Back to resources

CISO BriefIssue 01

In 5 days, 1 billion iPhones get a new AI agent by default. Your MDM won't see any of it.

iOS 27 goes GA on September 14, 2026. A few things worth deciding before Monday.

Executive Summary

On September 14, Apple ships iOS 27 to every supported iPhone. It comes with a rebuilt Siri AI that can act across apps, read what's on screen, and hand requests to outside agents like Claude, ChatGPT or Gemini. It works on BYOD and unsupervised devices, and from the lock screen. MDM has no policy for it, EDR has no visibility into it, and DLP won't catch data leaving through an agent. You have 5 days.

1.3B
AI agents expected by 2028
$234B
Agentic AI spend in 2026, per Gartner
88%
Of orgs hit an AI-agent incident (Q2 2026, Gartner)
ZERO
Built solutions monitor or block real-time AI-agent activity on mobile

What actually ships on Sept 14

iOS 27 introduces Siri AI: a rebuilt assistant that acts inside apps through App Intents and can hand requests to third-party agents. Apple Intelligence, and with it Siri AI, requires iPhone 15 Pro or later.

  1. Screen reading is now a standard agent capability.

    With a single user grant, an agent can read the active app's UI, including your CRM, your inbox and your business apps, sandboxed or not.

  2. App Intents open every app to agent control.

    Any app that exposed intents in iOS 26 or later can now be driven by a third-party agent without the user opening it.

  3. Siri AI is user-selectable per device, not per profile.

    On BYOD, an employee can route corporate context to any agent.

  4. Apple Intelligence runs on the Neural Engine.

    So not every prompt goes to the cloud. Agent tools and MCP requests do. Either way, cloud-based AI security has no visibility into what happens on the device.

The four blind spots

MDM

No policy for Siri AI

Intune, Jamf and Omnissa have no key to lock the Siri AI agent choice or limit App Intent exposure. Apple hasn't shipped the config profile yet.

EDR

Sandboxed & user approved

The agent acts under permissions the user granted. EDR and legacy mobile threat defence see approved activity. Nothing to flag.

DLP / CASB

Nothing to inspect in the cloud

Cloud-based AI security sees neither, and on BYOD, routing an employee's entire network through cloud inspection is not a privacy option.

The compounding one: BYOD × user-granted permissions × autonomous actions

An employee's own iPhone is unsupervised, so none of Apple's Siri or Intelligence configurations reach it. The agent they turned on works inside their work apps through App Intents, under permissions they granted, without opening a single app. Every control you own assumes at least one of those variables is corporate. None of them is.

Sources: Apple Platform Deployment, WWDC26 device management updates · Apple Platform Security, runtime process security · Apple Security Research, Private Cloud Compute

What Gartner is watching

Enterprise apps embedding at least one AI agent

2024
33%
Q1 2026
80%

80% of enterprise apps shipped or updated in Q1 2026 embed at least one AI agent, up from 33% in 2024. 17% of enterprises already run agents in production and another 60%+ plan to within 24 months. Mobile is where adoption is fastest and instrumentation is thinnest.

  • 17% in production
  • 60%+ planning, within 24 months
  • Neither

Gartner has agentic AI at the Peak of Inflated Expectations right now. The trough that follows is where security teams usually inherit the mess.

Peak of Inflated Expectations · nowTrough

The 5-day CISO checklist

  • Day 5

    Inventory

    Three questions for your Security team: how many managed iPhones can take iOS 27, how many are iPhone 15 Pro or newer (Apple Intelligence-capable), and how many are BYOD or User Enrollment.

  • Day 4

    Write a one-page interim AUP

    “Employees may not set a third-party AI agent as their iOS default while corporate data is on the device.” Hard to enforce, but you want it on record.

  • Day 3

    Defer the fleet update

    Apple lets you hold iOS 27 back 1 to 90 days on supervised devices, via declarative software update management. Set it now, before devices move to 27. After 90 days the upgrade is offered anyway, and BYOD you can't hold.

  • Day 2

    Audit App Intents in your own apps

    If your internal iOS apps exposed intents for Shortcuts, third-party agents can now call them without opening the app. Go through the list.

  • Day 1

    Prepare a comms line

    If an agent-related leak surfaces after launch, someone will ask whether you knew. You want to be able to say yes, and show what you did about it.

Legacy security asks

Is this allowed?

  • Is this malware?
  • Was user permission granted?
  • Is data flow permitted?

Agent Zero asks

Is the agent acting as intended?

  • Is the agent attributable to the user?
  • Does it align with the CISO's policy?
  • Is the action aligned with the user's intent?

From access control → intent control

MVP ready. Looking for design partners

We built the enforcement layer that runs where the agent runs.

Agent Zero is a native, on-device security layer that sees, blocks and audits every AI-agent action on iOS and Android before it leaves the chip. No cloud relay, no proxy, no added latency.

Our design-partner program is open: a live deployment on your fleet, your policies and your KPIs, with direct access to the two of us. It runs on supervised fleets and unmanaged personal devices alike, and no personal data leaves the phone.

Book a demo30 minutes, live on a real device.

Yes, AI. Zero drama.