Published Sep 23, 2026 · Updated Sep 24, 2026
Apple has a feature in its phones that it has never told anyone about. It has a name in the code, AutoLock, and one job: notice when an iPhone has been snatched out of a hand, and lock it before the thief gets anything useful out of it.
The interesting part is not the locking. It is the deciding. A phone that locks itself every time it gets jogged, dropped on a couch, or slid across a car seat would be worse than useless. So the code does not lean on one signal. It weighs five, and it lets safeguards outvote the whole thing.
None of this is shipping. The current iOS 27.2 beta carries new references to AutoLock. 9to5Mac read them on September 21, and MacRumors followed with the same code a day later. There is still no setting for it anywhere in Settings.
What the beta actually shows
The code points to a service that runs in the background, watching for the conditions that suggest a theft in progress. In beta 2 that service is switched on. The component that actually locks the iPhone is switched off.
That split is the most informative detail in the whole story. Apple can exercise the detection logic on real devices, with real motion and real connectivity data, without ever locking a phone that did not ask to be locked. It is how you test a theft detector: quietly, on live hardware, with the trigger disconnected.
The name in the code is AutoLock. The code refers to a potential theft signal that can request a lock. Request, not command. That word carries the design.
The five signals AutoLock watches

As 9to5Mac describes it, the detector weighs five separate inputs.
- A sharp acceleration, the kind of movement that looks like a phone pulled hard from a hand rather than carried in a pocket.
- A paired Apple Watch that stays unreachable for a set period.
- A lost connection to that paired Apple Watch.
- Network connectivity that stays gone for longer than expected.
- The device sitting unlocked past a certain interval.
Read that list again and notice how weak each entry is on its own. Phones accelerate sharply when you yank them off a charger. Watches drop out of range when you leave one on the bathroom counter. Networks vanish in elevators, parking garages and basements. A phone left unlocked on a desk is just Tuesday.
Any one of those describes normal life. Together, in the right order, across the right window of time, they describe something else: a phone moving fast, cut off from the watch that would normally vouch for it, off the network, and still unlocked. That combination is close to what a snatch looks like from inside the device.
Splitting the decision across several weak signals is also an answer to the hardest problem in this corner of security. A detector tuned to catch every theft fires on innocent behavior constantly. A detector tuned never to misfire misses the theft it exists for. Pooled weak signals get you out of that trap.
Why the design needs a veto, not just a vote
Signals can request a lock. Safeguards can veto it. That, per 9to5Mac, is how the code is put together, and it is the detail that separates a usable theft detector from a phone that fights its owner.
The vetoes named in the code include a successful biometric authentication, familiar locations (the same idea Stolen Device Protection already leans on), and certain foreground app activity that would otherwise look like evidence the phone had been taken. The code also describes a backoff mechanism that temporarily suppresses automatic locking after repeated lock events, so the phone cannot sit there locking itself in a loop.
Each veto fixes a specific false positive. You unlock with Face ID while walking, and the acceleration reading does not get the last word. Your kid grabs the phone off the kitchen table, and the familiar location blocks the lock. You are filming out of a car window, and foreground activity counts as evidence that a person is deliberately using this device.
The backoff is the tell that someone has thought about this like an engineer. Without it, a misread produces a lock, the lock produces an unlock, and the unlock sets up the next misread. Backoff breaks that cycle.
None of it is proven. A veto list is evidence of intent, not evidence that the false positive rate is low enough for real people.
AutoLock vs Stolen Device Protection

If you own an iPhone, you already have a theft feature. Stolen Device Protection arrived with iOS 17.3, and it is worth understanding before getting excited about AutoLock, because the two defend against different moments.
Stolen Device Protection works on where you are. Apple’s documentation says it adds a layer of security when the iPhone is away from familiar locations such as home or work. Away from those places, stored passwords and credit cards need Face ID or Touch ID with no passcode fallback, and security actions like changing the Apple Account password require an hour-long Security Delay plus a second biometric check. A thief who watched you type your passcode cannot use it to gut your accounts.
