Skip to content
Agentsmedium signalverified

ChatGPT now reads and sends your Apple Messages, on the Mac only

A plug-in in the ChatGPT desktop app reads and searches your iMessage, SMS and RCS threads and sends messages through Messages on your behalf. By default nothing goes out until you approve both the text and the recipients. There is a switch that removes that step, and OpenAI's own documentation argues against using it.

By Redakcija WebAiRadarPublished 2 min readwritten by a model

Source

ChatGPT plugins

ChatGPT dokumentacija · Original published August 20, 2026

The capability is narrower than the headline suggests and the setting under it is wider. The plug-in runs only in the ChatGPT desktop app for macOS, on Apple Silicon builds, and it is not available on the web, on mobile, in Codex CLI or in the IDE extension. Within that one surface it can read and search every iMessage, SMS and RCS conversation on the machine, and send new ones as you.

What it can do

Reading is the larger half. The plug-in can search your message history, summarize it, and draft replies that take earlier conversations into account. Sending goes through the Messages app itself, so the message arrives from your number and looks exactly like anything else you send.

macOS asks for its own permissions before any of this works, which means the operating system's consent dialog is the first gate. That is the same mechanism any Mac app has to pass, and it is worth knowing that granting it once covers the whole message store, not one conversation.

The default is approval, and that is the whole story

OpenAI's documentation is direct about it: by default ChatGPT sends messages only after you approve the message and its recipients. Both halves matter, because the recipient list is where an agent's mistake becomes someone else's problem.

There are then two ways to answer the prompt. Allow once approves the message in front of you. Always allow sending to this chat removes the confirmation for that conversation from then on, and the documentation says plainly what that costs: it "removes your final chance to review a message before ChatGPT sends it as you".

A vendor writing a warning against its own convenience setting is rare enough to notice, and it puts this in the same place every other agent has landed: the machine does the work, a person approves the step that cannot be taken back.

What to decide before you turn it on

The question is not whether the feature is useful. It is which conversations you are willing to make permanently sendable, because the always-allow switch is per chat and it does not expire. A work channel where every message is a status update is a different risk from a thread with your bank or your family.

The reading side deserves its own thought. Everything the plug-in searches becomes context, and a message store is the least curated archive most people own. If you would not paste a thread into a chat window, the plug-in should not be able to search it either — and the only control at that level is the macOS permission itself.

removes your final chance to review a message before ChatGPT sends it as you
OpenAI, ChatGPT documentation

Sources

BrandsChatGPT

Related

Agentsmedium signal

A proxy that stripped one header was doubling Claude Code's API bill

Version 2.1.239 fixes streaming on Bedrock behind proxies that remove the response Content-Type header. Claude Code silently fell back to re-running every turn without streaming, and each turn was billed twice. The same release makes cost estimates show the 1.1× premium that data-residency workspaces pay.

Anthropicverified

Screenshot of the GitHub Copilot panel inside Slack, under the heading "The new GitHub Copilot experience in Slack".
Agentsmedium signal

GitHub Copilot moved into Slack and Microsoft Teams on the same day

Both shipped on August 21 in public preview. Mention @GitHub in a channel and the agent triages issues, investigates failures, writes changes in a cloud sandbox and opens a pull request, with the conversation attached. The interesting part is not the capability list, which is familiar, but the room it moved into: the place where work gets discussed rather than written.

GitHubverified

A bobblehead figure of Nvidia's chief executive holding a game screen, above a green ARC-AGI-3 progress bar filled to 100%.
Agentsstrong signal

Nvidia's harness takes Claude Opus 5 from about 30% to a perfect ARC-AGI-3 score

Nvidia published a run in which AVO, its agent architecture, scores 100.00 RHAE on ARC-AGI-3 and clears all 183 levels across 25 environments. The same model evaluated on its own scores about 30%. In the same post Nvidia writes that the comparison is not a controlled ablation, and that sentence did not survive into the coverage.

NVIDIAverified