Apple’s AI privacy reports resist every attempt to read them

The record Apple offers so users can audit what its off-device AI requests handled is filled with encoded bundles that no ordinary tool can open.

AppleThreat Staff
2 Min Read

A record that cannot be opened is not much of a safeguard, and the one Apple offers for requests handled off a Mac resists inspection at every turn.

Finding the Apple Intelligence Report takes nothing more than a trip through Privacy and Security, and Apple says a requested copy spans the previous 15 minutes or seven days of AI interactions, holding messages and text typed into writing tools. That makes it the most detailed account an owner can obtain of what left the machine. The bulk of a typical copy, as Howard Oakley set out in a walkthrough at the Eclectic Light Company, consists of privateCloudComputeRequests. Their payloads are attestation bundles encoded in Base64, and since macOS 26.4 those bundles have used Protobuf, a format with no simple one-step converter into anything a person can read.

The tool Apple recommends

Apple’s own guidance is to verify the bundles with pccvre, a command hidden in the system’s security research directory. Using it means enabling the Private Cloud Compute research environment with a csrutil command issued from Recovery. Apple warns that this hands over additional access to hardware features and could expose more attack surface.

Transparency nobody can check

On an Apple silicon Mac running in ordinary user mode there appears to be no way to open the reports at all. Siri transcripts are easier to read but say little about which model handled a request or what information actually left the machine.

The gap matters because the report is the only first-hand record a user can obtain of off-device processing. Six months after the format changed, the safeguard exists on paper and cannot be inspected in practice.

Share This Article