Security1 distinct publisher3 min readUpdated
The macOS feature is off by default, and Business and Enterprise tenants need administrator approval first. That approval is the entire policy decision, and it happens once.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The macOS feature is off by default, and Business and Enterprise tenants need administrator approval first. That approval is the entire policy decision, and it happens once.
OpenAI has shipped Computer History, a feature in the macOS ChatGPT desktop app that converts recent computer activity into memories that ChatGPT and Codex can use [1][2]. The consequence for endpoint and identity owners is narrow and concrete: the feature produces unencrypted plain-text Markdown files describing what a person did, and those files stay on the laptop until someone deletes them [3][4]. The mechanics are unremarkable and that is the point. Computer History builds a timeline out of everyday use, grouping activity into summaries and noting which apps and websites fed each one [5]. OpenAI says it draws on interaction events plus text and other context exposed through macOS accessibility features, and that it replaces the earlier Chronicle research preview as a rebuilt system rather than a rename [6][7]. The company says it does not include screenshots or record audio, and that private-mode browsing is never included [8]. The gating is where administrators should pay attention. The feature is off by default and opt-in, and it requires the separate Memories feature to be on [9]. Pro users can switch it on themselves; Business and Enterprise users need administrator approval before they can opt in individually, and approval alone does not enable it for anyone [10]. In practice the admin action is a one-time permission to let individuals decide, which means the policy question has to be settled before the first approval request, not after users start clicking yes [2]. It is also unavailable in the European Economic Area, Switzerland, and the United Kingdom, so geography answers the question for some tenants and not for their US staff [11]. The retention design is worth reading twice. OpenAI says raw interaction-event files stay on the Mac, isolated in the ChatGPT app's data container, and are deleted after 48 hours, and that the same files are processed on its servers only to build summaries and not kept afterward [12][13]. The derived memory files persist indefinitely [3]. So the artifact with the sandbox and the timer is the short-lived one, and the artifact that survives is the unencrypted, human-readable summary [1]. OpenAI flags two risks itself. The memory files are not encrypted, so other programs running under the same macOS user account may be able to read them [4]. And the running context raises prompt-injection exposure: "if you visit a website containing malicious instructions, ChatGPT or Codex might follow those instructions," the company warned [14]. Mark Beare, head of Malwarebytes' consumer security unit and Malwarebytes Labs, warns the files could give infostealers a ready-made map of someone's workday [15]. Read together, the stated protection boundary is the local user account, which is the boundary commodity stealers are built to operate inside [3]. Ed Gaile, Principal Solution Architect at Appfire, put the test plainly to Help Net Security: "Would you let a coworker sit next to you all day, write down every click and keystroke, and keep the notes in a folder on your Mac?" [16]. His threshold was documentary: "If you would have to defend that log in a room, a client memo, a personnel note, a spreadsheet with real numbers, I would not turn it on for the work computer" [17]. His advice was to leave it off the work Mac and use a personal machine with nothing that would need explaining [18]. There are real controls if you allow it. Users pick which apps and websites contribute and can exclude any of them, a pause button in settings and the macOS menu bar halts collection without disabling the feature, and history can be cleared by the last ten minutes, hour, day, or entirely [19]. Each timeline entry's memory file can be revealed in Finder [20], which is also the fastest way to hand your DLP and EDR teams a path to watch.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
OpenAI's new Computer History feature turns recent Mac computer activity into memories that ChatGPT and Codex can use.
Computer History currently only works through the ChatGPT desktop app on macOS.
The memory files generated from interaction events are plain-text Markdown documents and remain until a person deletes them.
OpenAI flags that the memory files are not encrypted, so other programs running under the same macOS user account may be able to read them.
Computer History builds a timeline out of everyday computer use, grouping activity into summaries and noting which apps and websites contributed to each one.
OpenAI says Computer History uses interaction events, along with text and other context available through macOS accessibility features, to create summaries the user can review and delete.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-party product disclosures, single outlet
Nearly every factual element — capture mechanism, retention split, encryption status, opt-in and admin-approval gating, regional exclusions, prompt-injection risk — is attributed to OpenAI's own documentation and quoted directly, which is strong provenance for the mechanics. But it arrives through one publisher with no independent inspection of the memory files, no second outlet corroborating the gating details, and the risk framing resting on two named practitioner opinions rather than demonstrated exploitation.
Shipped and gated, uptake unknown
Availability is evidenced: the feature is live in the macOS ChatGPT desktop app and replaces a prior research preview. Everything beyond availability is unknown — no opt-in counts, no tenant-approval figures, no deployment or usage disclosure — and the design deliberately suppresses default adoption (off by default, dependent on Memories, admin approval required on Business and Enterprise, three major markets excluded).
Slightly overstated threat, accurate mechanics
The headline promise of handing infostealers 'a map of your Mac activity' runs ahead of the record: no incident, malware sample, or measured exposure is presented, and the article does not note that the file is only readable once a user opts in on a platform where malware already has user-account access. Against that, the mechanics are reported accurately and the sharpest risk statements are OpenAI's own, so the overstatement is one of emphasis rather than fabrication.
Vendor and consultancy voices in a security trade outlet
The two named commentators both have commercial stakes adjacent to the finding: a Malwarebytes executive warning about infostealers sells endpoint protection, and an Appfire solution architect advising against enabling it on work Macs sits in the enterprise-tooling advisory business. The outlet is a security trade publication whose audience rewards risk-forward framing. OpenAI's own statements carry the opposite incentive — foregrounding safeguards, local sandboxing and non-retention.
Mechanics reliable, consequences unverified
Confidence is moderate: the feature's documented behaviour and gating are well specified and directly quoted, so operators can act on them. Confidence is capped by single-publisher sourcing, absence of independent verification of file contents or retention behaviour, no OpenAI response to the critiques, and zero adoption data on which to judge real-world exposure.
invest
OpenAI's Computer History turns keystroke logging into a ChatGPT setting1 distinct publisher
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
product
Record, don't prompt: two labs converge on demonstration as the agent interface1 distinct publisher
build
Developer habit, priced at $965B: what Anthropic's run actually proves1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026