Apple's iOS 27 Can Now Tell You When You're Being Scammed, Mid-Call
Introduction
There is a particular kind of fraud that security engineers have struggled with for years, precisely because it defeats every technical safeguard by design. It is the social engineering scam, where a caller poses as your bank's department, your tax office, or a relative in trouble, and walks you, step by step, into making a payment or changing your own account details. Two-factor authentication does not stop this. Strong passwords do not stop it. The account holder is doing everything correctly, except they have been persuaded to do the wrong thing by someone skilled at sounding legitimate. With iOS 27 and iPadOS 27, released in September 2026, Apple has built a feature aimed specifically at that gap, called Impersonation Risk Detection.
What the feature actually does
The mechanism is narrower and more specific than it might first sound. Impersonation Risk Detection does not run continuously in the background scanning for scam calls the way a caller ID app might. Instead, it activates only when a supported app, not Apple's own apps necessarily, but any third party app that chooses to integrate it, requests a real time risk assessment at the exact moment a user attempts a sensitive action. Apple's own examples are specific: making a payment, changing a password, or modifying other critical account security information.
At that moment, the operating system runs an on-device analysis built on what Apple calls its Trust Insights framework. It draws on device use patterns, including the approximate number of recent phone calls and emails, Apple Account information such as app download and purchase history, and what Apple describes as interaction patterns, timing, context and basic sensor data. Crucially, Apple has been explicit that the system does not read the contents of Photos, Messages or Mail, and it does not examine the actual point of intrusion, meaning it cannot tell you whether the phone call you are currently on is itself fraudulent. What it is assessing, instead, is whether the pattern of behaviour surrounding this specific sensitive action looks statistically consistent with how a genuine user behaves, or with the pressured, rushed, coached pattern typical of someone being actively scammed.
The output is deliberately minimal. The requesting app receives only one of three labels, unknown, medium or high risk, never the underlying data that produced it. An "unknown" rating means no suspicious signs were detected, though Apple is careful to note this does not confirm the action is actually safe, only that nothing suspicious surfaced. Apple itself never sees the underlying device data used to generate the assessment either, though it does learn what type of action triggered the request in the first place. What the app then does with that risk label, whether to add a waiting period, prompt identity verification, or display an outright warning, is left entirely to the app's own design, not dictated by Apple.
Why the defaults and the fine print matter
Two details in how Apple shipped this feature are worth paying close attention to, because they reveal a lot about the threat model Apple was actually designing against. First, the feature is off by default. Users must manually navigate to Settings, then Privacy & Security, then Impersonation Risk Detection, and toggle on Share with App Developers, often requiring an Apple Account sign-in to activate. Second, and more tellingly, Apple built in a mandatory 24 hour delay before the toggle, once enabled, can actually be switched off. Apple's own guidance states plainly that if someone contacts you and insists you turn this feature off, treat that as a red flag. That is not a generic privacy disclaimer. It is Apple directly anticipating that scammers, once this feature becomes widely known, will start coaching victims to disable it mid-call, and designing a specific friction point to blunt exactly that manipulation.
Apps that have requested an assessment appear under a Recent Activity log, where users can review the specific actions that triggered each request and revoke access app by app, through a section Apple labels Reasons for Access. As of launch, Apple has not published a list of which apps actually support the feature, meaning its real world usefulness depends entirely on third party developers choosing to integrate it, something Apple cannot mandate.
How this compares to what Google has shipped earlier
Apple is not the first to market here, and the framing in early coverage of this feature, "it was just a matter of time," reflects that fairly accurately. Google began rolling out Scam Detection on Pixel phones in beta in late 2024, expanding it through 2025 using its on-device Gemini Nano model to analyse both phone calls and text messages in real time. The approaches differ in a meaningful way, though. Google's feature listens to an entire live conversation for scam-like conversational patterns, playing an audible beep at the start of a monitored call so both parties know AI analysis is active, and can interrupt mid-call with a warning. Apple's feature does not listen to anything resembling the call itself; it evaluates behavioural and account signals around a specific sensitive action a user is about to take, regardless of whether that action was prompted by a phone call, a text, or an email. Google's model is built around catching the scam as it happens in conversation; Apple's is built around catching the moment the user is about to act, irrespective of the channel that pressured them there. Both are opt-in or off by default, and both emphasise on-device processing and limited data sharing, reflecting a shared industry recognition that scam detection tools built on reading private conversations need unusually strong privacy guarantees to earn user trust.
