ChatGPT can now read and send your Apple Messages — what should a business do about it?
Short answer
On 20 August 2026 OpenAI shipped an Apple Messages plugin for the ChatGPT desktop app. With it, ChatGPT can read, search, draft and send messages through the Messages app on a Mac — covering iMessage, SMS and RCS.
The constraints matter as much as the capability:
- Apple silicon Macs only.
- ChatGPT Work and Codex only. It does not work in ordinary ChatGPT chats.
- Opt-in. It is a plugin you install, and it runs locally against files already on the machine.
- Sending asks for approval by default.
That last point is where the actual story is. Approval is a default, not a fixed property — a standing "always allow" can be granted, and OpenAI itself warns against doing it. When a vendor ships a capability and then tells you not to switch off its safety catch, the safety catch is the feature.
For a business, one line summarises the change: an AI assistant can now read the channel your one-time passcodes arrive in, and send messages as you, on a Mac your company may not manage.
What this is, and what it is not
Worth settling first, because the two get confused constantly and they point in opposite directions.
| Direction | What it means | |
|---|---|---|
| Apple Intelligence → ChatGPT | Apple calls out to ChatGPT | Siri and Writing Tools hand a request to ChatGPT and bring an answer back |
| ChatGPT → Apple Messages | ChatGPT reaches into a Mac app | ChatGPT reads your message history and can act inside Messages |
The first has existed for a while and is bounded by what Apple passes along. The second is new and is bounded by what you grant on your own machine. Anyone reasoning about the risk of one using their understanding of the other will get it wrong.
What it can actually do
The useful framing is not "it writes texts." It is that message history stops being an archive you scroll and becomes something you can query:
- What date did the supplier say the equipment would arrive?
- Summarise the thread with the project team and list every commitment I made.
- Read my last exchange with David and draft a reply confirming the install date.
That is genuinely useful, and it is exactly why the permissions are broad. You cannot answer questions about a conversation you cannot read.
The step that changes the risk category is the last one. Preparing a message is generative. Sending it is agentic — the software takes an action in the world under your name. Everything below follows from that distinction.
The one setting that matters
By default ChatGPT asks you to approve the message and the recipient before anything is sent. That approval is the control.
It can also be made standing. OpenAI's own guidance on the underlying Computer Use capability is explicit about how to treat that:
During a task, ChatGPT asks for your permission before it can use an app on your computer. You can choose Always allow [...] Use Always allow only for apps you trust ChatGPT to use automatically in future tasks
And the coverage of the Messages plugin puts it plainly: sending requires approval by default, and OpenAI warns against granting persistent approval.
Take the vendor at their word. The per-send confirmation is the thing standing between a misread instruction and a message going to the wrong person under your name — and recipient confirmation is not a nicety. "Send John the numbers we discussed" is ambiguous if you know three Johns, and the moment of disambiguation is the approval prompt.
Nobody enables "always allow" for Messages. Every send gets looked at.
The permission it asks for is bigger than the feature
Message history lives in a protected area of macOS, so the integration requires Full Disk Access, along with contacts and automation permissions.
Full Disk Access is not scoped to Messages. It is one of the most powerful grants macOS offers, and once given it applies to the application generally, not just to the feature that prompted for it. That is not a criticism of the design — there is no narrower permission that would let it read the message store — but it does mean the mental accounting has to be right:
| What the prompt feels like | What is actually granted |
|---|---|
| "Let ChatGPT help me with texts" | Broad local file access for the ChatGPT application |
The correct question at that prompt is never "do I want this feature?" It is "do I trust this application with this level of access to this machine?" Those can both be yes. They are different questions, and only one of them is being asked on screen.
Why SMS is the part to think about
Most discussion of this feature is about iMessage. The more interesting protocol is SMS.
Messages on a Mac holds SMS as well as iMessage, and SMS is where a great many businesses still receive one-time passcodes — banking, carrier portals, password resets, and any service where SMS is still the second factor.
Nothing here suggests ChatGPT will go looking for those codes. The point is narrower and it is about threat modelling: if your second factor arrives in a message store, and an AI assistant on the same machine has read access to that store, then the assistant's access, its account, and anything that can influence it are now part of your authentication perimeter.
