduced at: https://gizmodo.com/google-chrome-is-downloading-a-4gb-ai-model-onto-your-device-without-consent-researcher-warns-2000755201 ↩
- Alexander Hanff, “Anthropic Secretly Installs Spyware When You Install Claude Desktop,” That Privacy Guy, 18 April 2026: https://www.thatprivacyguy.com/blog/anthropic-spyware/ , also covered by The Register: https://www.theregister.com/2026/04/20/anthropic_claude_desktop_spyware_allegation/ ↩
- Proton Tech Fines Tracker: https://proton.me/tech-fines-tracker ↩

Leave a Reply