Product Launch

OpenAI's ChatGPT Messages Plugin Raises Privacy Alarm Over Non-Consenting Conversations

OpenAI launched a ChatGPT plugin for Apple's Messages app on Mac, allowing the AI to read, search, summarize, and draft messages from iMessage, SMS, and RCS. Privacy researchers warn the tool exposes conversations of people who never consented, as neither Apple nor OpenAI notifies other parties. The plugin can access years of synced Messages history, including end-to-end encrypted chats, raising concerns about consent and data protection.

Neura News

Neura News

Neura Market Editorial

August 24, 20265 min read
OpenAI's ChatGPT Messages Plugin Raises Privacy Alarm Over Non-Consenting Conversations

OpenAI launched a ChatGPT plugin for Apple's Messages app on Mac on August 20, giving the AI the ability to read, search, summarize, and draft messages from iMessage, SMS, and RCS. The rollout has drawn sharp criticism from privacy researchers, who say the tool exposes conversations of people who never agreed to participate.

The plugin works inside ChatGPT Work and Codex and requires Apple Silicon Macs. It asks for permissions including Full Disk Access, contacts, and automation. By default, the plugin asks the user for approval before sending a message, but it can access years of Messages history synced through iCloud. Neither Apple nor OpenAI notifies the other party in a conversation that the plugin is active, and there is no way for that other party to revoke access.

A Backdoor Built by the User

Privacy researcher Paul Walsh, who helped create an early W3C standard for content labeling, compared the plugin to a backdoor. "This is a backdoor, but it's built by the user, not the government," Walsh said. His argument centers on the fact that the plugin exposes messages from someone who never consented and may not use Apple devices or ChatGPT at all.

The concern is not hypothetical. Apple began rolling out end-to-end encrypted RCS between iPhone and Android in May, meaning conversations that were previously less protected are now encrypted. The plugin can still read those chats on the Mac where it is installed, regardless of the other party's wishes. That access cuts against Apple's privacy reputation, which has long been built on encryption that Apple itself cannot read.

The Shadow Profile Parallel

The mechanic is familiar to anyone who has followed Facebook's history. For over a decade, Facebook has built shadow profiles, which are records of non-users assembled from contact lists uploaded by users. Mark Zuckerberg confirmed the practice in 2018 congressional testimony. Facebook later added a tool for non-users to request deletion of data others had uploaded, but the company never eliminated contact uploading.

The through-line is the same: one person's choice to share data can expose someone else who never got a say. ChatGPT's Messages plugin runs on that same logic, applied to conversations instead of contacts. Critics argue the plugin is a privacy test for Apple's brand, a framing that Bloomberg also used in its coverage of the rollout.

Regulatory Precedent

There is precedent for regulators punishing this kind of data handling. In 2021, Ireland's Data Protection Commission fined WhatsApp €225 million for failing to disclose how it shared data with other Facebook companies. The fine was one of the largest penalties under GDPR to date. Meta, the parent company of both Facebook and WhatsApp, has faced repeated scrutiny over its data practices, yet the contact uploading mechanism still runs today.

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

The WhatsApp case shows that regulators can act when data sharing is opaque. The new plugin, however, operates through standard macOS permissions rather than any consent screen from Apple. That distinction matters because Apple's own documentation for ChatGPT with Apple Intelligence describes a narrower integration that asks users before information is shared. The new Mac plugin is distinct from that integration and does not use Apple's consent screen.

OpenAI's Defense and the Remaining Problem

OpenAI says the plugin runs locally and does not index all messages. The company says it only pulls content when asked, and sending is gated by approval unless the user turns that off per conversation. OpenAI itself recommends against turning off approval. Those safeguards address some technical concerns, but they do not solve the consent problem.

The other party in a conversation has no way to know the plugin exists, no way to object, and no way to revoke access. Even if the plugin never sends a message without approval, it can still read, search, and summarize entire threads. That means a user could ask ChatGPT to summarize a group chat that includes people who have never heard of the plugin.

Two Readings of the Same Plugin

Some coverage frames the plugin as a straightforward convenience win. A user can ask ChatGPT to draft a reply, find an old address, or summarize a long thread. Others see a company asking users to hand over private conversations of everyone they have ever texted without their knowledge. Both readings describe the same plugin.

The question worth asking is whether anyone asked the other side of the conversation first. The plugin's access to end-to-end encrypted chats with parties who never consented is a major privacy concern, and it challenges the trust Apple has cultivated around its messaging ecosystem. Apple's privacy reputation is built on encryption Apple itself cannot read, yet this plugin can read what Apple cannot.

The plugin was published on August 20, and the analysis here was published on Aug 24, 2026. The timing matters because Apple's RCS encryption rollout in May was meant to strengthen user privacy, and the plugin arrives only months later. OpenAI has not said whether it plans to add notification or consent features for non-users. For now, the plugin sits on Macs with full access to years of private conversations, and the people in those conversations never got a vote.

Related on Neura Market

More from Neura News

Industry

Travelers builds its own LLM to cut AI costs and sharpen insurance answers

Travelers Insurance has developed its own proprietary large language model, TravelersLLM, to reduce AI costs and improve performance on insurance-specific queries. The model, unveiled in June 2026, is cheaper to run than frontier models and is used alongside them, with queries routed based on task complexity. This move reflects a broader industry trend of managing AI expenses by using multiple models and routing tasks based on cost and quality.

Aug 24·4 min read
Developer

Roblox's "Prompt to Prod" Aims for Fully Autonomous Software Development

Roblox is advancing toward fully autonomous software development with its 'Prompt to Prod' initiative, led by Senior Director Andrew Swerdlow. The company uses AI agents for code review and experiment authoring, achieving a 68-70% acceptance rate on AI suggestions. By mining institutional knowledge from 700,000 pull requests and implementing layered security, Roblox aims to reduce human touchpoints and accelerate development while managing risks.

Aug 24·59 min read
Funding

XPENG Robotics Raises Over $900 Million in Record Embodied AI Round

XPENG Robotics has raised over $900 million in its first external funding round, valuing the humanoid robot unit at over $6.3 billion. The round, led by IDG Capital with participation from Gaorong Ventures and strategic backing from Tencent and Alibaba, marks the largest single-round private financing in China's embodied AI industry. Funds will support R&D, mass production of the IRON humanoid robot, and global expansion.

Aug 24·6 min read