The plugin is listed as available on all ChatGPT plans, including free access, according to OpenAI’s product documentation. However, “all plans” does not mean all ChatGPT devices or modes are supported.
The current requirements are:
Intel-based Macs are excluded by the Apple silicon requirement. Users must also install or enable the plugin through the ChatGPT app’s Plugins area and grant the macOS permissions needed for it to interact with Messages and related data. Reports describe permissions involving Full Disk Access, contacts, and automation.
For managed Business, Enterprise, and Edu workspaces, administrators can disable Apple Messages through the existing Computer Use control.
The most important control is the default approval step. Before sending, ChatGPT asks the user to approve both the proposed message and its recipients. That gives the user a final opportunity to catch an incorrect name, an unsuitable draft, or a message that should not be sent at all.
Users may relax repeated approval prompts, but doing so removes part of that review process. OpenAI and its documentation warn users to be careful with persistent approval, particularly when messages involve sensitive information.
A safer workflow is to ask ChatGPT to search, summarize, or draft first, then review every recipient and the complete message before approving delivery. Persistent approval is especially risky for conversations involving confidential work, legal matters, health information, money, passwords, or personal relationships.
OpenAI told TechCrunch that the plugin runs locally on the user’s device, does not create a full index of all messages, and reads messages when the user makes a specific request. Other reporting describes the connector as using macOS automation mechanisms to interact with the Messages app.
Those statements are relevant, but they do not amount to a complete, independently verifiable description of the data lifecycle. Public reporting does not fully establish:
The distinction matters: a connector can operate locally while the information it retrieves is still processed according to the policies and infrastructure associated with the user’s ChatGPT session. OpenAI’s local-processing and no-full-index claims narrow the apparent scope of access, but they should not be read as proof that message content never leaves the device or is never retained. The available public evidence does not support that stronger conclusion.
The integration illustrates a broader shift in ChatGPT from generating answers to operating software. Instead of copying a conversation into a prompt, a user can ask an agentic surface to locate relevant information in an application and take the next step. OpenAI’s plugin documentation describes plugins as extensions that add skills and interfaces to ChatGPT and Codex.
Messaging is a useful demonstration because it combines two different types of computer use:
The second step raises the stakes. A mistaken summary is inconvenient; a mistaken message can create a commitment, disclose private information, or damage a relationship. Approval prompts therefore function as an important boundary between assistance and autonomous action.
The plugin can save time when the task is low-risk—for example, finding a logistics detail in a long thread or turning a routine conversation into a draft. But Messages may contain information belonging not only to the user, but also to friends, colleagues, customers, and family members who never agreed to an AI system analyzing their conversations.
A cautious setup is:
The practical verdict is mixed: ChatGPT’s Apple Messages plugin offers genuine convenience and a clear example of agentic desktop automation, but its usefulness depends on granting access to unusually sensitive data. Until OpenAI publishes more detail about the complete data path and retention treatment, users should treat the integration as a powerful convenience tool—not as a guarantee that message content remains entirely local.