A Polymarket-adjacent tweet framing this as ChatGPT gaining access to your entire message history and texting people on your behalf went viral within hours of OpenAI's August 20, 2026 release — and the dystopian headline isn't entirely wrong, even if it skips the opt-in mechanics. OpenAI did ship an Apple Messages plugin for the ChatGPT desktop app on Apple silicon Macs. Installed from the Plugins tab and used inside Codex and ChatGPT Work, it can search, summarize, draft, and send iMessage, SMS, and RCS texts — after you grant macOS permissions that include Full Disk Access.
The reaction tracks a pattern explainx.ai has covered before: each new agent permission surface lands as a product feature and a privacy flashpoint at the same time. Sam Altman was still fielding backlash from his six-month "watch your screen" remarks when this plugin dropped. Messages is a sharper edge than screen capture for many users — it's credentials, medical threads, breakups, and two-factor codes in one database.
TL;DR: what people are actually asking
| Question | Verified answer (Aug 20–21, 2026) |
|---|---|
| Is this real? | Yes — listed in OpenAI's August 20, 2026 release notes and announced on the official ChatGPT account. |
| Where does it work? | ChatGPT desktop app, Apple silicon Macs only — inside Codex and ChatGPT Work, not regular ChatGPT chats. |
| Which message types? | iMessage, SMS, and RCS conversations stored locally on the Mac. |
| Do I need Plus/Pro? | OpenAI lists it on all plans; the gate is hardware (arm64) and surface (Work/Codex), not a specific subscription tier. |
| Can it send without asking? | No by default — approve content and recipients each time. Persistent per-chat approval exists but OpenAI warns against it. |
| What permissions? | Full Disk Access, contact names, and Automation for Messages — same class of gates as other Mac automation tools. |
| Does Apple endorse this? | Unknown. Reporting notes AppleScript/Accessibility access, not a first-party Apple integration. Apple and OpenAI are already in court over separate trade-secret claims. |
| Can I text ChatGPT from my phone? | No — this is ChatGPT acting on your Mac's Messages app, not iMessage-to-ChatGPT routing. |
What OpenAI shipped — and what it didn't
OpenAI's own wording is narrower than the viral tweet: "read and search iMessage, SMS, and RCS conversations and prepare or send messages through Messages." That's still a large capability — search and summarize are read powers; prepare and send are write powers — but the scope has hard boundaries worth separating from the hype.
In scope:
- Install the Apple Messages plugin from ChatGPT's public Plugins directory.
- Start a new Codex or Work session (not a standard chat).
- Ask ChatGPT to find a thread, summarize a long back-and-forth, pull a detail from an old conversation, or draft a reply.
- Send through Messages after you review content and recipients.
Out of scope (verified across OpenAI docs and reporting):
- Regular ChatGPT conversations — the plugin doesn't appear there.
- Intel Macs, web ChatGPT, mobile apps, Codex CLI, or IDE extensions.
- Texting ChatGPT from your iPhone via iMessage.
- Silent background sending — approval is the default product design.
OpenAI product lead Ari Weinstein described the release on X as a native integration of ChatGPT with Apple Messages. "Native" here means local Mac automation, not an Apple-signed API. Multiple outlets report the plugin uses AppleScript and Accessibility settings to interact with Messages — the same mechanism family as Codex computer use and other agent-control surfaces, not a new iMessage SDK from Cupertino.

Why the privacy reaction landed so hard
The tweet wasn't inventing a capability from whole cloth — it compressed a real permission trade into one scary sentence. Three separate concerns got bundled together:
-
Read scope. Full Disk Access exists because Messages history lives at
~/Library/Messages/chat.db. Any tool with that grant can query years of conversations — including codes, health results, financial threads, and messages from people who never agreed to AI processing. OpenAI says it does not build a persistent index of all messages, and the plugin runs locally, but local read access during a session is still full read access. -
Write scope. "Send texts on your behalf" is technically true once you approve a draft — and persistently true if you grant "Always allow sending to this chat." OpenAI's own documentation treats that as a security mistake: message threads are untrusted input, and standing send authority is a classic prompt-injection channel. A malicious or compromised thread could steer the agent toward sending something you didn't intend.
-
Apple's brand collision. Apple sells Messages as end-to-end encrypted and privacy-forward. A third-party agent reading that same datastore through Full Disk Access — while Apple and OpenAI are already suing each other — reads as a direct challenge to Apple's privacy story even if Apple didn't ship or approve the integration.
The dystopian framing overshoots on default behavior (approval is required; nothing runs until you install the plugin and flip macOS switches). It undershoots on second-order risk (what happens once agents with message access become normal at work, or once persistent approval feels convenient).
What to check before you enable it
If you're evaluating this as a builder or a daily ChatGPT Work user, treat it like any other high-privilege agent plugin — not like turning on dark mode.
