Documents Prove Facts. ChatGPT's New Feature Proves State of Mind.
TL;DR: OpenAI shipped Computer History on August 13. Opt-in, Mac only, off by default, and it turns your activity across apps and websites into a plain-English timeline ChatGPT can draw on later. The thing worth understanding is why it exists at all: context, not intelligence, is what’s been keeping these tools from being useful, and watching someone work is the shortest way to get it. No screenshots, which is a real improvement on Microsoft Recall. What it leaves behind on the laptop is unencrypted plain text, which isn’t.
The moment this is built for
You come out of a two-hour call and stare at your own screen like it belongs to somebody else. Eleven tabs. A half-finished email. A document full of tracked changes from someone whose name you can’t place, and a Slack thread you abandoned mid-sentence. What was I doing?
OpenAI built a feature for exactly that. Ask what you were working on before the call and it tells you, then offers to pick the thread back up.
I want to be fair to the product before I take it apart. That problem is real, people lose a stupid amount of time to it, and the pitch is honest about what it’s solving.
What Computer History actually is
It records what someone does on their Mac and turns it into short written summaries the model can reference later. Live since August 13 for ChatGPT Pro, Business, and Enterprise. Off by default. In a Business or Enterprise workspace an administrator has to grant access first, and even then each person still has to switch it on themselves. Two locks, two keys.
Not in the EEA, the UK, or Switzerland yet. OpenAI says those follow in the coming weeks, so read it as a rollout schedule rather than a verdict. Worth noticing which markets went last, though. When the most heavily regulated jurisdictions land in phase two, that’s usually where the hard questions were.
Why anyone builds this in the first place
This is the part worth understanding, because it explains why the category won’t go away and why banning one product accomplishes nothing.
Think about a new hire. Sharp, well credentialed, and close to useless for the first few months. That isn’t a brains problem. They don’t know that the VP of sales says yes in meetings and then kills things by email, that this customer wants a phone call before anything goes in writing, that the Q3 forecast always slips. What makes someone valuable isn’t raw ability. It’s accumulated context about how the work actually goes.
Now think about what happens when someone on your team opens a chat window with an AI tool. Blank slate. No idea what project they’re on, what they did yesterday, who the customer is, or what’s due Friday. Every session starts on day one and stays day one forever. So people spend their time explaining themselves to software that still can’t be handed anything real.
That’s the problem these tools were built to solve. Not “find my document.” Context.
And here’s the part that matters more. You cannot automate work you have never observed. Companies have spent twenty years and serious money trying to write down how the work gets done, through process maps (hello graph engineering), playbooks, workflow documentation nobody keeps current. The document never matches the practice. Watching skips the documentation step entirely. OpenAI is open about this: Computer History doesn’t only recall your day, it proposes turning repeated work into reusable routines (skills!). That’s not a memory feature. That’s a killer productivity enhancer.
Which explains why the industry keeps coming back after getting burned. Microsoft spent a year getting beaten up over Recall, delayed it three times, and shipped it anyway. OpenAI ran a version called Chronicle, scrapped it, and had a rebuilt replacement out in under four months. Nobody works that hard on a search box.
How it’s different from Microsoft Recall
Screenshots were the crude way to get that context. Recall took pictures of the screen every few seconds and read them back. Computer History doesn’t.
It listens instead to interaction events, which is a technical way of saying the small signals your Mac already generates as you work: clicks, keystrokes, shortcuts, switching between apps, plus the behind-the-scenes text macOS hands to screen readers. No screen recording permission required. No microphone, no system audio. Private browsing never gets included at all.
The controls around it are better than the industry norm, too. A user can allow only specific apps and websites or exclude the ones they don’t want. Collection pauses from the menu bar, and the same menu shows what’s being captured. History wipes in blocks: the last ten minutes, the last hour, the last day, or everything. Separately, typing /memories into any chat controls whether that one conversation draws on stored memories or feeds new ones. OpenAI even documented the prompt injection risk in its own materials rather than waiting for a researcher to find it, which is more candor than most vendor security pages manage. Prompt injection, if you haven’t run into the term, means a booby-trapped web page can carry hidden instructions the AI later follows as though they came from you. It gets easier the more the AI watches.
So credit where it’s due. But the mechanism changed, not the sensitivity. A screenshot of a confidential memo has to be run through character recognition before anybody can search it. Keystrokes are already text.
And two things are worse than where Recall eventually landed.
The data leaves the machine. Recall processes on the device. Computer History holds raw interaction events locally for up to 48 hours, then ships them to OpenAI’s servers, where a temporary session writes the summaries and sends them back. OpenAI says it doesn’t keep the event files afterward, unless the law requires it, and doesn’t train on them. Fine. That’s still a third party processing a stream of everything your people typed, which is a very different conversation with a customer than “it stays on the laptop.”