For most people the practical response is not to remove the plugin. It is the thing that was already true and is now more clearly true: SMS is the weakest second factor, and anything that matters should be on an authenticator app or a hardware key. This feature is a reason to finish that migration rather than a new argument against ChatGPT.
What IT can and cannot control
Two things are documented, and one thing is not — and the gap is worth stating rather than glossing.
Documented. OpenAI's Computer Use capability can be disabled by administrators through an admin-enforced configuration file, using [features].computer_use = false. Plugin availability is also administrable in managed workspaces.
Not documented, at least not anywhere we could verify. Whether that Computer Use switch specifically governs the Apple Messages plugin. It is a reasonable assumption — the plugin acts on a local application, which is what Computer Use covers — but OpenAI's Computer Use documentation does not name the Messages plugin, and an assumption is not a control.
So the honest instruction for an administrator is: verify it in your own tenant before you tell anyone it is blocked. Turn the control off, then try to use the plugin from a test account. That takes ten minutes and it is the difference between a policy and a belief.
This also only reaches managed devices and managed workspaces. A personal ChatGPT account on a personally-owned Mac that syncs a work iCloud account is outside all of it — which is a Shadow AI question rather than a plugin question, and the Shadow AI Assessment asks about exactly this.
Should you allow it?
A defensible position for most businesses:
- On managed Macs, decide deliberately. Either allow it with the always-allow prohibition in writing, or disable it — but verify the disable actually works rather than assuming.
- Never grant standing send approval. The vendor says so; there is no need to be more relaxed than they are.
- Treat Full Disk Access as the decision point, not the plugin. If ChatGPT is trusted with that on a work Mac, this feature is a small increment. If it is not, this feature is not the place to start making an exception.
- Move off SMS second factors for anything that matters. This is the nudge, not the reason.
- Be specific with staff. "Don't use AI with messages" will be ignored. "You can let it read and draft; you approve every send; never tick always allow" is a rule somebody can actually follow.
None of this is a reason to panic about the feature. It is a well-constructed integration that is opt-in, local, and defaults to asking. It is a reason to make one decision on purpose, before somebody makes it for you by clicking Allow.
Frequently asked questions
Can ChatGPT read my iMessages?
Yes, if you install the Apple Messages plugin and grant the macOS permissions it asks for. OpenAI announced it on 20 August 2026 for the ChatGPT desktop app. It can read and search Messages conversations covering iMessage, SMS and RCS, on Apple silicon Macs, in ChatGPT Work and Codex — not in ordinary ChatGPT chats.
Can ChatGPT send a text message for me?
Yes. That is the significant part of the announcement: it moves from suggesting a message to performing the send. By default it asks you to approve both the message and the recipient first.
Does ChatGPT ask before sending a message?
By default, yes — it asks you to approve the message and the recipients. That approval can be made standing through an "always allow" choice, and OpenAI explicitly warns against granting persistent approval. Their own guidance says to use always-allow only for apps you trust ChatGPT to use automatically in future tasks.
What is the single most important setting?
Not granting standing send approval. The per-send confirmation is what stands between a misread instruction and a message going to the wrong person under your name. Recipient confirmation is a security control, not a convenience — "send John the numbers" is ambiguous if there are three Johns in your history.
Why does it need Full Disk Access?
Message history is stored in a protected area of macOS, so reading it requires that permission, along with contacts and automation access. The important point is that Full Disk Access is not scoped to Messages — it applies to the ChatGPT application generally. The question at that prompt is not whether you want the feature but whether you trust the application with that level of access to that machine.
Is this the same as ChatGPT in Apple Intelligence?
No, and they point in opposite directions. Apple Intelligence calls out to ChatGPT — Siri or Writing Tools hand over a request and bring back an answer. This plugin is the reverse: ChatGPT reaches into a Mac application and can read your message history and act inside it. Reasoning about one using your understanding of the other will mislead you.
Which Macs and which ChatGPT plans support it?
Apple silicon Macs, in the ChatGPT desktop application, within ChatGPT Work and Codex. It does not work in regular ChatGPT chats. Availability can also depend on plan, workspace configuration and what an administrator has enabled.
Does it work with SMS as well as iMessage?
Yes — iMessage, SMS and RCS. SMS is the one worth thinking about, because it is where many businesses still receive one-time passcodes.
