Apple has quietly rewritten one of its most prominent privacy commitments. Under iOS 27, the company can store users' full Siri and dictation interactions — including the audio recordings themselves — and use them to train the artificial intelligence models behind Siri, as first reported by the German technology publication Heise Online.

The change ends a position Apple had stated categorically: that personal user data would never be used to train its AI foundation models. For more context on this story, see our ongoing artificial intelligence updates.

What the New Policy Says

The updated language appears in a privacy policy found in the final pre-release build of iOS 27, which shipped to the public on Monday, September 14. According to the policy, Apple can "store your entire interactions with Siri and the dictation function, including the audio data and transcripts of your typed and spoken Siri requests, as well as Siri's responses."

Apple emphasizes that the data is not linked to a user's Apple Account, and states that it "takes steps to ensure that personal data is not stored or used by Apple" — a formulation that sits awkwardly next to the permission it describes. Some of the collected data may be reviewed by what the policy calls only "review personnel," with audio material listened to exclusively by Apple employees.

The company frames the program as opt-in. When users activate Siri AI, a dialog asks them to help improve the assistant, and developers with access to the release candidate report the decline option is easy to miss: a visually inconspicuous "Not now" button on a screen that cannot be fully dismissed. Users who do opt in can reverse the choice later under Settings, then Analysis & Improvements.

A Quiet Edit to a Signature Promise

The policy change was preceded by an even quieter edit. Apple's published guidelines on responsible AI previously stated, in a complete sentence, that "your private personal data and interactions are never used to train our foundation models." That sentence's definitive ending has been removed and replaced with a caveat: "unless you explicitly choose to help improve them."

The revision matters beyond its wording, because it collides with the architecture Apple has spent two years marketing. Private Cloud Compute, the server system behind Siri AI and most Apple Intelligence features, was sold on a specific promise: cloud AI that handles requests as privately as an on-device model, with user data never stored long-term or exposed to third parties. Using Siri recordings as training material — and, for the first time in iOS 27, routing some Private Cloud Compute requests through Google servers — stretches that promise closer to the behavior of the cloud assistants Apple once positioned itself against.

Always-Listening Hardware Raises the Stakes

The timing is awkward for a second reason. Alongside its latest iPhones, Apple introduced two Apple Watch models this week designed to listen continuously. The devices can produce a transcript of the preceding fifteen seconds of conversation on demand, plus a daily "Siri Recap" summarizing the wearer's conversations — a feature Apple says also runs on Private Cloud Compute.

Always-on microphones feeding an assistant that can now retain interactions for model training is precisely the combination privacy advocates have warned about, and it arrives from the company that built its modern marketing around refusing to do exactly this.

Echoes of the 2019 Siri Grading Scandal

Apple has been here before. In 2019, the company suffered its most damaging privacy controversy when contractors employed by subcontractors described their work grading Siri audio recordings — snippets that frequently contained intimate conversations, medical information, and other personal details, handled under lax controls. Apple suspended the program, apologized, and later reintroduced human review as an opt-in feature with tighter safeguards.

The new policy resumes that data collection with a broader scope — full interactions rather than sampled audio clips, transcripts alongside recordings, and an explicit training purpose — while relying on a similar consent mechanism that many users will tap past without reading.

What Happens Next

Regulators in Europe and the United States have repeatedly scrutinized how consent dialogs for AI training are presented, and an opt-in screen with a prominent agree button and a low-contrast refusal option is the kind of design that attracts that scrutiny. For now, Apple's position is that the data stays inside its own systems, is decoupled from user identities, and is reviewed only under employee-only rules.

The deeper shift is strategic. Training competitive AI models requires enormous volumes of high-quality conversational data, and Apple — which entered the modern AI race later than its rivals — appears to have decided that its most valuable untapped resource is the hundreds of millions of Siri conversations that occur every day. The company that once made privacy the reason to buy an iPhone has concluded it can no longer afford to leave that data on the table. Whether users agree to hand it over, one "Not now" button at a time, will determine how much of it Apple gets.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →