The ChatGPT Apple Messages plugin, released on 20 August 2026, lets the AI search, summarise and reply to iMessage, SMS and RCS conversations on a Mac, but security experts warn that only the person installing it ever gives consent, according to Paul Walsh’s Substack.
Everyone else whose words appear in those threads is given no notice and no choice.
Security and privacy expert Paul Walsh calls the integration “one of the most dangerous things I have seen in technology,” warning it can function like spyware for people who rely on private communications.
OpenAI disputes the characterisation. The company says the plugin runs locally by default, only reads Messages when a user explicitly asks a question that requires it, and does not automatically upload or index message history.
How the ChatGPT Apple Messages plugin works
Users must install the plugin manually and grant ChatGPT three macOS permissions: AppleScript, Accessibility, and Full Disk Access. The AI does not begin reading conversations simply because the plugin is enabled, OpenAI says. A specific request (such as asking ChatGPT to summarise a thread) triggers the read.
By default, ChatGPT desktop stores conversations locally on the user’s computer. Messages content included in those conversations is not automatically synced to OpenAI’s servers. If a user chooses cloud storage, however, relevant Messages content follows the same retention policies as other conversation data and may remain in storage until actively deleted.
Walsh told Fortune that anyone he messages through iMessage would never know “that I have a third party inside that application.” For people who use encrypted messaging for sensitive conversations, he said, “it becomes dangerous.”
Encryption protection and the third-party risk
Walsh is not arguing that ChatGPT has broken Apple’s end-to-end encryption. His concern is what happens after an encrypted message arrives on a recipient’s Mac and becomes readable. Once another system can access a decrypted message, he said, “you have broken the fundamental concept.”
Dave Richardson, chief technology officer at mobile security company Lookout, said the spyware comparison was “a little too strong” because the feature is off by default and requires explicit user approval. Still, he said enabling the integration introduces “significant risk” to what has historically been a secure channel. “By granting third parties such as OpenAI or Anthropic access to these messages, you’re losing many of the benefits that end-to-end encryption has to offer,” Richardson said.
The backdrop matters. Proton published an analysis warning that the privacy implications extend to people who never use ChatGPT, because their messages can be accessed when a contact uses the plugin. Proton also flagged Full Disk Access as a broader security concern beyond Messages alone.
Proton’s analysis noted that in 2025 the UK government demanded access to end-to-end encrypted iCloud data. Apple responded by withdrawing Advanced Data Protection for UK users rather than creating a backdoor, a precedent Proton cites to illustrate how third-party access to decrypted message content can create vulnerabilities that circumvent encryption at the policy level, even when the cryptography itself is intact.
Walsh describes any server-side copy of content from an encrypted conversation as a potential “side door.” Authorities seeking information Apple cannot provide from an encrypted conversation could potentially seek a copy stored elsewhere, if one exists.
OpenAI says installing the plugin does not upload an entire Messages history, and that content accessed through it remains on the Mac by default.
The plugin uses existing macOS capabilities rather than a new iMessage API built by Apple. Fortune asked Apple whether it was considering additional safeguards as AI agents gain access to sensitive applications; Apple did not respond.
Lookout’s research, drawn from analysis of more than 420 million Android and iOS applications, found that permissions and capabilities of AI-related apps have continued to grow over the past year, with increased access tracked across eight categories of sensitive or high-risk capabilities. “There has been a trend we’ve seen quite steadily over the past year where AI services are asking for access to more and more data,” Richardson said.
Walsh was unambiguous on where he stands: “I would never build an iMessage integration that has the ability to read messages ever, because it breaks the fundamental protections that end-to-end encryption brings.”

