Administrators who wanted an update installed on a Mac immediately had a command for it. On the newest version of the operating system that command answers with an error, and nothing has replaced it.
Howard Oakley documented the change at the Eclectic Light Company after moving a Mac to macOS 27 Golden Gate. Under Sequoia and Tahoe, running sudo xprotect check or install queried Apple’s servers and pulled the latest protection data on demand. Golden Gate refuses both, returning an update error even when a newer package sits in iCloud. Neither command was ever documented, and the only remaining route for fresh data is a background service working to its own timetable.
Two halves of the same defense
XProtect arrives in separate pieces. One is the detection rule set that Gatekeeper consults before an app launches; since Sequoia, Macs keep two copies, one maintained by Software Update and one fetched by the background service. The other is XProtect Remediator, the scanning modules that sweep a Mac every 24 hours. Software Update still offers version 157 of that protection data, while Golden Gate ships with version 159, a build limited to macOS 27 and compiled for Apple silicon alone. It adds no new scanning modules and no change to the Bastion rules.
What administrators should watch
Because the manual path is gone, fleets that relied on a scheduled nudge will now take whatever version the background service decides to install, at whatever moment it chooses. That removes the option of pushing a detection update during an active incident.
Oakley points administrators to version 3.02 of his SilentKnight utility, which recognizes the newer numbering and reports it without complaint. Earlier builds treat the same values as faults, sending a help desk after a problem that does not exist.