In September 2026, Apple ships iOS 27, iPadOS 27, macOS 27 “Golden Gate,” watchOS 27, tvOS 27 and visionOS 27 together, the first time the whole line has landed at once. It changes what an operating system update means for anyone running a fleet of Apple devices.
Siri has been rebuilt around a 7B-parameter on-device model with screen awareness and cross-app context. Apple Intelligence becomes a system service rather than a collection of app features. Private Cloud Compute takes the heavier workloads into the cloud while claiming device-level privacy (Apple Newsroom).
That claim is the story. The promise is a trust architecture: stateless computation, verifiable transparency, non-targetability. The complications are also concrete: a $150,000 bounty finding in darwin-init, third-party model openings to Claude and Gemini, likely iCloud+ costs for heavy AI use, and a no-grace-period retirement of legacy MDM.
This page frames the five decision layers you will work through, then routes you to the article matching the layer you face now. Stay sceptical of the hype and treat every claim as testable.
In This Series
- Siri AI and the AI-Native Operating System in iOS 27 and macOS 27: What “AI-native” means and how the rebuilt Siri works.
- Private Cloud Compute and the Trust Infrastructure Behind Apple’s OS 27: How Apple extends device privacy into the cloud and what threatens it.
- Which Apple AI Workloads Leave the Device and What They Cost: The on-device versus cloud routing decision and its sovereignty and cost consequences.
- Apple Intelligence, Third-Party Models and Enterprise AI Governance: How to decide what to allow and block across Apple, Claude and Gemini.
- Declarative Device Management and the OS 27 Migration Deadline: Why legacy MDM is ending and how to plan the migration.
What does an “AI-native operating system” actually mean for iOS 27 and macOS 27?
An AI-native operating system treats an on-device foundation model as a system service rather than a feature inside individual apps. Intelligence goes ambient: the lock screen becomes a glanceable AI surface, and context flows across iPhone, AirPods and Watch instead of staying siloed per app. The six-platform simultaneous release is the proof point, a platform bet on system-wide AI, so evaluate it as an architectural shift.
Most of the AI you have lived with so far is bolted on: a chatbot in one app, a summarise button in another, a copilot panel somewhere else. Each ships its own model or cloud call, and nothing shares state.
OS 27 makes the model a shared system service. Apple frames it as purposeful and privacy-protected rather than capability for its own sake (Apple Newsroom), and Jamf calls it AI applied to real use cases (Jamf).
For your evaluation, three things matter: fewer cloud round-trips for routine tasks, cross-app context that changes how work flows across Mail, Notes and Calendar, and the lock screen emerging as a glanceable AI dashboard.
The iPhone, AirPods and Watch continuum is clear evidence that the boundary is dissolving. Siri AI syncs conversation history across products through iCloud. The boundary between devices is dissolving, alongside the boundary between apps.
That is the concept. The specifics are in how Siri AI turns iOS 27 and macOS 27 into an AI-native operating system.
What is Siri AI and how is it different from previous versions of Siri?
Siri AI is the rebuilt OS 27 assistant, running a 7B-parameter model on-device so it can hold context, read what is on screen and act across apps. The old Siri was scripted and intent-based, with frequent cloud round-trips and little memory. The difference matters for two reasons: fewer failures on routine tasks, and less of your data leaving the device. Think of it as a shift from a voice-command router to a persistent, screen-aware assistant.
Apple rebuilt Siri around the next generation of Apple Foundation Models, which run on device and on servers using Private Cloud Compute (Apple Newsroom). What matters is what the model can do: remember the current session and read the screen in front of you.
Legacy Siri was app-siloed and cloud-dependent. Siri AI keeps context across a conversation, understands what is on screen, and can act across apps. As Craig Federighi puts it, Siri AI combines broad world knowledge with onscreen awareness and personal context so users can “take action across apps more naturally than ever” (Apple Newsroom).
Heavier requests can still fall back to Private Cloud Compute, which is where the next two sections pick up.
