Building a robust mobile application risk management program requires defining clear business  impact tiers and rigorously assessing apps against them. iOS 27 raises the stakes on that work: Apple rebuilt Siri on a new foundation model and gave it the ability to call into third-party apps directly, making agentic AI part of the mobile app ecosystem for the first time.

NowSecure Platform now delivers initial support for iOS 27 mobile application security testing, identifying the App Intents used by Siri AI and all on-device or private cloud use of AI that iOS 27 brings to the front of the app experience. As organizations adopt Apple’s newest OS, NowSecure helps ensure mobile apps meet the highest standards for security, privacy and regulatory compliance.

What Changes for Mobile Apps Under iOS 27

With iOS 27, Siri AI can reach into apps, retrieve information and invoke actions on a user’s behalf without the user ever opening the app. Apple has set a retirement plan for the legacy SiriKit framework alongside this shift. Apps that only integrate through the deprecated SiriKit don’t get a grace period: they simply stop appearing in Siri AI, Spotlight and Apple Intelligence surfaces once iOS 27 ships. 

The security model changes along with it. Historically, mobile security meant securing the binary and locking down the APIs. Agentic workflows extend that boundary: a Siri AI request can now draw on context your app never sees and doesn’t control, then take an action your app exposed but didn’t initiate.

A New Kind of Attack Surface

NowSecure CEO Alan Snyder explains, “The agent lives outside your app. Say a user asks Siri to check their calendar and book a restaurant reservation. Siri reaches into your app through the App Intents you’ve configured, pulls the data it needs and eventually triggers the action, all without the user ever opening your app. That means your data and your actions can leave the app on their own. NowSecure has changed our approach to security testing to keep pace with that new reality.”

Across NowSecure-tested apps in June through August 2026, 24% had app functionality potentially exposed to Siri AI.

That’s an attack surface teams need to understand and test, not avoid.

What This Means for Regulated and Standards-Driven Teams

Security and compliance commentators have identified due-diligence questions for Siri and Apple Intelligence deployments involving regulated data. For Health Insurance Portability and Accountability Act (HIPAA)-regulated workflows, organizations should verify whether the relevant Apple service and data flow require a Business Associate Agreement and whether Apple offers an applicable BAA; Apple’s documented Health app provider data-sharing workflow includes a HIPAA BAA, but that does not establish BAA coverage for Siri or Apple Intelligence.

For Private Cloud Compute, organizations subject to General Data Protection Regulation (GDPR) should assess international-transfer obligations, controller/processor roles, applicable safeguards and whether Apple can provide sufficient location, subprocessor, and transfer documentation for the organization’s risk assessment. Location transparency may also affect vendor-resilience and business-continuity diligence, though Financial Industry Regulatory Authority (FINRA) Rule 4370 is a BCP requirement rather than a data-residency rule.

Finally, Apple Intelligence capabilities can affect PCI DSS scope when they store, process, transmit, or can impact the security of cardholder data. The determining factor is the data flow and the system’s access or security impact.

For banks, healthcare providers, technology companies, retailers, media and government agencies, that turns an abstract AI-risk conversation into a specific, scoped assessment to run this quarter.

OWASP moved in parallel: it published its Top 10 for Agentic Applications for 2026, giving AppSec teams a reference point for agentic risk the same way the OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Application Security Testing Guide (MASTG) anchor mobile security testing. Extending that mobile-specific rigor to App Intents and Siri AI is a natural next step.

Key Highlights of iOS 27 Support in NowSecure Platform

By extending support to apps built for iOS 27, NowSecure Platform helps AppSec and DevSecOps teams keep pace with Apple’s release cycle. Key features of this support include:

  • Initial testing coverage: NowSecure Platform delivers core iOS 27 testing, including an inventory of App Intents and their exposed data and actions, so teams can evaluate security posture as they update existing apps or build new ones for iOS 27.
  • AI model detection: NowSecure identifies on-device AI models and libraries, including apps that link Apple’s FoundationModels framework for on-device and Private Cloud Compute inference, plus cloud-based AI services, endpoints, and exposed API keys. 
  • Agentic surface coverage, coming soon: NowSecure is extending testing to the App Intents and Siri AI configuration details that determine how safely an app behaves under agentic AI. We will share more on this soon.
  • Ongoing updates: As Apple releases new iOS 27 features and patches, NowSecure will continue to expand coverage for mobile application security testing.
  • Seamless integration: For existing customers, testing iOS 27 apps in NowSecure Platform requires no new setup, maintaining continuity in app security testing workflows and DevSecOps integrations.
  • PTaaS: To test the agentic workflows and AI prompts outside of an app and between apps, NowSecure offers Pen Testing as a Service that is fully integrated into the NowSecure Platform capabilities.

By offering immediate day-one iOS 27 support, NowSecure helps organizations take advantage of Siri AI and App Intents while staying ahead of the security risks AI introduces and scaling their risk management programs to match.

Ready to test your iOS 27 app? Start testing today or request a demo of NowSecure Platform. For a deeper walkthrough of the Siri AI/App Intents risk model and a self-assessment scorecard, see NowSecure’s  iOS 27 Agentic Security Playbook.