ChatGPT now reads and sends your Apple Messages, on the Mac only
A plug-in in the ChatGPT desktop app reads and searches your iMessage, SMS and RCS threads and sends messages through Messages on your behalf. By default nothing goes out until you approve both the text and the recipients. There is a switch that removes that step, and OpenAI's own documentation argues against using it.
The capability is narrower than the headline suggests and the setting under it is wider. The plug-in runs only in the ChatGPT desktop app for macOS, on Apple Silicon builds, and it is not available on the web, on mobile, in Codex CLI or in the IDE extension. Within that one surface it can read and search every iMessage, SMS and RCS conversation on the machine, and send new ones as you.
What it can do
Reading is the larger half. The plug-in can search your message history, summarize it, and draft replies that take earlier conversations into account. Sending goes through the Messages app itself, so the message arrives from your number and looks exactly like anything else you send.
macOS asks for its own permissions before any of this works, which means the operating system's consent dialog is the first gate. That is the same mechanism any Mac app has to pass, and it is worth knowing that granting it once covers the whole message store, not one conversation.
The default is approval, and that is the whole story
OpenAI's documentation is direct about it: by default ChatGPT sends messages only after you approve the message and its recipients. Both halves matter, because the recipient list is where an agent's mistake becomes someone else's problem.
There are then two ways to answer the prompt. Allow once approves the message in front of you. Always allow sending to this chat removes the confirmation for that conversation from then on, and the documentation says plainly what that costs: it "removes your final chance to review a message before ChatGPT sends it as you".
A vendor writing a warning against its own convenience setting is rare enough to notice, and it puts this in the same place every other agent has landed: the machine does the work, a person approves the step that cannot be taken back.
What to decide before you turn it on
The question is not whether the feature is useful. It is which conversations you are willing to make permanently sendable, because the always-allow switch is per chat and it does not expire. A work channel where every message is a status update is a different risk from a thread with your bank or your family.
The reading side deserves its own thought. Everything the plug-in searches becomes context, and a message store is the least curated archive most people own. If you would not paste a thread into a chat window, the plug-in should not be able to search it either — and the only control at that level is the macOS permission itself.
„removes your final chance to review a message before ChatGPT sends it as you“
Sources
Related
A proxy that stripped one header was doubling Claude Code's API bill
Version 2.1.239 fixes streaming on Bedrock behind proxies that remove the response Content-Type header. Claude Code silently fell back to re-running every turn without streaming, and each turn was billed twice. The same release makes cost estimates show the 1.1× premium that data-residency workspaces pay.
Anthropicverified

GitHub Copilot moved into Slack and Microsoft Teams on the same day
Both shipped on August 21 in public preview. Mention @GitHub in a channel and the agent triages issues, investigates failures, writes changes in a cloud sandbox and opens a pull request, with the conversation attached. The interesting part is not the capability list, which is familiar, but the room it moved into: the place where work gets discussed rather than written.
GitHubverified

Nvidia's harness takes Claude Opus 5 from about 30% to a perfect ARC-AGI-3 score
Nvidia published a run in which AVO, its agent architecture, scores 100.00 RHAE on ARC-AGI-3 and clears all 183 levels across 25 environments. The same model evaluated on its own scores about 30%. In the same post Nvidia writes that the comparison is not a controlled ablation, and that sentence did not survive into the coverage.
NVIDIAverified