Quick Facts

  • OpenAI released an Apple Messages plugin for ChatGPT’s macOS desktop app on Aug. 20, 2026, enabling the AI to read, search, and send iMessage, SMS, and RCS texts.
  • The plugin works only on Apple Silicon Macs and functions within ChatGPT Work and Codex modes, not standard chat or web interfaces.
  • The launch came weeks after Apple sued OpenAI in July 2026 for alleged trade secret theft.

OpenAI shipped a new plugin on Aug. 20 that lets ChatGPT read and send Apple Messages from a Mac. The feature covers iMessage, SMS, and RCS conversations and is available to all ChatGPT subscription tiers, including free accounts.

The plugin runs inside ChatGPT Work and Codex, the agentic modes OpenAI has been building throughout 2026. It does not appear in standard ChatGPT chat windows, and it does not work in the web app, mobile apps, Codex CLI, or IDE extensions.

What It Does

Users can ask ChatGPT to suggest replies, draft and send messages, delete threads, or search message history. Because Apple’s Messages app syncs across devices, texts sent from a Mac through ChatGPT appear on connected iPhones and iPads.

The plugin uses AppleScript and macOS Accessibility tools to control the Messages app directly. OpenAI says all processing happens locally. Message content is not sent to or stored on OpenAI’s servers.

Setup requires granting Full Disk Access to the ChatGPT desktop app. The plugin is restricted to the Apple Silicon arm64 build, which excludes Intel Macs.

Privacy and Security Risks

By default, ChatGPT asks for user approval before sending any message. OpenAI warns users not to enable persistent approval, writing that doing so “removes your final chance to review a message before ChatGPT sends it as you.”

Once users grant the required permissions, ChatGPT has access to their full message history. Contacts whose messages are analyzed never consented to that access. End-to-end encryption protects iMessages in transit, but it does not block software the user has authorized to read local data.

Security researchers have flagged prompt injection as a specific risk. A malicious text could instruct ChatGPT to send messages without the user’s intent, particularly if persistent approval is enabled.

Enterprise Angle

OpenAI has told investors that enterprise revenue has overtaken its consumer business. The plugin’s integration with Codex and ChatGPT Work gives it a professional use case, letting workers manage communications through the same interface they use to produce documents and code.

That positioning raises questions for IT departments. A tool with full disk access and messaging rights on a work machine presents a policy decision for any company running ChatGPT Work on corporate hardware.

OpenAI co-founder Ari Weinstein posted on X that the integration “can also analyze your messages” and called it “really fun to get insights about who you talk to, and what you talk to people about.” That framing will likely draw scrutiny from compliance teams at regulated companies.

The release date carries significant weight. Apple sued OpenAI in July 2026 for alleged trade secret theft, accusing the company and its Chief Hardware Officer Tang Tan of a coordinated effort to extract confidential product information. Apple says more than 400 former Apple employees now work at OpenAI and alleges Tan coached departing staff on how to avoid Apple’s security procedures.

The two companies entered a high-profile partnership in 2024, when ChatGPT was integrated into Apple Intelligence on the iPhone. Apple has not said whether the lawsuit will affect that arrangement. OpenAI said it has “no interest in other companies’ trade secrets.”

ChatGPT reached approximately 1 billion weekly active users in July 2026. Android and Windows users have no equivalent messaging integration yet.

Read more: ChatGPT can now send texts for you with new Apple Messages plug-in

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.