Skip to content

AI Governance

OpenAI's ChatGPT can now remember everything you click and type on your Mac. Here is what business owners should know before an admin approves it.

On August 13, 2026, OpenAI added Computer History to the ChatGPT desktop app for macOS, available to Pro, Business, and Enterprise users. Once turned on, it watches activity across allowed apps and websites, clicks, typing, keyboard shortcuts, and app switches, and turns that activity into memories ChatGPT and Codex can reference later. It is opt-in and, in Business and Enterprise workspaces, an administrator has to grant access before anyone can turn it on. It is also true, by OpenAI's own documentation, that the memory files it creates are not encrypted, and that the feature increases the risk of a well-known AI vulnerability called prompt injection.

By Fabio Rabelo · Founder, ATLACIS ·

What happened

OpenAI's desktop app changelog for August 13, 2026 introduced Computer History, a new optional feature for ChatGPT Pro, Business, and Enterprise users on macOS. It builds an interaction-event stream from apps and websites a user allows, capturing clicks, typing, keyboard shortcuts, app switches, and other context macOS exposes through its accessibility system. Periodically, that stream is summarized into a timeline and into plain-text memory files that ChatGPT and Codex can use to answer questions like "what was I working on before my last break" or "prepare a summary of what I did yesterday for standup." OpenAI is explicit about what the feature does not do: it does not capture screenshots, screen recordings, microphone input, or system audio, and private browsing is never included. It replaces Chronicle, an earlier research preview that worked from screen captures, a design choice OpenAI frames as an improvement. The feature is off by default. Pro subscribers can turn it on individually. In a Business or Enterprise workspace, an administrator must first grant workspace access before any member can opt in, and granting that access does not turn the feature on for anyone by itself, each person still has to enable it themselves. Computer History is not currently available in the European Economic Area, Switzerland, or the United Kingdom. OpenAI's own documentation also describes two different storage stages, and they matter for different reasons. The raw interaction-event stream is isolated inside a sandboxed app container on the Mac and deleted after 48 hours. The memory files generated from that stream, plain-text Markdown summaries, are a separate matter: they stay on the filesystem until a user deletes them, and OpenAI states directly that they "are not encrypted by Computer History, and other programs running as your macOS user may be able to access them." OpenAI also states that Computer History "increases the risk of prompt injection from content in apps and websites."

Why it matters for business owners

A feature like this is going to look useful to almost anyone who tries it. Losing context between tasks, forgetting where a document lives, re-explaining the same background to an AI tool every time a chat resets, these are real, everyday frictions, and Computer History is built to remove them. That is exactly why a Business or Enterprise admin is likely to see a request to "enable Computer History" and treat it as a routine feature toggle rather than a decision worth a real review. It is not a routine toggle. Granting workspace access changes what a company-approved AI tool is allowed to observe on an employee's machine, potentially including the browser tabs, documents, and messaging apps that employee touches over the course of a normal day. The admin-approval step OpenAI built in is a real safeguard, but it only controls who is allowed to turn the feature on. It does not review what data ends up in unencrypted files on that person's laptop, and it does not stop an employee handling client records, financial data, or health information on the same machine from opting in without thinking through what that means.

What owners should not misunderstand

This is not a hidden or secret surveillance feature. It is disclosed, opt-in at the individual level, and gated behind administrator approval in Business and Enterprise workspaces. Describing it as OpenAI silently recording every keystroke without telling anyone would misstate what OpenAI actually shipped and documented in detail. It is also narrower than some past AI activity-tracking controversies. Computer History does not use the microphone, does not take screenshots, and does not record system audio, and OpenAI built it specifically to avoid the screen-capture approach of its own earlier Chronicle preview. Private browsing is excluded entirely. What should not get waved away is the specific admission sitting inside OpenAI's own documentation: the generated memory files are unencrypted, they persist indefinitely until deleted, and other software running under the same macOS user account can read them. That is a materially different risk than a 48-hour temporary cache. A memory file summarizing weeks of a controller's work inside accounting software, or a salesperson's activity inside a CRM, sits in plain text on the laptop for as long as nobody deletes it. OpenAI is not hiding this. It says so directly, and it is still worth taking seriously precisely because it is easy to skim past in a changelog entry.

The operational lesson

The real decision here is not "AI feature, yes or no." It is a data governance decision disguised as a convenience toggle, and it deserves the same scrutiny a business would give to installing any new software that watches employee activity across other applications. OpenAI's own warning about prompt injection sharpens the stakes. Computer History increases exposure to a known failure mode where malicious instructions embedded in a webpage or document get treated by the AI system as if the user had typed them. A feature that widens what an AI agent can see across a workday also widens where those instructions can hide. OpenAI's guidance to "turn it off during communications with other people unless you have their prior express consent" points at a gap the feature's design does not close by itself. Most people take calls, share screens, or message coworkers and clients from the same laptop they use for everything else. A consent problem that depends on an individual employee remembering to pause a background feature before every sensitive conversation is not a solved problem, it is a policy gap waiting for someone to forget.

