A senior executive wakes up, coffee in hand, and opens three articles his team flagged overnight: a regulatory update, a competitor's earnings call, and an industry report. He doesn't read them. He drops them into an AI assistant and gets three tight summaries in under a minute. Efficient. Nothing objectionable there; the articles are public, written by people who wanted them read widely.
Then he opens his messages. Fifteen new threads, across three different apps, from colleagues, a board member, his lawyer, his kids' school, and a friend. He forwards each one to the same AI assistant and asks it to draft a reply. For a few of them, the assistant doesn't just answer; it reaches back into the thread's history, pulls context from a conversation from three months ago, and folds that into the draft.
Somewhere in that second cup of coffee, a different question should occur to this executive, though it usually doesn't. Every person on the other end of those 15threads just had their words read, indexed, and reasoned over by a company they never agreed to share anything with.
The permission that only covers one side of the conversation.
This isn't a hypothetical. OpenAI released a plugin this month that lets ChatGPT on Mac search a user's Apple Messages directly, catch up on threads, summarize group chats, and send replies, all without the old copy-paste step. The user installing it has to explicitly grant access. Everyone else in every conversation that user has ever had does not, and, per OpenAI's own account, has no way of knowing the plugin exists.
One security researcher put it about as plainly as it can be put. Every person messaged through iMessage will never know a third party is inside that application, and will never be notified.
Others have pushed back on the word "spyware,” saying the feature is off by default and requires explicit consent, which is a meaningfully different category from software that steals access covertly.
However, even the more measured critics don't dispute the underlying point. Enabling the integration introduces real risk to a channel that has, for years, been treated as relatively private. Once a message is decrypted and readable on someone's device, another piece of software reading it from there has, in practical terms, routed around the protection the encryption was supposed to provide.
OpenAI's own account draws real limits around this. The plugin reads messages only when a user's request specifically calls for it, doesn't build a standing index of message history, and stores conversations locally on the Mac by default rather than uploading them to a server.
These are meaningful guardrails, and worth taking at face value. But guardrails around how much a company retains do not change the more basic fact. The decision to let an AI read a conversation was made unilaterally, by one participant, on behalf of everyone in it.
This was never really new, and that's exactly the point.
None of this is unprecedented in the strictest sense. People have been screenshotting texts, forwarding them, and pasting them into ChatGPT for years, with the same one-sided consent problem baked in from the start.
What has changed is scale and searchability. A screenshot is one message, deliberately chosen, in a moment someone decided mattered enough to share. A standing AI integration with Full Disk Access and years of message history is a fundamentally different object: a capability that can reach back through a relationship's entire written record the moment anyone asks it to, not a single disclosure someone chose to share.
A privacy-focused technology company made a version of this point in an analysis this week: the exposure isn't limited to people who use ChatGPT themselves. Someone who has never opened the app, never accepted a terms-of-service agreement, and never made any decision about AI at all can still have years of private conversations become searchable because the person on the other end of their texts decided it was convenient.
What this actually creates
Set the specific plugin aside for a moment, because the underlying dynamic is bigger than any one product, and it raises a set of questions worth sitting with rather than rushing past.
The consent question is the most obvious one, but it's also the least resolved. Under most existing privacy frameworks, a person controls what happens to data about them. A text message is, definitionally, data about two people, or more, in a group thread.
There is no clean mechanism today for the other party's consent to even enter the picture, and it's not obvious what one would look like: does a “this conversation may be AI-assisted” disclosure at the start of a thread do anything, practically, for someone who's already mid-conversation with a friend?
The liability question follows close behind, and it's the one I'd expect lawyers to start litigating soon. If an AI-drafted reply, built partly from a misread of an old message, causes real harm, professionally, financially, or personally, whose responsibility is it: the person who hit send, or the company whose model generated the draft?
And what happens the moment sensitive information from someone else's life- a medical detail mentioned in passing, a business conference shared months ago- gets folded into cloud-stored context that outlives the conversation it came from?
And then there's the question that should unsettle anyone paying attention: Am I using AI to summarize and answer my messages? There is every reason to believe the sender used AI to draft theirs; what exactly is happening in that exchange? Is it a conversation between two people anymore, or is it AI corresponding with AI, with two humans skimming the output and taking credit for a relationship that neither of them, in any meaningful sense, is actually conducting?
Should we just assume messaging isn't private anymore?
None of this means avoiding these tools. That ship has sailed for most of us. But a few practical habits go a long way. Treat any AI-messaging integration as a decision made on behalf of everyone you talk to, not just yourself, and think about who's in those threads before you grant access, not after. Keep genuinely sensitive conversations- legal, medical, anything you wouldn't want searchable years from now- on a channel you control end to end, without an AI layer sitting on top of it.
And, if you manage a team, put this in writing: decide deliberately whether client communications, HR conversations, or anything under legal privilege are allowed to pass through an AI assistant at all, rather than letting each employee make that decision alone, on your organization's behalf, one plugin install at a time.
The executive in the opening scene didn't do anything malicious. He didn't even do anything unusual; most of us are already doing similar things. But somewhere between summarizing public articles and outsourcing 15 personal replies, he decided on behalf of 15 other people who never got a vote.
Multiply that by however many of the 15 made the same decision back about him, and the honest picture of that morning's messaging isn't two people staying in touch. It's an arrangement none of them designed, and none of them were quite asked to join.