OpenAI has released a plugin for Apple Messages that lets users connect ChatGPT to the messaging service. The trouble is, it only needs one party in the conversation to opt in, and the AI has access to what everyone said.
The plugin went live on August 20, giving the chatbot the ability to read and search conversations, summarize recent chats, draft replies, and send messages via the Messages app on a Mac.
Users on all ChatGPT plans can access the plugin through the ChatGPT desktop app for macOS. OpenAI says it can be used in ChatGPT Work and Codex. The plugin works with iMessage, SMS, and RCS conversations on Apple silicon Macs.
In a post on X, OpenAI showed off several use cases for the new plugin, including using it to find birthdays, identify messages that need follow-ups, spot potential spam, or check a calendar and reply to someone with times you’re free.
Everyday conversations just got easier with the new Apple Messages plugin.
Search messages, catch up on conversations, draft and send replies—all with ChatGPT on your Mac. Now available in ChatGPT Work and Codex on desktop. pic.twitter.com/nicfZMuxZc — ChatGPT (@ChatGPT) August 20, 2026
As with many AI workflows, those shortcuts could certainly save people time. However, the privacy implications don’t end at the keyboard of the person who decides to install the plugin.
Conversations, by definition, involve more than one person, and the plugin gives one person the power to share words written by friends, relatives, coworkers, or anyone else they text with the AI chatbot.
Apple has made privacy a core part of its brand over the years, and many people choose iMessage because it uses end-to-end encryption. However, that protection has a limit.
Once a message reaches the recipient’s device and can be read there, end-to-end encryption doesn’t prevent that person from letting another app access it. That means the person you’re talking to can invite AI into your private conversation without you having any idea.
End-to-End Encryption Has Limits After a Message Arrives
Apple says iMessage uses end-to-end encryption, meaning only the sender and receiver can access a message’s content as it travels between devices. Not even Apple can decrypt the messages on its own. RCS conversations can also use end-to-end encryption, but SMS and MMS don’t.
The ChatGPT plugin won’t break iMessage’s encryption. Instead, the person on the receiving end of a message can grant ChatGPT access to the conversation on a Mac where the message is already readable.
Security and privacy expert Paul Walsh argues that this raises serious privacy concerns for people who choose an encrypted messaging service because they believe the conversation will stay between its participants
🛑 Do not add the ChatGPT Messages “plugin” to Apple Messages. And never use iMessage, SMS or RCS again. You’ll never know if the person you’re texting has been stupid and irresponsible enough to add this silent monitoring bot to your conversation. Governments no longer need to… https://t.co/xZ71OfD1Pz
— Paul Walsh (@Paul__Walsh) August 22, 2026
“This integration trades other people’s privacy for one person’s convenience,” Walsh wrote in a scathing critique of the plugin in an article on Substack.
Walsh, founder of security company MetaCert, was open about having a commercial interest in privacy-focused messaging.
One user on X went even further, warning that AI companies could end up “crawling through” years of personal messages.
OpenAI told TechCrunch that enabling the plugin doesn’t cause ChatGPT to catalog a user’s entire Messages history. Instead, doing so allows the chatbot to access messages when a user asks it to perform a task. OpenAI also says content from Messages that ChatGPT processes stays on the Mac by default and isn’t saved to its servers. However, users can choose to save that content to the cloud.
Even with OpenAI’s clarifications, it’s important to point out that users still have to give ChatGPT a great deal of access if they want to use the plugin. TechCrunch reports that the setup requires giving the ChatGPT desktop app Full Disk Access on a Mac.
Apple’s own support documentation says that the permission can grant an app access to all files on a Mac, including data from Messages, Mail, Safari, Home, Time Machine backups, and some administrative settings.
Permission to access those files doesn’t mean ChatGPT is reading all of them. But as a consumer, you still need to decide whether granting that level of access to a chatbot is worth it.
One Person Can Give ChatGPT Access to a Shared Conversation
Deciding for yourself whether to give ChatGPT extensive access to your personal data is only one part of the equation. You can’t control what the people you chat with decide to do with your messages.
And that’s the biggest part of the privacy question: how does consent work in a shared conversation when only one person has to decide whether AI gets access?
A family member may send something personal. A coworker may share information in a group chat. A source may speak to a journalist via iMessage because they believe the service’s encryption will protect the conversation as it travels between them.
If the person receiving those messages later asks ChatGPT to search for or summarize them, the sender isn’t asked for approval and may not even know the plugin is being used.
Of course, recipients have long been able to screenshot, forward, copy, or search messages themselves. However, AI changes the amount of work required. All a user has to do is ask ChatGPT to find information in old messages, summarize conversations, or pull details from messages. They can do all of this without manually going through each message thread.
The same tool that can help you find a forgotten birthday or missed follow-up can also search and analyze years of personal conversations.
Walsh says the risks are especially serious for people like whistleblowers, journalists, sources, lawyers, doctors, activists, and others who may rely heavily on private communications.
The issue isn’t whether people can completely control what happens after someone receives a message. Clearly, that’s not possible. The difference is how easily AI can turn a private chat into something that can be searched and analyzed on demand.
ChatGPT Can Go From Reading Messages to Sending Them
ChatGPT can do more than just read your messages; it can also write them for you and send replies on your behalf.
With ChatGPT’s default permission setting, you have to approve both the message and who it’s going to before anything is sent. You can approve a message once, or choose “Always allow sending to this chat” if you want to let ChatGPT handle future replies automatically. If you select that option, you won’t have to approve later messages sent to that conversation.
That change moves the chatbot from finding information inside personal conversations to participating in them. Checking a calendar and telling a friend when you’re free may be a small task, but the same system can increasingly make decisions across apps and communicate the result in your name.
The privacy question isn’t just about whether you personally decide to trust ChatGPT with your messages. As we give AI assistants greater access to the apps we use to communicate, we should also consider what that means for everyone on the other end of the conversation.
Originally published by Techopedia on August 24, 2026.