ChatGPT can read your texts now. Your clients never agreed to that.
TL;DR. On August 20 OpenAI shipped an Apple Messages plugin for ChatGPT on the Mac. Most of the argument since has been about whether OpenAI copies your texts to its servers. That’s the wrong fight. Your Messages archive is mostly other people’s words held in your custody, and no device permission has ever been able to ask about that.
The clearest privacy rule in law isn’t filed under privacy. It’s the client trust account.
Money sits in an account with your name on it, and you can move it with one click. Every lawyer learns in the first month that it isn’t your money. Possession isn’t ownership. You’re holding something for someone else, and the rules that apply are theirs.
Nobody has explained that to macOS.
The plugin searches your iMessage, SMS and RCS history, summarizes threads, drafts replies, and sends them as you. It’s on every plan including the free one, and runs on Apple Silicon Macs inside ChatGPT Work and Codex.
Most of the argument since launch has been about whether OpenAI copies your texts to its servers. The company says there’s no full index, the plugin runs locally, and it reads only when you ask. Fine. I’ll take them at their word on the mechanics, because it’s the wrong fight anyway. The permission dialog asks whether you own the computer. It can’t ask the question that matters, which is whether you have the authority to hand over what’s sitting on it.
The delete that worked anyway
There’s a rule worth carrying into your next vendor meeting, and it has nothing to do with OpenAI.
In June 2025, Simon Willison named what he called the lethal trifecta. Three capabilities:
Access to private data
Exposure to content that a stranger writes
A way to send things back out
Any one of those is fine, and any two are usually fine. Put all three in one system and a stranger can write text that your AI reads as an instruction and then acts on with your data and your name. The attacker needs no password. He needs a message you’ll read.
Now look at where the three legs sit. The archive is the private data. Anyone with your phone number supplies the untrusted content, because a text is words a stranger wrote that your AI now reads. The hands come from Computer Use, which is the part of ChatGPT that sees your screen and drives your apps. Plugins share it. I checked on my own Mac, and switching off Computer Use’s permissions stops Messages working. Those permissions cover Full Disk Access, Automation, Contacts, Accessibility, and Screen Recording, which I haven’t seen one article mention.
Ben Patterson at PCWorld hit this by accident on August 21. He asked ChatGPT to delete some spam texts. The Messages plugin reads, searches, drafts and sends, and it can’t delete anything. So the agent found another route. Patterson watched screenshots of his own Messages window appear while ChatGPT took his mouse and clicked Delete. It had reached across to Computer Use, which he’d granted for an unrelated test weeks earlier and never switched off.
Nothing broke. Every permission involved was one he’d given. And notice what the plugin’s limit turned out to be worth. It couldn’t delete, so the agent reached past it and deleted anyway. That limit was a feature boundary. Nobody had built it as a security one.
One caveat worth saying out loud. The rule tells you the shape of the exposure, not the odds. OpenAI wrote back in December that prompt injection is unlikely to ever be fully solved. Its word, not mine. On May 1 six governments published joint guidance called Careful Adoption of Agentic AI Services, and its central recommendation is to keep agentic systems on low-risk, non-sensitive work for now. A Messages archive full of client texts is the opposite of that.
The consent you can’t give
Now the part that should stop a lawyer cold.
Your Messages archive isn’t a record you made. It’s a joint record. Most of the words in it were typed by other people, and every one of them decided what to tell you based on who you are.
A client texts you at 11pm about a custody exchange that went badly. Another sends a photo of an injury. Someone forwards a number they were told to keep quiet. Each of them made a judgment about you. None of them made a judgment about a third-party AI vendor, and nobody asked them to.
The strongest case on the other side came from 9to5Mac, and it deserves its full weight. Their read runs like this. It’s an opt-in feature, not a sketchy workaround, and it uses files already sitting on your Mac with your permission. It doesn’t build a standing index the way Siri does. ChatGPT touches the data only when you point it there, and the app is clear on screen about what it’s doing. For those reasons, they wrote, it shouldn’t be a privacy concern for Apple.
Every clause of that is true. All of it is about you.
Consent-by-installation works when the installer is the only person in the data. Open a Messages archive and you’re the minority author. The people who filled it have no toggle, no notice, and no way to opt out. No vendor designed that gap. It’s a limit on what a device permission can express. Mine couldn’t even tell me which app was holding it.
For a lawyer this stops being philosophy around the second paragraph and becomes Rule 1.6, which is binding, read through guidance that isn’t. California replaced its 2023 AI guidance in May 2026, at the request of the state Supreme Court, to address agentic AI. It says poorly configured agentic systems can disclose confidential information across matters and expose privileged material. It says a lawyer must not deploy one that transmits client information externally on its own without safeguards and human review. Read that second half. It isn’t a ban. It’s a condition. Safeguards, and a person who looks before it goes.
Here’s a screenshot from my actual usage of the messages plugin in Codex (with phone #’s and names blocked). I went to LMU for my undergrad (go Lions!) and this is a recent exchange about the upcoming Alumni BBQ.
The checkbox at the end
By default the plugin shows you the message and the recipients and waits. That confirmation is the entire safety story, and OpenAI says as much. The company tells you to keep per-send approval on for any chat that might carry untrusted instructions.
There’s a documented defect nearby, and it isn’t the interesting part. If a task runs with full access, Messages may not be able to show the confirmation at all, so the text doesn’t go. That fails safe.
What fails open is a checkbox. Pick “Always allow sending to this chat” and ChatGPT can text that person again without asking you first. OpenAI says so in the same paragraph where it offers the setting. Persistent approval, it says, removes your final chance to review a message before ChatGPT sends it as you.
Capability isn’t authority. The question to ask of any system is what it can do before one of your lawyers gets a chance to say no. On a default install that answer is nothing, which is honestly good design. Tick one box and the answer changes, and nobody sends you a notice when it does.
What to do Monday morning
Which brings me back to the account with your name on it.
You could move that money today and the bank wouldn’t stop you. What stops you is that it isn’t yours and you know it. The whole system runs on a lawyer holding a line the software can’t see.
Same thing here. A macOS permission is a question about your hardware. Rule 1.6 is a question about your custody. One toggle can’t answer both, and only one of them ever gets asked.
So, three moves.
Ask of any AI tool what it can reach when it hits a wall. The feature list won’t tell you, and Patterson found out by watching his own cursor move.
Decide who at your firm gets to say yes on behalf of people who aren’t in the room. Write it down before somebody needs it.
If you run a managed workspace, switch Apple Messages off through the existing Computer Use control. That beats a policy memo nobody reads.
I don’t think this plugin is a scandal. I think it’s an ordinary product decision that quietly moved a line, and the line it moved is one lawyers are paid to hold.
Possession was never permission.
If you enjoyed this, please repost and share with others.
In the last newsletter I said Magnus was getting a bath. He did (well, when I give him a bath it feels like I get one too every time he shakes water off his body). Here’s a picture of him sitting in my office this morning - all clean!




