OpenAI Ships Read, Draft and Send Access to Apple Messages

OpenAI has released a native ChatGPT plugin that lets the assistant read, search, draft and send Apple Messages conversations directly from the ChatGPT desktop app on a Mac. The plugin covers iMessage, SMS and RCS threads, and it works only on the Apple Silicon build of the app, so Intel Macs are excluded for now. It ships across ChatGPT plans in the desktop app, including the business-oriented Work and Codex tiers, and 9to5Mac and MacRumors both reported the rollout on 20 August 2026.

Turning it on means granting three macOS permissions: automation, access to Contacts, and Full Disk Access. Those are broad grants by design, because the plugin needs to see message content to search and summarise it, and it needs contact names to address a reply correctly. OpenAI's own plugin documentation describes the feature as running locally on the Mac, with no remote access to Messages through the assistant.

Once installed, a person can ask ChatGPT to find a message buried in months of chat history, summarise what a group thread agreed on, or draft a reply in a particular tone. The assistant can then send that reply itself, through the Messages app, using the sender's own identity. That last step, composing and dispatching a message as the user, is the part that changes the risk profile of installing ChatGPT on a company laptop.

Approval Is the Only Brake, and It Can Be Switched Off

A single approval prompt stands between ChatGPT drafting a message and that message reaching a real person's phone. By default, OpenAI's system asks for confirmation before every send, showing the recipient and the text so the user can catch a mistake before it goes out. That default is the entire safety design: there is no second check, no delay, no review by anyone else.

Users can weaken that default. Selecting 'Always allow sending to this chat' removes the per-message prompt for a specific conversation, and OpenAI's own documentation warns that doing so gives up the user's last chance to review a message before it goes out under their name. The company recommends keeping per-send approval active for any chat that might contain misleading or manipulated instructions, an acknowledgement that the model can be steered by content it reads.

That warning matters because the plugin's read and send functions share the same channel. A message the assistant is asked to summarise could, in principle, also contain text aimed at the assistant itself, and the only thing standing between that text and an outgoing message is whichever approval setting the user happens to have chosen weeks earlier and forgotten about.

Why Send Access Changes the Calculation for a Business

Every mainstream AI assistant that has shipped on a work device until now has been a read-and-suggest tool, not a send tool. Copilot drafts an email a person still has to click Send on; a chatbot summarises a document but does not file it. ChatGPT's Apple Messages plugin crosses that line: once a chat is marked 'Always allow', the assistant can dispatch a real message, under a real employee's name, to a real client or colleague, without a human reading it first.

The data the plugin touches is exactly what a business would want protected: full message history across personal and work contacts, the contact list itself, and the pattern of who talks to whom and when. Full Disk Access is a broad macOS permission, and granting it to any application, let alone one that also has the ability to act, is normally the kind of decision that goes through an approval process, not a one-click plugin install.

None of that makes the feature reckless on its own; the approval gate is a real control, and OpenAI has documented the risk of removing it in plain language. What it does mean is that a permission-gated AI agent with the power to send messages as an employee has landed on the exact device fleet that IT and security teams are responsible for, and it arrived through a consumer app update rather than a procurement conversation.

What a Business Should Actually Do Before Employees Turn It On

A written stance needs to exist before this plugin appears on a managed Mac, not after. Security and IT teams should decide, through their MDM platform, whether the ChatGPT desktop app is permitted to request Full Disk Access, Contacts access and Automation privileges at all, and whether that decision differs for a personal BYOD Mac versus a company-issued one.

Where the plugin is permitted, the sane default is to require per-message approval as a standing policy and to treat 'Always allow sending to this chat' as something only a named risk owner can authorise, not an individual employee's convenience setting. Guidance to staff should be explicit: never let the assistant send on a client-facing or contractual thread without reading the draft first, and never grant persistent send access to a group chat with mixed personal and work contacts.

The employees most exposed are the ones who never read the permission dialog at all, so the policy has to travel with the software, not sit in a document nobody opens. A short internal notice, sent before the update reaches company Macs, costs far less than the first message a client receives that nobody on the team actually meant to send.