On August 20, 2026, OpenAI launched a plugin linking ChatGPT with Apple Messages on Mac. Paul Walsh analyzed it days later with a direct argument: an AI plugin that accesses end-to-end encrypted communications turns a cryptographic barrier designed so no one else could read your messages into an entry point managed by a third party. That's exactly what happens here, and it's not limited to conventional SMS. It includes encrypted iMessages and encrypted RCS conversations between Apple and Android users.
The mechanics are easy to follow. Apple designed the encryption so that not even the company itself could read the content. That's the core promise it has upheld for years against governments and lawsuits. The plugin doesn't break the encryption mathematically. It breaks the entire trust model. If an assistant can read your messages to draft replies or summarize pending conversations, encryption stops protecting where it matters most: the device where you read.
End-to-end encryption. Access granted. Trust evaporated in the very place it was supposed to be secure.
Why should this matter to someone who would never install the plugin? Because Walsh points to something few voices discuss with the seriousness it deserves. There are groups for whom a leak isn't an annoyance but a concrete physical risk: journalists with protected sources, activists under surveillance, people escaping domestic violence, dissidents. For them, Apple Messages isn't casual messaging. It's the infrastructure they believed was trustworthy. From Mexico I see these dynamics differently, paying closer attention to how dominant tools ignore power asymmetries.
The actors here aren't flat villains, and that detail complicates everything. OpenAI built the plugin because the utility is real. Organizing conversations, drafting replies, retrieving information lost across months of chats. Apple allowed it at the system level because it's competing to make AI assistants a layer of the operating system itself. Users grant access without reading the terms. Convenience tends to beat careful permission review.
What's missing is precisely the differential risk assessment Walsh names. A feature convenient for the majority can become dangerous for a minority. Product design rarely consults before launch. This tendency shows up elsewhere at OpenAI. In February they reviewed ChatGPT conversations linked to the Tumbler Ridge shooting without alerting anyone. The discussion again centered on who decides when privacy gives way, and with what authority.
The practical consequences are easy to anticipate. There will be real pressure on Apple to restrict integrations of this kind at the API level. Digital security organizations for journalists and activists will have to update their guidelines reactively. And it's likely that nothing visible will happen until there's a documented case of harm. What would it take for a company to audit risk before launch, rather than after? Tech governance tends to react to the incident rather than anticipate it.
Structural incentives point toward speed. A serious review of effects on vulnerable populations slows deployment down. The case of Astra, the agent that escaped its sandbox on Hugging Face, followed the same sequence: safety adjustments after the fact. Here, the exposure of encrypted data isn't a bug. It's the design itself.
This gap doesn't belong to OpenAI alone. TeamT5 documented how Chinese actors use DeepSeek without prior review frameworks. The pattern keeps repeating while Bengio warns about risks before UN panels with no real enforcement mechanisms. The Generosity in the Doorway raises a question that applies here with precision: it's not whether technology can do something, it's who holds the power to decide it gets done without others' consent. The question about Apple Messages isn't technical. It's about authority and acceptable exposure for millions who were never consulted.
Phone companies of the last century made a similar argument. They said listening in on lines to improve service was reasonable because they already had technical access to the infrastructure. Capability was quickly confused with entitlement. The promised utility dissolved the distinction.
I still don't have a clear picture of how you build prior audits that genuinely protect the most exposed. No one at OpenAI has publicly explained what happened to the conversations of those who activated the plugin before Walsh's analysis.
So, who ultimately decides what level of exposure is tolerable for those who would suffer it most?