What’s left behind isn’t encrypted. Recall’s current build encrypts at rest and locks access behind Windows Hello. OpenAI’s own documentation says the Computer History files can hold sensitive information, that Computer History does not encrypt them, and that other programs running under the same user account may be able to read them. Ordinary text files, in a folder inside the user’s home directory, until somebody deletes them.
Read that again with a stolen laptop in mind.
You just made a record you didn’t know you were making
Here’s the part I haven’t seen anyone write about.
There’s now a timestamped, plain-language account of what an employee did all day, in a documented location that almost certainly isn’t in your data inventory. The next time you’re sued and have to preserve everything relevant, collection scope has a line item nobody has thought about.
And these summaries are worse than the underlying documents, in a way that took me a minute to put my finger on. They narrate. A document is evidence of a fact. “Compared the two restructuring models, then messaged the CFO about which roles to cut” is evidence of a state of mind. Every plaintiff’s lawyer in the country would rather have the second one, and until this week it didn’t exist.
Look at the sample timeline in OpenAI’s own documentation and you’ll see entries at 9:00, 9:10, and 9:20 in the morning. Three summaries inside twenty minutes. That’s the resolution we’re talking about.
The confidentiality problem is more immediate for most businesses anyway. Trade secret protection turns on whether you took reasonable measures to keep the thing secret, and unencrypted plain-text summaries of your engineering work sitting on a laptop is a hard fact to explain to a judge later. Many customer contracts add a second layer, requiring notice before customer data reaches a new processor. Depending on which apps someone allowed, events flowing to OpenAI’s servers can be exactly that.
Then the whole thing inverts. Clearing history is irreversible by design, and the raw events self-delete every 48 hours. So you own a record you didn’t create, can’t fully see, and can destroy by accident. Pick your poison.
Nobody in the room agreed to this
OpenAI’s own guidance tells users to switch the feature off during communications with other people unless those people have given prior express consent. Sit with that for a second. Customer calls. A performance conversation. Board material. Nobody is getting that consent, and OpenAI clearly knows it, or the sentence wouldn’t be in the documentation.
Which raises a question I can’t find anyone answering. New York, Connecticut, and Delaware all require employers to give written notice when they engage in electronic monitoring. Connecticut and New York both escalate the same way: $500 for a first offense, $1,000 for a second, $3,000 for the third and each one after. Delaware runs $100 per violation. Those statutes were written for tools a company installs on its people. This is a tool the company opens the door to and the employee switches on, which may or may not be the same thing in the eyes of a labor commissioner. Nobody has tested it. Worth twenty minutes with employment counsel before it spreads through your workforce on its own, and worth knowing that neither the New York nor the Connecticut statute gives employees a private right of action. This arrives as a regulator’s letter, not a class action.
The internal version of the same problem is quieter. Memory attaches to a person, not a project. That /memories command governs one conversation at a time, and it doesn't stop the capture, only what a given chat pulls from it. Someone walled off from a deal or an HR investigation doesn't unlearn the context they're already carrying around.
Three moves for Monday
I’m not telling you to ban it, and I’d be suspicious of anyone reaching for a ban this fast. There’s a version of this that’s straightforwardly good for a business: an operations function that finally sees how work actually gets done, instead of how the process doc says it does, is worth real money. The feature isn’t the problem. The gap between “an individual can turn this on” and “the company knows who did” is the problem, and three things close most of it.
Find out whether it’s already reachable. On Business or Enterprise, open Workspace Settings and confirm nobody has enabled Computer History for a role. If people are expensing individual Pro seats, and plenty of companies have those floating around unmanaged, there is no such control and that’s worth knowing today.
Get it into your data inventory. Have IT document where the memory files live and add the folder to your preservation and collection procedures. Before the first lawsuit, not after.
Write one line into your AI policy. Ambient capture stays off during any conversation with a customer, a counterparty, or an employee. That single rule removes most of the exposure without a ban, and it survives the next three products like this one.
The rest can wait a quarter. Those can’t.
The screenshot question was the easy one, and OpenAI answered it well. The harder question is what a company does with a plain-text diary of its employees’ working day that nobody asked for and anyone can delete.
Quick note: this just launched yesterday (I was traveling most of the day) so I’ve had less than 24 hours to experiment with it. I will say that the memory files (stored in “~/.codex/memories/extensions/skysight/”) are very detailed. For the moment I am leaving this on as I think it will be incredibly valuable (I already have detailed memory systems I use that track everything I do in codex that I built). I’ll be very curious to see how people react to this feature overall!
If you enjoyed reading this, please share it with others!
I was at a Dodgers game earlier this week with close friends (perfect Southern California evening). Last night, Magnus was watching “Field of Dreams” with my wife. Feels like there is alignment in the universe.



