OpenAI quietly shipped one of the more consequential integrations of the year in late August: ChatGPT on Mac can now search your Apple Messages, draft replies, and send texts on your behalf. It’s currently limited to ChatGPT Work and Codex subscribers, but it’s a clear signal of where OpenAI wants ChatGPT to live — not as a tab you visit, but as something embedded in the tools you already use all day.

If you’re running a business, managing a team, or just trying to keep your own digital footprint sane, this is worth ten minutes of your time. Not because it’s a gimmick — it’s genuinely useful — but because of what it exposes, quite literally, about how these integrations are built and approved.

What OpenAI Actually Shipped

The feature works through a Messages plugin you attach inside a ChatGPT chat on a Mac. Once it’s connected, you can ask ChatGPT things like “check my unread iMessages and text myself a recap of what needs attention,” and it will scan your threads, pull out deadlines and action items, and reply through your own Messages app — as you, from your own number.

To get there, you need:

That’s a deliberately high bar. OpenAI has said the plugin doesn’t build a standing index of your texts — it only reads when you actively prompt it — and it can’t send anything without you approving the drafted message first. You also choose the access scope per conversation: one-off, for the session, or ongoing.

On paper, that’s a reasonably well-designed permission model. Multiple explicit approval steps mean nobody is enabling this by accident, and the “smallest scope that works” guidance from OpenAI is sound advice worth taking literally.

Where It’s Actually Useful

Set the hype aside and the practical use case is straightforward: message triage. If you’re the kind of operator who runs half your day through iMessage — clients, tradies, suppliers, staff — having something summarise a backlog of threads into “here’s what actually needs a reply today” is a genuine time saver. It slots into the same category as inbox-zero tools, just for text messages instead of email.

It also plays well with the broader trend of ChatGPT positioning itself as an orchestration layer across Slack, calendars, and now messaging — one place to ask “what am I behind on” instead of checking four apps.

For a solo operator or small team, that’s the appeal. For a business with any kind of compliance obligation, client confidentiality requirement, or shared device, it’s a different conversation.

The Part That Deserves More Attention

Here’s the bit that got glossed over in a lot of the initial coverage: this isn’t just about your privacy. It’s about everyone you’ve ever texted.

When you enable this plugin, ChatGPT gains access to years of message history synced through iCloud — not just the last few days. Every person in those threads texted you without any expectation their messages would end up readable by an AI system. They weren’t asked. They can’t revoke it. And critically, this extends to RCS conversations with Android users too, where the encryption was specifically designed to protect both sides of the exchange.

Privacy researchers have compared this to Facebook’s old “shadow profile” problem — where one person uploading their contacts exposed data about people who never signed up for the platform at all. The mechanism here is different, but the underlying issue is the same: one person’s opt-in becomes everyone-they’ve-texted’s opt-out-that-was-never-offered.

There’s also a business-continuity wrinkle worth knowing about: Apple sued OpenAI in July over alleged trade secret theft, and Apple has historically been protective of third-party access to iMessage. That tension doesn’t affect whether the feature works today, but it’s a reminder that integrations built on someone else’s platform can change — or disappear — with very little warning.

What This Means If You’re Running a Business

None of this means “don’t use it.” It means treat it the way you’d treat any tool that touches client or staff communications, because that’s what it is.

A few practical takeaways:

Keep it off shared or company-issued Macs by default. This is a personal productivity feature, not a team deployment. If someone on your team wants to trial it, that’s a conversation about company policy first, not an IT support ticket after the fact.

Think about who’s in your threads before you enable anything like this. If your text history includes clients, patients, or anyone covered by a confidentiality agreement or privacy obligation, that’s a real consideration — not a hypothetical one.

Scope access deliberately, every time. OpenAI’s own advice — smallest scope that works — is the right default. Session-only access beats permanent access in almost every real-world case.

Expect more of this, not less. iMessage is the first mainstream messaging app OpenAI has plugged into this deeply. It won’t be the last. Getting your team’s policy sorted now, before there are five of these integrations to think about, is a lot easier than retrofitting one after something goes wrong.

The Bottom Line

This is a well-built feature with a genuinely useful purpose, and the permission model behind it is more thoughtful than most. But “well-built” and “right for your business” aren’t the same question. If you’re weighing up how AI tools like this fit into your workplace — where the real risk sits, and where it doesn’t — that’s exactly the kind of assessment worth getting a second opinion on before you roll something out.


If you want a straight-talking read on how AI tools like this actually stack up for your business, get in touch or have a look at what we offer.

← Back to Blog Browse All Guides