ChatGPT Can Now Read iMessages on Mac. What Your Business AI Audit Should Check
On August 20, 2026, OpenAI shipped an Apple Messages plugin for the ChatGPT desktop app on macOS. Once the user grants permission, ChatGPT can read, search, summarize, draft, and send iMessage, SMS, and RCS messages through the Messages app (OpenAI release notes, OpenAI plugin docs, 9to5Mac). The interesting part for a business is not the feature — it is that an AI assistant now holds OS-level access to personal communications on work devices. That is a permission, consent, and data-retention event a business AI audit should check.
What the plugin can actually do
- Reads and searches iMessage, SMS, and RCS conversations on the Mac (OpenAI, MacRumors, Yahoo Tech).
- Can find, summarize, draft, or send a message (OpenAI, TNW); can analyze the archive — "summarising who you talk to and what you talk about" (TNW, MacRumors).
- Runs in ChatGPT Work and Codex on the macOS desktop app — not regular ChatGPT chats, not web/mobile, not Codex CLI or the IDE extension (OpenAI, Engadget, Unite.AI).
- Apple silicon only; does not run on Intel Macs (OpenAI, TNW).
- Does NOT let you interact with ChatGPT remotely through Messages (OpenAI, Yahoo Tech).
What data is exposed and what permissions are granted
- Opt-in setup: a permission screen appears during setup (OpenAI, Engadget).
- Full Disk Access in System Settings (Mac privacy preferences) (Engadget, MacRumors, TechCrunch).
- Access to contact names and to automation tools; the plugin uses AppleScript and Accessibility settings (Engadget, MacRumors).
- What it does NOT do (per OpenAI): no index of texts created (Engadget, TechCrunch); reads messages only when the user explicitly asks (Engadget, TechCrunch); will not send until the user explicitly approves the drafted message (Engadget).
- OpenAI statement: "We care deeply about user privacy, and the plugin is designed to be transparent and keep users in control of their Messages data." (Engadget)
Exposure caveats — say these carefully: OpenAI's docs do not spell out exactly which message bodies or metadata leave the machine for processing (TNW flags the gap) (TNW); group-chat participants are not asked for consent when ChatGPT analyzes a conversation (TNW). Phrase these as open questions, not confirmed facts.
Send approval flow — where the control actually lives
- Sending is gated by default: ChatGPT sends only after the user approves the message and its recipients (OpenAI, OpenAI docs, TechCrunch).
- Two choices: "Allow once" (single send) or "Always allow sending to this chat" (persistent approval for that conversation) (OpenAI docs, 9to5Mac).
- OpenAI discourages persistent approval: "Persistent approval removes your final chance to review a message before ChatGPT sends it as you. Use it only when you accept that risk." (OpenAI docs, TechCrunch)
- Revocable under Settings > Computer use > Messages > Always allowed to send (OpenAI docs).
- Known issue: tasks set to Full access or otherwise disabling approval prompts may break the send confirmation; OpenAI's remedy is "Ask for approval" or "Approve for me" (OpenAI docs, TNW).
How to review AI tools that access personal communications (business audit)
Lead with the principle: the audit question is not "is the vendor good?" — it is "what can this tool read, what can it send, who decided that, and who can undo it?" The 17-question checklist below maps to exactly that frame.
A. Inventory and exposure
1. How many company Macs run the ChatGPT desktop app, and how many have the Apple Messages plugin enabled?
Start with the inventory — you cannot audit what you haven't counted. (OpenAI, OpenAI docs)
2. Which employees granted Full Disk Access to ChatGPT during setup?
Full Disk Access is the grant that unlocks the Messages archive — record who has it. (Engadget, MacRumors, TechCrunch)
3. Does anyone on the team use "Always allow sending to this chat" (persistent approval)?
OpenAI discourages persistent approval because it removes the final review before a send. (OpenAI docs, 9to5Mac)
4. Are the Macs Apple silicon (arm64)?
Intel Macs are unaffected — the plugin does not run there. (OpenAI docs, TNW)
B. Permissions and controls
5. Who in your org can disable the plugin?
Admins can via the Computer Use control in managed workspaces. (OpenAI docs, Unite.AI)
6. Are tasks that involve Messages set to "Ask for approval"/"Approve for me" rather than Full access?
Known issue: Full-access tasks can break the send confirmation. (OpenAI docs, TNW)
7. Is there a documented owner for reviewing AI tool permissions — someone who can revoke access on request?
Aligns with the AI agent permissions audit lockdown framework: name the owner.
8. How would you detect that a message was sent by ChatGPT rather than a human?
No such indicator is documented — treat as a monitoring gap.
C. Consent and employee policy
9. Does your employee AI-use policy cover AI tools that read personal communications on work devices?
Policy question; no source claims OpenAI requires it.
10. Is persistent send approval explicitly prohibited in policy?
Given OpenAI's own guidance against persistent approval, a policy ban is the defensible default. (OpenAI docs, TechCrunch)
11. Have employees been told that group-chat participants are not asked for consent when ChatGPT analyzes a conversation?
