What is causing the elevated Static AI false positive alerts on macOS, and what is Sentinel One doing to fix it?
SentinelOne is aware of increased Static AI false positive alerts triggering on legitimate macOS system processes following the July 27, 2026, macOS Tahoe 26.6 update. A multi-stage fix is in progress, including:
In the interim, if you have upgraded or plan to upgrade to macOS Tahoe 26.6 in the near term, it is recommended that you apply the Policy Override (PO) to avoid potential false positives and disruption to your environment.
Policy Override in the Management Console overrides a default option in the Agent configuration. You can send a Policy Override to a Site, to an Account, or to Global. The Policy Override page is available for users with the edit Policy role permission. Advanced Mode is not required.
|
⚠ Important
|
Account and Global users can do this task
From Platform version W SP1, Policy Override configurations now have an Expand option to see the configuration settings more clearly. This shows as a toggle at the top of the Policy Override window.

|
Field |
Description |
|
Configuration Name |
Name of the policy override as an asset. |
|
Platform |
Select the OS of the Agent configuration to change. |
|
Version |
Enter the build number of the Agent, in the format XX.X.X.XXX, or select All. Policy overrides are defined for a specific build number OR for ALL Agents. When you upgrade or add Agents with a different build number, duplicate each policy override that is for a specific version, or change the override to apply to all Agents. |
|
Description |
Explain the change and the reason. |
|
Access Level |
|

If the parameters to change are in a hierarchy, make sure you include the parent key and enclose the child parameters and the parent properly:

When Agents are upgraded, or new Agents of a different version are added to the environment, you must configure the policy override for the new Agent Version. When a package with a new Agent is added to your Management Console:
|
Note: There are different ways to change Agent configuration. See the Agent Configuration Hierarchy to learn more. Some configuration changes are only available through Sentinelctl and NOT through Policy Override. In the SentinelCTL documentation, commands that show Agent Configuration JSON syntax are available in Policy Override. See Advanced: Changing Agent Configuration Manually to change the configuration for one or more selected Agents and not a whole group. |