Open-Source RemoveMacAI Deletes macOS 27's Apple Intelligence Models With SIP Still On
TL;DR
RemoveMacAI is an MIT-licensed command-line tool that turns off Apple Intelligence on macOS 27, deletes the on-device models, and stops macOS from downloading them again. It never touches System Integrity Protection (SIP). It asks Apple's own asset daemon to delete the files, then installs a configuration profile that points future model downloads at a dead local port. The repo is six days old, has about 800 GitHub stars, and drew 537 points and more than 350 comments on Hacker News on Sunday. The mechanism was mapped a week earlier by a quieter project called pared, which RemoveMacAI credits and which has 32 stars.
The problem: models you can't decline
Using Apple Intelligence on macOS 27 is optional. Storing it is not. MacRumors reported on September 23 that Apple removed the toggle that used to disable Apple Intelligence in macOS 27 and iOS 27, so the models download whether you use them or not.
Apple's support document says the features need up to 14 GB of storage on Macs with an M3 or later and at least 12 GB of unified memory, and up to 8 GB on other supported Macs. The Storage pane in System Settings often shows more. MacRumors saw 20.67 GB on an M4 Pro Mac mini, cites an Ars Technica reading of 22.42 GB on an M3 MacBook Air, and points to a Reddit screenshot showing 30.16 GB on the release candidate.
Treat the Storage pane as a rough guide. MacDailyNews relays an AppleInsider test in which deleting the main model folder from Recovery took the pane's figure from 27.59 GB to 3.07 GB, while free space rose by about 14 GB. On a 256 GB Mac that is still a real slice of the disk.
The mainstream advice so far has been to leave it alone. Tom's Guide told readers on September 22 to let macOS manage the assets "rather than trying to rip them out yourself."
What RemoveMacAI does
You run one command, confirm, and approve one profile in System Settings (macOS requires that click). The tool then:
- Turns off 14 features: Siri, the ChatGPT extension, Writing Tools, Genmoji, Image Playground, summaries in Mail, Messages, Safari, Notes and notifications, inline text predictions, Spatial Photos, Photos Clean Up, and Xcode predictive code completion.
- Removes five model sets: the Apple Intelligence foundation models, the image and Genmoji models, and the models for Spatial Photos, Photos Clean Up, and Xcode code completion.
- Blocks re-downloads for every set it removed.
Install is a curl | bash one-liner that runs the binary from a temporary directory, or a Homebrew tap. removemacai status lists each feature and the size of the models on disk, off --dry-run previews the changes, off --keep <features> spares the ones you use, and revert undoes everything. It supports Apple silicon on macOS 27 only.
One thing it cannot remove: a process named Siri keeps running, because in macOS 27 the Spotlight window runs under that name. You can evict the models, but the name stays on the lease.
How it deletes SIP-protected files with SIP on
The model files are protected, which is why earlier tools took the hard road. pared's README lists three: Unintelligence and Apple Intelligence Remover fall back to Recovery for protected models, and the Delete Apple Intelligence guide has you temporarily disable SIP. RemoveMacAI does neither. It works in three moves.
1. A profile flips Apple's own switches
The tool generates a configuration profile using the restriction keys Apple documents for device management, such as allowWritingTools, allowGenmoji, allowImagePlayground, and allowExternalIntelligenceIntegrations. Features with no restriction key, like notification summaries and inline predictions, get a forced preference instead. It is the same machinery an IT department uses on a managed fleet, applied by you to your own Mac.
2. Apple's daemon does the deleting
The tool loads Apple's private UnifiedAssetFramework, opens an XPC connection to com.apple.siri.uaf.subscription.service, and sends a reset request naming the model sets to drop:
{
"Operation": "ResetAssetSets",
"AssetSets": ["com.apple.modelcatalog"]
}
Apple's daemon holds the entitlements needed to remove protected assets, so SIP never has to come off. Think of it as filing a work order with the building's janitor instead of picking the storeroom lock: the person with the keys does the job, and the lock stays intact. pared's documentation adds one sharp warning: the AssetSets list must always be explicit, because omitting it means every asset set.
