One Opt-In, Millions of Conversations
OpenAI last week rolled out a plugin for ChatGPT on Mac that allows the AI to search iMessage, SMS, and RCS conversations, summarize group chats, draft replies, and send messages directly through Apple Messages. The user installing it must explicitly grant ChatGPT several macOS permissions—AppleScript, Accessibility, and Full Disk Access—but no one else in those conversations is notified or asked.
According to OpenAI, the plugin runs locally by default and does not automatically upload or index a user's message history. ChatGPT only reads Messages after a user makes a request that specifically requires information from them, the company said.
That technical boundary has not quieted critics.
'One of the Most Dangerous Things I Have Seen'
Security and privacy expert Paul Walsh called the Messages integration 'one of the most dangerous things I have seen in technology,' warning it can function like spyware for people who depend on private communications.
'Every single person I send a message to through iMessage will never know that I have a third party inside that application, and they will never be notified,' Walsh told Fortune.
Walsh's concern is not that ChatGPT has broken Apple's end-to-end encryption. His argument is about what happens after an encrypted message arrives and becomes readable on a recipient's Mac. Once another system can read a message after it has been decrypted, he said, 'you have broken the fundamental concept.'
Dave Richardson, CTO at mobile security company Lookout, told Fortune he could understand the spyware comparison, though he considers the term 'a little too strong' given that the feature is off by default and requires explicit user action. Still, Richardson said enabling the integration introduces 'significant risk' to what has historically been considered a secure channel.
'By granting third parties such as OpenAI or Anthropic access to these messages, you're losing many of the benefits that end-to-end encryption has to offer,' Richardson said.
Privacy-focused technology company Proton published an analysis Tuesday warning that the privacy implications extend to people who never use ChatGPT, because their messages can still be accessed when someone they communicate with installs the plugin. Proton also flagged Full Disk Access—one of the required macOS permissions—as a broader security consideration.
The Consent Gap Is the Story
The ability to share a private message with a third party is not new. A user can screenshot a text or paste it into ChatGPT manually. What changes with the plugin, Walsh argues, is the ease and scale: AI can now search across years of conversations the moment a user asks it to, pulling in messages from contacts who made no such choice.
'That's you breaking that person's trust,' Walsh said of a screenshot. 'It's not you allowing a third party inside the conversation.'
---
The numbers here are straightforward, and the market will price them accordingly: the more AI agents embed themselves in personal communications infrastructure, the larger the liability surface for every platform involved. OpenAI's opt-in framing is technically accurate—but opt-in for one party is opt-out-impossible for everyone else in the thread. Free enterprise thrives on informed consent and clear property rights over personal data. A plugin architecture that grants one user the power to expose another person's private communications without notice does not meet that standard. Regulators have noticed slower-moving targets than this one. The question is whether OpenAI moves to close the consent gap before Washington decides to close it for them.