AutoLock works on how the phone got there. It is trying to answer a question about physics: did this device leave a hand at speed, away from the watch that normally travels with it? That is the moment Stolen Device Protection never sees, because nobody is changing a password in the first second after a snatch.
Together they cover the two halves of one incident. AutoLock would be the response to the grab. Stolen Device Protection is the reason the grab does not become an account takeover.
They overlap in one place worth naming: both lean on the idea of a familiar location, so both depend on location data being accurate at the moment it matters.
What you can turn on today
AutoLock is not something you can enable. Stolen Device Protection is, and if it has never been switched on, that is a five-minute job worth doing now rather than the week a phone goes missing.
Open Settings, then Face ID & Passcode, then Stolen Device Protection, and turn it on. It needs two-factor authentication on your Apple Account, a device passcode, Face ID or Touch ID, Significant Locations enabled in Location Services, and Find My turned on. Find My cannot be switched off while the feature is active, which is the point of it.
Two settings inside are worth knowing. By default, the stricter behavior applies only when you are away from familiar locations, because Apple assumes the person holding the phone at home is you. You can require the security checks always instead. The stricter of the two is more annoying and more protective, and if you carry sensitive work on a phone, take the annoying one.
Familiar locations fill in over time. Home and work usually show up first, and a week of normal use is typically enough for the list to be useful.
One account level habit beats any single toggle. A password manager means a stolen phone does not automatically mean compromised accounts everywhere, and our picks for the best password manager apps for iPhone split the ones that work offline from the ones that quietly need a server. Anyone carrying client material around, the same logic runs through our security minded app picks for lawyers.
What to expect, and what not to
Nothing is announced. There is no date, and Apple has not commented on the code. The honest reading is that AutoLock is under active development, the detection layer is being exercised on real devices, and the part that would lock your phone is dormant on purpose.
That last detail should temper any excitement about timing. A service running behind a disabled trigger is a long way from a feature with a Settings toggle, a support document and a tested false positive rate. It could arrive in a point release. It could be rebuilt. It could be shelved, and anyone who has watched Apple for a few years knows that happens.
If you are running beta software at all, our walkthrough on how to update to iOS 27 covers the install order and the checks worth doing straight afterward, because the beta track and the stable track ask different things of your backup.
Frequently Asked Questions
Is AutoLock available in iOS 27.2?
Not as a feature you can use. The current iOS 27.2 beta carries references to the service and, per 9to5Mac, runs the detection layer in the background with the locking component disabled. There is no toggle, no support document, and no Apple announcement.
How is AutoLock different from Stolen Device Protection?
Stolen Device Protection reacts to where the phone is, tightening passcode restrictions once you are away from familiar locations. AutoLock is aimed at the instant of the theft itself, using motion, a paired Apple Watch, connectivity and unlocked time. One protects your accounts after a phone is gone. The other is trying to stop the phone being useful in the first place.
Does AutoLock need an Apple Watch?
Not exclusively. Two of the five signals involve a paired Apple Watch that goes unreachable or drops its connection, but the detector also weighs acceleration, network loss and how long the device has been left unlocked. An iPhone with no watch paired can still satisfy some of the conditions.
Will my iPhone lock itself at the gym or in my pocket?
That is exactly what the veto layer exists to prevent. A successful Face ID or Touch ID check, a familiar location, and certain foreground app activity can all override a lock request, and a backoff mechanism suppresses repeated automatic locks. The design goal is a phone that does not fight its owner, but the false positive rate is unproven until real users have it.
When will AutoLock ship?
Unknown, and Apple has said nothing. Code in a beta is intent, not a release plan. Treat any specific date you see online as speculation.
The short version
Apple is building a lock that reads the physics of a snatch rather than waiting for a thief to start acting like one, and it is building it carefully enough that the locking part is switched off while the detection part runs. That restraint is the most encouraging thing in the code.
What you can do tonight is switch on Stolen Device Protection, confirm Find My is on, and make sure that a thief without your accounts is all a thief gets.
Is your app on this list? Add a free "Featured on iOS App Lists" badge to your website or press kit.