Does this mean AI can read my two-factor codes?
If your codes arrive by SMS on a Mac where the plugin has read access, they are within reach of an assistant that can read the message store. Nothing suggests ChatGPT goes looking for them, but it changes the threat model: your message store becomes part of your authentication perimeter. The practical response is to move anything that matters off SMS and onto an authenticator app or hardware key, which was already the right answer.
Can a company block the Apple Messages plugin?
Probably, and it is worth verifying rather than assuming. OpenAI documents that administrators can disable the underlying Computer Use capability through an admin-enforced configuration setting, and that plugin availability is administrable in managed workspaces. What we could not verify is documentation stating that the Computer Use switch specifically governs this plugin. Turn the control off in your own tenant and then try to use the plugin from a test account before telling anyone it is blocked.
Does installing the plugin give ChatGPT access to everything automatically?
No. It requires explicit macOS permission grants, and it runs locally against files already on the machine. But those grants are broad once given, which is why the permission prompts deserve reading rather than reflexive approval.
What should we tell staff?
Something specific enough to follow. "Do not use AI with messages" gets ignored. "You may let it read and draft, you approve every send, and you never tick always allow" is a rule people can actually apply. On managed Macs, decide deliberately whether the plugin is permitted at all.
Is this feature dangerous?
No. It is opt-in, runs locally, and defaults to asking before it acts — a better-constructed integration than most. The risk is not the design, it is the combination of a broad permission grant, a defeatable approval prompt, and a message store that contains more than people remember it does.
Related articles
- What separates AI agents that ship to production from the ones that stay demos? — the same approval-proportional-to-consequence principle, at enterprise scale.
- What is Shadow AI and how do you find it? — personal ChatGPT on an unmanaged Mac is a Shadow AI question, not only a plugin question.
- How to create a corporate AI acceptable use policy — standing send approval belongs in the integrations section, in writing.
- AI security checklist for businesses: 40 controls — identity, agent approval and the five CIO questions.
- Shadow AI Risk Assessment — a free, private check on what AI is already reaching inside your business, including personal accounts on unmanaged machines.
- What does AI data governance actually require in 2026? — the governance layer this sits inside.
References
OpenAI's own documentation for the approval model and the administrator control, and two independent outlets for the announcement details, checked against each other. Where the documentation does not say something — specifically, whether the Computer Use control governs this plugin — this article says so rather than filling the gap with a reasonable-sounding assumption.
- MacRumors — ChatGPT Can Now Read and Send iMessages on Mac— source for the statement that sending a message requires user approval by default and that OpenAI warns against granting persistent approval, for the macOS permissions required (Full Disk Access, contact names, automation), and for availability being limited to ChatGPT Work and Codex in the desktop app rather than ordinary ChatGPT chats.
- 9to5Mac — ChatGPT update adds Apple Messages integration on Mac— source for the capability set (read and search Messages chats, prepare or send messages), for coverage of iMessage, SMS and RCS, for the Apple silicon requirement, and for the integration running locally against files already on the Mac rather than indexing message content.
- ChatGPT Learn — Computer Use— OpenAI's own documentation, and the source for the quoted approval model and the always-allow guidance, and for administrators being able to disable Computer Use through an admin-enforced configuration setting. Note what it does not say: it does not name the Apple Messages plugin, which is why this article recommends verifying the control in your own tenant rather than assuming it applies.
- ChatGPT Learn — Plugins— source for how plugins are discovered and enabled, and for plugin availability being administrable in managed workspaces.
- Engadget — ChatGPT on Mac can now read and respond to Apple iMessages— corroborating coverage of the 20 August 2026 announcement, used to confirm the date and the described capabilities against a second independent source.
- ADAM Pulse Knowledge Base — What separates AI agents that ship to production from the ones that stay demos?— the general principle this is a consumer-scale example of: the difference between an assistant that produces text and one that takes an action, and why approval should be proportional to consequence.
Managed network and communications services, SDVOSB. We support Apple fleets alongside the networks they sit on, so this one is close to home: the interesting question is never whether a feature is safe in the abstract, it is what your staff will have clicked Allow on by the time anyone writes a policy. Support: (888) 989-4872 · support@adampulse.us