ChatGPT Can Now Read and Send Your iMessages on a Mac OpenAI rolled out support on August 20 for controlling Apple Messages from ChatGPT on the Mac, allowing the assistant to read, search, summarize, draft and send texts, available in ChatGPT Work and Codex on desktop. The feature requires granting Full Disk Access, Automation, and Contacts permissions, and OpenAI warns that persistent approval removes the final chance to review messages before sending. ChatGPT can now work inside Apple Messages on a Mac. That is useful, but the permission tradeoff is bigger than the convenience pitch. OpenAI has moved ChatGPT closer to your private conversations. Bloomberg reported that the company rolled out support on August 20 for controlling Apple Messages from ChatGPT on the Mac, letting the assistant read, search, summarize, draft and send texts from the Messages app. The official ChatGPT account said the Apple Messages plugin is available in ChatGPT Work and Codex on desktop. That is a narrower claim than saying every ChatGPT user gets it today. It also matters because Work and Codex are not casual toy surfaces. They are where people already ask AI agents to handle documents, code, schedules and decisions that used to sit inside separate apps. Messages is different. Your texts are where passwords get sent, arguments happen, doctors confirm appointments and customers ask the thing they won't put in an email. To make the plugin work, you grant macOS permissions that deserve a pause: Full Disk Access, Automation and Contacts. Full Disk Access is the heavy one. It lets an app reach protected local data that macOS normally keeps behind a wall, including the Messages database on the Mac. Automation is what lets software tell Messages to send something. Contacts helps ChatGPT match names to people. Keep the approval step on. Google Gemini has 900 million users and barely any of them chose it https://startupfortune.com/google-gemini-has-900-million-users-and-barely-any-of-them-chose-it/ Google Gemini has hit 900 million monthly active users and 27.9% of the AI chatbot market, but nearly all of that growth came from Android defaults and Search integrations rather than user preference. The engagement gap with ChatGPT is still wide, and for founders choosing AI stacks in 2026, the distinction between distribution and genuine... - google gemini user adoption rate https://startupfortune.com/google-gemini-has-900-million-users-and-barely-any-of-them-chose-it/ - why people stop using gemini https://startupfortune.com/google-gemini-has-900-million-users-and-barely-any-of-them-chose-it/ OpenAI's setup flow keeps one safety check by default: before ChatGPT sends a message, you see the recipient and the draft. You can allow that one send, or you can choose persistent approval for a conversation. OpenAI's own guidance warns that persistent approval removes your final chance to review a message before ChatGPT sends it as you. Read that twice. A company shipping the feature is also telling you where the dangerous button is. The permission is the story Apple Messages has never been just another chat app. Apple says iMessage is end-to-end encrypted, and in May it said end-to-end encrypted RCS was beginning to roll out in beta for iPhone users running iOS 26.5 with supported carriers. That protects messages in transit. It does not mean a Mac app with local permission can't read what is already stored on the computer. That is the gap AI agents are starting to exploit, in the ordinary sense of the word. They don't need Apple to redesign Messages. They need the user to click through permissions built for backup software and other power-user utilities. Once that happens, the assistant can become a layer over the inbox. Frankly, that is a much bigger change than a smarter reply box. A search tool that finds what your contractor said last month is helpful, and a drafting tool that writes a careful reply to a client is useful too. Fine, so far. But the same path also gives an AI system access to years of family chats, work threads and two-factor codes that were never written with an outside assistant in mind. The weak point is automatic sending The risky part is not that ChatGPT can draft a message. People have copied AI-written replies into Messages for years. The new thing is that the assistant can move from drafting to sending inside the same workflow. That last step changes the trust calculation, because a bad summary is annoying while a bad text can damage a relationship or send private information to the wrong person. OpenAI has already been explicit about prompt-injection risk in other Mac features. When 9to5Mac covered ChatGPT's Computer History feature on August 13, it noted that OpenAI warned malicious content in apps or websites could increase that risk. Messages creates a cleaner path for the same problem: an incoming text is content from someone else, and an AI agent may later read it as context for an action. Apple has not publicly explained how it views this kind of Messages access through ChatGPT. Bloomberg framed the rollout as likely to raise privacy concerns for Apple. That's the right read. The question is not whether one OpenAI plugin behaves properly on day one. It's whether this becomes the normal way AI assistants ask to sit inside personal data on the Mac. OpenAI quietly upgraded every free ChatGPT user to a smarter model and the competition should be worried https://startupfortune.com/openai-quietly-upgraded-every-free-chatgpt-user-to-a-smarter-model-and-the-competition-should-be-worried/ OpenAI's GPT-5.5 Instant is now the default model for all free ChatGPT users, cutting hallucinations by 52.5% and improving multi-turn reasoning. The move reflects intensifying competition from Google Gemini and Anthropic's Claude at the free tier, and raises questions about where the boundary between free and paid should sit as OpenAI accelerates... - free ChatGPT upgrade to smarter model https://startupfortune.com/openai-quietly-upgraded-every-free-chatgpt-user-to-a-smarter-model-and-the-competition-should-be-worried/ - OpenAI GPT-5.5 Instant default rollout https://startupfortune.com/openai-quietly-upgraded-every-free-chatgpt-user-to-a-smarter-model-and-the-competition-should-be-worried/ You can use the feature and still be cautious. Let ChatGPT search and draft if that saves time. Make it ask before every send. The convenience is real, but so is the permission you are handing over. Also read: AI Data Centers Become a $130 Billion Political Liability in 2026 https://startupfortune.com/ai-data-centers-become-a-130-billion-political-liability-in-2026/ • Ramp Launches a Free AI Model Router That Already Cut Client Costs 40% https://startupfortune.com/ramp-launches-a-free-ai-model-router-that-already-cut-client-costs-40/ • Harvey Built Its Own Legal AI Model instead of Renting One From OpenAI https://startupfortune.com/harvey-built-its-own-legal-ai-model-instead-of-renting-one-from-openai/