ChatGPT Can Now Draft and Send Your Text Messages. Here's What You Need to Know.
OpenAI has released a new Apple Messages plug-in for ChatGPT that lets the chatbot read, sort, draft, and send iMessages directly from your iPhone. The integration went live on August 20, 2026, and extends to Codex and ChatGPT Work, bringing the same message-handling capabilities to developer and enterprise users. The pitch is straightforward: ChatGPT becomes a first-class client for your text history, proposing follow-up messages based on previous conversations and helping you manage message threads without leaving the Messages app.
What Can ChatGPT Actually Do With Your Messages?
The launch demo showcases several practical use cases. ChatGPT can propose follow-up messages to contacts based on conversations from the previous day, delete threads, draft outbound texts, and search through old message history to find information that Apple's built-in iMessage search has historically struggled to locate. This positions ChatGPT as an operating layer sitting on top of apps you already use, rather than trying to replace them entirely.
The plug-in slots into a category that competing AI agents have been circling for months. Message triage, calendar handling, and email drafting are the obvious near-term jobs for a general-purpose assistant, and Messages is the most-used app on iPhone for a large share of Apple's user base. Getting a foothold there means ChatGPT is no longer confined to its own window.
How to Use ChatGPT's Message Features Safely?
- Enable Per-Message Review: OpenAI explicitly discourages turning on persistent approval, the setting that would let ChatGPT send messages without your confirmation. The company warns that enabling this setting "removes your final chance to review a message before ChatGPT sends it as you." Always review before sending.
- Understand Local Processing: OpenAI stated that the plug-in runs locally on your machine and does not create an index of all your messages. However, the specifics of what message content leaves your device and for how long remain unclear in public materials.
- Watch for Hallucinations: A chatbot reading, drafting, and sending texts is exactly the sort of capability where a subtle failure,a hallucinated fact, a misread thread, an autofilled contact,becomes a message you cannot unsend. The local-runtime claim narrows the surface area but does not eliminate this risk.
Why Privacy Concerns Matter Here?
Privacy is the immediate question surrounding this integration. OpenAI addressed concerns in a statement to Bloomberg, explaining that the plug-in runs locally on a user's machine and "doesn't create an index of all someone's messages." However, what that means in practice remains vague. The company has not spelled out in public materials how much message content leaves the device or for how long it persists on OpenAI's servers.
The design tension is real and significant. An assistant that always pauses for approval is slower and less useful for batch tasks like replying to a day's worth of conversations at once. An assistant that never pauses can send a hallucinated message under your name to your contacts, which is a category of failure with social consequences that no benchmark score fixes. OpenAI's decision to encourage per-message review suggests the company is taking this risk seriously, even if it means sacrificing some of the efficiency gains users might expect.
How Does This Fit Into OpenAI's Broader Strategy?
The Messages plug-in lands in the middle of a broader OpenAI push on business features. The company has been clawing back ground on Anthropic among US businesses, recently expanding Zero Data Retention to its frontier models and previewing a Private Safety Processing feature. These moves are aimed squarely at enterprise buyers who need to know what happens to their data.
The strategic read is that OpenAI is quietly turning ChatGPT into an operating layer that sits on top of the apps users already have. A Messages plug-in, plus Codex, plus ChatGPT Work is the same product wearing three hats: the chatbot as a shell over the phone, the IDE, and the workplace. Whether users trust ChatGPT enough to hand over their inbox is the question that decides how far that layer extends.
This development also reflects a broader shift in how AI companies are approaching integration. Rather than asking users to abandon their existing tools and move to new AI-native platforms, companies like OpenAI are embedding themselves into the workflows and apps people already rely on daily. The success of this approach will depend not just on technical capability, but on user confidence in the safety and privacy of these integrations.