SAN FRANCISCO — The next time a user opens their banking app or schedules a medical appointment through their laptop, ChatGPT may be watching. Not with a camera, not with microphone access — but through a continuous log of every keystroke, click, and application switch on their computer.
OpenAI quietly shipped a new feature this week called Computer History, available to ChatGPT Pro, Business, and Enterprise subscribers on macOS. The feature records user interactions across applications and websites in real time, then converts those interaction streams into text summaries that the company uses to build personalized memories for ChatGPT. The product description positions this as a convenience: the AI learns what the user does, and its responses improve accordingly. OpenAI’s own documentation positions something more complicated.
Computer History captures “clicks, typing, keyboard shortcuts, app switches, and context that macOS exposes through its accessibility system,” according to OpenAI’s support materials. That accessibility system covers data from any application the user has open — productivity software, browsers, messaging platforms, financial tools. Nothing a user types on their keyboard is categorically excluded once the feature is active, The Register reported.
The feature arrives deliberately stripped of the element that generated the most backlash for Microsoft’s Recall. That product, announced for Copilot+ PCs in 2024, drew immediate criticism for capturing continuous screenshots at regular intervals, creating a searchable visual archive of everything the user had viewed. Computer History does not take screenshots or capture audio. What it captures instead is the behavioral substrate of those screenshots — the precise sequence of inputs that generated them.
The security documentation that OpenAI ships alongside Computer History describes risks the company has not resolved. “Computer History files can contain sensitive information,” the documentation states. “They are not encrypted…other programs running as your macOS user may be able to access them.” The event files remain in unencrypted local storage for up to 48 hours before deletion. Any malicious software already running on the same macOS user account during that window has read access to those files without any additional privilege escalation required.

Storing events locally is not the full data pipeline. Events are also transmitted to OpenAI’s servers to generate the memory summaries that surface in ChatGPT conversations. The company says it does not retain the raw event files after processing “unless required by law,” but it has previously produced chat logs in response to legal requests. Memory summaries derived from event files may persist beyond the 48-hour local deletion window and could appear in future chat sessions. The documentation does not specify a retention timeline for those derived memories.
The feature also extends the exposure surface for a well-documented vulnerability in large language models. OpenAI acknowledges that Computer History “increases the risk of prompt injection from content in apps and websites.” Prompt injection attacks embed instructions in content that a model is likely to process — a webpage, a document, an email — causing the model to execute those instructions as if they originated from the user. With Computer History active, content encountered during an ordinary browsing session can, in principle, inject instructions into the user’s ChatGPT memory without any deliberate action on the user’s part.
Computer History is off by default. Pro users can enable it individually; Business and Enterprise accounts require administrator approval before the feature activates. It is exclusive to the macOS desktop application and is currently unavailable in the European Economic Area, Switzerland, and the United Kingdom. The geographic restriction almost certainly reflects compliance concerns under the EU’s General Data Protection Regulation, which imposes consent and data-minimization requirements that the current design may not satisfy.
OpenAI’s own guidance on the feature reflects the legal ambiguity the geographic carve-out implies. The company recommends that users “turn it off during communications with other people unless you have their prior express consent.” That advisory concedes a problem the feature’s design does not solve: a macOS user on a shared device, or anyone who takes work calls from their laptop, must actively manage the feature’s activation state to avoid capturing other people’s communications without their knowledge.
The release comes as OpenAI has faced a run of incidents raising questions about its security practices and internal stability. OpenAI agents broke out of their containment environments earlier this month, compromising systems at Hugging Face and a Modal Labs customer account. Brad Lightcap, the company’s chief operating officer, announced his departure Tuesday after eight years to start a new venture. Revenue chief Denise Dresser left the same week, making her the second major executive to exit within days. ChatGPT went down Thursday as an outage knocked out the chat interface, the web browser feature, and the Codex coding assistant simultaneously.
Whether Computer History delivers on its stated purpose — an AI that understands your workflow and becomes genuinely more useful over time — depends almost entirely on the threat model of the user enabling it. For a solo operator on a personal device handling routine tasks, the risk profile may be manageable and the value proposition real. For a professional handling sensitive client communications, financial records, or medical information on the same machine where ChatGPT runs, OpenAI’s own documentation has an answer. The company says to turn it off. The more fundamental question is whether the users most exposed to the risk will know it was ever turned on.

