With iOS 27, the Passwords app becomes agentic: change compromised passwords without manual intervention
With iOS 27, Apple brings agentic artificial intelligence directly into credential management. The new feature integrated into the Passwords app uses Apple Intelligence and Safari to navigate websites, access accounts, and autonomously update weak or compromised passwords, all with a single tap from the user.
The functionality is described in Apple's announcement: the system "navigates agentically on behalf of the user, accesses accounts, and updates them with secure passwords." This is not about filling out a suggested form: Passwords executes the entire sequence of login and credential modification without further manual intervention. The newly generated passwords are saved in the iCloud Keychain and synchronized across devices and apps.
Permissions and management of two-factor authentication
Before acting, the feature requires explicit user consent. If two-factor authentication is enabled on accounts, the system also asks for temporary permission to access one-time verification codes found in Messages or Mail, allowing the entire password change flow to be completed without getting stuck on the second factor.
Under the hood, the feature relies on next-generation Apple Foundation Models, executed partly locally on the device and partly on Private Cloud Compute. Apple has developed these models in collaboration with Google and Gemini.
Availability
The feature is available in beta for developers starting June 2026 and will reach the general public with iOS 27 in the fall. The automation of password management and the rotation of potentially compromised credentials seems to be one of the most concrete agentic applications presented at WWDC 2026, precisely because it addresses a real problem that nearly all users tend to overlook: old, weak, or already exposed passwords that remain active for years.