OpenAI's new Apple Messages plugin gives ChatGPT access to the Messages application on a Mac. Once enabled, users can ask ChatGPT to find conversations, summarize them, draft replies, and send messages.
That has understandably raised questions about what it means for iMessage privacy. The starting point is understanding what the plugin does and, just as importantly, what it doesn't do.
The OpenAI plugin doesn't break iMessage's end-to-end encryption; it’s accessing messages after they have been decrypted on an authorized device. That's a capability applications have had in various forms for years.
What this plugin is changing is the accessibility and scale of that access. ChatGPT puts the ability to search, extract, and analyze potentially years of messaging history into a tool used by hundreds of millions of people. This functionality previously required a user to manually copy messages, export data, or use specialized software. But now, they can accomplish this conversationally with AI.
That has some important implications for privacy and security.
End-to-end encryption is designed to prevent intermediaries from reading a message as it travels between participants. The message is encrypted on the sender's device and decrypted on an authorized recipient's device.
Once it reaches that endpoint, however, it has to become readable. Otherwise the recipient couldn't read it either.
That's where the Messages plugin operates. On an Apple silicon Mac where the user has granted ChatGPT the necessary permissions, ChatGPT can access conversations available through Messages, including iMessage, SMS, and RCS. OpenAI says the plugin operates locally and doesn't maintain its own separate index of those messages.
So the encryption is doing exactly what it is supposed to do. The privacy issue begins after decryption.
This is where security and privacy become a practical matter. You may have chosen iMessage specifically because you trust its end-to-end encryption. But every conversation has at least one other endpoint, and you don't control what happens there.
Someone you communicate with could give ChatGPT access to Messages and ask it to find every conversation you've had about a particular topic, summarize everything you've told them over several years, or extract specific information from those conversations.
They could always have done versions of this manually. They could copy and paste a message into ChatGPT, forward it, take a screenshot or export their message history.
What is changing in a meaningful way is that there is no longer any friction to accomplish this. Capabilities that once required enough knowledge and effort that relatively few people used them can now become routine because they're reduced to a prompt.
And the other participants in those conversations have no visibility into whether that is happening on any of the endpoints in their network.
The next question is what happens when information from Messages is actually used in a ChatGPT interaction.
For consumer ChatGPT accounts, OpenAI says conversations may be used to improve its models unless the user turns off "Improve the model for everyone." Temporary Chats aren't used for training. OpenAI says data from ChatGPT Business, Enterprise and its API products isn't used for training by default.
That doesn't mean your private messages suddenly become publicly searchable or that another ChatGPT user can simply ask for them.
But there is still a significant change in how the data is handled. Information that originated inside an end-to-end encrypted conversation can be submitted to another company for processing and, depending on the user's account and settings, potentially used to improve the model.
The person whose messages are being processed may have no idea that has happened and no ability to control the ChatGPT settings of the person at the other end of the conversation.
Of course, as we have found in many other instances, what giant cloud providers say they’re doing in a lawful, compliant fashion is not always what they’re actually doing, so whether or not users should fully trust these claimed constraints and mechanisms is another topic. As the saying goes, let the buyer beware.
For governments and organizations operating under data-sovereignty requirements, or anyone with data-sovereignty concerns, there is a separate issue.
End-to-end encryption is attractive partly because it reduces the number of third parties that can access message content. If decrypted message content is subsequently provided to OpenAI, that trust model changes.
OpenAI is a U.S. company and is subject to valid U.S. legal demands for information within its possession, custody, or control. Under the CLOUD Act, U.S. service providers can in certain circumstances be compelled to produce data they control even when that data is stored outside the United States.
That doesn't provide the U.S. government with unrestricted access to ChatGPT data. Legal process still applies. But organizations using encrypted communications specifically to limit exposure to foreign jurisdictions need to consider what happens when users introduce another service provider into the information flow.
The question isn't simply where the original iMessage was encrypted or stored. It is where the information goes after somebody asks an AI system to do something with it.
In this era of increasing geopolitical conflict and the breakdown of legal rationales to safeguard privacy agreements between countries, whether users or organizations believe they can afford to trust governments to abide by the constraints of “valid” legal demands can’t be ignored.
For IT and security teams, this is also another reason to pay attention to how employees use consumer messaging applications for work.
Read more on what risks are hidden in digital collaboration.
Sensitive business communication already spills into iMessage, WhatsApp, Signal and other channels that may sit outside corporate governance. Employees discuss customers, incidents, projects, personnel matters and other business information through applications that most corporate security teams don't monitor or control.
Now consider what happens when an employee uses a personal Mac to give an AI application access to those conversations. Or when an external party in that employee’s messaging network, such as a business partner or client, does the same.
Information can move from a corporate system into a personal messaging application, onto an employee or externally controlled endpoint, and potentially into an external AI service. Along that path, it can bypass corporate controls for data loss prevention, retention, auditing and approved AI usage.
OpenAI's Messages plugin hasn't created that problem. It has made one part of the path considerably easier to use.
That's the larger security implication. End-to-end encryption remains an important protection, but it can't govern what happens to information after it reaches an authorized endpoint. As AI becomes more deeply integrated into the applications people use every day, organizations increasingly have to secure not only how information gets somewhere, but what can happen to it once it arrives.