AI Edge Gallery is Google's showcase app for on-device AI, and a practical way to run a capable model with no connection at all. Download a model once and everything runs on the phone: multi-turn chat with a thinking mode that shows the model's reasoning, Ask Image for questions about photos from the camera or gallery, Audio Scribe for transcribing and translating recordings, and a Prompt Lab for single prompts with control over settings such as temperature and top-k. Agent Skills add tools such as Wikipedia lookups and maps, and Mobile Actions controls the device offline through a fine-tuned FunctionGemma 270M.
It centres on Google's Gemma models, now including the Gemma 4 family, running on the LiteRT runtime, and it can download other models from the Hugging Face LiteRT community or load your own, with a benchmark screen that shows how each performs on your hardware. Google labels it an experimental beta.
The project is Apache-2.0 with about 24,800 stars, and has been covered by Android Authority and others since its 2025 launch. It is on Google Play and the App Store, needs Android 12 or iOS 17 and up, and offers an APK for devices without Google Play plus a newer macOS build.
- Repository: github.com/google-ai-edge/gallery
- Licence: Apache-2.0 (Apache License 2.0)
- Language: Kotlin. Stars: 24.8K. Forks: 2,708. Last push: Oct 2, 2026.
- Scan: safe, Oct 2, 2026, commit c7e9ccd
Who it is for
Android and iPhone owners who want an AI assistant that works offline and keeps photos and recordings on the device, and developers checking how well a model runs on a given phone before building on it.
Getting started
1. Android 12+: install from Google Play, or sideload ai-edge-gallery.apk from the latest release
adb install ai-edge-gallery.apk2. iPhone or iPad on iOS 17+: install from the App Store
https://apps.apple.com/us/app/google-ai-edge-gallery/id67496453373. macOS: download the app
curl -LO https://dl.google.com/google-ai-edge-gallery/macos/dmg/GoogleAIEdgeGallery-0.1.0.dmgModels are downloaded inside the app, and larger ones need a recent phone with plenty of memory. The release page also has APKs built for specific Snapdragon and Tensor chips; ai-edge-gallery.apk is the general build.
Safety scan
We cloned google-ai-edge/gallery at commit c7e9ccd on Oct 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no suspicious code patterns, no installers and no bare-IP URLs across 574 files and about 73,000 lines, nearly all Kotlin. The one committed binary is the standard Gradle wrapper jar.
- We read the analytics code. Analytics.kt logs Firebase events for capability choices, model downloads, button clicks, skills, MCP use and inference metrics such as model name, accelerator, latency, tokens per second, token counts and memory use. No event carries prompt or response text or images. The repository has no google-services.json, so a build you make yourself sends nothing; the Play Store and App Store builds are configured by Google. Firebase Messaging is also included, for notifications.
- The repository holds the Android app only. The iOS app and the macOS download are not in it, so this scan says nothing about them.
- No lockfile the scanner reads (Gradle uses a version catalogue), so no advisories were queried. Models download from Hugging Face, and an allowlist of models comes from this repository on GitHub.
- Two workflows, none using pull_request_target, using only GitHub's own actions. Licence and contributing guide present; no security policy, Dependabot or CodeQL.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | None: nothing runs at install beyond the package manager itself. |
| Committed binaries | 1 executable or compiled object committed; listed under the raw findings. |
| CI workflows | 2 workflows. None use pull_request_target. No third-party actions. |
| Network hosts | 14 distinct hosts referenced from source; most often www.apache.org, github.com, huggingface.co, ai.google.dev. No URLs to bare IP addresses. |
| Known vulnerabilities | No lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day. |
| Project hygiene | Has licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Committed binaries (1)
Android/src/gradle/wrapper/gradle-wrapper.jar: JAR, 48 KB
By the numbers
| Stars | 24.8K |
|---|---|
| Forks | 2,708 |
| Contributors | 16 |
| Commits | 601 |
| Open issues | 239 |
| Open pull requests | 152 |
| Releases | 27 |
| Latest release | 1.0.19 |
| Licence | Apache-2.0 |
| Main language | Kotlin |
| Project age | 1 year |
| Last push | Oct 2, 2026 |
| Tracked files | 574 |
| Lines of code | 72.8K |
| Checkout size | 14 MB |
Lines by language: Kotlin 62.4K, HTML 4,230, JSON 2,857, Markdown 1,988, Protobuf 744, JavaScript 233.
Questions
Is Google AI Edge Gallery free?
Yes. The app is free on Google Play and the App Store, the source is Apache-2.0, and there are no subscriptions or usage limits because the models run on your device. Models such as Gemma are free to download under their own terms.
Does AI Edge Gallery work without internet?
Yes, once a model is downloaded. Chat, image questions, transcription and the other tasks run entirely on the device. You need a connection to download models, skills that look things up, such as Wikipedia and maps, go online when used, and when connected the store builds send Firebase Analytics usage events (model names, speeds, token counts), not your prompts or images.
Which phones can run AI Edge Gallery?
Android 12 or later and iOS 17 or later. Small models run on most recent phones; larger Gemma models need more memory and a newer chip, and the built-in benchmark shows how fast a model runs on your device before you rely on it.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
