Apple iOS/iPadOS 26 must disable ChatGPT connection for Apple Intelligence.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-278827AIOS-26-015400SV-278827r1150855_ruleCCI-000366medium
Description
The ChatGPT feature of Apple Intelligence allows DOD information to be downloaded from the DOD iPhone/iPad and processed by the ChatGPT application in the cloud. The ChatGPT feature of Apple Intelligence increases the risk of compromise of sensitive DOD information. SFR ID: FMT_MOF_EXT.1.2 #47
STIGDate
Apple iOS/iPadOS 26 Security Technical Implementation Guide2025-12-01

Related Frameworks

4 paths across 3 frameworks
NIST 800-531 mapping
CM-6
1.00
  • DISA · V1R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1712 mappings
3.4.1
1.00
  • DISA · V1R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.4.2
1.00
  • DISA · V1R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000366
1.00
  • DISA · V1R2 · disa_xccdf · related

Details

Check Text (C-278827r1150855_chk)

This check procedure is performed on the device management tool. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the iOS management tool, verify "Allow ChatGPT" is unchecked. Note: Each MDM/EMM server will define the exact label for the control to disable connections to cloud-based third-party artificial intelligence (AI) apps, including ChatGPT. If access to all cloud-based third-party AI apps, including ChatGPT is not disabled in the management tool, this is a finding.

Fix Text (F-83266r1150854_fix)

Install a configuration profile to disable ChatGPT (and any other available third-party AI app) connection for Apple Intelligence. Configuration Profile Key: allowExternalIntelligenceIntegrations, allowExternalIntelligenceIntegrationsSignIn