Tech Notes · AI
An AI loophole in your pocket: Why Apple’s Writing Tools require a second look
Apple's Writing Tools can route selected text through free ChatGPT with one tap, exposing work data. Here is what that means and what your team should do.
March 31, 2026
Generative AI keeps adding convenient productivity tools, but the landscape changes so fast that using them thoughtfully and securely takes attention, especially with proprietary or sensitive information. Recent Apple OS updates are a case in point: they enable some AI features without the guardrails we recommend for organizational use.
The feature: quick and easy writing assistance
Apple's new Writing Tools help users proofread, rewrite, and summarize text across apps. By default some of these tools use a private AI model, but others can hook into the free version of OpenAI's ChatGPT.
The core capability is advanced text work: proofreading, rewriting and rephrasing, and summarizing. Writing Tools can be accessed directly from the text selection menu (the same menu where "Cut," "Copy," and "Paste" appear) within virtually any text field across many applications, including Mail, Notes, Messages, and third-party apps. A typical user drafting an email to a client in the Mail app can have Writing Tools suggest a reply based on the message thread, or take a lengthy message and boil it down to a few bullet points.
To use the ChatGPT features, you need to have set up your own ChatGPT account, which can be just a free account. That is where the question of privacy gets muddy.
The loophole: a gap in governance
Most users won't find it easy to distinguish between the privacy Apple promises generally for "Apple Intelligence" and the terms and conditions of a free ChatGPT account. The problem is that when you use free genAI tools, there is no guarantee that your input data (proprietary emails, drafts, or internal notes) won't be used to train the large language model (LLM), which makes that input essentially public. This OS integration, activated by a single menu tap on selected text, makes it easy to do something we strongly advise against: sending work-related data through a free genAI application.
The result is that many people using the ChatGPT-powered Writing Tools may be exposing work-related data, in an unprotected way, to OpenAI's LLM.
Google has released a fix to close this loophole in its own apps, letting administrators disable Writing Tools within Gmail, Docs, and other Workspace apps. But it is available only to Workspace Enterprise clients who have implemented strict mobile device management (MDM). Most small to medium-sized businesses operate at the Business Standard or Business Plus tier, which does not offer this fix.
What you should do
- Build awareness. Make sure your team understands that extending Apple's Writing Tools to the ChatGPT features is a gateway to a free LLM that is not recommended or permitted by your IT department.
- Review your organization's use of generative AI. If staff are already using free tools to improve their workflow (many people are), make sure they have access to a paid version that protects organizational security.
- Participate in a cybersecurity assessment. This is exactly the kind of nuance we review as part of our cybersecurity assessments, where we look for gaps in which default behavior conflicts with your business interests.
If you're concerned about how AI tools interact with your company data, let's start a conversation. Security isn't just about firewalls and passwords anymore. It's about knowing where your data goes when you click "Rewrite."
For a free consultation and written estimate, send us a message.