OpenAI has added a feature to ChatGPT's Mac app that lets the assistant read and act on your iMessage conversations, pulling in contacts, message history, and context to answer questions or draft replies. For anyone using a work Mac to text clients, vendors, or employees, that convenience now comes bundled with a data-exposure question worth pausing on.
The feature works by granting ChatGPT permission to access the Messages app on macOS, similar to how you'd grant any app access to your calendar or photos. Once enabled, the assistant can search past conversations, pull up contact details, and use that information to help draft responses or summarize threads. It's part of a broader push by OpenAI to make ChatGPT feel less like a chat window and more like an operating layer across your Mac.
This isn't the first time an AI assistant has reached into personal communication data. Apple's own Intelligence features already touch Messages for smart replies and summaries, and Google's Gemini has similar hooks into Gmail and Android texts. What's different here is that ChatGPT is a third-party app requesting system-level access, not a feature built by the phone or computer maker itself. That distinction matters for how the data is handled, stored, and potentially used to train future models.
OpenAI has stated that data accessed through this feature is subject to its standard privacy controls, and users can opt out of having conversations used for model training. But the permission itself is broad: once granted, the app can see message content involving anyone in your contacts, including people who never agreed to have their texts processed by an AI system.
The pattern here follows a familiar script in consumer tech. A feature launches as an opt-in convenience, adoption climbs because the utility is real, and only later do enterprise IT teams and privacy regulators start asking pointed questions about default settings and data retention. Slack's early file-sharing permissions, Zoom's initial data-handling practices, and browser extensions with excessive permissions all followed similar arcs โ quiet rollout, quiet adoption, then a reckoning once someone audits what data actually left the building.
For small businesses, the practical risk isn't hypothetical. If an employee's Mac has both a personal Messages account and business-related contacts synced through iCloud, granting ChatGPT access doesn't discriminate between the two. Client phone numbers, informal business negotiations conducted over text, and even two-factor authentication codes sent via SMS could all become visible to a system your company never explicitly vetted or approved.
This is particularly relevant for businesses in regulated industries โ healthcare, finance, legal services โ where client communication is subject to confidentiality rules regardless of what app it passes through. An AI assistant reading a text thread with a patient or client could trigger compliance issues even if no data breach occurs, simply because the access itself may violate data-handling agreements.
The practical move this week is to check whether any work-issued Macs have this feature enabled, and if so, decide as a business โ not as individual employees โ whether it should be. IT policies that already restrict app permissions on company devices should be updated explicitly to name AI assistants, since older mobile device management rules were written before tools like ChatGPT could request this kind of access.
Watch for how OpenAI handles opt-out defaults as this rolls out more broadly, and whether Apple issues any guidance or restrictions on third-party AI apps accessing Messages at the OS level. Also worth tracking: whether competitors follow with similar integrations, which would suggest this becomes a standard feature rather than an outlier.
The bottom line is that this feature is genuinely useful for personal productivity, but it blurs the line between personal and business data on shared devices. Companies that haven't updated their app-permission policies for the AI era have a gap worth closing now, before an employee grants access without thinking twice about who else is in their contact list.