ChatGPT Can Now Read Your Texts: AI Wants Everything from Your Apps
I'm LongbridgeAI, I can summarize articles.OpenAI has launched an Apple Messages connector for ChatGPT on Mac. With user authorization, the AI can retrieve and analyze iMessage chat histories and draft replies. This feature transforms fragmented chats into structured data, assisting with organizing to-do lists and coordinating schedules. Additionally, OpenAI recently introduced Finances and Health features that connect to bank accounts, aiming to enhance the AI's understanding of users' current situations and task execution capabilities by integrating multi-source data
ChatGPT can now directly "browse" your iMessages.
In the early hours of today, OpenAI officially launched the Apple Messages connector for ChatGPT on Mac. After granting the necessary system permissions, you can type "@" and select "Messages," allowing ChatGPT to retrieve and analyze chat records and help you draft replies.

Turning Fragmented Chat Logs into Actionable Structured Data
For instance, if you tell ChatGPT, "Summarize what I need to follow up on from yesterday," it will review yesterday's chat logs to identify conversations that were left unresolved.
In an example demonstrated by OpenAI, a friend in a book club asked, "When is our next gathering?" After locating this message, ChatGPT checked the calendar to confirm the event time and then drafted a reply.
Another example involves the common scenario of making dinner plans. If a friend invites you to dinner next week via Messages, you can ask ChatGPT to check your calendar and inform them of your available time slots.
However, ChatGPT does not take the initiative to send replies on your behalf. You must edit the text in the card if needed, and only after you confirm and click send will the message appear in the iMessage conversation thread.
Such scenarios are ubiquitous in chat histories. Casual mentions of birthdays by friends, work tasks colleagues plan to handle next week, family dinner arrangements... These trivial matters can now be actively accessed by the model, becoming "context" for understanding the user's current situation and continuing task execution.
This reflects an increasingly obvious trend in OpenAI's recent product changes.

Image | ChatGPT Finances
ChatGPT Finances, launched in May this year, allows users to connect bank accounts, credit cards, and investment accounts via Plaid. Once connected, users can directly ask ChatGPT where their money has been spent recently, what fixed subscriptions they have, and how their assets and liabilities have changed.

Image | ChatGPT Health
The previous ChatGPT Health feature followed a similar logic. After connecting to Apple Health and medical records, ChatGPT can reference sleep, exercise, activity, and other health information within the scope of user authorization.
With Messages, the model has begun to access users' chat records, as well as the complex daily schedules and interpersonal relationships behind those chats.
Viewing these features together, OpenAI's strategy is clear: indirectly obtain more information about individuals through the apps and services they already use.

Image | TechRadar
This differs somewhat from traditional ChatGPT "Memory." Memory primarily comes from content users actively provided to ChatGPT in the past; these connectors, however, access real data long recorded by other applications.
Previously, to have ChatGPT analyze a conversation, you needed to take screenshots or copy chat logs; to discuss recent spending, you had to find your bills yourself; to ask why you've been tired lately, you first had to provide details about your sleep and exercise habits.
After integrating these apps, the model no longer requires you to "speak up." The "you" that ChatGPT understands is thus expanding from a few sentences in a dialog box to various records left behind in daily life.
Questions arise accordingly: Hasn't Apple always strictly isolated different apps and data?
Indeed. For security and privacy reasons, Apple has built a formidable moat over the past decade using sandbox mechanisms and entitlements.
A fitness app granted Health permissions does not thereby gain access to Messages chat logs; similarly, the "Messages" app, which stores years of chat content, has no reason to access your health data.

Interestingly, facing this robust sandbox, OpenAI cleverly chose a rather geeky "unconventional" path.
It leveraged macOS's long-existing advanced permissions and automation mechanisms to bypass traditional app boundary constraints: by requesting "Full Disk Access," it directly reads the local SQLite chat database, and then uses native APIs such as AppleScript, Apple Events, and Accessibility to parse and draft messages.
The sandbox and underlying security mechanisms have not failed, but OpenAI has skillfully exploited permission gaps left by the system for high-level automation tools, breaking the long-standing tacit product boundaries.
Apple Guards the Gate, But Who Orchestrates?
Apple itself has been working on connecting system services for many years.
In the era of "Shortcuts," chaining rules heavily relied on humans manually building a strict and rigid pipeline: "Read calendar availability → Filter available slots → Match contacts → Format text → Invoke Messages to send."

Image | AppleInsider
What to read at each step and what to do with the results were basically predefined by humans. Shortcuts executed according to these rules.
AI Agents directly overturn this logic. Users only need to casually say, "Check when I'm free next week and reply to Xiao Wang to arrange a meal." The model can then decompose the task itself:
First, understand the invitation context in the "Messages" app, determine who "Xiao Wang" is from the "Contacts" app, enter the "Calendar" app to find available slots, and finally send the drafted reply back to the "Messages" app for confirmation.

Data silos still exist, and permissions have not disappeared, but large models are beginning to build a new "semantic bus" layer above these sandboxes.
These data points, originally fragmented across various corners of the system, are being pieced together into an increasingly complete and vivid individual profile. Thus, a new question emerges: In future operating systems, who will be responsible for this orchestration?
As the lawsuit between Apple and OpenAI intensifies, this question becomes even more subtle.

Image | Generated using AI
Mark Gurman reported in May this year that the two-year cooperation between the parties had clearly cooled. OpenAI believed that the partnership with Apple had not yielded expected benefits and was even studying legal action at the time.
Two months later, Apple formally sued OpenAI for theft of trade secrets; OpenAI subsequently countered publicly and requested the court to dismiss the lawsuit. It took only two years for the two companies to go from partners to litigants.
Meanwhile, Apple is accelerating its Siri AI, hoping to embed it more deeply into iPhone, iPad, and Mac.

Image | The Verge
The two companies are obviously no longer in their "honeymoon period." Existing macOS permissions still allow ChatGPT to delve deeper into these system services, but Apple may not be willing to see OpenAI long occupy the position of "understanding user intent and scheduling system services."
Apple still firmly holds the keys at the lowest level. Which apps can access which data, which actions require confirmation, and which permissions must never be crossed are ultimately determined by the system.
But after users grant authorization, the ability to understand natural language, judge which services to call, and organize them into a complete task chain is becoming the new entry point in the AI era.
Apple spent over a decade putting data and apps into distinct "rooms" with clear permissions; if Siri AI can smoothly understand intent and freely schedule these rooms within the authorized scope, it is most qualified to become the system's native "commander-in-chief."
Otherwise, while Apple still guards the gate, the command authority to issue orders may fall into the hands of someone else's AI.
Risk Warning and Disclaimer
The market carries risks; invest with caution. This article does not constitute personal investment advice, nor does it consider the specific investment objectives, financial status, or needs of individual users. Users should consider whether any opinions, views, or conclusions in this article align with their specific circumstances. Investment based on this content is at your own risk.
