OpenAI wants ChatGPT to read your text messages. The harder question for the ChatGPT Plugin is whether the people you’re texting ever agreed to that.

On August 20, OpenAI launched a Messages plugin for ChatGPT that lets the chatbot search, summarize, draft and send conversations from Apple’s Messages app on Mac, covering iMessage, SMS and RCS (Rich Communication Services, the modern replacement for SMS). It works inside ChatGPT Work and Codex on Apple Silicon Macs, requires Full Disk Access plus contacts and automation permissions, and by default asks users to approve a message before it sends.

The ChatGPT Plugin Reads More Than Your Own Messages

Once granted access, ChatGPT can pull from years of Messages history synced through iCloud, not just recent texts. Apple began rolling out end-to-end encrypted RCS between iPhone and Android in May, meaning a conversation an Android user believed was locked down can now potentially be read by a third-party AI if the iPhone user on the other end enables the plugin. Neither Apple nor OpenAI notifies that other person, and there’s no way for them to revoke it.

Privacy researcher Paul Walsh, who helped create an early World Wide Web Consortium standard for classifying and labeling online content, has argued the plugin functions like a backdoor built by the user rather than the government: the recipient’s decision to grant access exposes messages from someone who never consented and who may not even use an Apple device or ChatGPT.

This Is Facebook’s Contact Problem, Again

The mechanic is familiar. Facebook has spent over a decade building so-called “shadow profiles,” records of people who never signed up for the platform, assembled from contact lists that other users voluntarily uploaded. Mark Zuckerberg confirmed the practice in 2018 congressional testimony, and it has drawn sustained public criticism ever since. Facebook never eliminated contact uploading; the mechanism runs today, though the company later added a tool letting non-users request deletion of data others uploaded about them.

Regulators have separately penalized Meta over related failures. In 2021, Ireland’s Data Protection Commission fined WhatsApp €225 million for failing to disclose to users and non-users how their data was shared with other Facebook companies, one of the largest penalties issued under the EU’s General Data Protection Regulation (GDPR) to date.

The through-line: one person’s choice to share data can expose someone else who never got a say. ChatGPT’s Messages plugin runs on the same logic, applied to conversations instead of contacts.

What OpenAI Says It’s Doing Differently

OpenAI says the plugin runs locally, doesn’t index all messages, and only pulls content when asked. Sending stays gated by approval unless a user turns that off per conversation, which OpenAI itself recommends against. Bloomberg has framed the rollout as a privacy test for Apple’s brand, built for years on encryption Apple itself can’t read.

Apple’s own documentation for using ChatGPT with Apple Intelligence describes a narrower, Apple-built integration where users control when ChatGPT is used and are asked before information is shared. That framework is distinct from the new Mac plugin, which runs through standard macOS permissions rather than Apple’s own consent screen.

Is The New ChatGPT Plugin For iMessage Actually A Good Thing?

Some coverage has framed the plugin as a straightforward convenience win, a feature that saves a few seconds of typing. Others see a company asking users to hand over the private conversations of everyone they’ve ever texted, without those people’s knowledge. Both readings describe the same plugin. The question worth asking isn’t whether ChatGPT can now read your messages. It’s whether anyone asked the other side of the conversation first.

This article was originally published on Forbes.com