On 8 June 2026, Apple announced third-generation Apple Foundation Models, including AFM 3 and ADM 3. Apple disclosed two on-device and three cloud models designed together for text, speech, vision, image generation and agentic tool use.
This release brief was checked against first-party material on 10 August 2026. The date above is the public announcement date, not the date a repository was created or a third-party provider added the model. Where access or weights arrived later, that distinction is recorded below.
Release record
| Field | Verified detail |
|---|---|
| Announcement | 8 June 2026 |
| Availability or weight release | 8 June 2026 in Apple operating-system betas and developer frameworks, with feature availability varying by device and region |
| Release type | proprietary on-device and Private Cloud Compute foundation-model family |
| Access | embedded Apple Intelligence experiences and approved developer frameworks; no downloadable general-purpose weights |
| Architecture | five models spanning a 3B dense core, a 20B sparse on-device model, server PT-MoE models and an image diffusion model |
| Maximum stated context | feature-specific limits; Apple did not publish one family-wide token context maximum |
What changed
AFM 3 is an unusually broad vertically integrated release. AFM 3 Core Advanced stores a 20B sparse model in flash and loads 1B to 4B parameters for a request, while cloud models run through Private Cloud Compute. The family also includes a dedicated image model and a more capable Cloud Pro system. Evaluation therefore has to follow the router and hardware path: a result from one device, locale or cloud tier cannot stand in for the whole family.
The practical comparison is therefore not simply whether third-generation Apple Foundation Models, including AFM 3 and ADM 3 has the largest headline score. Teams need to ask whether its architecture, access terms, latency, tool behaviour and evaluation setup match the workload they actually intend to run. A model can lead one harness while losing on cost, refusal behaviour, multilingual quality or repeatability in another.
Benchmarks worth retaining
| Evaluation | Reported result | How to read it |
|---|---|---|
| AFM 3 Cloud text preference | 64.7% versus 8.7% for the 2025 server model | Apple side-by-side human evaluation |
| AFM 3 Core text preference | 45.6% versus 23.3% for the 2025 on-device model | Aggregate human preference comparison |
| Core Advanced voice MOS | 4.15 versus 3.87 production baseline | Five-point mean-opinion score at 1B active parameters |
These are release-time results, not independently reproduced guarantees. Most results are Apple’s side-by-side human evaluations against its 2025 systems, and beta feature behaviour may change before stable operating-system releases. Scores should remain attached to the disclosed effort setting, agent harness, tool access, timeout, context-management policy and judge model. Moving a number into a procurement sheet without those conditions creates false comparability.
Architecture and access
third-generation Apple Foundation Models, including AFM 3 and ADM 3 is described as five models spanning a 3B dense core, a 20B sparse on-device model, server PT-MoE models and an image diffusion model with feature-specific limits; Apple did not publish one family-wide token context maximum of stated context. Its access position at verification time is embedded Apple Intelligence experiences and approved developer frameworks; no downloadable general-purpose weights. That wording matters: open weights, source-available weights, an API, a product preview and a research demonstration give adopters very different rights and different levels of reproducibility.
Before deployment, record the exact model identifier or checkpoint, inference stack, quantisation, reasoning setting, region, price schedule and supplier terms. If the release uses a custom licence, read the licence itself rather than relying on the word “open” in launch copy. If it is API-only, preserve the dated documentation and change-notice route because the served snapshot can change without a downloadable artefact.
What an evaluation should test next
For third-generation Apple Foundation Models, including AFM 3 and ADM 3, a credible internal gate should include:
- a frozen set of representative tasks with pass, fail and abstain criteria;
- a matched baseline using the same tools, timeout, prompt budget and reviewer rubric;
- repeated runs to expose variance rather than reporting a single best attempt;
- latency, token use and total task cost alongside task success;
- adversarial, multilingual and long-context cases relevant to the real deployment; and
- rollback evidence showing the previous model can be restored safely.
The wider model change-control guide explains how to keep model, prompt, tool and corpus changes reconstructable. The AI dependency inventory guide covers the release and supplier records needed after deployment.
AIEngine verdict
AFM 3 is a major foundation-model announcement even without public weights. Its central engineering claim is privacy-aware routing across device and cloud, which should be tested with network isolation, device coverage and observable fallback behaviour.
This is a launch assessment, not a certification. Benchmark leadership is useful evidence of where to test; it is not authorization to place the model in a high-impact workflow without domain evaluation, security review and an accountable owner.
Primary sources
- Apple AFM 3 research overview
- Apple Foundation Models framework
- Apple Private Cloud Compute security guide
Image provenance
Hero image: Apple Machine Learning Research official artwork. The locally served WebP is a crop of the first-party release or model-card asset recorded in the repository provenance manifest.



