Morning Overview

ChatGPT can now read and send your texts through a new Apple Messages plug-in

OpenAI has extended ChatGPT into one of the most personal corners of a Mac: the text-message inbox. A new plug-in lets the assistant reach directly into Apple Messages, where it can read conversations and send replies on a user’s behalf.

The integration, released on August 20, 2026, works across iMessage, SMS, and RCS conversations. It turns ChatGPT from a chatbot that answers questions into a tool that can act inside a messaging app, drafting and sending texts rather than only discussing them.

What the plug-in can do

The feature gives the assistant a range of abilities inside Messages. It can read, search, summarize, and send messages, and it can suggest follow-up replies based on texts that have come in.

Beyond composing and sending, the plug-in can delete unwanted messages and search through message history to surface specific information. That combination positions it as a way to triage a busy inbox, not just to fire off a single reply. Summarizing a long thread or pulling a specific detail out of months of back-and-forth are the kinds of tasks that are tedious to do by hand, and handing them to an assistant is a large part of the plug-in’s appeal.

The ability to draft context-aware replies is what most distinguishes it from a simple automation. Because the assistant can read the surrounding conversation, its suggested responses can reflect the tone and content of what came before, rather than offering generic canned text that ignores the thread.

Where it runs and who can use it

Availability spans all subscription tiers of ChatGPT, including free users. The integration functions within the ChatGPT Work and Codex modes on the macOS desktop app, tying it to the Mac experience rather than a phone.

There are hardware limits. The plug-in operates on Apple silicon Macs and does not support Intel-based machines, which narrows the pool of devices that can run it to newer hardware. Tying the feature to the desktop app rather than a mobile release also reflects how much of the integration depends on system-level access that a Mac can grant but a locked-down phone environment generally cannot.

The permissions it demands

Because the assistant reaches into a system app, the setup requires broad access. Users must grant Full Disk Access, along with permissions for contact names and automation tools, for the integration to work effectively.

Those are significant permissions to hand any application, since Full Disk Access reaches well beyond a single app’s own files. The requirement underscores how deeply the plug-in has to hook into the operating system to read and manage messages. Apple stores conversations in a protected database on the Mac, and reaching that data is what forces the broad grant rather than the narrower, per-folder permissions many apps request.

The guardrails on sending

OpenAI has built in a check before any message leaves the device. By default, ChatGPT requires user approval before sending, so a person can review both the content and the recipients before a text goes out.

That approval step is meant to prevent the assistant from firing off messages autonomously. It keeps a human decision between a drafted reply and its delivery, an important boundary for a tool operating inside private conversations. The safeguard matters because a message sent in error, to the wrong recipient or with the wrong content, cannot be recalled once it reaches another person, unlike a draft that can be edited or discarded.

The requirement also addresses the risk that an assistant misreads intent and composes something a person would not have chosen to say. By making the human the final gate on both wording and recipients, the design leaves room to catch a mistaken tone or an unintended send before it becomes a real exchange.

How the privacy design works

The plug-in is structured to keep message data on the user’s own machine. It runs locally on the device, and the content of messages is stored locally on the computer rather than saved to the company’s servers.

That local-first approach is a direct response to the obvious concern about letting an AI assistant into a text inbox. Keeping the message content on the device narrows how far that private data travels, even as the assistant works with it. Text conversations often contain highly sensitive material, from financial details to private exchanges with family, so where that content is stored and whether it leaves the machine are central questions for anyone weighing the feature.

Why the integration matters

Letting an assistant read and send texts is a meaningful step beyond answering prompts in a chat window. As described in coverage of the release, the plug-in lets ChatGPT act inside a core Apple app rather than staying confined to its own interface.

The trade-off it presents is convenience against access. The plug-in can lighten the work of managing messages, but it does so only after a user grants deep system permissions and lets an AI tool into a private conversation stream, a bargain each person will weigh differently. For someone who fields a heavy volume of texts, the time saved may justify the access, while a more privacy-conscious user may decide that no efficiency gain is worth opening a message archive to an outside tool.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview