Apple App Store Seeks Way to Safely Integrate AI Agents
Apple App Store is planning rules to let AI agents operate in its marketplace while protecting user privacy, security and the platform’s commerce model.
Lauren Collins ·

Apple App Store plans rules to permit AI agents while preserving user privacy, security and App Store commerce before its annual developer event.
Why agents pose a policy headache
Software agents can carry out multi-step tasks autonomously, which creates enforcement gaps for app marketplaces built on fixed approvals. Some agents can generate or assemble ancillary code or mini-apps at runtime, raising questions about how pre-approval and screening apply.
Apple has already moved to block certain coding tools and services it views as incompatible with its guidelines, a stance that highlights the tension between maintaining platform control and embracing new developer tools. That approach risks alienating engineers who see agency-driven automation as a major productivity and product innovation vector.
Apple’s internal response and next steps
People briefed on the work say Apple engineers are designing an App Store framework intended to allow agentic functionality while enforcing the company’s privacy and security standards. The design reportedly aims to limit freewheeling behaviors that have led to destructive outcomes in experimental agent systems.
Apple’s Siri strategy — which uses Google’s Gemini to coordinate tasks across apps — suggests the company is moving toward sanctioned cross-app automation rather than an outright ban. Apple is widely expected to spotlight its AI plans at its annual developer conference next month, though officials have not confirmed whether agent rules will be announced there.
Keeping developers on the platform is a commercial imperative. App analytics firm Appfigures estimates Apple earned nearly $50 billion in App Store commissions in 2025, an increase of about 20% year-over-year, underscoring how essential the ecosystem is to Apple’s services revenue.
That economic backdrop helps explain why Apple is unlikely to simply block agents wholesale; doing so could drive talent and businesses toward alternative distribution channels or competing platforms. At the same time, unchecked agents could enable fee avoidance, malware distribution, or other behaviors that Apple’s current policies seek to prevent.
What this means for developers and users
Developers building agent-powered tooling face a narrow window to work with Apple’s emerging rules, which will likely require transparent behavior, limits on dynamic code generation, and clear user controls. Consumers could benefit from richer automation if Apple establishes predictable safeguards that reduce security and privacy risks.
What to watch next: the precise technical mechanisms Apple proposes for certifying agent behavior, how payment and in-app purchase rules apply to agent-generated transactions, and whether enforcement favors certification over prohibition. The company’s balance between openness and control will shape the broader market for agentic applications.
Implications: Apple must reconcile developer demand for agentic features with obligations to preserve platform integrity and revenue. Observers should expect tight technical specifications and phased rollout plans rather than an immediate, blanket acceptance of agent-driven apps.