Apple has delivered a great new security feature with iOS 27 and iPadOS 27, though it's not one that made headlines. Called Impersonation Risk Detection, it analyzes device behavior in real-time to flag active social engineering scams — the kind that trick you into handing over access yourself, even when your passwords and two-factor codes are working as intended. It runs entirely on-device, so Apple never sees your photos, texts or any other personal content.
When a supported app requests a risk assessment, it receives a label with none of the underlying data behind that determination. This is an opt-in feature, making it a complementary tool to all the other steps you take to be safe online. Security features like two-factor authentication are great, but Impersonation Risk Detection is built for a different kind of danger. Social engineering scams don't force their way through your defenses, but rather convince you to open the door yourself.
Impersonation Risk Detection works to detect the signs of a scam as it's happening. When you take a sensitive action, such as making a payment or changing account security details, a supporting app can request a real-time risk assessment. Your phone generates that assessment by analyzing interaction patterns, timing, context and basic sensor data, which all runs on-device. Based on this analysis, the system assigns one of three risk levels: Unknown, Medium, or High.
To enable this function, go to Settings > Privacy & Security, scroll down to Impersonation Risk Detection, and toggle on Share with App Developers. Apple also mentions that if someone contacts you and insists you turn this feature off, you should treat it as a red flag. Toggling the feature off can take up to 24 hours to take effect. This feature only works with apps that are built to support it, and Apple hasn't published a list of them yet.