As AI systems move into operating systems, privacy no longer turns only on whether a model runs locally. A local assistant may assemble email, calendar entries, files, screenshots, notifications, and app intents; retain embeddings or summaries; invoke tools; emit telemetry; or route difficult requests to cloud infrastructure. Local inference reduces some exposure, but it answers only one question: where computation occurs. It does not answer who may assemble context, what derived state persists, which actions are authorized, or how updates change the system's authority. We develop an OS-centered privacy framework for on-device AI that treats privacy as an institutional accountability problem rather than a deployment attribute. The framework specifies a threat model, a six-part privacy risk taxonomy, privacy-by-architecture controls, and a four-level audit rubric. We demonstrate the rubric through a documentation-bounded comparison of Apple Intelligence/Foundation Models, Android AICore/Gemini Nano, and Microsoft Recall. Meaningful privacy in on-device AI depends on constrained information flow, bounded authority, visible user control, and auditable governance across the operating-system lifecycle.
翻译:随着AI系统融入操作系统,隐私不再仅取决于模型是否在本地运行。本地助手可能会整合邮件、日历条目、文件、截屏、通知和应用意图;保留嵌入向量或摘要;调用工具;发送遥测数据;或将复杂请求路由至云端基础设施。本地推理能够减少某些信息暴露风险,但它仅回答一个问题:计算发生在何处。它无法回答:谁可以整合上下文、哪些衍生状态被持久保留、哪些行为被授权、或者系统更新如何改变其权限范围。我们提出一个以操作系统为中心的端侧AI隐私框架,将隐私视为制度性问责问题而非部署属性。该框架定义了威胁模型、六部分隐私风险分类体系、架构性隐私控制措施,以及四级审计评估准则。我们通过对Apple Intelligence/Foundation Models、Android AICore/Gemini Nano和Microsoft Recall进行文档约束下的比较,验证了该评估准则。端侧AI的有意义隐私取决于操作系统全生命周期内的受约束信息流、有限权限、可见用户控制与可审计治理。