The full architectural picture, including the routing boundary where requests leave the device, is in what Siri AI actually is.
What is Private Cloud Compute and how does it extend Apple device privacy into the cloud?
Private Cloud Compute (PCC) is Apple’s server-side inference system for AI workloads too heavy to run on-device. It extends device privacy into the cloud through three properties: stateless computation (requests run in memory and nothing is retained), verifiable transparency (the software is published to an inspectable log), and non-targetability (no one can route your request to a specific node). The test for you is whether those guarantees hold under independent scrutiny.
PCC exists to run heavier AI workloads without the conventional cloud-privacy trade-off. Normally, cloud inference means trusting someone else’s server and retention policy. Apple’s answer is to extend the device’s privacy properties server-side (Apple Security).
Together they form the enterprise trust equation Apple is selling. The same infrastructure underpins Apple Reference Image, a photo-provenance system that verifies whether an image was captured by an iPhone camera.
PCC is the backbone of Apple’s differentiated privacy story. But the claims now extend beyond Apple’s own data centres, onto Google Cloud with NVIDIA GPUs, which raises new questions about jurisdiction that the sovereignty section below picks up.
The trust analysis, including the Google Cloud and NVIDIA expansion, is in how Private Cloud Compute extends Apple privacy into the cloud.
What does the CVE-2026-20685 darwin-init vulnerability reveal about Private Cloud Compute’s security model?
CVE-2026-20685 was a path-traversal flaw in PCC’s darwin-init provisioning process that allowed root-level file writes. A researcher found it through Apple’s Virtual Research Environment and was paid $150,000. It shows the trust model has a real attack surface: attestation verified the installed software, but not the writable data-volume configuration that drives runtime behaviour. For you, it is a reason to scrutinise PCC like any other infrastructure.
darwin-init is the first userspace process on a booting PCC node, running as root before the steady-state services enforce the node’s security assumptions (Sentry). Drinor Selmanaj found the path traversal and used it to redirect the node’s inference and telemetry to a server he controlled.
The bounty program worked. The flaw was found inside Apple’s Virtual Research Environment, which boots a genuine PCC image so researchers can test it. Apple rated it information disclosure at CVSS 6.5 and fixed it in PCC release 5E290.3 (Sentry). As Selmanaj notes, it is a thirty-year-old vulnerability class, but that is the point: securing the inference pipeline matters as much as securing the model itself.
Base your own assessment on Apple’s Private Cloud Compute security documentation and on independent, non-vendor analysis. The full CVE analysis, plus the NVIDIA and Google confidential-computing comparison, is in the Private Cloud Compute trust model and the darwin-init finding.
Private Cloud Compute vs on-device AI processing — which workloads leave the device and why?
The split is a data-exposure decision, not a performance benchmark. Lightweight, latency-sensitive and privacy-sensitive tasks stay on-device; heavier inference — larger models, complex reasoning, agentic tool use — leaves for Private Cloud Compute. Workloads leave the device because of model size, memory pressure and capability requirements. Your evaluation should start from what data is in the request and what happens to it after inference, then work back to performance.
Apple’s Foundation Models split into two groups: on-device models and cloud models running on Private Cloud Compute (Apple Machine Learning Research). The routing logic distinguishes the two by task sensitivity.
The 12GB unified-memory threshold is the hardware gate for fleets. The largest on-device model requires at least 12GB of unified memory, and the features that depend on it, expressive voices and advanced dictation, fall back to Private Cloud Compute on devices below that floor (Fleet). That makes routing a hardware question as much as a privacy question.
The full routing, sovereignty and cost treatment is in which Apple AI workloads leave the device and what they cost. It pairs with the PCC trust section, because routing and trust are two halves of the same exposure decision.
How should you assess whether Private Cloud Compute meets your data sovereignty, residency and compliance requirements?
Treat PCC as you would any third-party infrastructure. Confirm where processing occurs, what is retained and for how long, and what residency guarantees exist in writing. The EU and China change the answer significantly. The harder question is the undisclosed Google Cloud regions behind the PCC expansion. Weigh attestation and transparency against jurisdiction, and do not assume Apple’s privacy language covers your obligations.
