Your private context is becoming the interface
ChatGPT’s Apple Messages plug-in, Slack’s collaborative vibe-coding channels, Google’s AI chatbot-tuned Discover feed and Meta glasses in the workplace all point in the same direction: AI is moving into the places where people already talk, browse, work and get watched. For product builders, the hard problem is no longer just making the assistant useful; it is deciding who controls the context, when the AI is allowed to act, and how visible that action should be.
TechCrunch
ChatGPT can now send texts for you with new Apple Messages plug-in
ChatGPT can now send texts for you with new Apple Messages plug-in.
techcrunch.com

The most revealing detail in OpenAI’s Apple Messages plug-in is the approval setting. A draft reply still feels like assistance. Persistent approval starts to feel like a proxy with your social life in its hands.
TechCrunch reported that ChatGPT can now connect to a Mac user’s Apple Messages inbox through a new plug-in, search message history, analyse conversations, draft replies and send texts. It works with ChatGPT Work and Codex on macOS. The obvious read is convenience: fewer tabs, fewer copy-pastes, faster replies.
I think that misses the real product shift. The assistant is no longer waiting inside its own box. It is entering the private context where meaning already lives.
That is a very different problem from making a chatbot smarter.
Context is becoming the product surface
For years, AI products have competed on model quality, latency, tools and integrations. Those still matter. But these launches point to a more awkward frontier: context control.
Messages are not documents. Slack channels are not IDEs. Discover is not a settings page. Smart glasses are not phones with worse manners. These are social surfaces with existing norms about who can see, speak, remember and act.
Slack’s new coding product makes this clearer than the Apple example because it is more intentionally supervised. The Verge reported that Slack Code creates project-specific channels where teams can bring in agents like Claude Code, Devin, Vercel Agent and GitHub Copilot, inspect diffs, preview output and approve work. The agent is not hidden in a terminal session or a separate developer dashboard. It is put in the room.
That is a smart product instinct. If agents are going to change shared codebases, they need a shared cockpit: visible work, audit trails, review points, and a place for humans to argue before the bot ships the wrong thing. Slack is treating agentic coding less like individual productivity software and more like a team sport with logs.
Compare that with Apple Messages. A personal inbox is also a workflow, but the permissions are far more intimate. The cost of a bad code diff is often technical debt. The cost of a bad text may be trust. Product builders love removing friction, but in private communication, friction is sometimes the safety mechanism.
Google is making the same move on the attention side. The Verge reported that Discover is getting a chatbot-style interface where users can describe what they want to see, with Google saying the feed will adjust and remember those requests. That sounds like better personalisation. It is also a quiet change in the contract: instead of tuning a feed through taps and inferred behaviour, you instruct it conversationally.
That matters because feeds are already preference machines. Giving them a chat interface makes them feel more obedient, but it may also make the boundary between “I asked for this” and “the system learnt this about me” harder to see.
Then there is the blunt social version of the same issue: Meta glasses in public workplaces. The Verge reported on workers being filmed, harassed and turned into content by people wearing AI-powered Meta smart glasses. The interface is hands-free for the wearer, but the capture is imposed on everyone nearby. That is the part ambient AI marketing tends to glide past.
Economists have an old name for part of this: the principal-agent problem. You delegate work to someone else, then need incentives, monitoring and limits so the agent does not act against your interests. AI makes the “agent” cheap, tireless and embedded in places where the principal is not always obvious. In a group chat, who is the principal? The account holder, the workplace, the team, the person being recorded, or the platform?
The next generation of AI product design will be less about prompt boxes and more about permission architecture. Who owns the context? Who can invite the model in? What does the model remember? When can it act? Who gets notified? Can bystanders refuse?
Builders who answer those questions well will make AI feel useful without making it feel invasive. Builders who ignore them will learn that context is powerful because it is private, shared and socially loaded.
The interface is moving into the room. The hard part is deciding who gets a key.
Read the original on TechCrunch
techcrunch.com