The plugin, initially detailed by MacRumors and further explored by Fortune, empowers ChatGPT users to perform a suite of powerful functions. From summarizing lengthy group chats and searching through years of old texts to drafting contextually relevant replies and even sending messages directly from a Mac, the integration streamlines communication workflows. The allure for users is clear: an intelligent assistant embedded directly into their most frequent communication channels, promising efficiency and reduced cognitive load. However, the mechanism of its access—requiring only the individual user to approve the plugin’s installation—has raised significant alarm bells. Crucially, while the installer grants permission, other participants in those conversations are neither notified nor given an opportunity to consent to their private communications being processed by an AI.
This unilateral consent model opens a new, complex front in the ongoing privacy and security debate surrounding AI agents. As these intelligent systems gain access to increasingly sensitive and personal facets of people’s digital lives, the boundaries of individual data sovereignty are being aggressively tested. Security and privacy expert Paul Walsh has not minced words, characterizing the Messages integration as "one of the most dangerous things I have seen in technology." He warns unequivocally that it possesses characteristics akin to spyware, particularly for individuals who rely on encrypted messaging for sensitive or confidential communications.
OpenAI, the developer behind ChatGPT, has sought to mitigate these concerns by outlining the plugin’s default operational parameters. According to the company, the plugin runs locally on the user’s Mac by default, meaning that the content of messages is processed on the device itself rather than being immediately uploaded to OpenAI’s servers. Furthermore, OpenAI states that ChatGPT only accesses and reads Messages when a user explicitly prompts it to, rather than continuously indexing or automatically uploading an entire message history. This implies a user-driven interaction model, where access is granted on a per-query basis. Yet, even with these safeguards, the fundamental issue remains: one person’s decision to opt in can effectively render years of conversations, including messages from countless individuals who never agreed to such access, searchable and summarizable by an AI.
Walsh articulated the profound implications of this scenario to Fortune, stating, "Every single person I send a message to through iMessage will never know that I have a third party inside that application, and they will never be notified." This lack of transparency and secondary consent mechanism is particularly troubling for individuals engaged in sensitive discussions, where the expectation of privacy is paramount. For those who deliberately choose end-to-end encrypted messaging platforms precisely for their enhanced security and confidentiality, Walsh warns, "it becomes dangerous." The very concept of a private conversation is redefined when an invisible AI agent can silently parse and retain its content.
OpenAI rolled out this plugin for ChatGPT on Mac, expanding its utility beyond simple text generation to active engagement with personal data streams. Users can search iMessage, SMS, and RCS conversations, quickly catch up on threads, draft replies, and send them directly via Apple Messages. The installation process is not trivial; it explicitly requires users to grant ChatGPT several macOS permissions, including AppleScript, Accessibility, and Full Disk Access. These are highly privileged permissions that grant extensive control over the operating system and its data. AppleScript allows applications to control other applications, Accessibility provides deep access to UI elements and user input, and Full Disk Access, as its name suggests, allows access to all files on the user’s hard drive.
OpenAI reiterates that simply enabling the plugin does not trigger an automatic indexing or reading of conversations. Instead, a user must make a specific request that requires information from Messages for ChatGPT to initiate access. For example, asking "Summarize my conversation with John Doe about next week’s meeting" would prompt the AI to access that specific thread.
Walsh’s core concern is not that ChatGPT has miraculously "cracked" Apple’s robust end-to-end encryption (E2EE). He acknowledges that the cryptographic integrity of the messages in transit likely remains intact. Instead, his alarm centers on what happens after an encrypted message reaches its intended recipient and is decrypted, becoming readable on that person’s Mac. He draws a stark comparison, arguing that giving ChatGPT such access is functionally equivalent to installing spyware. "Let’s say we agree it’s encrypted. Perfect mathematics hasn’t been broken," Walsh conceded. However, he emphasized that "once another system can read a message before it is encrypted or after it has been decrypted, you have broken the fundamental concept" of secure communication. The "fundamental concept" being that the message remains private between the intended sender and receiver, even after decryption.
The ability for an individual to share a private message with a third party is not entirely new. Users have always been able to screenshot texts, forward them, or manually copy and paste them into other applications, including chatbots. What fundamentally changes with the Messages plugin is the ease and scale with which an AI can search, analyze, and synthesize information across an entire history of conversations once a user grants it access. This shift from manual, intentional sharing to automated, programmatic access is where Walsh identifies the critical distinction.
He argues that manual sharing, while potentially a breach of trust, is a distinct action. "That’s you breaking that person’s trust," Walsh said in reference to taking a screenshot. "It’s not you allowing a third party inside the conversation." The AI plugin, in his view, represents a systemic integration of a "third party" directly into the communication channel, operating with an entirely different scope and scale.