The geography is not uniform. Siri AI will not be available in China while Apple works through regulatory requirements (Apple Newsroom). In the EU, Mac and Apple Vision Pro users get Siri AI when set to a supported language, but it is not initially available on iOS, iPadOS and watchOS (Apple Newsroom).
The open question that matters most is the Google Cloud regions. Apple has not disclosed which regions host PCC, and financial terms and capacity commitments are also undisclosed (InfoQ). Jonathan Sandhu, a systems architect, framed the test for InfoQ: what happens to the privacy guarantees when Google’s infrastructure faces a compliance obligation Apple’s would not? That is the variable to chase in writing rather than infer from marketing.
For the full routing and sovereignty treatment, see the on-device versus cloud routing and cost comparison. The PCC trust section explains how the protections work.
How should you decide which Apple Intelligence and Siri AI features to allow versus block on managed devices?
The allow/block decision is an acceptable-use and data-boundary question. Separate what runs on-device from what reaches Private Cloud Compute or a third-party model, then map each feature to your data-governance rules. Default-deny anything that sends data you cannot classify. Default-allow clearly on-device, low-risk features. Control the grey zone in between. The policy you write here becomes the enforcement you configure later through Declarative Device Management.
On-device features like writing tools or onscreen awareness carry a different risk profile than anything that reaches PCC or an external model like Claude or Gemini.
The intelligence settings configuration exposes device-wide toggles and per-app controls for Mail, Notes and Safari (Apple Deployment Guide), which Fleet advises reviewing against your acceptable-use policies before OS 27 ships (Fleet).
AI feature governance now lives in Declarative Device Management, so the decision you make here sits downstream of routing and upstream of your MDM configuration.
The full governance framework, including the exact keys to configure, is in enterprise AI governance across Apple Intelligence and third-party models, and the DDM section below explains where it gets enforced.
How does Apple’s enterprise AI approach compare to Microsoft Copilot or Google Gemini for enterprise device fleets?
The three take different default positions. Apple anchors on on-device and Private Cloud Compute inference with a hardware-rooted privacy story. Microsoft couples Copilot to the Microsoft 365 and Azure estate. Google ties Gemini to Workspace and Google Cloud. Compare them on data flow, retention, residency and lock-in rather than raw capability. The choice turns on whose infrastructure your data ends up in.
The useful framework is how each handles cloud inference. InfoQ lays out three tiers: eyes-on with retention, ZDR (zero data retention), and ZOA (zero operator access), where cryptographic proof shows no operator, including the cloud provider, can access inference data (InfoQ). Apple’s PCC sits at the ZOA end. That is a real difference, and it is the one worth probing in a vendor bake-off.
Lock-in is the other axis. Apple opening its Foundation Models framework to Claude and Gemini complicates the closed-versus-open framing, since a third-party model can sit behind the same API surface as the on-device model (Google Developers Blog).
For the full enterprise comparison and the board-facing framing, see the enterprise AI comparison across Apple, Microsoft and Google.
What is Declarative Device Management and why is it becoming the default for managing Apple device fleets?
Declarative Device Management (DDM) replaces the legacy profile-and-command model. The device reports its state and enforces a declared desired state, which reduces polling and improves reliability. In OS 27 it becomes the standard substrate for AI feature governance, privacy controls, software updates and identity. For you, DDM is where the allow/block decisions from your governance work get enforced, so its maturity in your MDM vendor is a readiness question now.
Legacy MDM works by polling and commanding. A server asks the device what it looks like, then tells it what to do. That adds latency and failure modes. DDM flips it: the device reports its state and applies a declared desired state itself (Apple Deployment Guide).
The OS 27 release absorbs AI governance, privacy and identity into that declarative substrate. Platform SSO moves to DDM, with web-based authentication and QR-code sign-in. Status reporting replaces MDM queries that added latency without real-time accuracy. The shift touches VPN, content caching, web filtering, intelligence, Siri, SSO and privacy management in one release (Fleet).
