
TLDR
OpenAI's Apple Messages plugin lets ChatGPT read, search and send iMessages, SMS and RCS on Apple silicon Macs, with message content subject to model training by default. Privacy researcher Paul Walsh says it exposes third-party participants without consent.
KEY TAKEAWAYS
What the plugin does
Most users will enable this without reading the fine print, and that is the problem. OpenAI released the Apple Messages plugin for the ChatGPT desktop app on 20 August 2026, giving the AI the ability to read, search and send iMessages, SMS and RCS conversations on Apple silicon Macs.[1] Intel-based Macs are excluded from this release.[2]
Once enabled, ChatGPT can surface message history, analyse patterns across conversations and draft outbound messages. OpenAI product staff member Ari Weinstein said the integration lets users get insights about who you talk to, and what you talk to people about.[5] Weinstein also said users can edit messages before sending.[6]
How sending works and what OpenAI says about data
By default, ChatGPT asks for per-message approval before sending, including confirmation of recipients, though users can grant persistent approval for individual chats.[2] That approval layer looks like a safeguard, but the sharper question is what happens to the content before any message leaves the device.
OpenAI's data retention documentation covers this directly: all conversations in the macOS app, including those accessed through the Messages plugin, follow the same policy as the web version. By default, message content may be used to train OpenAI's models unless the user actively opts out.[3] OpenAI has published no separate data handling policy specific to the Messages plugin.
Security and privacy concerns
Privacy researcher Paul Walsh put it plainly, saying the plugin functions like a backdoor, exposing participants' messages without their consent and undermining iMessage's end-to-end encryption guarantees.[4] The structural problem Walsh identifies is that end-to-end encryption protects data in transit between devices, but offers nothing once an application on the receiving device passes that content to a third-party AI service.
The consent gap runs deeper. The person who installs the plugin opts in for themselves; every contact whose messages are then ingested and potentially used for model training has no say in that arrangement.
Australian workplace exposure
In many Australian workplaces, iMessage has become the default channel for informal team coordination: quick decisions, client updates, deal conversations that never reach email or a project management tool. Pulling AI into that channel drags sensitive business discussions into OpenAI's data pipeline with no clear boundary between personal and corporate communications.
For operators, the question is immediate. Staff using iMessage for work on Apple silicon Macs with the ChatGPT desktop app installed bring their business conversations into scope the moment they enable the plugin. Enterprise opt-out settings exist but require deliberate configuration. The plugin shipped on 20 August 2026 and is available now in the Apple silicon build of the ChatGPT macOS app.
SOURCES & CITATIONS
FREQUENTLY ASKED QUESTIONS
Does the ChatGPT Apple Messages plugin work on Intel Macs?
Are my iMessages used to train OpenAI's AI models?
Can ChatGPT send an iMessage without my approval?
What is the privacy risk for people I message?

Takeshi Mori writes about technology and start-ups. He is curious about how products get built and who they are really for, and he would rather see a thing working than hear it described.



