The Permission Prompt Is Not the Policy
OpenAI’s new Apple Messages plugin lets ChatGPT on Mac read, search, summarize, draft, and send messages after permission.
That sounds like a feature. Inside a company, it is a boundary test.
Messages are not a neutral inbox. They hold pricing, client conflict, employee issues, legal fragments, and decisions nobody ever wrote down properly. When an assistant can search that layer, “the user clicked allow” is not much of a policy.
The old rule was simple: do not paste sensitive data into the chatbot.
That rule is breaking because the useful tools no longer wait for paste. They connect to the places where the work already lives.
So the question changes.
Which systems can AI read? Which can it draft into? Which can it send from? Who approves access? What never goes in, even if the tool can reach it?
This does not need a giant governance theater. It needs a short permission map that normal people can remember before the macOS prompt appears.
The private workflow boundary is moving.
If the business does not draw it, the app will.