The signals to watch are declarative software updates, Platform SSO, Automated Device Enrolment, Return to Service and the Endpoint Security Framework, with Apple’s WWDC26 documentation as the primary reference.
The migration deadline and how to evaluate vendors is in the Declarative Device Management migration deadline.
Why is Apple retiring legacy MDM mechanisms across all OS 27 releases with no grace period?
Apple is collapsing the old profile-based and command-based mechanisms into the declarative substrate rather than maintaining two paths in parallel. The no-grace-period timing means non-compliant management can fail silently at enrolment, profile installation and software updates the moment devices update. The signal is strategic: Apple wants AI governance and management to live in one declarative model. Your risk is measured by how far your vendor has migrated rather than by what their roadmap promises.
Apple is eliminating legacy mechanisms to make DDM the single management path rather than run dual paths. Fleet puts it plainly: the legacy software update MDM support does not fail gracefully, it stops functioning (Fleet).
Translate that into what breaks first. Apple’s own list of what no longer functions includes software update commands, software update queries, recommended cadence settings and deferrals (Apple Deployment Guide). The first failure point is network security: select system processes now enforce stricter TLS requirements for device management, enrolment, profile installation, app installation and software updates. 9to5Mac’s read: those tasks simply fail for non-compliant vendors (9to5Mac).
Your pre-rollout list should verify TLS 1.2 compliance with your vendor and confirm their DDM support for updates, identity and privacy controls.
For prioritisation against the hard deadlines, see the no-grace-period migration and readiness plan.
What happens to Intel Macs and Exchange Web Services support when macOS 27 arrives?
macOS 27 “Golden Gate” is Apple Silicon-only. macOS 26 “Tahoe” was the last full Intel support release, with Intel security updates expected to end around fall 2028. Exchange Web Services is also deprecated in favour of Microsoft Graph. The practical effect is a hardware and identity timeline running in parallel with the AI migration: Intel Macs in your fleet need a replacement plan, and mail connectivity needs a Graph migration path before EWS stops working.
Fleet puts the end of Intel security updates around fall 2028 (Fleet). Three years is a short runway when the work lands at once.
Exchange Web Services runs on its own clock. Microsoft begins disabling EWS on October 1, 2026, with full permanent shutdown on April 1, 2027. Apple is working with Microsoft to move Mail, Calendar, Contacts, Notes and Reminders to the Microsoft Graph API, with its own Graph support arriving in a future macOS 27 update (Fleet).
These two timelines are identity-and-hardware work, separate from but parallel to the AI migration. The 12GB unified-memory angle ties them together: capable on-device AI is gated by hardware that older Intel Macs cannot meet.
For sequencing the hardware, identity and management work into one deadline-driven plan, see the OS 27 deadline-driven migration plan.
Resource Hub: iOS 27 Deep Dives
The Foundation: What OS 27 Is and How Apple Secures It
Siri AI and the AI-Native Operating System in iOS 27 and macOS 27. What “AI-native” means, how Siri AI differs from legacy Siri, and how its 7B-parameter on-device model uses screen awareness and cross-app context.
Private Cloud Compute and the Trust Infrastructure Behind Apple’s OS 27. How PCC extends device privacy into the cloud, and what the Google Cloud and NVIDIA expansion reveals about the trust model.
The Decisions: Data Exposure, Cost, and Governance
Which Apple AI Workloads Leave the Device and What They Cost. Which workloads go on-device versus to PCC, and how to weigh sovereignty, compliance and iCloud+ cost signals.
Apple Intelligence, Third-Party Models and Enterprise AI Governance. How to decide which Apple Intelligence and Siri AI features to allow or block, and how Apple’s approach compares to Copilot and Gemini.
The Deadline: Migration and Readiness
Declarative Device Management and the OS 27 Migration Deadline. Why legacy MDM is being retired with no grace period, how to evaluate vendor readiness, and what Intel Mac and EWS deprecation mean for your timeline.
