The AI tools employees use every day — coding agents, desktop assistants and the connectors that link them to business systems — can now be seen, configured and audited on the Mac at operating-system level. That was the message to IT and security leaders at a pair of breakfast briefings hosted this week by Apple-first managed services and Jamf specialist Onsite IT, together with Jamf, concluding in Johannesburg on Thursday.
The briefings addressed a gap most organisations privately admit: AI adoption has outrun AI governance. According to Jamf’s AI Governance Survey of 687 IT and security leaders (Q2 2026), 72.9% of organisations have deployed AI in some form, 81.7% report AI risk exposure, and 22% have already had an AI-related cost or security incident. Counterintuitively, the organisations furthest along report incidents at the highest rate — roughly 40% higher among deeply integrated adopters than among those still exploring.
The reason, both companies argued, is architectural. AI agents run natively on the device, configure themselves through files that change with every vendor release, and act with the permissions of the signed-in user. The security controls most organisations rely on — network proxies, cloud access brokers and cross-platform endpoint tools — watch the wrong layer.
“Every organisation we spoke to this week gave the same answer to the same question: they do not know what AI is running on their Macs,” said Clayton Campbell, Managing Director of Onsite IT. “That is not a technology failure, it is a visibility gap — and it is now one that can be closed on the platform businesses already run. Boards asking about AI risk can be shown evidence rather than a policy document.”
The capability behind the briefings, Jamf AI Governance, became generally available on 1 July 2026 and is included in the Jamf for Mac plan at no additional licence cost. It inventories AI applications and MCP servers across a Mac fleet, applies vendor-correct policy for tools such as Claude Code, Claude Desktop and OpenAI Codex through curated postures validated by Anthropic, enforces those policies tamper-proof at OS level, and generates a board-ready AI posture report with a full audit trail crosswalked to the EU AI Act and NIST AI RMF.
“We saw this pattern with the Mac itself — people brought the device they wanted before IT had sanctioned it, and the market solved it,” said Freek de Jonge, Regional Sales Manager at Jamf. “AI is following the same curve, faster. Governance that lives at the operating-system level is how productivity and control stop being a trade-off.”
The regulatory clock adds urgency. High-risk obligations under the EU AI Act take effect in December 2027, and South African organisations already carry a duty of care under POPIA: personal information processed by an AI tool is still personal information. Procurement questionnaires increasingly ask how AI use is governed — and a policy document is no longer an accepted answer.
