Skip to content

Security3 publishers2 min readPublished

Free RemoveMacAI tool deletes 12 GB of Apple Intelligence models from macOS 27

RemoveMacAI, a free command-line tool, turns off Apple Intelligence on macOS 27 and deletes about 12 GB of downloaded models. It works through a configuration profile with System Integrity Protection left on, so admins get the disk space back without weakening the system-file safeguard.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • macOS 27 has no single switch for Apple Intelligence, and the models stay on disk after the features are turned off.
  • The tool's configuration profile uses Apple's built-in restriction keys and redirects downloads of every removed model to a local port that is closed, and the request fails.
  • Apps using Apple's Foundation Models framework, the Shortcuts Use Model action, Visual Intelligence and Calendar's natural-language editing all stop working.
  • One revert command restores the previous settings, and macOS fetches the models again when a feature needs them.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Teams whose internal apps or Shortcuts call Apple's on-device models have to choose which features to exempt before running it, or lose that capability on every Mac it touches.
  • constraint A process-list check for Siri cannot confirm the removal worked, because on macOS 27 the Spotlight window runs under the Siri name.
  • cost Backing the change out costs bandwidth: up to about 12 GB per Mac comes back down as features ask for the models again.

Installation is one command, through either a curl installer or Homebrew. The tool runs only on Macs with Apple silicon [4][3]. It lists what is currently on, asks for confirmation, then opens System Settings, where macOS requires the user to approve the configuration profile [5]. On a fleet, that means someone at each machine. The Help Net Security write-up does not cover pushing the profile through MDM [5].

Deletion goes through Apple's asset service [7]. A dry-run mode prints the planned changes without applying them, and a flag keeps specific features on [8]. The default scope is wide. Siri goes, "Hey Siri" and its menu bar icon included, and so do the ChatGPT extension, Image Playground, Genmoji and Writing Tools [9]. Summaries are disabled across Mail, Messages, Safari, Notes and notifications, and the same goes for smart replies in Mail, inline predictive text, Photos Clean Up, Spatial Photos and code completion in Xcode [9].

Dictation keeps working. It is a separate setting, and its speech models stay on disk [11].

For a security team, the risk sits in the install path. A script piped from curl runs with whatever trust the person at the keyboard gives it. According to the developer, the tool makes no network requests and collects no data [14]. The code is MIT-licensed and published on GitHub, so anyone piping the installer from curl can read it first [14][15].

What to watch

  • A documented way to deploy the same restriction keys and port redirect through MDM without a user approving the profile on each Mac.
  • Independent review of the MIT-licensed code on GitHub testing the developer's statement that the tool makes no network requests.
  • A macOS 27 update that adds a single Apple Intelligence switch or changes how models download, either of which would change what the closed-port redirect does.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories