OpenAI just gave ChatGPT the keys to your iMessage inbox. The AI can read your texts, search through old conversations, draft replies, and send messages in your name. This is not a demo. It is live in the ChatGPT desktop app for Mac right now.
I felt my stomach drop when I read the setup steps. Full Disk Access. Contacts permission. Automation tools. These are the permissions you give to backup software, not to a chatbot.
The feature works through what OpenAI calls the Apple Messages plugin. It runs on Apple Silicon Macs. Once you enable it, ChatGPT can pull up recent conversations, answer questions about what is in them, and compose and send replies as you. It can search through iMessage, SMS, and RCS chats. It can summarize threads. It can find specific messages.
OpenAI says users must actively consent to all of this. The setup is deliberately friction-heavy. You click through opt-in screens in both the ChatGPT app and macOS System Settings. You grant Full Disk Access. You approve contacts and automation permissions. There are guardrails. By default, ChatGPT asks for approval before each send. You can switch on persistent approval to skip that step. OpenAI itself discourages this setting because it removes the last human check before an AI texts your contacts in your name.
This is clever engineering. I will say that plainly. The plugin runs locally on the machine. It relies on existing macOS tools like AppleScript and Accessibility features. OpenAI says it does not build an index of your full message history. The integration is available across all plans in the ChatGPT desktop app, including ChatGPT Work and Codex.
But here is the catch.
Granting an AI system this level of access to your personal conversations creates risks that no amount of local processing can fully eliminate. Once ChatGPT has Full Disk Access and can read your Messages database, the boundary between what the AI sees and what could potentially be exposed grows thin. A bug. A misconfiguration. A future feature update that changes how data flows. Any of these could turn your private texts into something far less private.
Apple has spent over a decade building its brand on privacy. The company markets iMessage as end-to-end encrypted. It tells users their conversations stay on their devices. It positions itself as the guardian of your digital life. Now a third-party AI can read and send those messages. Apple did not build this. Apple did not approve this. Apple is watching this happen.
The timing could not be worse. Apple sued OpenAI in July, accusing the company of stealing trade secrets through former Apple employees. The lawsuit alleges that OpenAI recruited more than 400 former Apple workers and sought confidential product information through hiring interviews. Apple asked a federal judge for a preliminary injunction to bar OpenAI from using alleged stolen secrets while the case proceeds. OpenAI filed a motion to dismiss, calling the lawsuit meritless and saying it has no use for Apple's trade secrets.
This legal fight is about talent and hardware ambitions. But it is also about trust. Apple's privacy brand depends on controlling who touches your data. OpenAI's new plugin puts an AI inside your Messages app while Apple is in court accusing OpenAI of crossing lines it should not cross.
OpenAI says the plugin does not allow users to interact with ChatGPT remotely through Messages. The feature does not work in regular ChatGPT chats. You must open the desktop app. You must enable the plugin. You must grant permissions. Each step requires a click. Each click is a choice.
That choice is the problem. Most people will not read the permission screens. They will click through because they want the feature to work. They will not think about what Full Disk Access means. They will not imagine a future where a bug or a hack exposes years of personal texts. They will trust the opt-in flow because it looks official. It looks safe.
I have been burned by trusting opt-in flows before. So have you. Companies design these screens to feel protective while asking for everything. The language is clear. The implications are not.
Apple now faces a dilemma. Blocking the plugin could look anti-competitive. Allowing it undermines the privacy promise Apple has sold for years. The company could tighten macOS permissions. It could require stricter review for apps that access Messages. It could do nothing and hope users make the right choice.
Users will not make the right choice. They will make the easy choice. They will enable the feature because it is useful. It is genuinely useful. Asking an AI to summarize a long group chat or draft a reply while you are driving is the kind of convenience people want. The value is real. The risk is real too.
What happens when ChatGPT sends a message you did not mean to send? What happens when it summarizes a conversation and gets something wrong? What happens when a future update changes the default settings? What happens when a vulnerability lets someone else read what ChatGPT can read?
OpenAI has answers for some of these questions. The company says it discourages persistent approval. It says the plugin runs locally. It says users must edit messages before they are sent. These are good guardrails. They are not perfect.
Nothing is perfect. That is the point. Wonder without the catch is advertising. The catch is what makes the wonder trustworthy. This feature is wonderful. It is also risky. Both things are true.
Apple and OpenAI are fighting in court over trade secrets. They are also fighting over something deeper. Who gets to decide what privacy means when AI can read your texts? The answer will not come from a judge. It will come from the choices users make when they see that opt-in screen.
I hope people read it. I hope they think about what they are giving away. I hope they remember that convenience always has a price. The price just got personal.