AI tools can now access encrypted messaging platforms like iMessage, raising serious questions about confidentiality, attorney-client privilege, and discovery exposure that encryption alone cannot resolve.
Businesses have long treated end-to-end encryption as a reliable safeguard for sensitive communications, but the integration of AI into messaging and collaboration platforms introduces an entirely different category of risk.
Apple’s iMessage uses end-to-end encryption to protect messages in transit, but that protection does not govern what happens when an AI system is later granted permission to access those stored communications.
The issue has become especially pressing with the introduction of an Apple Messages plug-in for ChatGPT on Mac, which reportedly allows users to search conversations, summarize exchanges, draft responses, and send messages with appropriate authorisation.
Available reporting indicates the plug-in requires affirmative permissions and operates locally to interact with the Messages database, rather than automatically uploading a user’s entire communications archive to OpenAI.
The relevant risk inquiry should focus on what information is retrieved for a specific task, what data crosses the device boundary, applicable retention policies, and what derivative records are created in the process.
Businesses must also distinguish this new plug-in from the pre-existing ChatGPT integration within Apple Intelligence, which operates under a different permission model and involves separate data-handling rules.
A privileged text exchange between a chief executive and general counsel may be encrypted in transit, but once an AI assistant is instructed to summarise those messages, an entirely different set of questions arises about processing, retention, and third-party access.
Organisations must determine whether message content is processed entirely on-device, whether any information is transmitted to an AI provider’s cloud, whether content is retained, and whether it can be used to train models.
The American Bar Association’s Formal Opinion 512 makes clear that lawyers using generative AI remain responsible for protecting client information and must understand how the technology operates well enough to evaluate its risks.
Florida Bar Ethics Opinion 24-1 similarly instructs lawyers using generative AI to investigate a provider’s data-retention, data-sharing, and self-learning policies, and to take reasonable precautions to protect confidential information.
Businesses should resist the oversimplified conclusion that using any AI tool automatically destroys attorney-client privilege, as the analysis depends heavily on the architecture, contractual terms, and configuration of each specific product.
The more productive question for risk management is not whether AI automatically waives privilege, but whether the organisation has structured its AI use so that confidentiality can be defended if privilege is later challenged.
Consumer and enterprise AI services must not be treated as interchangeable, since account type, configuration, permissions, contract terms, and actual data flows produce materially different legal outcomes for businesses relying on those tools.
OpenAI’s documentation notes that when ChatGPT is used through Apple’s integration without a ChatGPT account, OpenAI states it does not receive the user’s IP address, store the requests, or use those requests to train its models.
The most significant enterprise risk may not arise from an intentionally deployed corporate AI tool, but from employees connecting AI applications to personal devices that contain years of sensitive company communications.
Executives routinely use text messaging for matters including pending transactions, litigation strategy, internal investigations, employment decisions, and communications with outside counsel, all of which could be exposed through a personal AI integration.
Businesses should immediately inventory not just AI applications but the specific systems and data repositories those applications can access, including messaging platforms, document management systems, and collaboration tools like Teams and Slack.
Organisations should adopt a three-tier classification for AI tools covering those approved for privileged information, those approved for general business use only, and those not approved pending review.
Legal and IT teams should treat AI configuration as a core component of litigation readiness, ensuring they understand where AI-generated artifacts reside and how those records can be preserved, collected, or deleted in response to a legal hold or regulatory demand.

