OpenAI on Thursday introduced a new ChatGPT plugin for Mac that can read, search, draft, and send messages through Apple’s Messages app, a move that puts the AI company directly into the iPhone maker’s tightly controlled messaging ecosystem and is likely to raise fresh privacy questions.

The feature, available across all ChatGPT plans in the desktop app for macOS, works with iMessage, SMS, and RCS conversations. It also functions inside ChatGPT Work and Codex, meaning users can deploy it for professional workflows, not just personal chats. By default, ChatGPT sends messages only after a user approves both the content and the recipients, but OpenAI warns that enabling persistent approval removes the final review step before a message goes out.

Apple has long marketed itself as a privacy-first company and has historically been protective of the contents of users’ messages. An OpenAI tool with the ability to access Apple customer data and send texts on a user’s behalf is therefore likely to attract scrutiny from both Apple and privacy advocates. An Apple representative did not immediately respond to a request for comment.

The rollout lands at a moment of unusual tension between the two companies. Apple sued OpenAI last month, accusing the AI provider of misappropriating information about unreleased products. Against that backdrop, the new Messages integration represents a direct encroachment on Apple’s software territory.

OpenAI said the plugin runs locally on the Mac and relies on existing operating system tools such as AppleScript and Accessibility to interact with the Messages app. The company also emphasized that it does not create an index of all of someone’s messages and that access requires explicit user consent.

Setting up the integration involves several opt-in steps. When a user first enables the feature, a permissions screen appears in ChatGPT stating that the computer’s on-device message history will be accessed. Users must also change privacy-related preferences within macOS System Settings, including enabling Full Disk Access, and grant ChatGPT permission to access contact names and automation tools. The setup resembles what is required for popular AI-based automation software such as Codex Computer Use.

OpenAI’s plugin guide details the risks of persistent approval, how to revoke access, and a known issue involving tasks that disable approval prompts. The feature currently works only on Apple silicon Macs, not Intel machines.

Beyond the Messages plugin, the latest ChatGPT update includes several other improvements. Pinned chats now sync across the desktop app and iOS, users can share read-only snapshots of local Codex threads, and Site owners can invite workspace members to co-edit content. OpenAI also expanded its Computer History feature to Pro, Business, and Enterprise users in the European Economic Area, Switzerland, and the UK.

The Messages integration also threatens to step on the turf of Apple’s upcoming Siri AI, which is designed to comb through users’ messages and other on-device content. That capability has been viewed as a potential competitive edge for Apple over third-party chatbots. Apple has previously moved to shut down similar attempts to expand access to iMessage, most notably blocking Beeper Mini, an app that brought iMessage functionality to Android devices.

The new plugin arrives as OpenAI continues to broaden ChatGPT’s reach across platforms and business models. The company has been expanding its advertising platform into dozens of European markets and has signaled plans to introduce ads to users in India, while keeping higher-priced subscription tiers ad-free. OpenAI has also launched a dedicated ChatGPT for Teens experience aimed at users aged 13 to 17, with study-oriented features and parental oversight tools.

For Apple, the development presents a delicate situation. The company has positioned privacy as a core brand value, yet OpenAI’s plugin requires users to grant deep system-level permissions that could allow message data to be processed by an outside AI provider. While OpenAI says processing happens locally and does not involve building a central index of conversations, the practical privacy implications will depend on how much data actually leaves the device during normal use.

The integration also highlights a broader shift in how AI assistants are beginning to operate across operating systems. Rather than waiting for platform owners to build native AI features, third-party developers are increasingly using existing automation frameworks to gain access to core apps. That approach can accelerate feature availability but also raises questions about security, consent, and the long-term control platform owners have over their own ecosystems.