Interestana
Home/News/ChatGPT Messages Plugin Raises Privacy Concerns for Non-Users
Fortune3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

ChatGPT Messages Plugin Raises Privacy Concerns for Non-Users

ChatGPT Messages Plugin Raises Privacy Concerns for Non-Users

ChatGPT has introduced a new Apple Messages plugin for Mac, enabling the AI to directly search users' past text conversations, summarize group chats, draft replies, and send messages. This integration, rolled out last week, allows users to access and manage their iMessage, SMS, and RCS conversations through ChatGPT. To enable this functionality, users must explicitly install the plugin and grant it several macOS permissions, including AppleScript, Accessibility, and Full Disk Access. OpenAI states that the plugin operates locally by default and only accesses Messages when a user explicitly requests it, without automatically uploading or indexing message history. However, security experts have voiced significant concerns regarding the privacy implications for individuals who are part of conversations with a user who has enabled the plugin but have not themselves consented to their messages being accessed by AI.

Paul Walsh, a security and privacy expert, described the Messages integration as "one of the most dangerous things I have seen in technology," warning that it could function as spyware. He highlighted that a user's decision to opt into the plugin means years of conversations, including messages from people who never agreed to AI access, can become searchable. Walsh explained that individuals communicating with someone who has enabled the plugin would "never know that I have a third party inside that application, and they will never be notified." This lack of notification and consent is particularly concerning for those who use encrypted messaging for sensitive discussions, making the integration "dangerous" in such contexts.

While OpenAI asserts that the plugin does not create an index of a user's Messages or begin reading conversations simply upon enablement, and requires a specific user request to retrieve information, the core issue remains the unilateral access granted to conversations involving non-consenting parties. The plugin's ability to search and potentially analyze years of personal communications without the explicit agreement of all participants represents a novel challenge in the evolving landscape of AI agent privacy. The debate centers on whether the convenience offered to the plugin user outweighs the privacy rights of their conversational partners. This development underscores the growing need for clear guidelines and robust consent mechanisms as AI technologies become more deeply integrated into personal communication platforms.

Original source — read the full reporting at the publisher:

Read on Fortune

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next