
OpenAI’s ChatGPT now requires full disk access on Macs to read, search, and send messages through Apple’s Messages app.
Plugin capabilities
The recent update to ChatGPT’s macOS desktop app adds a plugin that connects directly with Messages. OpenAI states the tool can review iMessage, SMS, and RCS conversations, create summaries, and dispatch texts for users—all processed locally on the device.
OpenAI confirmed the Apple Messages plugin is available to all subscribers in the macOS desktop app. It does not permit remote interaction with ChatGPT through Messages, nor does it operate within regular ChatGPT chats. Users must approve each action individually instead of granting ongoing access.
The company positions the feature as a way to retrieve past conversations, compose replies, or suggest alternatives to popular messaging services. Sample prompts include locating specific details in message history or drafting new texts based on existing threads.
Security and privacy considerations
The plugin’s operation depends on broad system permissions. It needs Full Disk Access in macOS System Settings, along with contacts and automation permissions. OpenAI recommends against enabling continuous approval, noting that doing so removes the final review step before ChatGPT sends a message.
While OpenAI asserts the plugin does not build a permanent index of messages, it still processes the content. The advice to avoid persistent approval has not fully addressed concerns about data handling.
Related: Trump Targets Robotics with New Restrictions
The tool currently works only on macOS, though OpenAI may expand it to iPhones and iPads. Such a move would likely renew conflicts with Apple, which has restricted third-party AI developers from the same deep system access it reserves for its own services. In Europe, the Digital Markets Act adds complexity by requiring Apple to offer equal API access to competitors, a demand the company has resisted over privacy concerns.
The plugin arrives as Apple prepares its own AI features, including an upgraded Siri that promises similar insights from personal data. Unlike OpenAI’s approach, Apple postponed Siri’s European launch, citing unresolved privacy issues under the DMA. The difference highlights a broader tension between convenience and user control.
OpenAI’s implementation does not clearly breach macOS security protocols, so Apple is not expected to block it right away. However, the company’s strategy for iOS remains uncertain. If ChatGPT gains comparable access on mobile devices, it could pressure Apple to act, especially if regulators enforce the DMA’s equal-access requirements.
Trust remains a central issue. Users must grant extensive permissions to an AI that, despite local processing, operates without full transparency. Uncertainty about how the plugin interacts with message data raises questions about the true meaning of informed consent.
The feature remains optional, and OpenAI stresses user control in its communications. Yet as AI tools become more embedded in daily tasks, the boundary between helpful and intrusive will continue to shift. The real challenge will emerge when similar capabilities reach iOS, where the volume of sensitive data is even greater.
Recent moves by Apple to limit third-party AI access reflect broader industry caution about granting such permissions.

