Check: APPL-26-005160
Apple macOS 26 (Tahoe) STIG:
APPL-26-005160
(in version v1 r1)
Title
The macOS system must disable Apple Intelligence Writing Tools. (Cat II impact)
Discussion
Apple Intelligence features that use off device Artificial Intelligence (AI) must be disabled. Using off-device AI poses a data loss risk.
Check Content
Verify the macOS system is configured to disable Apple Intelligence Writing Tools with the following command: /usr/bin/osascript -l JavaScript << EOS $.NSUserDefaults.alloc.initWithSuiteName('com.apple.applicationaccess')\ .objectForKey('allowWritingTools').js EOS If the result is not "false", this is a finding.
Fix Text
Configure the macOS system to disable Apple Intelligence Writing Tools by installing the "com.apple.applicationaccess" configuration profile.
Additional Identifiers
Rule ID: SV-277184r1149004_rule
Vulnerability ID: V-277184
Group Title: SRG-OS-000095-GPOS-00049
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-000381 |
Configure the system to provide only organization-defined mission essential capabilities. |
Controls
| Number | Title |
|---|---|
| CM-7 |
Least Functionality |