Invest1 distinct publisher2 min readPublished
OpenAI's assurances about local processing describe what the vendor does with your texts. They say nothing about who agreed to supply them.
The Investor · Invest desk
Compiled by The InvestorSomething wrong?How this is made
Take OpenAI's account of the plugin at face value: local by default, no automatic upload, no index, no reading until the user asks for something from Messages [4]. Every one of those assurances is about vendor handling. None of them is about authorisation. The macOS permission sheet knows exactly one human being, the one holding the laptop, and that person is the only one asked [2].
Look at what is actually granted. AppleScript, Accessibility and Full Disk Access [3] are device-level grants issued by the device owner, and Apple's consent model has no concept of the other people whose words are sitting in the store. A two-party thread produces one approval and one non-approval. A group chat produces one approval and everyone else [1]. The party who consents is never the only party whose data is reached, and there is no in-thread signal to the others: Walsh's point is that recipients "will never know that I have a third party inside that application, and they will never be notified" [6].
The encryption argument is where the two named experts converge despite the label fight. Richardson's description is the uncontroversial one: end-to-end encryption stops the network operator and the platform from reading or altering a message in transit, while the endpoints can still read it on arrival [9]. Walsh takes the same fact somewhere sharper, arguing that once another system reads the plaintext before encryption or after decryption, "you have broken the fundamental concept" [7]. Richardson thinks "spyware" is too strong, because spyware takes without permission and this ships off by default behind an explicit grant [8]. Walsh uses the word anyway [5]. Both of them agree the channel's guarantee thins out once a third party can read the decrypted archive [9].
The screenshot comparison is the one worth dismantling, because it is the defence that will be offered. Walsh draws the line himself: forwarding a text is breaking someone's trust, not letting a third party inside the conversation [10]. Mechanically, a screenshot is a single artefact selected by a person who read it first. Search across years of threads is a standing capability applied to material nobody selected, including messages sent long before the plugin existed [1].
For anyone running a business, the exposure sits in an awkward place. Your own device policy governs your machines. It does not govern the counterparty who installed the plugin on theirs, and confidentiality in a messaging thread is only as good as the least careful endpoint. Proton's analysis lands on the same asymmetry from the consumer side: people who never use ChatGPT can still have their messages read [11].
Ranked by verification strength, evidence, and original report placement.
Users must explicitly install the plugin and grant ChatGPT several macOS permissions, including AppleScript, Accessibility and Full Disk Access.
According to OpenAI, the plugin runs locally by default, only reads Messages when a user explicitly asks it to, does not automatically upload or index a user's message history, and does not create an index or begin reading merely because the plugin is enabled; a request must specifically seek information from Messages.
Security and privacy expert Paul Walsh calls the Messages integration "one of the most dangerous things I have seen in technology" and warns it can function like spyware for people who depend on private communications.
OpenAI rolled out the plugin last week for ChatGPT on Mac, allowing users to search iMessage, SMS and RCS conversations, catch up on threads, draft replies and send them through Apple Messages.
The person installing the Apple Messages plugin has to approve the access, but everyone else in those conversations does not; one person's decision to opt in can make years of conversations searchable by AI, including messages from people who never agreed.
Walsh told Fortune that if he enabled the integration, "Every single person I send a message to through iMessage will never know that I have a third party inside that application, and they will never be notified."
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Mechanism documented, impact unquantified
The factual core - what the plugin does, what permissions it needs, and OpenAI's stated processing limits - is on the record, and the consent asymmetry follows directly from the described grant model rather than from speculation. But the cluster rests on one article from one publisher, the risk assessment is expert opinion rather than measurement, and there is no independent technical audit, no Apple statement and no documented incident.
No uptake data supplied
The sources establish that the plugin shipped and that Proton published an analysis, but disclose no install counts, active-user figures, enterprise deployments or telemetry. Release alone is not adoption, and inferring uptake from a launch report would be a guess.
Rhetoric runs ahead of demonstrated harm
The strongest language - 'one of the most dangerous things I have seen in technology' and the spyware framing - outruns what is evidenced: the feature is off by default, requires explicit grants, reads on demand and keeps conversations local unless the user opts into cloud storage, and no incident or misuse is reported. The gap is modest rather than large because the underlying consent defect is real and undisputed even by the sources that push back on the framing.
Commercially interested voices on both sides
Every substantive voice has a stake: OpenAI defends its own shipped feature; Lookout is a mobile security vendor whose CTO both validates and softens the risk framing; Proton is a privacy-focused competitor in encrypted communications whose analysis reinforces the alarm. Walsh is presented as an independent expert with no disclosed commercial tie, which is the one partial offset.
Structural claim solid, magnitude uncertain
Confidence is moderate: the consent-boundary claim is logically tight and grounded in on-record product facts, but the cluster is one article from one publisher, adoption is unmeasured, the loudest characterizations are contested within the same piece, and the mitigating technical detail is vendor-supplied and unverified.
product
Record, don't prompt: two labs converge on demonstration as the agent interface1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
product
A long press in ChatGPT is now the fastest visual assistant on an EU iPhone2 distinct publishers
science
Claude's watermark is a compliance artefact, not a cheating detector1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.