OpenAI announced Computer History for ChatGPT on August 13, 2026, giving the Mac desktop app a new way to turn computer activity into memories ChatGPT and Codex can use later. The feature has already drawn a familiar comparison: Windows Recall. But for business leaders, the sharper question is not whether the feature sounds useful. It is whether your company is ready for AI tools to ingest employee activity as future context.
What to do this week: do not roll this out across your workspace yet, and do not ignore it either. If you run a ChatGPT Business or Enterprise plan, confirm the admin setting is still off by default. Then decide who, if anyone, should test it under a written rule set.
What Computer History Actually Records on Your Mac
According to OpenAI's documentation, Computer History is off by default and only available in the ChatGPT desktop app on macOS for Pro, Business, and Enterprise users. Once a user turns it on, it builds an “interaction-event stream” from allowed apps and websites. OpenAI says that stream can include clicks, typing, keyboard shortcuts, app switches, and context exposed through macOS's accessibility system. ChatGPT periodically turns those events into text summaries and local memory files that ChatGPT and Codex can draw on later.
OpenAI is explicit that this is not the same as its earlier Chronicle research preview, which used screenshots. Computer History, the company says, does not capture screenshots, screen recordings, microphone input, or system audio, and private or incognito browsing is never included. The business issue is still real: a click-and-keystroke activity stream is a new category of workplace context collection, even without screen images.
Who Can Turn It On: The Admin Approval Chain
The rollout has a layered consent model, which matters more for businesses than for individual users. OpenAI's docs state that ChatGPT Pro users can enable Computer History themselves. Business and Enterprise users cannot: an administrator has to explicitly grant access before any workspace member can turn it on. Even after admin approval, the feature still requires Memories to be enabled and the individual user to opt in on their own device.
That gives businesses three gates: workspace access, individual opt-in, and Memories. All three conditions have to be satisfied before Computer History can collect activity for that user. The practical implication is simple: a company can currently block this feature by leaving the admin console setting untouched.
Where the Data Goes and Who Can Read the Memory Files
This is the part worth reading twice. OpenAI says Computer History temporarily stores interaction-event files on the Mac for up to 48 hours, inside the ChatGPT App Group. OpenAI periodically processes those events on its servers to generate memories, but says it does not retain the event files after processing unless required by law. Generated memories return to the Mac as local Markdown files, typically under a path like ~/.codex/memories/extensions/skysight/, and remain there until the user deletes or clears them.
OpenAI's own warning, quoted across CNET, ZDNET, and The Next Web, is worth repeating because it is the company's language, not press speculation: the generated memory files can contain sensitive information, are stored as plain-text Markdown, and do not receive additional encryption from Computer History itself. Other programs running as the same macOS user may be able to access them. That is not a breach and nothing has been reported leaking. It is a design tradeoff OpenAI is disclosing up front.
There is a second data flow to track: when ChatGPT or Codex later pulls a memory into a chat, that memory content and related interaction events become part of that conversation. For ChatGPT Business and Enterprise workspaces, OpenAI says business inputs and outputs are not used to train its models by default. For Pro users in personal workspaces, model-improvement use depends on the user's Data Controls settings.
The Prompt Injection Risk Nobody Has Solved Yet
OpenAI's documentation directly states that Computer History increases prompt injection risk from content encountered in allowed apps and websites. The Next Web's coverage notes that OpenAI recommends excluding apps that handle health, financial, or personal data. This is the same risk class that has followed agentic browsing and computer-use features all year, discussed at length in AIN's look at the agent stack moving from demos into infrastructure decisions.
Once an AI system is ingesting activity and content from apps and websites as future context, malicious or manipulated material in an allowed source can become a way to steer the system later, not just inform it.
An AI Governance Institute analysis goes further, recommending updated acceptable-use policy, endpoint controls, and documented regional blocks. That is one outside group's framing, not an OpenAI position, and I would not rely on it for product mechanics. Use OpenAI for the facts. Use governance analysts for the questions your policy should answer.
A Safe Starting Point If You Decide to Pilot It
Availability is still narrow. OpenAI says Computer History is not currently offered in the European Economic Area, Switzerland, or the United Kingdom, and it only works with Memories enabled on the ChatGPT desktop app for macOS, not through an API key or Amazon Bedrock. OpenAI's launch documentation describes Computer History as macOS-only and does not announce Windows or mobile availability.
If you want to try it, start small. Pick one or two low-risk workflows. Exclude HR, health, finance, legal, client-confidential work, and password managers. Treat communication apps separately: OpenAI says Computer History should be turned off during communications with other people unless they have given prior express consent.
That consent point may matter more for employers than the Markdown file format. A company can decide to pilot activity memory for a narrow internal workflow. It should not quietly create a system that captures events from chats, meetings, client messages, or employee conversations without a clear consent rule.
If this post has you thinking about employee privacy, data controls, and AI oversight, AI Governance from Oxford Saïd is a strong next step. It focuses on the oversight, accountability, and policy questions that help teams use AI responsibly instead of treating governance as an afterthought.*
Closing Takeaway: What to Check Before You Decide
- Confirm your Business or Enterprise admin console still has Computer History turned off, and decide who is authorized to change that.
- If you pilot it, write an explicit exclusion list covering HR, health, finance, legal, client-confidential, and password manager apps before anyone opts in.
- Establish a rule for communication apps. OpenAI says Computer History should be off during communications with other people unless they have given prior express consent.
- Check your organization's ChatGPT data controls to understand what happens to chat content once a memory gets pulled into a conversation.
- Treat prompt injection as an open risk, not a solved one, and factor that into which apps and websites you allow to contribute.
None of this calls for a blanket ban. It calls for someone in your organization actually reading the admin settings before an employee finds the toggle first.
Sources
- Computer History, OpenAI ChatGPT Learn.
- ChatGPT and Codex changelog, OpenAI ChatGPT Learn.
- OpenAI announcement post on X, OpenAI.
- How your data is used to improve model performance, OpenAI Help Center.
- Enterprise privacy at OpenAI, OpenAI.
- ChatGPT's Computer History tracks your clicks and keystrokes, The Verge.
- ChatGPT Can Now Add Your Mac Activity to Its Memories, CNET.
- ChatGPT's new Computer History tracks your Mac activity to create a timeline, ZDNET.
- OpenAI's new ChatGPT feature logs your keystrokes and stores them in plain text, The Next Web.
- ChatGPT can now remember what you did on your Mac, The New Stack.
- OpenAI's Computer History Feature Brings Keylogging and Prompt Injection Into Enterprise Scope, AI Governance Institute.

