A Mac user who installs OpenAI's new Apple Messages plugin can ask ChatGPT to search years of old texts, summarise a group chat, or draft and send a reply, all from the desktop app. The setup requires three macOS permissions: AppleScript, Accessibility, and Full Disk Access. Once granted, ChatGPT can read iMessage, SMS, and RCS conversations on request.
The person granting that access agreed to it. Everyone else in every one of their conversations did not, and has no way of finding out that they need to.
Fortune's reporting on the rollout, published 26 August, put that gap to OpenAI, Lookout, and Proton. OpenAI's position is that the plugin runs locally by default, only reads Messages when a user makes a specific request that needs them, and does not build a standing index of a user's history. Lookout's CTO, Dave Richardson, called the resulting risk "significant" and noted that routing messages through a third party undermines much of what end-to-end encryption is supposed to buy you. Proton's own analysis, published separately, reached the same conclusion. Security researcher Paul Walsh, whose original research on the integration both prompted the Fortune piece and was cited in Proton's write-up, put the asymmetry plainly: someone else only has to install it on their end.
OpenAI's "local by default, request-triggered" description is a policy commitment, not an architectural one. The plugin does not use a scoped, Apple-sanctioned Messages API with a narrow read boundary; it runs on the same general-purpose AppleScript and Accessibility automation surface any Mac utility has had available for years, backed by Full Disk Access. That is the gap this site's readers will recognise: the claim describes intended behaviour, and the permission grant describes actual capability, and the two are not the same thing. A future update, a bug, or a change of policy does not require a new consent step to widen what gets read, because the technical boundary was never narrower than the promise.
The plugin itself is, at the time of writing, Mac-only; OpenAI has confirmed it isn't available in ChatGPT on the web or mobile, or in the Codex CLI or IDE extension. That distinction matters less than it sounds. Messages in iCloud syncs iMessages across every device signed into the same Apple ID, and Text Message Forwarding does the same for SMS, MMS, and RCS conversations with non-Apple contacts, both close to default settings for anyone who reads texts on their Mac at all. Once either is on, the Mac's local Messages database holds the same conversation history as the phone, regardless of which device a message was actually typed on. The plugin's Full Disk Access grant reads that local database with no way to tell a message composed on the Mac from one composed on an iPhone that has never had the plugin anywhere near it. Being an iPhone-only household offers no protection either, provided a Mac somewhere is signed into the same Apple ID.
The second gap sits in what happens if a user opts into cloud-stored ChatGPT conversations. OpenAI's own documentation confirms that Messages content pulled into a cloud-stored conversation then follows the same retention policy as everything else in it, and can inform Memories. "Local by default" describes a starting configuration, not a guarantee, and the actual data-residency outcome for someone else's private conversation now depends on a setting the recipient never saw and could not have consented to.
None of this requires breaking encryption. Walsh's framing is the correct one: the message reaches its destination exactly as designed, decrypts exactly as designed, and only then does a second piece of software get a look at the plaintext. The mathematics holds. The endpoint doesn't.
For anyone communicating with a journalist, that endpoint exposure is not an abstract privacy question, it is the whole basis on which a source agrees to talk.
Journalistic material held on a reporter's own devices carries real legal protection in England and Wales. Material that would identify a confidential source is "excluded material" under PACE 1984 section 11, the more tightly protected category; general journalistic material not held in confidence is "special procedure material" under section 14. Neither can be obtained on an ordinary search warrant. Both require an application under Schedule 1 to a Circuit Judge for a production order, heard inter partes, with excluded material subject to a materially stricter access-condition test. That protection attaches to the journalist's own devices and, by extension, to material physically or electronically in their possession.
It does not attach to a copy of the same conversation sitting on OpenAI's servers, and PACE is not the only gap here. OpenAI is a US company. A domestic Schedule 1 order has no reach over data an American provider holds on American infrastructure; the mechanism for that is the Crime (Overseas Production Orders) Act 2019, operating since 2022 through the UK-US Bilateral Data Access Agreement, which lets a UK judge issue an order compelling a US-based provider to produce data directly, without the source protection carve-outs PACE builds in for journalism and without the slower mutual legal assistance route it replaced. The Act's stated exceptions cover material subject to legal privilege and confidential personal records; nothing in the reporting on it points to an equivalent exemption for journalistic material. Whether that gap has been tested against a real source-protection case is, as far as this piece can establish, an open question, and one worth a lawyer's eye rather than this one's; the structural exposure, source copied onto foreign-held infrastructure that two different UK legal regimes were built without reference to each other, is not in doubt.
