Blog

Claude vs ChatGPT's New Apple Messages Plugin: What to Weigh Before an AI Agent Reads Your Texts

August 2026 · 6 min read · AI Strategy

A phone full of message lines with a dotted arrow pointing to a friendly robot face
← Back to all posts

OpenAI shipped a plugin on 20 August that lets ChatGPT's macOS desktop app read, search, summarise and send messages across iMessage, SMS and RCS on Apple Silicon Macs. It is available on every tier including the free plan. It will tell you who you talk to and what about, and by default it asks for approval before sending anything on your behalf. Setting it up means granting Full Disk Access plus contacts and automation permissions.

It is a genuinely useful consumer feature and a good marker of where agent access is heading. Not just documents and email, but the full record of how a person communicates. For personal use that trade-off is a personal call. For a business it is a different conversation, because an AI agent holding Full Disk Access to a device's entire message history is exactly the sort of access that needs a written position before someone enables it, not after.

What the plugin actually does

  • Reads, searches and summarises iMessage, SMS and RCS history on Apple Silicon Macs, across every ChatGPT tier including free.

  • Sends messages on the user's behalf, with an approval prompt on by default. Defaults can be changed by the user.

  • Requires Full Disk Access plus contacts and automation permissions, which in practice is broad local access, not access scoped to one app.

The permission scope is the part worth sitting with. Full Disk Access is not a messaging permission. It is a device permission, and once granted it applies to whatever the application chooses to read, now or after a future update. That is not an accusation about any particular vendor's intentions. It is a statement about what the permission model allows, and it is the same reason your IT policy probably already treats Full Disk Access requests as a decision rather than a click-through.

Why this is a business problem, not a features comparison

On a work-issued Mac, a message history is rarely just personal. It contains client names, deal terms, scheduling for matters under NDA, and in professional services it very often contains information about third parties who never consented to any of it. Under the Australian Privacy Act, the obligations attached to that information sit with the business regardless of which AI vendor's software did the indexing. A Sydney firm cannot point at a plugin's terms of service as its compliance position.

Claude takes a narrower default path here. Connectors and computer-use actions are scoped to what the user explicitly grants, and anything sensitive routes through an approval step before it happens. That is the same governance model already applied to Gmail, Slack and file access. It is a meaningfully different starting posture, though it is worth being clear that a scoped connector granted carelessly is still a broad grant. The model helps; it does not make the decision for you.

The policy questions worth answering first

Before any messaging-adjacent AI feature goes on a work device, get answers to these in writing. It takes an afternoon and saves an incident review:

  • What is actually being indexed, and is any of it information about people who are not your staff or your customers?

  • Where does that data live once indexed, and for how long? Retention is the question most often skipped.

  • Who approved the access, and does that person have the authority to accept the Privacy Act exposure that comes with it?

  • What is the removal path if you change your mind, and does revoking the permission actually delete what was already indexed?

  • Does this device hold client information covered by a contract that says where data may be processed? Plenty do, and nobody checks until later.

What not to conclude from this

This is not an argument that agent access to communications is inherently wrong. Handled properly it is one of the higher-value things an AI assistant can do, and teams that get the governance right ahead of time move faster than teams that ban it and then quietly discover people are using personal accounts instead. A shadow-AI problem is worse than a governed one.

It is also not an argument that a single vendor has solved this. Every serious assistant is moving toward broader device and account access, and the approval-step-by-default pattern is becoming common rather than distinctive. The differentiator over the next year will be how granular the grants are and how legible the audit trail is when someone asks what the agent read. Those are the two things to test in a trial, and they cost nothing to check before rollout. A permissions review at this scope typically runs $3,500, against a notifiable data breach exposure that starts well into six figures once you count legal, notification and remediation.

If your team is weighing AI tools that touch personal or client communications, it is worth getting the access model right before rollout rather than after an incident. Automata AI scopes exactly this kind of connector and permissions review as part of a Claude setup engagement for Australian businesses, book a session if you want it done before the first person clicks allow.

Ready to move from AI pilot to production?

We help mid-market Australian businesses deploy AI automations that actually reach production and deliver measurable ROI.