3. Downloads get pointed at a dead port
For each removed set, the profile sets DownloadServerBaseURLOverride-<assetType> in the com.apple.MobileAsset domain to a URL on 127.0.0.1:9. Port 9 is the old discard port and the README describes it as closed, so the download fails instead of refilling the disk. pared's README explains why this needs a profile: mobileassetd reads the setting from managed preferences, and its sandbox denies ordinary system defaults.
The 32-star project underneath
RemoveMacAI is upfront about where the hard part came from. Its README, source comments, and third-party notices all credit pared, by a developer who goes by 4evy, as the tool that "first mapped the asset service, the model sets and several of the settings keys." pared's repo dates to September 22. RemoveMacAI's first public release came on September 29.
pared is the more configurable tool: a 21-feature catalog, a per-feature policy, and modules for nix-darwin and Home Manager. It also asks more of you. Its Homebrew install requires Xcode 27, and policy, profile, and cleanup are separate steps. RemoveMacAI, by Om Lahore, is one command with a prebuilt binary.
The reverse engineering has 32 stars. The one-liner has about 800. Distribution remains undefeated.
Caveats before you run it
- It depends on private Apple internals. A private framework and an undocumented XPC service can change in any update. It has already broken once: on some Macs, including those on macOS 27.0.1, the per-set status reported 0 for installed models, so
offremoved nothing until version 0.2.3 switched to the asset service's inventory. The changelog shows five releases since September 29. - The restriction keys are deprecated. Apple's documentation marks keys like
allowWritingToolsandallowGenmojias deprecated from macOS 26.4 in favor of declarative device management. The project says it is tested on 27.0. Deprecated is not removed, but plan for it. - Free space does not come back instantly. The README says the asset service releases the models right away, but macOS deletes the files on its own schedule, and the Storage pane keeps counting them until then. The project publishes no savings figure.
removemacai statusshows yours. - Things break on purpose. Apps that use Apple's on-device models through the Foundation Models framework, the Use Model action in Shortcuts, Visual Intelligence, and natural-language editing in Calendar all stop working. Dictation keeps working.
- Read before you pipe. A recurring complaint on Hacker News was the
curl | bashinstall, and you are also approving a system-scope profile from a days-old repo. The installer verifies a SHA-256 checksum, but that checksum comes from the same release as the binary, so it catches a corrupted download and not a tampered release. Since 0.2.3, releases also carry a GitHub build provenance attestation that ties the binary to the public source at its tag, and--dry-runwrites out the profile so you can inspect it before installing anything.
Why builders should care
Two things here outlast the tool.
An on-device model is no longer a safe assumption on the Mac. If you ship on the Foundation Models framework, some of your users will now have no model at all, by choice, behind a profile that blocks the download. Check availability and degrade gracefully instead of assuming every Apple silicon Mac on macOS 27 has one.
The polite route beat the forceful one. Earlier approaches attacked the files with Recovery scripts and disabled SIP. pared found the request the system already honors and got a cleaner result with the security model intact. When a platform locks something down, look for the daemon that is allowed to do the job, and ask it.
Key Takeaways
- RemoveMacAI (MIT) turns off 14 Apple Intelligence features on macOS 27, removes five model sets, and blocks their re-download. One command reverts it.
- SIP stays on because Apple's own asset daemon performs the delete, triggered by a
ResetAssetSetsrequest over XPC. - A configuration profile redirects model downloads to
127.0.0.1:9through a MobileAsset override key, so the models do not come back. - The mechanism was mapped by pared (32 stars). The one-command tool built on it has about 800 stars and 537 Hacker News points.
- It relies on a private framework and deprecated restriction keys, and it already needed a fix for macOS 27.0.1.
- Mac developers building on the Foundation Models framework should handle the model being absent.
Sources: RemoveMacAI on GitHub, RemoveMacAI changelog, RemoveMacAI third-party notices, pared on GitHub, Hacker News discussion, MacRumors, Apple support: Apple Intelligence requirements, Apple device management restrictions, MacDailyNews, Tom's Guide