Australian and New Zealand organisations are being given new tools to uncover and restrict the use of artificial intelligence applications across workplace Macs, as employees increasingly install AI assistants without the knowledge of their IT or security teams.
Apple device management company Jamf has released AI Governance, a capability designed to identify AI software running on managed devices, enforce company policies and produce reports for security audits and regulatory compliance.
The release deals with a problem that has moved quickly through workplaces over the past two years.
Employees can now install AI coding assistants, desktop applications and command-line tools capable of reading files, connecting to cloud services and interacting with other business systems, sometimes without anyone checking what information those tools can reach.
Jamf claims AI Governance is the first native, operating system-level AI control plane developed for Macs. It is being made generally available across Australia and New Zealand through Jamf for Mac, with immediate support for Claude Code, Claude Desktop and OpenAI Codex.
Shadow AI is becoming harder for employers to ignore
For many organisations, the immediate concern is not the AI software that has been formally approved, but the tools employees are already using outside established company policies.
This so-called Shadow AI can leave security teams with little understanding of what applications are running, which files they can access or whether company information is being sent to external models.
Network monitoring and cloud security services can identify some AI traffic, although they do not always reveal what an application is doing directly on a Mac.
Locally installed AI agents can operate as background processes, use command-line interfaces and interact with files before data ever reaches a network control.
AI Governance uses Jamf’s existing telemetry agent to identify AI applications, agents and large language model runtimes across a managed fleet.
Jamf says this includes command-line developer tools and background agents, with no additional monitoring agent required on each device.
The system can also inspect and apply controls covering model access, network permissions, file system access, tenancy settings, MCP servers and configurations specific to individual AI vendors.
Policies can be installed before a user first signs into an AI agent and remain available when the device is offline, creating an initial security baseline that is more difficult for an employee or application to alter.
A vendor control tracking engine will monitor supported AI platforms as their settings change or new controls become available.
That will be important for IT departments dealing with products that are being updated far more quickly than the policies traditionally used to govern workplace software.
“AI adoption across the enterprise is moving faster than existing technology policies can keep up,” said Beth Tschida, CEO at Jamf.
“Organisations need governance that matches the way AI tools actually operate on Mac. This means visibility into what’s running, policy controls enforced directly on the endpoint, and reporting that helps security teams demonstrate compliance,”
“Our AI Governance capability delivers that natively from the same platform customers already trust to manage and secure Apple devices.” Tschida
Employers can restrict tools by team or department
The controls allow administrators to decide which AI applications are sanctioned and apply different access policies across departments or employee groups.
A development team, for example, may be permitted to use an AI coding agent under restricted conditions, while employees handling financial, legal or customer information could face tighter controls.
Jamf says vendor-specific configurations can be deployed across an entire Mac fleet without administrators having to manually reproduce the correct settings for each AI platform.
The company has also introduced an executive AI posture report intended to give chief information officers and security executives a snapshot of AI use within their organisation.
The reporting capability is compatible with security information and event management systems and is designed to support existing compliance frameworks.
It could give organisations a clearer record of which AI tools were operating at a particular time, where they were used and what restrictions had been applied.
Eventbrite has been testing the controls as it considers how employees can use AI without weakening oversight of company systems.
Its security team said the ability to apply policies through an existing management platform reduced the need to introduce another standalone security product.
“Like many organisations, we want to enable teams to use AI tools productively while maintaining appropriate governance and oversight,” said Sam Lalli, Security Engineering & SOC Manager at Eventbrite.
“What impressed us about Jamf’s AI Governance was how quickly we could apply policy across our Mac fleet without adding another point solution or creating friction for developers.”
“Having this critical capability built into the same device management platform we already use, really simplifies AI governance for our team,” Sam Lalli continued.
Endpoint controls extend into cloud services
The risks surrounding AI agents do not stop at the device. An agent running on a company Mac may connect to cloud platforms, business applications and internal data through Model Context Protocol servers, creating a chain of access that can be difficult to follow after something goes wrong.
Jamf is working with Okta to connect endpoint controls with identity and access management.
IT and security teams can discover AI tools running on macOS devices through Jamf and register those agents with Okta for AI Agents, giving each agent a managed identity and limiting it to approved resources.
Under the integration, Jamf determines which MCP servers can operate on a device, while Okta controls which cloud resources those servers can reach.
Agents use short-lived, vaulted credentials instead of long-lived static keys, and their actions can be authorised and recorded as they move between the endpoint and cloud services.
The Okta integration can be deployed through the Jamf console without manual API configuration or certificate management.
Organisations can also configure an approved agent development platform, including Amazon Bedrock AgentCore, so AI traffic is processed through sanctioned cloud infrastructure.
The combined system is intended to help security teams establish which agents ran on particular Macs, what those agents were authorised to access and what they did between the device and a software-as-a-service application.
That record may become increasingly important when investigating a data leak or trying to establish whether an AI agent acted outside its approved role.
“While some enterprise AI agents run locally, they access data across a vast cloud ecosystem, requiring coordinated security between the endpoint and identity layers,” said Harish Peri, SVP & GM of AI Security, Okta.
“By anchoring Okta for AI Agents to Jamf’s endpoint enforcement, every agentic connection on a managed Mac is authenticated, authorised, and fully visible from the device to the data,”
“Together, we’re helping organisations become secure agentic enterprises by giving them more control over what AI agents can access and on whose behalf,” said Peri.
AI-related incidents increase as adoption deepens
Jamf’s recently released AI Governance Survey found organisations with deeply integrated AI were 40 per cent more likely to report an incident than businesses still exploring the technology.
The finding suggests the risk is growing alongside practical adoption, particularly as AI systems are allowed to reach deeper into company data and everyday employee workflows.
It also raises questions about whether businesses can accurately investigate AI-related incidents if they do not know which tools were installed in the first place.
A written workplace policy may offer little protection when an unsanctioned agent is already running locally with permission to read files or communicate with external services.
Spending on AI governance is expected to reach US$492 million in 2026 and exceed US$1 billion by 2030, based on Gartner research cited by Jamf.
“With spending on AI governance expected to reach $492 million in 2026 and surpass $1 billion by 2030, organisations are reassessing the tools and strategies needed to stay ahead of both regulatory and operational risk.”
Gartner also addressed the discovery of workplace AI agents in its Top Cybersecurity Trends for 2026 report.
“Cybersecurity leaders must identify both sanctioned and unsanctioned AI agents, enforce robust controls for each and develop incident response playbooks to address potential risks.”
Jamf AI Governance is now available through Jamf for Mac with support for Claude Code, Claude Desktop and OpenAI Codex.
More information is available from the Jamf AI Governance website, with support for further AI platforms expected as the company expands its vendor control tracking system.
=

