CISO BriefIssue 01
In 5 days, 1 billion iPhones get a new AI agent by default. Your MDM won't see any of it.
iOS 27 goes GA on September 14, 2026. A few things worth deciding before Monday.
Executive Summary
On September 14, Apple ships iOS 27 to every supported iPhone. It comes with a rebuilt Siri AI that can act across apps, read what's on screen, and hand requests to outside agents like Claude, ChatGPT or Gemini. It works on BYOD and unsupervised devices, and from the lock screen. MDM has no policy for it, EDR has no visibility into it, and DLP won't catch data leaving through an agent. You have 5 days.
- 1.3B
- AI agents expected by 2028
- $234B
- Agentic AI spend in 2026, per Gartner
- 88%
- Of orgs hit an AI-agent incident (Q2 2026, Gartner)
- ZERO
- Built solutions monitor or block real-time AI-agent activity on mobile
What actually ships on Sept 14
iOS 27 introduces Siri AI: a rebuilt assistant that acts inside apps through App Intents and can hand requests to third-party agents. Apple Intelligence, and with it Siri AI, requires iPhone 15 Pro or later.
Screen reading is now a standard agent capability.
With a single user grant, an agent can read the active app's UI, including your CRM, your inbox and your business apps, sandboxed or not.
App Intents open every app to agent control.
Any app that exposed intents in iOS 26 or later can now be driven by a third-party agent without the user opening it.
Siri AI is user-selectable per device, not per profile.
On BYOD, an employee can route corporate context to any agent.
Apple Intelligence runs on the Neural Engine.
So not every prompt goes to the cloud. Agent tools and MCP requests do. Either way, cloud-based AI security has no visibility into what happens on the device.
The four blind spots
No policy for Siri AI
Intune, Jamf and Omnissa have no key to lock the Siri AI agent choice or limit App Intent exposure. Apple hasn't shipped the config profile yet.
Sandboxed & user approved
The agent acts under permissions the user granted. EDR and legacy mobile threat defence see approved activity. Nothing to flag.
Nothing to inspect in the cloud
Cloud-based AI security sees neither, and on BYOD, routing an employee's entire network through cloud inspection is not a privacy option.
The compounding one: BYOD × user-granted permissions × autonomous actions
An employee's own iPhone is unsupervised, so none of Apple's Siri or Intelligence configurations reach it. The agent they turned on works inside their work apps through App Intents, under permissions they granted, without opening a single app. Every control you own assumes at least one of those variables is corporate. None of them is.
Sources: Apple Platform Deployment, WWDC26 device management updates · Apple Platform Security, runtime process security · Apple Security Research, Private Cloud Compute
What Gartner is watching
Enterprise apps embedding at least one AI agent
- 2024
- 33%
- Q1 2026
- 80%
80% of enterprise apps shipped or updated in Q1 2026 embed at least one AI agent, up from 33% in 2024. 17% of enterprises already run agents in production and another 60%+ plan to within 24 months. Mobile is where adoption is fastest and instrumentation is thinnest.
- 17% in production
- 60%+ planning, within 24 months
- Neither
Gartner has agentic AI at the Peak of Inflated Expectations right now. The trough that follows is where security teams usually inherit the mess.
The 5-day CISO checklist
Day 5
Inventory
Three questions for your Security team: how many managed iPhones can take iOS 27, how many are iPhone 15 Pro or newer (Apple Intelligence-capable), and how many are BYOD or User Enrollment.
Day 4
Write a one-page interim AUP
“Employees may not set a third-party AI agent as their iOS default while corporate data is on the device.” Hard to enforce, but you want it on record.
Day 3
Defer the fleet update
Apple lets you hold iOS 27 back 1 to 90 days on supervised devices, via declarative software update management. Set it now, before devices move to 27. After 90 days the upgrade is offered anyway, and BYOD you can't hold.
Day 2
Audit App Intents in your own apps
If your internal iOS apps exposed intents for Shortcuts, third-party agents can now call them without opening the app. Go through the list.
Day 1
Prepare a comms line
If an agent-related leak surfaces after launch, someone will ask whether you knew. You want to be able to say yes, and show what you did about it.
Legacy security asks
“Is this allowed?”
- Is this malware?
- Was user permission granted?
- Is data flow permitted?
Agent Zero asks
“Is the agent acting as intended?”
- Is the agent attributable to the user?
- Does it align with the CISO's policy?
- Is the action aligned with the user's intent?
From access control → intent control
MVP ready. Looking for design partners
We built the enforcement layer that runs where the agent runs.
Agent Zero is a native, on-device security layer that sees, blocks and audits every AI-agent action on iOS and Android before it leaves the chip. No cloud relay, no proxy, no added latency.
Our design-partner program is open: a live deployment on your fleet, your policies and your KPIs, with direct access to the two of us. It runs on supervised fleets and unmanaged personal devices alike, and no personal data leaves the phone.
Yes, AI. Zero drama.