This is one outlet's own report from Fortune — the article as it was filed.
AIPROPX ReportFortune · 2h ago
ChatGPT can now search years of your texts—but security experts are most worried about the people who never opted in
ChatGPT no longer has to wait for people to copy and paste their texts into the chatbot. Now it can search for them itself.
A new Apple Messages plugin lets ChatGPT search old texts, summarize group chats, draft replies, and send messages from a Mac. The person installing it has to approve the access—but everyone else in those conversations does not.
That is opening a new front in the privacy and security debate about AI agents as they gain access to increasingly sensitive parts of people’s digital lives. Security and privacy expert Paul Walsh calls the Messages integration “one of the most dangerous things I have seen in technology” and warns it can function like spyware for people who depend on private communications.
But according to OpenAI, the plugin runs locally by default, only reads Messages when a user explicitly asks it to, and does not automatically upload or index a user’s message history. But one person’s decision to opt in can make years of conversations searchable by AI, including messages from people who never agreed to give it access.
Explaining what would happen if he enabled the integration himself, Walsh told Fortune : “Every single person I send a message to through iMessage will never know that I have a third party inside that application, and they will never be notified.”
For people who deliberately use encrypted messaging for sensitive conversations, he said, “it becomes dangerous.”
OpenAI rolled out the plugin last week for ChatGPT on Mac, allowing users to search iMessage, SMS, and RCS conversations, catch up on threads, draft replies, and send them through Apple Messages. Users must explicitly install the plugin and grant ChatGPT several macOS permissions, including AppleScript, Accessibility, and Full Disk Access.
According to OpenAI, ChatGPT does not create an index of a user’s Messages or begin reading conversations simply because the plugin has been enabled. The company added that a user must make a request that specifically seeks information from Messages before ChatGPT will access them.
Walsh’s concern isn’t that ChatGPT has cracked Apple’s end-to-end encryption. Instead, it centers on what happens after an encrypted message reaches its intended recipient and becomes readable on that person’s Mac. He compares giving ChatGPT that access to installing spyware, arguing the encryption itself can remain intact while another piece of software gains access to the readable messages.
“Let’s say we agree it’s encrypted. Perfect mathematics hasn’t been broken,” Walsh said. But once another system can read a message before it is encrypted or after it has been decrypted, he said, “you have broken the fundamental concept.”
When private messages become searchable
The ability to share a private message with a third party isn’t completely new. Someone can screenshot a text, forward it, or copy and paste it into ChatGPT. What changes with the Messages plugin is how easily an AI can search information across conversations once a user grants it access.
Walsh argues that distinction matters because the person granting the access isn’t the only person whose information appears in those conversations.
“That’s you breaking that person’s trust,” Walsh said in reference to taking a screenshot. “It’s not you allowing a third party inside the conversation.”
Dave Richardson, CTO at mobile security company Lookout, told Fortune he could understand why some might compare the integration to spyware, though he believes the term is “a little too strong.” Spyware typically accesses and steals information without a user’s permission, he said, while the Messages feature is off by default and requires users to explicitly grant access.
Still, Richardson said enabling the integration introduces “significant risk” to what has historically been considered a secure channel for communication.
End-to-end encryption protects a message as it travels between devices, Richardson explained, preventing the network operator or platform provider from reading or modifying it. But the devices on either end can still access the message once it arrives.
“By granting third parties such as OpenAI or Anthropic access to these messages, you’re losing many of the benefits that end-to-end encryption has to offer,” Richardson said.
Privacy-focused technology company Proton raised similar concerns in an analysis published Tuesday, warning the privacy implications can extend to people who never use ChatGPT because their messages can still be accessed when someone they communicate with uses the plugin. Proton also pointed to Full Disk Access, one of the macOS permissions required during setup, as a broader security consideration.
OpenAI says Messages stay local by default
There are important limits to how much access the integration gives OpenAI.
ChatGPT only reads Messages after a user makes a request that specifically requires information from them, according to the company. Asking ChatGPT to summarize messages from a conversation with a particular contact, for example, would cause it to read that thread.
ChatGPT desktop stores conversations locally on the user’s computer by default, according to OpenAI. Messages content included in those conversations is therefore not automatically synced to the company’s servers. If a user chooses to store a ChatGPT conversation in the cloud, however, relevant Messages content follows the same retention policies as other content in that conversation. Conversation data may remain in cloud storage until a user deletes it and may also inform Memories stored in the cloud.
That distinction is central to Walsh’s most serious warning. He argues that if content from an encrypted conversation is stored on another company’s servers, it could create another potential point of access for hackers, insiders, governments, or law enforcement.
Walsh describes that as a potential “side door” around end-to-end encryption rather than a technical break in the...
AIPROPX is an independent multi-source news index — we track, compare, and connect coverage from across the web into one place you won't find anywhere else.