r/iOSProgramming 2d ago

Question Xcode 27 agentic coding security

Has anyone been using the new agentic coding features in Xcode 27?

Im still wrapping my head around AI tools as of this year as it had been made a requirement at my job. The industry is moving in this direction whether I like it or not.

Since being laid off Ive been trying to learn more about using these tools effectively in my free time.

Had an experience at work where Claude CLI decided to completely ignore directions to not leave a certain project folder. Since then I am VERY apprehensive about using it on a personal machine. I don't trust them to be frank. Im using Claude Code/ Codex on the web and they're fine for the most part.

Is adding an agent via Xcode 27's Intelligence features the same as installing the CLI or desktop version of these things? Or is it a more restricted approach?

3 Upvotes

9 comments sorted by

9

u/[deleted] 2d ago

[deleted]

3

u/code_isLife 2d ago

Ok. Data sent to them I completely understand. Just worried that it will end up poking around my Mac of its own volition again.

I see why people buy Mac mini’s for this type of thing (if a bit excessive).

I’ve got an older MacBook I might wipe and try to use as a server

0

u/ElectricKoolAid1969 1d ago

What do you mean "again"?

1

u/code_isLife 1d ago

I described the situation in my post.

2

u/caguilar51 2d ago

Yes, it works the same way as their CLI or desktop counterparts with the difference that configuration lives inside an Xcode Folder and it won’t take the one on your user directory. So… you might have to configure it twice

2

u/TeeDee144 2d ago

Basically if you are using a consumer account/license, you should expect very little to no privacy. Nearly all ai providers are training their data on you and how you interact with their models.

Now if you have an enterprise contract, like copilot for work/school, that has a strict policy that prevents training and you’re operating in more of a container.

0

u/ElectricKoolAid1969 1d ago

Isn't AI learning how you want to interact with it over time a good feature in many ways?

0

u/TeeDee144 1d ago

For personal use, maybe, if you knowingly and willingly agree to it.

For enterprise use, you don’t want your employees feeding company secrets, client data, or other sensitive information into a model that can improve/maybe help your competitors. The only way right now to use AI in a secure/privacy respected manor for enterprise is to have a contract with the AI provider that runs your info in a personalized secure environment that will not leak into their broader models.

My sister in law is using a 3rd party physical AI device that listens and records her work meetings. Makes notes and action items out of it. But she’s a federal gov health contract worker. Some 3rd party company is now gaining access to very private and maybe even medical discussions breaking HIPPA. Companies like Teams and Slack though offer these features built into the meeting software and will not use the data to train. It’s a fireable offense IMO but she’s also an idiot so it’s par for the course.

0

u/ElectricKoolAid1969 1d ago

I don't trust them to be Frank either!

Alfred maybe, but not Frank.