What a serious business should do next

Before an administrator grants workspace access to Computer History, or before a Pro user turns it on unprompted, read OpenAI's own documentation on the feature rather than the changelog summary. The detail that matters most for a business, that generated memory files are unencrypted and readable by other local software, is stated plainly on OpenAI's own page, not buried or hidden. Decide, in writing, which roles should even be eligible to request access. An employee who never touches regulated or sensitive data on their laptop is a very different case from a bookkeeper, a healthcare intake coordinator, or anyone handling client financial records on the same machine they use for ChatGPT. If a business does move forward, use the exclusion controls OpenAI provides. Computer History lets a user exclude specific apps and websites from contributing to the history, and that control should be treated as mandatory, not optional, for any app that touches client, financial, health, or legal information. Set a clear internal rule about calls and shared screens: pause or exclude communication apps before any conversation with a client, patient, or colleague who has not agreed to be part of an AI-generated activity record. Do not leave that judgment call to the moment. If none of this maps to a real, recurring workflow problem the business already has, leave the feature off. A memory convenience layer is not worth the exposure for a business that does not have a specific, well-defined use for it yet.

The Atlacis view

This is not a story about a reckless AI company. OpenAI documented what Computer History captures, where it is stored, how long it lasts, and where it falls short, in more detail than most vendors bother to publish. That transparency is exactly what makes it a useful test case: even a well-disclosed feature can carry real exposure if a business adopts it as a routine click instead of a governance decision. Atlacis helps owners slow down at exactly this moment, when a new AI feature shows up asking for expanded access to how employees actually work. That means reading what the vendor actually says the feature does, mapping which roles and workflows would be touched, and deciding deliberately whether the convenience is worth the exposure for this business, not whether it sounds useful in a changelog. A feature can be honestly disclosed and still be the wrong choice for a specific team handling specific data. The job is knowing which one your business is looking at before an admin clicks approve.

The short version

  • OpenAI added Computer History to the ChatGPT desktop app for macOS on August 13, 2026. It turns clicks, typing, and app-switching activity into memories ChatGPT and Codex can reference later.
  • The feature is off by default. Pro users can enable it individually; in Business and Enterprise workspaces, an administrator must grant access before any member can opt in.
  • OpenAI's own documentation states the generated memory files are not encrypted and that other programs running under the same macOS user account may be able to access them. Those files persist until deleted.
  • OpenAI also states directly that Computer History increases the risk of prompt injection from content in apps and websites, and recommends pausing it during conversations with people who have not consented.
  • This is not hidden surveillance. It is disclosed, opt-in, and admin-gated, which is exactly why it is easy to approve as a routine toggle rather than review as a data governance decision.
  • Before granting access, read OpenAI's own documentation, decide which roles should be eligible, use the app and website exclusion controls for anything touching client or financial data, and set a clear rule for calls and shared screens.
Tags:AI governancedata exposureAI vendor riskemployee AI usebusiness AIAI decision-makingAI securityprivate AI
FAQ

Common questions

Does Computer History record everything I type, even passwords?
OpenAI's documentation says it captures interaction events macOS exposes through its accessibility system, including clicks, typing, keyboard shortcuts, and app switches, across allowed apps and websites. It does not capture screenshots, screen recordings, microphone input, or system audio, and private browsing is excluded. Nothing in OpenAI's documentation categorically excludes sensitive typed content such as passwords from the apps and sites a user has allowed, which is why the exclusion controls and the choice of which apps to include matter.
Is Computer History safe to turn on for a business?
It depends on the role and the data involved. OpenAI's own documentation states the generated memory files are unencrypted and may be readable by other local programs, and that the feature increases prompt injection risk. For an employee who does not handle sensitive client, financial, or health data on the same machine, the risk may be manageable. For anyone who does, a business should exclude the relevant apps or leave the feature off until a specific, reviewed use case justifies it.
Does admin approval mean the feature is already on for everyone in the workspace?
No. OpenAI's documentation is explicit that granting workspace access only allows members to choose to turn the feature on. It does not enable it for anyone automatically. Each person, including Pro users, must opt in individually after access is granted.
Keep reading

More from the blog

Private Claude conversations and work documents turned up searchable on Google this weekend. Here is what business owners should know before trusting an AI tool's share button.

Over the weekend of July 25 to 26, 2026, Reddit users found that shared Claude conversations and Artifacts were showing up in Google search results, some containing medical records, children's contact information, and internal company documents. 404 Media, TechCrunch, Futurism, and VentureBeat independently confirmed the exposure and Anthropic's response. Nothing indicates a breach of private accounts. The material exposed was limited to what users themselves chose to mark shareable, which is exactly why the story matters: a share button that reads as sending a private link can end up publishing a page the open web eventually finds.

Samsung banned ChatGPT in 2023 after employees leaked code. Three years later they are deploying AI to every employee. Here is the governance lesson.

In 2023, Samsung employees uploaded proprietary semiconductor code and internal meeting notes to ChatGPT. Samsung banned all generative AI tools. Three years later, the company announced one of OpenAI's largest ever enterprise deployments. The arc between those two decisions is the governance lesson most business owners have not finished drawing.

AI access is now an operational risk

AI access can change without warning. Treat vendor dependency, data exposure, and fallback workflows as operational risk, not just a tool choice.

Make better AI decisions, starting with one call.

Book a free AI Fit Call. We will tell you what to use, what to avoid, and where to start. No jargon, no pressure.