1. Confirm you're in the right surface
This only runs in Codex or ChatGPT Work on an Apple silicon Mac with the desktop app installed. If you're looking for message help in a normal ChatGPT thread, you're in the wrong place — and if you're on Intel hardware, the plugin won't run at all.
2. Read the macOS permission prompts literally
Setup requires Full Disk Access for the ChatGPT app, plus Contacts and Automation for Messages. ChatGPT shows its own consent screen noting that on-device message history will be accessed. Those are separate from Apple's Siri-to-ChatGPT extension, which remains off by default and uses a different path.
If you've used Jessamyn West's guide to turning off unwanted AI, think of this as the inverse problem: here you're deliberately granting a broad gate, and you should know exactly which app holds it.
3. Keep send approval per-message
OpenAI's default — approve content and recipients each time — is the right posture. Do not enable persistent "always allow" for a chat unless you accept that a poisoned thread could send as you without a final human check. Revoke standing approvals under ChatGPT Settings → Computer Use if you already flipped one on during testing.
4. Separate read use cases from send use cases
Searching and summarizing old threads is a read operation with its own sensitivity (credentials, third-party privacy). Sending is a write operation with reputational and social risk. You can choose to use the plugin for retrieval tasks while still drafting sends yourself — the product doesn't force you to auto-send.
5. Assume session content may leave the Mac
OpenAI's local-processing statement covers how the plugin reaches Messages, not a guarantee that every Codex/Work prompt and model response stays on-device. If a thread contains secrets, treat the model context as a separate exposure surface from the Messages database itself. Same discipline as Claude Code permission modes: scope what the agent sees, don't assume "local plugin" means "local model."
6. Remember the people on the other end of the thread
Your contacts didn't opt into OpenAI processing their side of a conversation. Summarizing a group chat for your own recall is one thing; piping entire threads into a cloud model is a secondhand privacy decision — the same class of objection that made Altman's screen-recording comments controversial.
How this fits OpenAI's 2026 agent push
The Messages plugin is one tile in a much larger mosaic OpenAI has been assembling all year: ChatGPT Work as a long-running task agent, Codex with computer use on Mac and Windows, a public Plugins directory replacing the old app directory, and parallel safety-facing launches like ChatGPT for Teens with tighter defaults for minors.
The tension is product-level: OpenAI ships opt-in approval flows and explicit warnings on the dangerous settings, while also expanding the set of real-world surfaces agents can touch. Messages is simply the most emotionally loaded surface they've added so far.
Policy context — briefly
Federal AI safety legislation remains unlikely in prediction markets — Polymarket priced a US AI safety bill before 2027 at roughly 13% as of mid-July 2026, down slightly from earlier in the month. That doesn't make consumer messaging integrations illegal; it means private product choices and macOS permission gates are still the primary controls for features like this, not a comprehensive federal framework. Worth knowing if you're weighing whether "someone will regulate this soon" is a reason to enable it casually.
What people are asking on social
"So ChatGPT can read ALL my texts now?" Only if you install the plugin, open Codex or Work, and grant Full Disk Access. Nothing changes for users who never touch the Plugins tab.
"Is this the same as Apple Intelligence reading my messages?" No. Apple's on-device AI features run inside Apple's stack with Apple's toggles. This is the ChatGPT desktop app using automation permissions you grant separately.
"Why would anyone want this?" OpenAI's suggested prompts skew practical: find a plumber's last message, summarize a long group chat before replying, draft a follow-up you forgot to send. The utility case is real; the trust case is separate.
"Is this on by default?" No. Plugin install + macOS permissions + active Codex/Work session. Multiple opt-in layers.
Related on explainx.ai
- ChatGPT Work vs Codex: complete guide — the only surfaces where Messages works
- Sam Altman: ChatGPT watching your screen in six months — the adjacent privacy backlash timeline
- OpenAI Codex computer use on Windows and Mac — same permission philosophy, different surface
- Agent Plugins: OpenAI's open standard for agent tooling — where the Messages plugin sits in the stack
- How to disable unwanted AI features (Jessamyn West guide) — the inverse skill: knowing what's on and turning it off
- ChatGPT for Teens: Study Mode and safety controls — OpenAI's tighter defaults for a different audience
- Claude Code permission modes explained — scoping agent access on your machine
- Primary source: OpenAI ChatGPT release notes — August 20, 2026
Feature details, permission requirements, and platform support reflect OpenAI's August 20, 2026 release notes and contemporaneous reporting as of August 21, 2026. Apple did not publish a companion announcement; treat Apple's involvement as unconfirmed beyond third-party reporting. Intel Mac support, future iOS integration, and cloud retention specifics beyond OpenAI's public statements should be treated as unverified until OpenAI documents them directly.
