Got a tip for us?

The Siri AI Privacy Limits Apple Doesn’t Advertise

Apple has tried to cover all the bases to protect your privacy, including one the company often receives criticism for: providing enough information or access for independent outside security researchers or research companies to examine their security and privacy claims.

So far, the company has operated Apple Intelligence and PCC for two years, and only a single flaw was found by a researcher examining the disclosed components (the researcher was awarded Apple’s top security bounty). None have been discovered in any public-facing portions of the system. That doesn’t guarantee anything in the future, but it’s a good sign.

You should consider how Siri AI and Apple Intelligence affect your privacy, and what you might do about it:

  • Siri conversation syncing is secured with end-to-end encryption among your devices, like other sorts of data that are available exclusively on your devices, such as your conversations in Messages and entries in Passwords, and not via iCloud.com. If someone could access your Apple Account and to log into iCloud.com, they can’t see your Siri conversations. Someone would have to use your account information to add a device to your Apple Account set, or take over one of your devices.
  • You have to trust that Apple is making the right decisions. Their transparency helps, because you know that hundreds—maybe tens of thousands?—of people are looking for weaknesses in a system that will be used by hundreds of millions of people every day. But there’s nothing you can do, unless you’re a security researcher, to further that work. So it’s a bit of a binary trust/no trust option.
  • You don’t know when and if your personal data leaves your devices to use PCC—at Apple or in Google Cloud—so you can’t flip a switch to say “only use on-device models,” or “only use Apple’s PCC nodes when off-device.”
  • We don’t see a way that you can entirely disable Apple Intelligence, so you can’t per se prevent your information from being processed in the cloud. You can disable Siri, though you must disable it entirely to not use Siri AI—there’s no mode of Siri without Apple Intelligence on devices that support Apple Intelligence. Fully disabling Siri turns off all Apple Intelligence features related to Siri, likely covering a significant portion of off-device transactions involving more general information. You can turn off some features that rely on Apple Intelligence for individual apps, but not all such features.
  • While Google, Intel, and Nvidia are involved in the new Google Cloud-based portion of PCC, you aren’t being asked to trust how they manage privacy as such. Apple has built the secure stack that runs on the nodes. The risks here are firmware or hardware exploits that could compromise the non-Apple elements in Google Cloud. However, if Apple has done their work correctly, those exploits still wouldn’t allow targeting of individual data or exposure of that data. In particular, while each of those companies has security features in their hardware, Apple isn’t relying on those features for protection—they’re another layer before Apple’s secure stack is encountered by attackers.
  • Your data should be off-limits to government access just like any end-to-end encrypted data. The process Apple describes should prevent the company or any partner from having access to any of the keys required to access information inside a PCC transaction. However, it’s not yet clear how fully Apple will allow inspection of that process outside the software that runs it. That is, we don’t know whether they’ll allow testing of their cryptographic infrastructure.

Our frank conclusion is that if it’s intolerable to you to have any personal data potentially be processed outside of your devices, you will be unable to use iOS 27, iPadOS 27, or macOS 27 on Apple hardware that supports Apple Intelligence.

Otherwise—and we fall into this category—we rely on the information Apple has provided and non-affiliated researchers to keep them honest.