OpenAI made a surprising announcement last month: Users of its Mac app would now be able to integrate ChatGPT with their Messages app.
AI fans welcomed the development, which was advertised by the company as an easy way to help people with “everyday conversations.”
But technical researchers are alarmed by how this could weaken the conversational encryption on which Apple built its strong reputation for user privacy.
“In the past 20, 30 years, I can’t think of anything worse than this,” Paul Walsh, a security and technical expert, told Straight Arrow.
Download the Straight Arrow app today to get the stories that matter free from manipulation, bias or agenda.™
Point phone camera here
For Mallory Knodel, a technologist who works on platform security, it brings up memories of a long-rejected cyber-monitoring idea known as the “Ghost” proposal.
What actually happened?
It sounded like any new product announcement. “Everyday conversations just got easier with the new Apple Messages plugin,” OpenAI wrote on X.
“We’ve added native integration with iMessage, so ChatGPT can now send & read messages for you!” posted Ari Weinstein, an OpenAI product manager, adding “It can also analyze your messages! It’s really fun to get insights about who you talk to, and what you talk to people about.”
Some of the replies to Weinstein’s post were enthusiastic, describing the development as “dope” and “sick.”
But other X users shared concerns about privacy issues with the way the product was designed. Conversations take (at least) two people. If one person wants to give ChatGPT access to a conversation history, there’s currently no way for the other person to decline.


That includes messages and images sent by anyone, to anyone — including minors and ex-romantic partners. Messages could contain conversations about medical issues or complaints to colleagues.
This could hand OpenAI a valuable data-rich map of the names, phone numbers and relationships between Apple’s users, even if they don’t use ChatGPT or OpenAI’s products, Walsh told Straight Arrow.
The integration is only available on Mac computers, and OpenAI has not provided information about how many people are using the desktop version of its app. However the data exposed could include anyone who has ever used iMessage from any device — estimated to be almost 60% of Americans. The phone version of ChatGPT app hit a billion global users in June.
What’s the problem?
Apple has a strong reputation for protecting users’ privacy — and people have used iMessage with that expectation. But if another app can access, read, analyze and store messages sent through iMessage, Walsh said, then “it removes the entire benefit” of Apple’s private messaging system.
“When enough people in the world add this, it means that every person they’ve ever communicated with has been Hoovered up, if those conversations have been exposed,” Walsh told Straight Arrow.
Walsh has been in the security industry for over three decades and owns technical patents used widely by cybersecurity companies. His public statements criticizing the product have been echoed by the encrypted email platform Proton, which recommends that people not enable the integration.
What is encryption?
End-to-end encryption (E2EE) is a way to make sure that people’s personal messages stay private. In the simplest terms, every device has a “secret” password and a “public” password. If you want to send someone a message, your device will use the recipient’s public password to turn your message into unreadable data. The only way to turn it back into real data is to use the recipient’s secret password. That way, only the intended recipient can read the message — and it can’t even be decoded by the company that’s sending the message for you.
This is the basic system at the heart of chat apps like iMessage, Whatsapp, Signal and Facebook Messenger. It was also the case on Instagram until May, when Meta removed it there. And it’s not available on TikTok, LinkedIn or X.
“There was a campaign for many years to try to get Twitter to encrypt DMs, and they never really did,” Knodel told Straight Arrow.
Allowing another app to read encrypted messages is an issue of consent, Knodel told Straight Arrow. The integration doesn’t tell people that the messages they think they’re sending to a friend are being read by a third party.
So, why did this happen? And why now?
The technical capacity for this has always existed, Walsh said, because it uses a computer access protocol that is foundational to the way anti-virus software works.
But “this is not a normal plugin,” he said. “This is asking for the deepest, most intrusive permissions you can imagine.”
“Apple wouldn’t have comprehended” the idea that a company would build a consumer application that reads encrypted messages, he said. “I think internally inside Apple, they’re probably in a quandary right now.”
Neither OpenAI nor Apple responded to Straight Arrow’s requests for comment.
A tempting ‘treasure trove’
The potential data involved is likely very tempting for a company training AI.
Knodel told Straight Arrow that the AI race could be changing how companies that host messaging apps think about the data being generated by their users. Increasingly, she said, the trend is “moving away from privacy as a business model to everything being about AI.”
She sees a distinction between social media, which is more public, and messaging, which has always been intended to be private.
AI companies constantly need fresh, novel, real-world data for training; interpersonal messages are a “treasure trove,” she said. They’re “full of slang. There’s a lot more multilingualism,” Knodel said. And, she thinks, it is tempting for messaging companies to weaken their own security protocols to be able to use that data to compete in AI model training.
The consequence, she believes, is a blurring of the lines “between what we would consider messaging apps that retain the guarantees of confidentiality and privacy,” and those that have features or integrations driven by a desire to gather user data.
“The main thing people loved about Apple is they promoted its privacy features,” like end-to-end encryption, she added. It is not clear, from the product announcement, whether Apple was consulted on this new feature.
Apple’s relationship with OpenAI
Walsh said he would never use iMessage with anyone again, unless he could be sure they were not also using ChatGPT. And he would make that recommendation to everyone — although it could be too late if historic chats are already exposed.
“Apple is going to hurt big time with this,” he said.
The two companies have partnered in the past. In 2024, Apple and OpenAI announced a partnership, which allowed the integration of ChatGPT into Siri intelligence. However, that change did not allow Siri to intercept or read messages.
As reported by the Guardian at the time, then-CEO Tim Cook told reporters that Apple planned to usher in a “new standard for privacy in AI.” Cook also said then that any messages or information read by their system is always encrypted on the device or on Apple’s servers.
Apple filed a federal suit against OpenAI in July, alleging the latter company had stolen trade secrets.
The ‘Ghost’ proposal
Apple’s encryption prevents the government and the police from accessing private messages digitally. But as a U.S. company, any data stored on OpenAI’s servers can be subpoenaed by the FBI under the CLOUD Act, Walsh said.
“Adding OpenAI or any company that has the ability to read messages is effectively removing the entire benefit of end-to-end encryption,” he told Straight Arrow.
Knodel said the way ChatGPT designed this product reminded her of “The Ghost Proposal.”
Messaging platforms usually notify everyone in the thread when a new user joins a chat. However, in 2018, two people working for the British intelligence agency GCQH suggested that encrypted messaging platforms should design a way to “silently add a law enforcement participant to a group chat or call.”
This would allow any conversation to be secretly monitored, without breaking the end-to-end encryption that messaging companies knew was important to their users.
Organizations like the Electronic Frontier Foundation argued this kind of secret listening to conversations would be an “encryption backdoor with all the security and privacy risks that come with it.”
What can users do?
Artificial Intelligence companies keep rolling out integrations to find new uses for their products. It doesn’t always land well. Meta and Google both recently retracted features within days after public outcry.
Knobel said it’s important to bear in mind that people have a right to privacy.
“I think we’ve all arrived at the idea that you should be able to have a private conversation, even if it’s intermediated by the Internet,” she said. “AI is coming for that assumption.”
Walsh recommended people assess how comfortable they feel about their level of risk and exposure, and choose messaging platforms on that basis.
“It’s actually good ethical practice to not use AI in a conversation that involves other people,” he said.
Round out your reading
- All your questions about napping, answered.
- Trump’s $5,000 promise echoes past payouts that never materialized.
- Inside the effort to make data centers pay their share of electricity costs.
- Why did the Feds seize the ’largest Martian meteorite on Earth’?
- Photos and video show exactly where and when Trump visited Ground Zero after 9/11.