Group-chat consent is an unaddressed gap — document the disclosure rule. (TNW)
12. For client-facing conversations: is there a disclosure rule when messages may be processed by an AI tool?
Grounded in the group-chat gap — the business must decide its own rule. (TNW)
D. Data retention and processing
13. Can you state, from documentation, exactly which message content is transmitted to OpenAI for processing?
OpenAI's docs do not spell this out — the correct audit answer is "no, and that gap should be flagged." (TNW)
14. What is OpenAI's retention/deletion policy for messages the plugin processes?
Not documented in the verified sources — do not invent an answer; mark as open. (TNW)
15. Does the plugin create an index of texts?
OpenAI spokesperson says no — but confirm from vendor documentation at audit time, not just press quotes. (Engadget, TechCrunch)
E. Vendor and administrator posture
16. Have you asked your AI vendor for: what data leaves the device, where it is processed, retention, and admin controls?
Enterprise admin data guidance is NOT published — ask and document the answer. (TNW)
17. If an employee leaves, is there a documented offboarding step to revoke plugin permissions?
Offboarding must include revoking Full Disk Access and any persistent approvals.
Consent and data-retention questions for employees
These are the questions a business should put in an employee AI-use policy:
- Do employees know that ChatGPT on their Mac can read their Messages archive once they grant Full Disk Access? (Engadget, MacRumors)
- Is "Allow once" the only permitted send mode, and is persistent approval banned? (OpenAI docs, TechCrunch)
- What happens to messages that go to OpenAI for processing (retention, training, deletion)? — the answer is not documented; flag as an open item. (TNW)
- Are customers/clients aware their messages may be processed by an AI tool? (Group-chat participants are not asked for consent — the business must decide its own disclosure rule.) (TNW)
- Is there a revocation procedure (revoke persistent approval, disable plugin via Computer Use control)? (OpenAI docs, Unite.AI)
How to frame this in a business AI audit
Position this as a permissions and consent audit item, not a scare story. The feature is opt-in, sending is gated by default, and OpenAI's documented posture is user control (OpenAI docs, Engadget, TechCrunch).
- Audit output: an "AI tool access register" row per tool — data it can read / actions it can take / who approved / how to revoke.
- Suggested verdict framing: acceptable with controls (approval gating on, persistent approval off, plugin disabled where not needed) (OpenAI docs, Unite.AI).
- Deep-dive: pair this with the AI agent permissions audit lockdown framework and the general AI agent security audit method. The sibling case — Claude Code sessions messaging each other — covers the agent-to-agent side of the same consent question.
Frequently asked questions
Can ChatGPT read my iMessage, SMS, and RCS messages?
Yes — the Apple Messages plugin in the ChatGPT desktop app on macOS can read and search iMessage, SMS, and RCS conversations, and can prepare or send messages through Messages, but only after you grant macOS permissions during setup. It runs only on Apple silicon Macs and works in ChatGPT Work and Codex, not regular ChatGPT chats. (OpenAI, OpenAI docs, 9to5Mac)
What permissions does the ChatGPT Messages plugin need?
Setup requires Full Disk Access in System Settings, plus access to the names of your contacts and to automation tools. The feature is opt-in, and OpenAI says the plugin does not create an index of your texts and only reads messages when you explicitly ask. (Engadget, MacRumors, TechCrunch)
Can ChatGPT send messages without asking me?
Not by default. ChatGPT sends a message only after you approve the message and its recipients. You can choose "Allow once" per send, or "Always allow sending to this chat" for persistent approval — which OpenAI discourages because it removes your final chance to review a message before it is sent as you. (OpenAI, OpenAI docs, TechCrunch)
Does OpenAI see my messages? What happens to them?
OpenAI has not documented exactly which parts of a conversation are transmitted for processing. The plugin runs locally on the device and OpenAI says it does not create an index of texts, but what is sent to OpenAI when you ask it to summarize or analyze an archive is not spelled out in the release notes or plugin docs. Businesses should treat this as an open question to confirm with the vendor. (Engadget, TechCrunch, TNW)
Can my business disable the ChatGPT Messages plugin?
Yes. In managed workspaces, administrators can disable Apple Messages through the existing Computer Use control, the same mechanism that governs other desktop-agent capabilities. (OpenAI docs, Unite.AI)
Should employees be allowed to use ChatGPT with their personal messages on a work Mac?
That is a policy decision, not a technical one. The audit position: the feature is opt-in and sending is gated by default, but granting Full Disk Access gives ChatGPT read access to the entire Messages archive, group-chat participants are not asked for consent, and OpenAI has not published enterprise guidance for mixed personal/professional archives. If the business permits it, require approval gating, ban persistent approval, and document the consent and retention questions above. (OpenAI docs, Engadget, MacRumors, TNW)
Accuracy note
Announced Aug 20, 2026 in OpenAI's release notes; plugin included only in the Apple Silicon (arm64) build; available on all plans with the functional surface in ChatGPT Work and Codex; sending gated by default with "Allow once" vs persistent approval (OpenAI discourages persistent); known issue where Full-access tasks can break the send confirmation; admins can disable via the Computer Use control. OpenAI has NOT documented exactly which message content is transmitted for processing, has NOT published enterprise admin data guidance for managed Macs, and Apple was not part of the announcement — those are open questions, not confirmed facts. No claim here that OpenAI "secretly reads texts" or "trains on iMessages" — the plugin reads only after opt-in permission grants and only when prompted. Apple sued OpenAI in July 2026 (trade secrets) and previously cut off third-party iMessage access (Beeper Mini, 2024) — background context only.