If your team manages Apple devices, AI governance has likely become part of the job. Jamf admins are developing policies for the AI tools and agents appearing on managed endpoints, and Jamf Nation User Conference (JNUC) 2026  reflects that shift with sessions on agentic administration, AI operations and automated workflows. 

NowSecure will join the conversation this week September 23–25 in Kansas City, Mo., with another question to consider: What happens when AI appears inside a mobile app your organization has already approved? 

Device-level controls provide one part of the picture. Mobile apps add another. AI can arrive inside apps you already approved through SDKs and embedded services your security team may never have vetted and through routine updates that add AI functionality after an app passes review.

NowSecure testing of 50,000 mobile apps found that 53% contained AI components that conventional device-level review may not surface. Our 2026 Mobile App Risk Management Survey reinforces the concern: 95% of organizations say they deploy AI in their mobile apps, while 37% do not monitor AI behavior in the apps they develop or deploy.

That visibility gap is about to widen as Apple is adopting new functionality to support agentic AI. iOS 27 makes Siri AI and App Intents a more prominent part of the mobile app ecosystem, allowing Siri to retrieve information and invoke actions through App Intents an app exposes, sometimes without the user opening the app.

Across apps NowSecure tested in June, July and August, 24% had app functionality potentially exposed to Siri AI and Apple Intelligence. That meaningfully expands what an app, and by extension an agent acting through that app, can reach and do on a managed device.

Jamf’s device-level controls and app-level risk intelligence address different parts of the same problem. A complete assessment needs to consider the app itself as well as the device it runs on.

IT and security teams can enforce strong device policies and still lack visibility into whether an approved app just added an AI SDK, what data that SDK touches or whether an agent can now trigger an action inside the app on the user’s behalf. Third-party risk inside apps organizations already trust may not surface through device management alone, yet that information can change an allow or restrict decision.

Turning App-Level Intelligence Into a Workflow Decision

Visibility only helps when teams can act on it. This is where NowSecure Mobile App Risk Intelligence (MARI) fits into a workflow your team already runs.

MARI supplies intelligence organizations can use to inform approval, restriction and remediation workflows. Teams can approve an app when its behavior aligns with policy, investigate one containing an unapproved AI component, reassess an app after an update introduces new capabilities and document the evidence behind each decision.

MARI does not make the policy decision. It gives the people responsible for that decision concrete evidence they can act on.

MARI does not make the policy decision. It gives the people responsible for that decision concrete evidence they can act on.

Sessions Worth Adding to Your JNUC Agenda

Several JNUC sessions explore the connection among AI governance, automation and security. Beyond NowSecure’s sessions, three are worth adding to your schedule.

The AI-Empowered Jamf Admin: From Scripts to Agents
Thursday., Sept. 24, 9:00–9:45 a.m.

Speakers: Rob Potvin, Senior Consulting Engineer, Jamf, and Daniel MacLaughlin, Senior Consulting Engineer, Implementation, Jamf

Explore MCP, agentic administration, Jamf API queries and the guardrails organizations need before allowing agents to act within enterprise systems. Potvin and MacLaughlin will demonstrate how they use AI agents, natural-language interfaces and AI-assisted health scoring in real Apple fleet management workflows.

Building Trusted AI Operations for Apple Fleets with Tines and Jamf
Thursday, Sept. 24, 1:00–1:15 p.m.

Speaker: Sam Berniard, Senior Partner Solutions Engineer, Tines

Learn how organizations can combine device management and AI governance with automated workflows for broader visibility and control. Berniard will explain how organizations can operationalize AI across Apple fleets while maintaining enterprise visibility and governance.

Routine Business: Turning Jamf Signals into ServiceNow Actions
Friday, September 25, 10:15–11:00 a.m.

Speakers: Jenny Zou, Apple Platform Engineer, Tapestry, Inc., and Robert Barlow, Lead EUC Architect, Tapestry, Inc.

See how teams can turn Jamf signals into ServiceNow tickets and automated response workflows. Zou and Barlow will share a practical framework for converting device intelligence into action when devices drift, age out or present security risks.

Join NowSecure at JNUC

Modernizing Mobile App Approvals: How Travis County Uses NowSecure + Jamf to Reduce Risk
Thursday, Sept. 24, 11:30 a.m.–12:15 p.m.

Speakers: Frank Roberts, Senior Systems Engineer, Travis County Texas; Kevin Lewis, Senior Solutions Engineer, NowSecure; and Michael Covington, VP, Portfolio Strategy, Jamf

Travis County replaced a weeks-long mobile app approval process with a faster, evidence-based workflow. Roberts, Lewis and Covington will explain how the process works, what NowSecure reports reveal and how security, legal and compliance teams use those findings to make informed app decisions.

Securing AI in Your Business: The Mobile Edition
Thursday, Sept. 24, 4:15–5:00 p.m.

Speakers: Adam Boynton, Senior Security Sales Manager, Jamf, and Brian Murphy, Senior Vice President, NowSecure

Learn how to identify which mobile apps contain AI and understand what data those components can reach. Boynton and Murphy will show how Jamf controls and NowSecure application intelligence can work together to uncover hidden AI components and data flows while connecting AI governance across Mac and mobile.

Join NowSecure at JNUC
Join NowSecure at JNUC

Keep the Conversation Going

JNUC’s Braindates offer another way to explore these questions beyond the breakout rooms in a birds-of-a-feather roundtable format. Topics worth proposing or joining in the Braindate Lounge include:

Shadow AI in Mobile Apps: Do You Know Where It’s Hiding? 

Wednesday, Sept. 23, 3:30 p.m.

Explore how AI components enter app portfolios through SDKs, updates and embedded services, plus what teams need to make informed governance decisions.

Agentic Workflows on iOS 27: What Changes for Mobile Risk? 

Wednesday, Sept. 23, 4:30 p.m. 

Discuss what App Intents and Siri AI mean once apps and agents can take actions or reach data across application boundaries.

Beyond Allow or Block: Making Evidence-Based App Decisions

Thursday, Sept. 24, 9 a.m. 

Bring a mobile app your organization uses and discuss the security, privacy and AI risk your team should know about.

Add Mobile App Risk to Your JNUC Agenda

Explore the JNUC sessions above, join one of the Braindate conversations or bring an app your organization relies on and talk with the NowSecure team about the security, privacy, SDK and AI questions worth investigating.

Preparing for agentic workflows on iOS 27? Download the NowSecure iOS 27 Agentic Security Playbook to assess your exposure and identify practical next steps.