In This Series
- Siri AI and the AI-Native Operating System in iOS 27 and macOS 27
- Private Cloud Compute and the Trust Infrastructure Behind Apple’s OS 27
- Which Apple AI Workloads Leave the Device and What They Cost
- Apple Intelligence, Third-Party Models and Enterprise AI Governance
- Declarative Device Management and the OS 27 Migration Deadline
Suggested reading order: Siri AI and the AI-native OS, then the Private Cloud Compute trust layer, then routing and cost, then governance, then the migration deadline. Each article stands alone but builds on the one before it.
A mandatory migration deadline doesn’t come with extra headcount. Hiring permanently to cover a temporary push means carrying that cost long after the deadline passes. SoftwareSeni’s extended development teams scale up for the migration and back down once it’s done, so you’re not left holding redundant capacity.
scale my engineering team up for a deadline-driven push and back down once it’s done →
“SoftwareSeni are extremely valuable partners of our business, and have been integral to our growth to date. They have provided a range of technical resources, which could be scaled up or down depending on our requirements. For any one looking to expand their development team or establish from scratch, we would highly recommend seeking our their services.”
— Joshua K, Co-Founder, rePrecinct
Frequently Asked Questions
Why is Apple moving Private Cloud Compute onto Google Cloud infrastructure?
It is about capacity: a six-platform release needs more than Apple’s own data centres can provide. It also means your data may traverse infrastructure Apple does not operate directly. Covered in Private Cloud Compute and the Trust Infrastructure Behind Apple’s OS 27.
How does Apple’s 7B-parameter on-device Siri AI model work with screen awareness and cross-app context?
The 7B-parameter model reads what is on screen and draws context across apps to act on your current task, running locally to keep latency low and data on-device. It is the capability that turns Siri from a voice-command router into a persistent assistant. Detail is in Siri AI and the AI-Native Operating System in iOS 27 and macOS 27.
How does Siri AI compare to third-party Foundation Models like Claude and Gemini on macOS 27?
Siri AI is Apple’s on-device default, while Claude and Gemini arrive as external integrations that send inference to a third party. The comparison turns on data flow and trust model as much as raw capability. See Apple Intelligence, Third-Party Models and Enterprise AI Governance.
How should you weigh the cost of iCloud+ for heavy AI use against on-device processing limits and server-side fallback?
iCloud+ pricing signals that heavy server-side AI may not be free, and daily image-generation limits already point that way. On-device processing avoids the meter but hits memory and model limits. See Which Apple AI Workloads Leave the Device and What They Cost.
Why do the most capable on-device AI features require 12GB of unified memory?
The largest on-device model needs that memory floor to hold its weights and context locally. Below it, devices fall back to Private Cloud Compute. It is a hardware gate. Covered in Which Apple AI Workloads Leave the Device and What They Cost.
What is the Apple Reference Image system and how does it prove a photo was taken with an iPhone?
It validates provenance through Private Cloud Compute, anchoring authenticity in the camera hardware rather than software alone. It is Apple’s counterweight to AI-generated imagery. Detail is in Private Cloud Compute and the Trust Infrastructure Behind Apple’s OS 27.
Where can I find Apple’s official WWDC26 device management documentation?
Apple’s WWDC26 device management sessions and the Declarative Device Management configuration reference are the primary sources. The key deprecations are catalogued in Declarative Device Management and the OS 27 Migration Deadline.
Is Apple Intelligence actually private enough for my company’s data?
The architecture is stronger than a conventional cloud AI service: stateless computation, verifiable transparency and non-targetability. The guarantees still need independent verification, so treat it as a trust decision you can test. See Private Cloud Compute and the Trust Infrastructure Behind Apple’s OS 27 and Which Apple AI Workloads Leave the Device and What They Cost.
Absorbing this migration into your existing team’s roadmap, or bringing in capacity built for the push? Talk to SoftwareSeni about extended development teams for the push