A quiet policy change with a very real rejection risk
If you’ve submitted an app to the App Store recently without reading the review guidelines line by line, there’s a real chance you’re not compliant with the new App Store AI disclosure rules. This isn’t a future proposal – it’s live, it’s checked during review, and Apple has confirmed apps can be removed post-approval if they’re later found non-compliant.
What actually needs disclosing
Two distinct things are covered, and it’s worth separating them because the obligations differ:
- AI-generated content shown to users. If your app generates or displays AI-generated content in any form – text, images, summaries, recommendations – you need a clear, user-facing disclosure. This isn’t satisfied by a line in your privacy policy; Apple expects it to be visible in the actual interaction, typically via an in-app notice or prompt at the relevant point.
- Sharing user data with third-party AI systems. If your app sends any user data to an external AI provider – for processing, personalisation, or anything else – you must disclose which AI service is used and what data is shared, and get clear user permission before that sharing happens. A vague “we may use AI” clause in a EULA doesn’t meet this bar.
Why “identifiable user information” is the phrase to pay attention to
The requirement is strictest where personally identifiable data is involved. If your third-party AI integration only touches genuinely anonymous, non-identifying inputs, your obligations are lighter – but most real integrations (chat features, personalised recommendations, anything tied to a user account) don’t clear that bar. Treat “does this touch anything identifiable” as your first filter when auditing existing AI features against the App Store AI disclosure rules.
Practical steps before your next submission
- Inventory every AI feature in your app – both content you generate and any call out to a third-party AI API – and note what data each one touches
- Add an explicit in-app disclosure at the point of interaction for anything user-facing and AI-generated, not buried in settings or a legal document
- For third-party AI calls involving user data, implement an actual permission flow that names the AI service and the data being shared, and gate the feature behind that permission
- Re-check your privacy nutrition label in App Store Connect – it needs to reflect any AI data sharing accurately, not just your general data practices
- Document your compliance decisions before submitting, since removal after approval is explicitly on the table if a later audit disagrees with your read of “identifiable”
Where this sits alongside the rest of September 2026’s App Store changes
This lands in the same window as another procedural tightening: from September 2026, Apple requires an explicit response or attestation when submitting new apps or updates, and when notarising apps for alternative distribution. Neither change is a huge engineering lift on its own, but both are exactly the kind of thing that causes an otherwise-ready submission to bounce in review if you haven’t budgeted time for them.
The bigger picture
Apple clamping down here fits a pattern that’s shown up across the industry through 2026: platforms are moving from “AI features are novel, disclose loosely if at all” to treating AI transparency as a hard compliance requirement, not a nice-to-have. If you’re building or maintaining an iOS app with any AI surface area at all, this is worth a dedicated review pass rather than something you patch reactively after a rejection – the cost of getting it wrong now includes losing an already-approved app, not just a delayed launch.

Leave a Reply
You must be logged in to post a comment.