Information
The External Intelligence Extensions allows Apple Intelligence to interface with 3rd part generative AI tools. Apple's external intelligence extension represents a calculated risk. They are extending their on-device privacy and security model to the cloud with PCC (Private Cloud Compute), and then carefully integrating with a third-party AI like ChatGPT, emphasizing user consent, data minimization, and strong contractual obligations. However, the inherent nature of sending data to an external service means a degree of trust is placed on that third party's security posture and adherence to agreements. However, sending data to an external service is additional risk that must be reviewed and accepted in an organizational security plan.
While Apple has put significant effort into designing Apple Intelligence with a privacy-first approach, the external intelligence extension introduces legitimate security risks that might lead an individual or organization to disable it.
Solution
Profile Method:
Create or edit a configuration profile with the following information:
- The PayloadType string is com.apple.applicationaccess
- The key to include is allowExternalIntelligenceIntegrations
- The key must be set to <false/>
- The second key to include is allowExternalIntelligenceIntegrationsSignIn
- The key must be set to <false/>
Impact:
The user would lose the ability to use Apple Intelligence to compose completely new text or access a broader range of resources directly within your apps. You could not use Siri or the Writing Tools to draft a complex email from scratch or generate creative content that goes beyond on-device capabilities but would need to use separate third-party AI providers.
Item Details
Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION
References: 800-53|AC-20(1), 800-53|AC-20(2), 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1, CSCv7|9.2
Control ID: a581548143efa06c583b206de22247e2317c99339826deaa5c81748fd9e51608