Your personal AI account on that managed work iPhone won't stay private for long, as Jamf is expanding enterprise controls directly into mobile apps and browsers in 2027.
The Jamf platform additions were unveiled at the Jamf Nation User Conference in Kansas City. Most of the new AI protections are targeted for the fourth quarter of 2026, while several management and support tools won't enter public beta until early 2027.
Unlike the AI-assisted administration recently added through Addigy Intelligence, Jamf's new controls concentrate on the AI services employees use and the information those services can reach.
Personal AI accounts come under management
Jamf's existing AI Governance feature can discover AI tools running on managed Macs, enforce policies, and produce reports for internal reviews or regulators.
Upcoming browser controls will extend visibility into Safari, Chrome, Edge, Firefox, and other browsers. IT teams will be able to identify the use of personal AI accounts and apply policies when an employee attempts an action such as uploading a corporate file.
IT teams will be able to identify the use of personal AI accounts and apply policies. Image credit: JamfThe controls won't give an employer access to the employee's personal account. Instead, enforcement will happen through the managed browser and device when protected information is about to leave the organization.
Deeper activity insights will show flagged AI use by device, user, and command line. Separate reports will estimate token usage and costs by tool, model, provider, user, and device without capturing prompts or responses.
Mobile AI Governance will bring similar monitoring and policy controls to native apps and browsers on managed iPhones and iPads. Administrators will be able to detect, monitor, or block AI use through Jamf's device-management and on-device content-filtering systems.
App Insights will also identify whether installed software uses Apple Intelligence, local third-party models, or cloud-based AI. Its existing risk scoring covers outdated versions, possible data leakage, and sideloaded code.
Browser governance, mobile controls, deeper activity reporting, cost estimates, and the expanded App Insights feature are all targeted for general availability in the fourth quarter of 2026.
Local AI keeps company data on the device
Another planned feature will let organizations deploy preferred inference engines and local models through Jamf Blueprints. The system is designed to run AI workloads on Apple hardware without sending prompts or company data to a cloud provider.
Local deployment gives IT teams a way to choose which models are available while keeping sensitive work on managed hardware. Organizations could also update or replace those models through the same Blueprints system used for other device configurations.
Blueprints relies on Apple's declarative management architecture, which lets devices maintain an assigned state without waiting for a traditional sequence of commands from a management server.
A separate data-loss prevention feature will discover sensitive information, track its movement through macOS, and apply controls before the data reaches an unapproved destination. Both local AI deployment and the data-loss prevention system are targeted for the fourth quarter.
Apple management moves further into code
The new Platform API Gateway brings Jamf's APIs for Blueprints, compliance benchmarks, and device data into one place. Customers and partners can use those connections to build and deploy configurations, manage devices, and check compliance.
Jamf already maintains a Terraform provider for managing Blueprints and compliance benchmarks as code. The provider is now part of a wider effort to make Jamf administration work with version control, peer review, and rollback systems commonly used for cloud infrastructure.
Local deployment gives IT teams a way to choose which models are available while keeping sensitive work on managed hardware. Image credit: JamfBoth the Platform API Gateway and Terraform support are generally available.
Jamf Routines will also move to a hosted automation engine with more than 1,500 integrations and controls over where organizational data is stored. General availability is targeted for the first quarter of 2027.
Routine Mac support gets more automation
Automated app lifecycle management will let administrators choose software from a curated Mac catalog and have Jamf install and update it. Employees can also request approved software through Self Service+.
Blueprints will gain App Store deployment across Mac and iOS, providing one workflow for catalog software and App Store apps. The expanded app management tools are targeted for the fourth quarter.
A future Self Service+ experience will let employees describe problems such as lagging video calls and receive explanations with recommended fixes. Users can approve those fixes without opening an IT ticket.
Device health monitoring will examine memory, battery data, and crashes to identify Macs that may need attention. Detected problems can then be connected with appropriate remediation.
Automated Ring Deployments will take a staged approach to software updates. Organizations can begin with a pilot group, pause a rollout when problems appear, and expand deployment after an administrator approves the next stage.
Self-service diagnostics, device health monitoring, and ring deployments are scheduled to enter public beta in the first quarter of 2027.
Jamf Tap will assign a shared device to a shift worker after the employee taps an RFID or NFC badge, and is scheduled for public beta in the first quarter of 2027. Jamf Device Checker is already available, letting workers verify device readiness or resolve problems without waiting for IT.
Pricing is available on request, and varies a great deal depending on deployment size and other factors.