OpenAI launched a ChatGPT plugin for Apple's Messages app on Mac on August 20, giving the AI the ability to read, search, summarize, and draft messages from iMessage, SMS, and RCS. The rollout has drawn sharp criticism from privacy researchers, who say the tool exposes conversations of people who never agreed to participate.
The plugin works inside ChatGPT Work and Codex and requires Apple Silicon Macs. It asks for permissions including Full Disk Access, contacts, and automation. By default, the plugin asks the user for approval before sending a message, but it can access years of Messages history synced through iCloud. Neither Apple nor OpenAI notifies the other party in a conversation that the plugin is active, and there is no way for that other party to revoke access.
A Backdoor Built by the User
Privacy researcher Paul Walsh, who helped create an early W3C standard for content labeling, compared the plugin to a backdoor. "This is a backdoor, but it's built by the user, not the government," Walsh said. His argument centers on the fact that the plugin exposes messages from someone who never consented and may not use Apple devices or ChatGPT at all.
The concern is not hypothetical. Apple began rolling out end-to-end encrypted RCS between iPhone and Android in May, meaning conversations that were previously less protected are now encrypted. The plugin can still read those chats on the Mac where it is installed, regardless of the other party's wishes. That access cuts against Apple's privacy reputation, which has long been built on encryption that Apple itself cannot read.
The Shadow Profile Parallel
The mechanic is familiar to anyone who has followed Facebook's history. For over a decade, Facebook has built shadow profiles, which are records of non-users assembled from contact lists uploaded by users. Mark Zuckerberg confirmed the practice in 2018 congressional testimony. Facebook later added a tool for non-users to request deletion of data others had uploaded, but the company never eliminated contact uploading.
The through-line is the same: one person's choice to share data can expose someone else who never got a say. ChatGPT's Messages plugin runs on that same logic, applied to conversations instead of contacts. Critics argue the plugin is a privacy test for Apple's brand, a framing that Bloomberg also used in its coverage of the rollout.
Regulatory Precedent
There is precedent for regulators punishing this kind of data handling. In 2021, Ireland's Data Protection Commission fined WhatsApp €225 million for failing to disclose how it shared data with other Facebook companies. The fine was one of the largest penalties under GDPR to date. Meta, the parent company of both Facebook and WhatsApp, has faced repeated scrutiny over its data practices, yet the contact uploading mechanism still runs today.
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
The WhatsApp case shows that regulators can act when data sharing is opaque. The new plugin, however, operates through standard macOS permissions rather than any consent screen from Apple. That distinction matters because Apple's own documentation for ChatGPT with Apple Intelligence describes a narrower integration that asks users before information is shared. The new Mac plugin is distinct from that integration and does not use Apple's consent screen.
OpenAI's Defense and the Remaining Problem
OpenAI says the plugin runs locally and does not index all messages. The company says it only pulls content when asked, and sending is gated by approval unless the user turns that off per conversation. OpenAI itself recommends against turning off approval. Those safeguards address some technical concerns, but they do not solve the consent problem.
The other party in a conversation has no way to know the plugin exists, no way to object, and no way to revoke access. Even if the plugin never sends a message without approval, it can still read, search, and summarize entire threads. That means a user could ask ChatGPT to summarize a group chat that includes people who have never heard of the plugin.
Two Readings of the Same Plugin
Some coverage frames the plugin as a straightforward convenience win. A user can ask ChatGPT to draft a reply, find an old address, or summarize a long thread. Others see a company asking users to hand over private conversations of everyone they have ever texted without their knowledge. Both readings describe the same plugin.
The question worth asking is whether anyone asked the other side of the conversation first. The plugin's access to end-to-end encrypted chats with parties who never consented is a major privacy concern, and it challenges the trust Apple has cultivated around its messaging ecosystem. Apple's privacy reputation is built on encryption Apple itself cannot read, yet this plugin can read what Apple cannot.
The plugin was published on August 20, and the analysis here was published on Aug 24, 2026. The timing matters because Apple's RCS encryption rollout in May was meant to strengthen user privacy, and the plugin arrives only months later. OpenAI has not said whether it plans to add notification or consent features for non-users. For now, the plugin sits on Macs with full access to years of private conversations, and the people in those conversations never got a vote.

