OpenAI recently dropped a macOS update that turns ChatGPT into your personal text-messaging proxy. With Full Disk Access enabled, it can read, search and parse your entire Apple Messages history, draft follow-ups or send messages from your Mac.
Unsurprisingly, the initial hot takes focus on user caution: do you really want an AI reading your texts? But framing this as an individual choice misses the point. This isn’t a privacy trade-off for the person who clicked “allow” – it’s a non-consensual data grab for every contact on the other end of the line.
The Missing Consent Factor
For most people, iMessage’s end-to-end encryption means one thing: nobody outside the chat can see what you wrote. That promise is why many Apple users stick around. The new ChatGPT plugin politely asks for the keys to that chat once the message arrives on your Mac.
The moment one participant toggles on Full Disk Access, ChatGPT can index, search and digest the entire thread on their Mac – including every message sent by third parties. People who have never touched an OpenAI product, granted permissions or intended to share their words are then exposed. There are no alerts sent out and no privacy toggles to flip. Their only choices are leaving the chat or convincing the Mac owner to revoke the plugin.
OpenAI’s public statements focus on the enabling user’s control and note that the plugin doesn’t give ChatGPT access to conversations on other devices. But on the enabling user’s device, the other person’s messages are part of the local archive that ChatGPT can now analyse.
The opt-in is per device, not per conversation and not per contact. Everyone who has ever sent a message to that device has had their words included in the dataset, regardless of whether they know it.
More from Cybersecurity
- Vega Introduces Detection Skills A New Open Standard For AI Reasoning in Agentic Cyber Defence
- OpenAI Launches Private Misuse Tracking – How Can It Detect Misuse Without Storing Sensitive Enterprise Data?
- Premier League Clubs Face £100,000 Fines Under New Mandatory Cybersecurity Rules
- Schools And Universities Are Now The Most Hacked Organisations In The World
- France’s Tax Agency Lost 678,000 Accounts To A Cyberattack – How Will SaaS Fight AI-Accelerated Breaches?
- How RuView Tracks Human Movement And Breathing Without Cameras – Is Your Home Already Watching You?
- Zero-Day Attacks: What Happens When Hackers Find A Flaw Before Anyone Can Fix It?
- Trump Greenlights Private Tech Firms To Join The Fight Against Cybercriminals
Why the Enterprise Risks Are Far Worse
Individual privacy is only part of the story. The corporate fallout is far more important, coverage has largely ignored the enterprise exposure.
Managed Mac users running ChatGPT Work often hold message histories that blur the line between personal and professional communication. Because iMessage stores client discussions, team chats, investor updates and casual banter in one local database, the plugin reads and indexes every item without distinction. OpenAI hasn’t published clear guidance on how administrators should treat Messages data in the context of ChatGPT Work. It’s also unclear whether any technical controls limit the plugin’s ability to process personal iMessage history on company-managed devices.
This creates a second consent problem that goes beyond the individual user. External contacts messaging a corporate machine have no idea their texts are being fed into an enterprise AI tool. Whether it’s a client discussing a deal or a friend sharing a quick update, their words enter a managed company workflow without their knowledge or approval.
In environments where ChatGPT Work is encouraged or mandated as a productivity tool, employees may be enabling a feature that exposes their personal contacts’ messages to systems governed by corporate policy, without either party knowing.
Why Agentic AI Breaks Modern Consent Models
This isn’t just an OpenAI or iMessage vulnerability – it’s a flaw in the wider agentic AI rollout.
Giving an AI assistant the green light to scan local machine archives like email, calendars or messaging apps means it inevitably processes third-party data at scale. Legacy consent models are unprepared for this dynamic. Opt-in systems operate on the assumption that a user only controls their own data, failing completely when one person’s setting alters the privacy of every contact in their system.
The Aura breach earlier this year was initiated through one employee’s actions that exposed hundreds of thousands of records. The ChatGPT iMessage plugin isn’t a security breach, but it follows a similar logic: one person’s decision creates exposure for people who had no part in making it. The difference is that in this case, the exposure is by design, and the people affected have no way of knowing it has happened.
End-to-end encryption protects messages in transit. It’s always relied on an assumption that the endpoints (the devices where messages arrive) remain trusted and controlled by their participants. This plugin formalises a dangerous new category of endpoint risk. By granting an AI open, queryable access to an entire chat database via one user’s local permission, it systematically exposes third parties without sending a single alert.
