Apple is rolling out new Siri Audio Intelligence features that listen to your surroundings, and it wants you to know it can’t hear what you’re saying.
At Wednesday’s iPhone Duo launch event, the company announced Siri Recap, Live Rewind, Sound Recognition, and Music Recognition. Alongside the announcement, Apple released a document explaining how it plans to balance AI “ambient listening” with user privacy. The company says raw audio from the new features “is handled within dedicated hardware, is not saved as a file, and is not accessible to the operating system, apps, or Apple.”
The Secure Exclave and the S11 Chip
The privacy promise rests on a piece of hardware called the Secure Exclave. It’s a hardware-isolated compartment built into the S11 chip, the processor that powers the new Apple Watch Series 12 and Apple Watch Ultra 4.
The S11 chip’s Secure Exclave processes sensor data separately from the rest of the system. Apple says data processed there cannot be accessed by watchOS, apps, the user, or Apple itself. Audio from the microphone enters the Secure Exclave, where it is initially processed for speech, sounds, or music. The company says this happens “without transcribing or storing the raw audio.”
That buffer is a continuously overwritten stream that exists only within the protected hardware and never creates an audio recording.
What the Four Features Do
The four new features each use the microphone in different ways. Apple’s document does not describe what Siri Recap or Live Rewind actually do beyond their names. Based on the names alone, Sound Recognition appears to identify sounds and Music Recognition appears to identify music, but the document does not detail how either is turned on.
Apple says users control “whether and when” Audio Intelligence features are active. Live Rewind is the clearest example: it requires users to double-tap the Digital Crown every time they want to activate it. The double-tap starts the feature, though the document describes a continuously overwritten audio buffer in the Secure Exclave, which implies the microphone processes audio on an ongoing basis.
When Data Leaves the Watch
Some Audio Intelligence features need to transfer information to your iPhone. Apple says that when this happens, the transfer is encrypted through both devices’ Secure Exclaves. Users also choose what text to keep from Siri Recap and Live Rewind.
Text from Audio Intelligence will sync with end-to-end encryption if you have a device passcode and use iCloud’s two-factor authentication.
What Apple Is Promising
The document is notable for how absolute its language is. Apple isn’t saying it limits access to raw audio — it’s saying the company cannot access it at all. The Secure Exclave is a physical barrier, not a policy.
That distinction matters. A policy can change; a hardware design is much harder to alter. If the Secure Exclave works as described, there is no raw audio file to subpoena, hack, or leak.
Apple’s promise covers the entire chain of audio handling. The microphone captures sound, the Secure Exclave processes it, and the buffer overwrites itself continuously. At no point in that chain does a recording exist. The company also says the raw audio “is not accessible to the operating system, apps, or Apple,” which closes off the software routes that might otherwise expose the data.
| Feature | What the Document Says | How It’s Turned On | Where Processing Happens |
|---|---|---|---|
| Siri Recap | Not described in the document | Not specified in the document | Secure Exclave on S11 chip* |
| Live Rewind | Not described in the document | Double-tap Digital Crown | Secure Exclave on S11 chip* |
| Sound Recognition | Not described in detail in the document | Not specified in the document | Secure Exclave on S11 chip* |
| Music Recognition | Not described in detail in the document | Not specified in the document | Secure Exclave on S11 chip* |
*Apple’s general description of Audio Intelligence ties processing to the Secure Exclave; the document does not confirm each feature individually.
The Limits of the Promise
Apple’s document describes what happens inside the watch, but it doesn’t address every scenario. The company says audio from the microphone enters the Secure Exclave “where it is initially processed.” The word “initially” leaves room for later steps, but the document as quoted does not say what those steps are or where they occur.
The company also notes that users choose what text to keep. That means some text derived from audio does exist outside the Secure Exclave — the encrypted text that syncs to iCloud. Apple says this text is protected by end-to-end encryption.
The document does not say what happens to that text if a user does not have a passcode or does not use iCloud’s two-factor authentication. It also does not say whether the text is stored on Apple’s servers, on the user’s devices, or both. Those questions remain unanswered.
Why This Matters
Ambient listening features have always raised privacy questions. A microphone that’s always on is a microphone that could be recording. Apple’s answer is to make recording physically impossible by design.
The Secure Exclave approach is a continuation of Apple’s broader privacy strategy. The company has spent years marketing privacy as a core feature of its products, and the S11 chip’s design extends that promise to always-on audio processing.
Apple is also making a competitive claim here. The document positions the Secure Exclave as a hardware-level guarantee rather than a software policy. The document does not compare Apple’s approach to any other company’s.
What Users Should Know
The practical takeaway is simple: the new Audio Intelligence features are opt-in, and the raw audio never becomes a file. Live Rewind requires an explicit double-tap every time. The recognition features are user-controlled, though the document does not specify exactly how.
If you have a passcode and iCloud two-factor authentication enabled, any text derived from Audio Intelligence is end-to-end encrypted.
Apple’s document is worth reading in full. It’s a rare, detailed look at how a major tech company handles one of the most sensitive types of data there is: the sound of your life.
The company is asking users to trust that its hardware does what it says. For now, that’s the best anyone can offer.
Source: theverge.com
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

