NE Times
Technology

Should You Let ChatGPT Read and Send Your Apple Messages on a Mac?

OpenAI’s Apple Messages plugin can read, draft and send Mac messages, putting Full Disk Access and send approvals at the centre of its privacy model.

Arjun Nair

Commentary & Analysis ·

5 min read
A closed silver laptop on a plain wooden desk beside a cup of coffee in soft morning window light

ChatGPT can now search your Apple Messages and send replies for you on a Mac. Before you switch it on, it's worth knowing what you're handing over: Full Disk Access, contacts and automation permissions. Here's what the plugin can actually do, what stays on your machine and what doesn't, and the one setting you should leave exactly as it is.

Verified key facts

  • OpenAI release notes: The Apple Messages plugin launched on 20 August and is available on all ChatGPT plans in the macOS desktop app.
  • OpenAI release notes: The plugin can read and search Messages chats and prepare or send messages, but it is used through ChatGPT Work and Codex rather than ordinary ChatGPT chats.
  • MacRumors: The integration supports iMessage, SMS and RCS, is limited to Apple silicon Macs, and uses AppleScript plus macOS Accessibility/automation mechanisms.
  • MacRumors: Users must grant Full Disk Access along with contacts and automation permissions for the integration to function.
  • OpenAI: A send requires approval of the message and recipients by default; OpenAI specifically warns about persistent approval and provides revocation guidance.
Advertisement

The new feature crosses from composing text into operating a private inbox

OpenAI's 20 August release turns ChatGPT on a Mac from a tool that can suggest a reply into one that can inspect Apple Messages and, with permission, send the reply itself. OpenAI's release notes say the public Apple Messages plugin can read and search conversations on the Mac and prepare or send messages. MacRumors reports that this includes iMessage, SMS and RCS conversations. The feature is available across ChatGPT plans but only on Apple silicon Macs and only through ChatGPT Work and Codex, not ordinary chat threads. That combination is important. The commercial headline is convenience: find a birthday, catch up on a group chat or send an availability message without manually switching apps. The privacy headline is broader: an AI agent is being granted operating-system access to one of the most intimate databases on a personal computer.

Advertisement

Full Disk Access is not a cosmetic permission

MacRumors says the integration requires Full Disk Access in macOS System Settings, plus access to contact names and automation tools. On a Mac, Full Disk Access is a high-trust permission because it allows an application to reach data that normal sandbox restrictions would block, including protected application databases. The Messages database lives locally, which is why the plugin needs that level of access to search old threads. Users should therefore treat installation as a security decision rather than a simple feature toggle. A person who only wants drafting help can still copy and paste selected text into ChatGPT without opening the whole message history to the desktop app. The plugin's value comes precisely from not having to do that manual selection; the trade-off is that the application receives much broader local capability.

Advertisement
Advertisement

AppleScript and Accessibility make the feature powerful - and legible to macOS

According to MacRumors, the plugin uses AppleScript and macOS Accessibility or automation controls to drive the Messages app. That is different from a hidden server-side connection to Apple's iMessage network. The architecture means the Mac itself becomes the integration point: ChatGPT searches local message data and tells the Messages application what action to perform. This design has a practical advantage because macOS exposes permission controls that a user can revoke. It also means users should review System Settings after installation and understand which application can control which other application. OpenAI's Business release notes add that workspace administrators can disable Apple Messages through existing computer-use controls. For organisations, that makes the question not merely whether the feature is useful, but whether employees should be able to grant an AI agent access to workplace and personal correspondence on the same machine.

Advertisement

Local operation does not mean every task is confined to the Mac

Some reporting has summarised OpenAI's position by saying the plugin works locally and does not build a permanent full index of a user's message history. That is a meaningful privacy property, but it should not be mistaken for a promise that message content can never be processed by ChatGPT. When a user asks the model to summarise a conversation, identify follow-ups or draft a reply based on several messages, relevant text has to become part of the task context so the model can perform the request. The exact data-handling rules then depend on the user's plan, workspace and OpenAI settings. The safer description is therefore narrow: the integration searches the Mac's local Messages data rather than requiring a permanent remote mirror of every conversation. Users should still avoid assuming that invoking AI on a sensitive thread is equivalent to leaving that thread untouched on-device.

The default approval step is the most important safety control

OpenAI says messages are sent only after the user approves both the text and recipients by default. That human confirmation separates reading and drafting from an irreversible external action. A bad summary is inconvenient; a message sent to the wrong person can disclose private information, create legal exposure or damage a relationship. OpenAI's release notes explicitly point users to guidance about the risks of persistent approval, and MacRumors says the company warns against granting it casually. Persistent permission can make repetitive workflows faster, but it also removes the moment at which a user notices a hallucinated detail, the wrong group chat or an instruction embedded in a malicious message. For most people, the extra click is not friction to eliminate; it is the boundary that keeps an assistant from becoming an autonomous correspondent.

Group chats create an authenticity question as well as a data question

Business Insider reported immediate discomfort from some users at the idea of AI-generated personal texting. That reaction is not merely sentimental. Messages often carry context that depends on tone, history, jokes, family dynamics and an expectation that the sender chose the words. An AI-generated calendar reply may be harmless; an AI-mediated apology, condolence or emotionally sensitive conversation raises different expectations. The plugin can also search multiple conversations, which makes it useful for finding commitments but increases the consequences of misidentifying people with similar names. OpenAI's examples include finding birthdays and follow-ups, tasks where factual retrieval matters more than style. Users will need their own social rule for when automation is acceptable, because macOS permission screens can govern access and sending but cannot decide when a human relationship deserves a human-written response.

Default approval on 20 August is the privacy hinge to preserve

The release date is fixed, but the most consequential product choice is the default that came with it. On 20 August, OpenAI shipped Apple Messages support with send approval turned on, not with blanket authority to write to contacts. That should remain the baseline as the integration evolves. Apple silicon exclusivity and the Work/Codex limitation may expand later; the permission model matters more than those launch constraints. Users who enable the plugin should review Full Disk Access, Contacts and Automation permissions, leave per-send confirmation in place unless they have a very narrow trusted workflow, and remove persistent approvals they no longer need. The feature demonstrates how quickly AI assistants are moving from advice into action. Its usefulness will be judged by how much labour it saves; its trustworthiness will be judged by whether that action remains visible, revocable and deliberately authorised.

Sources

  • OpenAI release notes (openai.com)
  • OpenAI Business release notes (help.openai.com)
  • MacRumors (www.macrumors.com)
  • Business Insider (www.businessinsider.com)
  • Verification note: OpenAI says the plugin does not require a permanent full remote index of Messages; this should not be paraphrased as “message content never leaves the Mac” when a user asks ChatGPT to process a thread.
Share
Sponsored Content

You may also like to read