It also defeats the standard tradecraft. Disappearing messages and delete-after-read settings assume the deletion is the end of the story. If the recipient's plugin has already read and, depending on their storage setting, copied the content before it expires, the message has been preserved somewhere with an entirely different retention policy before it ever vanished from the app that promised it would.
It is tempting to read all this as a risk that applies to ordinary users and stops at the door of anyone properly protected: politicians, in particular, on the assumption that GCHQ issues them something more hardened than an off-the-shelf iPhone. That assumption does not survive contact with how UK political communication actually works.
The National Cyber Security Centre, part of GCHQ, does provide guidance to what it calls "high-risk individuals," a category that explicitly covers elected representatives, candidates, activists, staffers, journalists, academics, and the legal profession under its Defending Democracy programme. It also runs an opt-in phishing and malware alert service, Personal Internet Protection, for the same group. Both are advisory. Neither issues a hardened device or mandates specific software; the guidance for personal messaging on a personal device amounts to enabling two-step verification, using disappearing messages, and being careful who else is in the chat.
Separately, ministers and officials are governed by Cabinet Office guidance on Non-Corporate Communication Channels, covering WhatsApp and personal email used for government business. That guidance is under active review, commissioned 2 July 2026 and led by Professor Sir Anthony Finkelstein, with a report due in early 2027. The Institute for Government has linked the review's timing directly to the Mandelson files controversy and the recurring question of what happens to decisions made and then deleted on personal apps.
The track record this guidance is meant to be governing is not reassuring. The Lockdown Files exposed roughly 100,000 WhatsApp messages between Matt Hancock and colleagues from the pandemic response. David Cameron's lobbying for Greensill Capital ran substantially over WhatsApp and SMS. The Covid Inquiry surfaced extensive government decision-making conducted the same way. The Information Commissioner's Office found "inadequate data security" in how ministers used personal channels during the pandemic and called for a review as far back as 2022. The Institute for Government has reported that between 13 and 31 percent of officials in some departments have WhatsApp on their work phones, and has called, so far without success, for a rule against personal phones for substantive government business. Even Parliament's own security understanding has been shown to be shaky in public: a select committee chair once told the BBC that GCHQ contacts had advised him Gmail was safer than the parliamentary email system, prompting NCSC and Parliament to correct him on the record.
None of that is a hardened baseline. It is a working environment that already runs largely on consumer messaging apps and personal devices for substantive business, with the disappearing-messages habit used at least as much for managing what gets kept as for security. Every official, aide, and journalist's contact in that environment sits inside the same Apple ecosystem this piece opens with, where a single synced Mac is enough to expose the full cross-device conversation history, phone included. The "high-risk individual" the NCSC's own guidance is meant to protect is not a hypothetical edge case for this threat model. It is the default case.
Note the term worth being precise about: "politically exposed person," commonly shortened to PEP, is a financial-crime category under the Money Laundering Regulations 2017, used for enhanced due diligence on people entrusted with prominent public functions and those close to them. It has nothing to do with communications security. NCSC's own "high-risk individual" is the correct term here, and usefully, it already bundles politicians in with journalists, lawyers, and academics under one definition, which is the same group whose source relationships and legal protections this plugin quietly sits outside of.
The question the Fortune piece leaves open is the one that actually matters: not whether ChatGPT can be trusted with a user's own messages, but who a user's contacts are now required to trust on their behalf, without being told, without a vote, and without the legal or institutional protections that were built for a world where reading someone's messages required either a warrant or a screenshot.
Editor's note: Hat tip to Paul Walsh, whose original LinkedIn post on the integration is what put Fortune onto the story, and this piece into motion. His independent research and commentary run on Substack.
The Sovereign Auditor covers digital sovereignty, cybersecurity governance, and data protection policy, with particular focus on Isle of Man jurisdiction and Crown Dependency issues.
Payments via PayPal. Credentials delivered by email. No Substack. No Stripe. No middlemen.