Why this matters well beyond the US
Google has already signalled that it sees markets like India as a genuine proving ground for this category of tool, having launched Pixel-based scam detection there in November 2025 specifically citing the scale of digital fraud losses in the country, alongside partnerships with Indian financial apps including Google Pay, Paytm and Navi to warn users during risky screen-sharing sessions, a common vector in Indian banking fraud. That context matters for Apple's rollout too. Social engineering scams impersonating banks, government tax departments and law enforcement are a dominant and rapidly growing fraud category across much of Asia, and a feature that specifically targets the moment someone is being walked through a fraudulent payment, rather than relying on the victim recognising the scam themselves, addresses exactly the mechanism that most existing fraud prevention tools miss.
The honest limitation
Apple has been careful, in its own language, to frame this as a supplementary safeguard rather than a complete solution to telecom and online fraud, and that caution lines up with what the broader behavioural analytics industry has already learned the hard way. The feature depends entirely on third party app adoption that has not yet been detailed, it is switched off by default so most users will never encounter it without deliberately enabling it, and an "unknown" risk rating explicitly does not mean an action is safe, only that nothing suspicious happened to surface.
The deeper issue is one every company working on behavioural fraud detection has run into before Apple did: these systems are only as reliable as the baseline of "normal" behaviour they are measuring against, and that baseline is not stable across every type of user. Industry data on behavioural biometrics, the broader category of technology Apple's system belongs to, puts typical false positive rates for flagging new device, location, or timing combinations in the range of 15 to 25 percent before careful tuning, and practitioners in the field note that elderly users in particular tend to show higher variance in their interaction patterns, which makes them statistically harder for these models to read correctly, not easier, despite being exactly the population most targeted by impersonation scams in the first place. The risk is not hypothetical or confined to finance. In eldercare technology more broadly, a documented case from a California pilot programme saw a fall detection system switched off entirely after it generated so many false alarms that it triggered repeated, unwanted social service visits to an older adult's home, a clear illustration of what happens when a protective automated system cannot adequately account for the exact population it was built to protect.
Apple has not published performance data on how Impersonation Risk Detection behaves across these edge cases, new phones, irregular usage patterns, older users less familiar with typical app behaviour, and that silence is worth noting rather than assuming away. What Impersonation Risk Detection represents is not a solved problem, but a genuine, technically serious first attempt by a major platform to intervene at the exact moment social engineering scams succeed, the point of action, rather than relying on users to have correctly identified the deception several steps earlier. Whether it meaningfully reduces fraud losses at scale will depend less on the underlying design, which appears carefully thought through, and more on two things outside Apple's direct control: how many developers actually build it into the apps people use for banking and account security, and how well the system holds up for exactly the users who need it most.
References
- Help Net Security, "Apple's new iOS 27 feature looks for signs you're being scammed." https://www.helpnetsecurity.com/2026/09/24/apple-ios-27-impersonation-risk-detection/
- 9to5Mac, "iOS 27 adds scam-prevention feature to iPhone, here's how to enable it." https://9to5mac.com/2026/09/16/ios-27-adds-scam-prevention-feature-to-iphone-heres-how-to-enable-it/
- 9to5Mac, "Security Bite: iOS 27 now lets apps ask your iPhone if you're being scammed." https://9to5mac.com/2026/09/21/security-bite-ios-27-now-lets-apps-ask-your-iphone-if-youre-being-scammed/
- Engadget, "Apple's new iPhone and iPad security feature can protect you from scammers." https://www.engadget.com/2271157/apple-iphone-ipad-impersonator-risk-detection-new-security-feature/
- gHacks Tech News, "iOS 27 Adds Impersonation Risk Detection to Help Protect Against Social Engineering Scams." https://www.ghacks.net/2026/09/21/ios-27-adds-impersonation-risk-detection-to-help-protect-against-social-engineering-scams/
- BigGo Finance, "Apple Rolls Out On-Device Scam Detection in iOS 27 Ahead of High-Risk Transactions." https://finance.biggo.com/news/89a0ae92-1603-4ac9-aef9-b8b466e6ac40
- MacObserver, "iOS 27 Impersonation Risk Detection: How Apple's anti-scam setting works." https://www.macobserver.com/news/ios-27-impersonation-risk-detection-anti-scam-setting/
- Google Blog, "New AI-Powered Scam Detection Features to Help Protect You on Android." https://blog.google/security/new-ai-powered-scam-detection-features/
- Digital Trends, "Google Pixel 9 is getting a scam detection upgrade you'll want on your phone." https://www.digitaltrends.com/phones/google-pixel-scam-detection-gemini-nano-ai-calls-messages-safety/
- Gulf News, "Google ramps up AI scam protection in India." https://gulfnews.com/technology/media/google-ramps-up-ai-scam-protection-in-india-1.500355149









