A professional texts a client something sensitive — a pricing figure, a contract detail, a candid read on a deal. Somewhere in that exchange, an AI assistant has already read the thread, searched the history, and is ready to draft the reply. That’s not a hypothetical anymore. As of August 2026, ChatGPT on Mac can read, search, summarize, draft, and send Apple Messages, according to Bloomberg. The access it requires is broader than most users will expect.
The Permission Problem Is the Story
Enabling this integration isn’t a single checkbox — it’s a sweeping set of system-level concessions that extend well beyond your message threads.
Enabling this feature requires Full Disk Access, Contacts access, and Automation permissions, according to Engadget and Bloomberg. Full Disk Access — per Apple’s own support documentation — exposes data across multiple protected areas of a Mac, not just the Messages folder. That’s not a minor concession buried in a settings screen; it’s the entry fee.
Here’s exactly what gets granted:
- Full Disk Access: Exposes protected data across your Mac, well beyond Messages alone, according to Apple’s documentation.
- Contacts permission: Required for ChatGPT to resolve names and addresses in Messages workflows; macOS demands explicit user authorization for this access.
- Automation permission: Allows ChatGPT to operate the Messages app on your behalf, including sending texts.
- Message history access: The tool reads on-device conversation history to search and summarize threads, per Bloomberg reporting.
- Sending capability: ChatGPT can dispatch messages; OpenAI reportedly defaults to per-send confirmation, according to Forbes — but that’s a setting, not a structural safeguard.
Bloomberg reported in August 2026 that ChatGPT can read and send messages on a Mac — a capability the outlet described as having the potential to raise significant privacy concerns for Apple.
The Business Risk Nobody’s Talking About
For anyone using Messages in a professional context, this feature introduces risks that most IT policies aren’t yet equipped to address.
Consider the workplace Mac user relying on Messages for client communication or internal coordination. Enabling this casually puts that person in genuinely uncharted territory. An employee switching this on without IT sign-off could expose client names, meeting logistics, or sensitive threads — with zero visibility to anyone managing security. That’s not paranoia; that’s a plausible Tuesday afternoon.
OpenAI says the plugin runs locally and doesn’t build a full message index, per Bloomberg and Computerworld. Local processing is meaningfully less alarming than a cloud-based approach. But local doesn’t shrink the permission footprint. Granting Full Disk Access is like handing a houseguest a master key because they occasionally water your plants — the key doesn’t disappear when the plants are fine. This kind of broad software permission mirrors risks documented in cases involving a surveillance app built to exploit similar access.
One prior incident makes this harder to dismiss: OpenAI’s Mac app previously stored chat histories in plain text before issuing a patch, according to Macworld and TechRadar. Apple has faced its own data-exposure issues, including confidential files exposed via iCloud to former employees.
The feature may genuinely save time. But useful and safe aren’t synonyms. Before clicking Allow, decide whether Full Disk Access is a trade worth making — because permissions granted in a hurry rarely get reviewed carefully later.






























