ChatGPT Can Now Read iMessages on Mac. What Your Business AI Audit Should Check

Published August 21, 2026My Business AI Audit

On August 20, 2026, OpenAI shipped an Apple Messages plugin for the ChatGPT desktop app on macOS. Once the user grants permission, ChatGPT can read, search, summarize, draft, and send iMessage, SMS, and RCS messages through the Messages app (OpenAI release notes, OpenAI plugin docs, 9to5Mac). The interesting part for a business is not the feature — it is that an AI assistant now holds OS-level access to personal communications on work devices. That is a permission, consent, and data-retention event a business AI audit should check.

What the plugin can actually do

What data is exposed and what permissions are granted

Exposure caveats — say these carefully: OpenAI's docs do not spell out exactly which message bodies or metadata leave the machine for processing (TNW flags the gap) (TNW); group-chat participants are not asked for consent when ChatGPT analyzes a conversation (TNW). Phrase these as open questions, not confirmed facts.

Send approval flow — where the control actually lives

How to review AI tools that access personal communications (business audit)

Lead with the principle: the audit question is not "is the vendor good?" — it is "what can this tool read, what can it send, who decided that, and who can undo it?" The 17-question checklist below maps to exactly that frame.

A. Inventory and exposure

1. How many company Macs run the ChatGPT desktop app, and how many have the Apple Messages plugin enabled?
Start with the inventory — you cannot audit what you haven't counted. (OpenAI, OpenAI docs)

2. Which employees granted Full Disk Access to ChatGPT during setup?
Full Disk Access is the grant that unlocks the Messages archive — record who has it. (Engadget, MacRumors, TechCrunch)

3. Does anyone on the team use "Always allow sending to this chat" (persistent approval)?
OpenAI discourages persistent approval because it removes the final review before a send. (OpenAI docs, 9to5Mac)

4. Are the Macs Apple silicon (arm64)?
Intel Macs are unaffected — the plugin does not run there. (OpenAI docs, TNW)

B. Permissions and controls

5. Who in your org can disable the plugin?
Admins can via the Computer Use control in managed workspaces. (OpenAI docs, Unite.AI)

6. Are tasks that involve Messages set to "Ask for approval"/"Approve for me" rather than Full access?
Known issue: Full-access tasks can break the send confirmation. (OpenAI docs, TNW)

7. Is there a documented owner for reviewing AI tool permissions — someone who can revoke access on request?
Aligns with the AI agent permissions audit lockdown framework: name the owner.

8. How would you detect that a message was sent by ChatGPT rather than a human?
No such indicator is documented — treat as a monitoring gap.

C. Consent and employee policy

9. Does your employee AI-use policy cover AI tools that read personal communications on work devices?
Policy question; no source claims OpenAI requires it.

10. Is persistent send approval explicitly prohibited in policy?
Given OpenAI's own guidance against persistent approval, a policy ban is the defensible default. (OpenAI docs, TechCrunch)

11. Have employees been told that group-chat participants are not asked for consent when ChatGPT analyzes a conversation?
Group-chat consent is an unaddressed gap — document the disclosure rule. (TNW)

12. For client-facing conversations: is there a disclosure rule when messages may be processed by an AI tool?
Grounded in the group-chat gap — the business must decide its own rule. (TNW)

D. Data retention and processing

13. Can you state, from documentation, exactly which message content is transmitted to OpenAI for processing?
OpenAI's docs do not spell this out — the correct audit answer is "no, and that gap should be flagged." (TNW)

14. What is OpenAI's retention/deletion policy for messages the plugin processes?
Not documented in the verified sources — do not invent an answer; mark as open. (TNW)

15. Does the plugin create an index of texts?
OpenAI spokesperson says no — but confirm from vendor documentation at audit time, not just press quotes. (Engadget, TechCrunch)

E. Vendor and administrator posture

16. Have you asked your AI vendor for: what data leaves the device, where it is processed, retention, and admin controls?
Enterprise admin data guidance is NOT published — ask and document the answer. (TNW)

17. If an employee leaves, is there a documented offboarding step to revoke plugin permissions?
Offboarding must include revoking Full Disk Access and any persistent approvals.

Consent and data-retention questions for employees

These are the questions a business should put in an employee AI-use policy:

How to frame this in a business AI audit

Position this as a permissions and consent audit item, not a scare story. The feature is opt-in, sending is gated by default, and OpenAI's documented posture is user control (OpenAI docs, Engadget, TechCrunch).

Run the free AI audit tool →

Frequently asked questions

Can ChatGPT read my iMessage, SMS, and RCS messages?

Yes — the Apple Messages plugin in the ChatGPT desktop app on macOS can read and search iMessage, SMS, and RCS conversations, and can prepare or send messages through Messages, but only after you grant macOS permissions during setup. It runs only on Apple silicon Macs and works in ChatGPT Work and Codex, not regular ChatGPT chats. (OpenAI, OpenAI docs, 9to5Mac)

What permissions does the ChatGPT Messages plugin need?

Setup requires Full Disk Access in System Settings, plus access to the names of your contacts and to automation tools. The feature is opt-in, and OpenAI says the plugin does not create an index of your texts and only reads messages when you explicitly ask. (Engadget, MacRumors, TechCrunch)

Can ChatGPT send messages without asking me?

Not by default. ChatGPT sends a message only after you approve the message and its recipients. You can choose "Allow once" per send, or "Always allow sending to this chat" for persistent approval — which OpenAI discourages because it removes your final chance to review a message before it is sent as you. (OpenAI, OpenAI docs, TechCrunch)

Does OpenAI see my messages? What happens to them?

OpenAI has not documented exactly which parts of a conversation are transmitted for processing. The plugin runs locally on the device and OpenAI says it does not create an index of texts, but what is sent to OpenAI when you ask it to summarize or analyze an archive is not spelled out in the release notes or plugin docs. Businesses should treat this as an open question to confirm with the vendor. (Engadget, TechCrunch, TNW)

Can my business disable the ChatGPT Messages plugin?

Yes. In managed workspaces, administrators can disable Apple Messages through the existing Computer Use control, the same mechanism that governs other desktop-agent capabilities. (OpenAI docs, Unite.AI)

Should employees be allowed to use ChatGPT with their personal messages on a work Mac?

That is a policy decision, not a technical one. The audit position: the feature is opt-in and sending is gated by default, but granting Full Disk Access gives ChatGPT read access to the entire Messages archive, group-chat participants are not asked for consent, and OpenAI has not published enterprise guidance for mixed personal/professional archives. If the business permits it, require approval gating, ban persistent approval, and document the consent and retention questions above. (OpenAI docs, Engadget, MacRumors, TNW)

Accuracy note

Announced Aug 20, 2026 in OpenAI's release notes; plugin included only in the Apple Silicon (arm64) build; available on all plans with the functional surface in ChatGPT Work and Codex; sending gated by default with "Allow once" vs persistent approval (OpenAI discourages persistent); known issue where Full-access tasks can break the send confirmation; admins can disable via the Computer Use control. OpenAI has NOT documented exactly which message content is transmitted for processing, has NOT published enterprise admin data guidance for managed Macs, and Apple was not part of the announcement — those are open questions, not confirmed facts. No claim here that OpenAI "secretly reads texts" or "trains on iMessages" — the plugin reads only after opt-in permission grants and only when prompted. Apple sued OpenAI in July 2026 (trade secrets) and previously cut off third-party iMessage access (Beeper Mini, 2024) — background context only.