# Google AI Edge Foresight: The Security Settings and Checks to Run Before You Let It Listen > Google AI Edge Foresight is a privacy-first, local-first meeting notetaker for Apple Silicon Macs that runs Gemma-family models on-device and sends no audio, transcripts or files to the cloud. That genuinely removes the cloud-breach risk — but it does not remove risk, it MOVES it: to your Mac, to meeting consent, and to the local files you let it index. Here is the practical security checklist: full-disk encryption, macOS permission least-privilege, recording consent, scoping the local knowledge base against prompt injection, verifying it really is offline, and treating an experimental developer tool like one. Source: https://playciso.com/blog/google-ai-edge-foresight-security-settings-checks · Published: 2026-10-11 · Publisher: PlayCISO (https://playciso.com) Primary source: https://developers.google.com/edge/foresight --- [Google AI Edge Foresight](https://developers.google.com/edge/foresight) is a **privacy-first, local-first** meeting notetaker for Apple Silicon Macs. It runs Gemma-family models **on-device** — EmbeddingGemma for on-device search, Gemma for generation — and processes your meeting audio, live transcripts and reference files **without sending any of it to the cloud**. That is a genuine privacy win: no server to breach, nothing to intercept in transit, nothing sitting in a vendor’s data lake. But here is the part a security leader has to internalise: **local-first does not remove the risk, it relocates it** — onto your Mac, onto meeting consent, and onto the local files you let it read. The cloud notetaker’s threat model was “someone breaches the vendor.” Foresight’s threat model is “your laptop _is_ the vendor.” Here is the checklist to run before you let it listen. ## 1. Lock the device — it is now the vault Every transcript, every recording and the entire search index live on the Mac. The encryption state of that machine is your whole data-protection story. - Enable full-disk encryption (FileVault). Without it, a lost or stolen laptop hands over every meeting you have ever captured. - Strong login password + short auto-lock. Full-disk encryption only protects a powered-off or locked machine. - Don’t run it on a shared login. Use a dedicated macOS user account; local data is only as private as the account boundary. - Mind the backups. If Time Machine or iCloud backs up the app’s data folder, your “local-only” transcripts are now in your backup too — make sure that backup is encrypted, and confirm the app folder is not silently syncing to a cloud drive, which would quietly undo the entire local-only promise. ## 2. Treat recording as a consent and legal decision Foresight captures microphone and system audio — which means it is recording the other people in the room or call. - Get explicit consent. Recording-consent laws vary by jurisdiction; some require only one party to agree, others (including several US states) require all parties. The safe, professional default is to tell everyone the meeting is being recorded and transcribed, and get agreement, before you start. - Make it visible. A standing “this meeting is being transcribed” notice beats a quiet background capture nobody agreed to. ## 3. Grant the minimum macOS permissions On macOS the privacy permission model (TCC) is your privilege boundary. Open **System Settings → Privacy & Security** and review exactly what Foresight has been granted: - Microphone and Screen & System Audio Recording — needed for its core job; keep them scoped and revoke when not in use. - Files & Folders / Full Disk Access — grant the narrowest option. Avoid Full Disk Access if the app works without it; that single toggle is the difference between “reads the folders I chose” and “can read everything.” - Accessibility / Automation — if requested, understand why before granting; these are powerful. ## 4. Scope the knowledge base — it is a trust boundary Foresight lets you point the assistant at project folders, calendars and documents to build a searchable index. That convenience is also an attack surface. - Index only what it needs. Never point it at credential stores, SSH keys, password-manager exports, legal/privileged folders, or your entire home directory. - Assume indexed content can carry instructions. A poisoned document or a booby-trapped calendar invite can contain hidden prompt-injection text; when the assistant later reads it, that text can try to make the assistant surface other privileged files it can reach. Be wary of indexing anything sourced from outside your control. - Separate sensitive projects. Don’t co-mingle a client’s privileged material with a casual notes index. ## 5. Respect that it is experimental software Google ships Foresight as an **experimental developer tool**. Early-stage edge-AI software may lack the hardened sandboxing, privilege boundaries and enterprise-grade auditing of a mature commercial app. - Keep it off your most sensitive meetings — legal, M&A, board, or regulated data — until the hardening and your own governance catch up. - Isolate it where you can (a dedicated account or device for the experiment), and don’t make it load-bearing for anything you cannot afford to lose or leak. ## 6. Verify the claims — don’t take “offline” on faith - Provenance. Download only from Google’s official source, and confirm the app is properly code-signed and notarized before first run. - Prove it’s offline. Point a host firewall (macOS application firewall, or a tool like LuLu or Little Snitch) at it and confirm it is not making unexpected outbound connections. “Local-first” is a claim you can and should verify. - Keep it updated. Experimental tools change fast; track releases and re-check permissions after updates. ## 7. Know where the data lives — and how to destroy it - Locate the store. Know which folder holds the audio, transcripts and index so you can find, review and purge them. - Dispose deliberately. Delete recordings and transcripts you no longer need, and secure-delete when the content was sensitive. - Control exports. If you export notes, send them somewhere governed — not an auto-syncing shared folder that re-exposes what you kept local. ## The bigger pattern On-device AI like Foresight is a real step forward for privacy, and the right instinct is to encourage it over shipping every meeting to someone else’s cloud. But “it runs locally” is not a security control — it is a _change of threat model_. The questions just move: is the device encrypted, did everyone consent, what is the tool allowed to read, and can it be tricked by the content it reads? Answer those four and local AI becomes a genuine upgrade. Skip them and you have simply moved the breach from a server you don’t control to a laptop you forgot to lock. If you want to pressure-test the one that bites quietest — a local assistant being manipulated by the content it ingests — our [PromptScan](/tools/promptscan) walks the prompt-injection patterns to watch for, and the [AI Governance Policy Pack](/tools/ai-governance-pack) helps you write the policy for when and how on-device AI tools are allowed to touch company data. For the broader baseline, the [Security Control Library](/tools/control-library) right-sizes the controls behind all of this to your org. _Based on Google’s public developer documentation and early reporting as of October 2026. Foresight is an experimental tool and its behaviour and permissions may change between releases — verify the current version’s settings for yourself before relying on any of the above._