Dave Richardson, CTO at mobile security company Lookout, offered a slightly more nuanced perspective. While he understands the comparison to spyware, he believes the term is "a little too strong." He differentiates by pointing out that traditional spyware typically accesses and exfiltrates information without the user’s explicit knowledge or permission, whereas the Messages feature is opt-in and requires explicit user consent. Nevertheless, Richardson acknowledged that enabling this integration introduces "significant risk" to what has historically been considered a secure channel for communication.
Richardson further elaborated on the principles of end-to-end encryption. He explained that E2EE is designed to protect a message as it traverses networks, ensuring that neither the network operator nor the platform provider can read or modify its content. However, the devices at either end of the communication, once they decrypt the message, naturally have access to its readable form. "By granting third parties such as OpenAI or Anthropic access to these messages," Richardson warned, "you’re losing many of the benefits that end-to-end encryption has to offer." The promise of E2EE is not just secure transit, but a robust barrier against external access to the content itself, a barrier that is effectively bypassed when a user’s device provides direct access to decrypted messages.
Privacy-focused technology company Proton echoed these significant concerns in a recent analysis. Proton highlighted that the privacy implications extend far beyond the individual ChatGPT user, potentially affecting anyone with whom that user has communicated. Even individuals who have never touched ChatGPT could have their messages accessed and processed if someone they converse with enables the plugin. Proton also specifically pointed to the "Full Disk Access" permission—one of the macOS permissions required during setup—as a broader security consideration. This permission is exceptionally powerful, granting an application carte blanche access to virtually all user data, raising questions about potential misuse or vulnerabilities even if the AI’s intended use is limited to Messages.
OpenAI’s clarifications regarding local processing by default are central to addressing some of these fears. The company states that ChatGPT desktop stores conversations locally on the user’s computer by default, meaning that Messages content accessed through the plugin is not automatically synced to OpenAI’s servers. This local processing model would theoretically keep the data out of OpenAI’s direct cloud infrastructure. However, a critical caveat exists: if a user chooses to store a ChatGPT conversation in the cloud (a common feature for syncing across devices and preserving chat history), then any relevant Messages content included in that conversation would follow the same retention policies as other cloud-stored data. This content could also inform "Memories" stored in the cloud, an OpenAI feature designed to personalize future interactions based on past conversations.
This distinction is crucial to Paul Walsh’s most serious warnings. He argues that if content from an encrypted conversation eventually finds its way to another company’s servers (even if initiated by the user choosing cloud storage for their ChatGPT conversations), it could create an entirely new, potentially vulnerable "point of access." This could expose data to hackers, malicious insiders, or even governmental and law enforcement requests. Walsh describes this as a potential "side door" around end-to-end encryption, rather than a technical break in the encryption itself. Authorities seeking information that Apple cannot provide from an end-to-end encrypted conversation might then potentially seek a copy stored elsewhere, if such a copy exists on OpenAI’s servers due to a user’s cloud storage settings. While OpenAI’s default local storage mitigates this, the option for cloud storage introduces this risk.
The Messages integration is part of a broader, accelerating trend: AI services are aggressively expanding their reach into various data streams and device capabilities. Lookout’s research, provided to Fortune, reveals a consistent increase over the past year in the permissions and capabilities sought by AI-related applications across both Android and iOS platforms. Their analysis of over 420 million apps shows a particular uptick in iOS AI apps seeking access to sensitive or high-risk categories of data and device functions. "There has been a trend we’ve seen quite steadily over the past year where AI services are asking for access to more and more data," Richardson noted, pointing to a systemic push by AI developers to enhance utility by integrating deeply into users’ digital lives.
It’s important to note that the Messages plugin leverages existing macOS capabilities rather than a new, dedicated iMessage API built by Apple specifically for ChatGPT. This means Apple has not necessarily "blessed" this specific AI integration but rather provided the foundational operating system permissions that allow such an integration to be built by third parties. Fortune reached out to Apple to inquire whether it anticipated existing macOS permissions being used in this manner for AI agents and if it was considering additional safeguards. Apple did not provide an immediate response.
Walsh stresses that the risks posed by third-party software accessing sensitive information are not inherently unique to ChatGPT or AI. What is fundamentally changing, he argues, is the unparalleled speed, scale, and sophistication with which AI can search, analyze, and synthesize vast amounts of information once it gains that access. The sheer processing power of AI amplifies the potential impact of any data breach or privacy compromise. "I would never build an iMessage integration that has the ability to read messages ever," Walsh declared, "Because it breaks the fundamental protections that end-to-end encryption brings."
As AI agents continue to evolve and become more capable, a significant portion of their perceived usefulness will inevitably come from their ability to access and interact with an ever-growing portion of people’s digital lives. The inherent complication in this expansion is the overlapping nature of those digital lives. With the Apple Messages plugin, one individual’s decision to grant an AI access can inadvertently expose years of conversations that were created by, and participated in, by countless other people who never consented to an AI’s presence in their private communications. This fundamental conflict between individual convenience, collective privacy, and the expanding capabilities of AI will continue to define the technological landscape in the years to come.

