Apple Intelligence is designed to protect your privacy at every step. It’s integrated into the core of your iPhone, iPad, and Mac through on-device processing. So it’s aware of your personal information without collecting your personal information. And with groundbreaking Private Cloud Compute, Apple Intelligence can draw on larger server-based models, running on Apple silicon, to handle more complex requests for you while protecting your privacy.
https://www.apple.com/apple-intelligence/
Apple Intelligence

Apple Intelligence is for the everyday and it‘s deeply integrated into iPhone, iPad, Mac, and Apple Vision Pro with groundbreaking privacy.

Apple

🆕 on the Security Blog: Private Cloud Compute

Built with custom Apple silicon and a hardened operating system, Private Cloud Compute extends the industry-leading security and privacy of Apple devices into the cloud, making sure that personal user data sent to PCC isn’t accessible to anyone other than the user — not even to Apple.

https://security.apple.com/blog/private-cloud-compute/

Private Cloud Compute: A new frontier for AI privacy in the cloud - Apple Security Research

Secure and private AI processing in the cloud poses a formidable new challenge. To support advanced features of Apple Intelligence with larger foundation models, we created Private Cloud Compute (PCC), a groundbreaking cloud intelligence system designed specifically for private AI processing. Built with custom Apple silicon and a hardened operating system, Private Cloud Compute extends the industry-leading security and privacy of Apple devices into the cloud, making sure that personal user data sent to PCC isn’t accessible to anyone other than the user — not even to Apple. We believe Private Cloud Compute is the most advanced security architecture ever deployed for cloud AI compute at scale.

Private Cloud Compute: A new frontier for AI privacy in the cloud - Apple Security Research

@fj I'm still not sure how this is going to work.

It doesn't matter how private is when working in normal operations, if you can just 'steer' user devices to honeypot servers, it's useless. (hence why all the 'you don't have to trust apple' marketing speak around iCloud Private Relay is a complete fabrication.)

They do mention Intel SGX & AWS Nitro, which is likely going to be more private than Apple PCC, because with those, the entity doing the attestation is independent from the entity that controls the servers (i.e. Microsoft software running on an Intel CPU), but with Apple, it's Apple software running on Apple Silicon.