A Rebuilt Memory System, Not Screenshots
OpenAI launched Computer History in the ChatGPT desktop app for macOS on August 13, 2026, replacing the screenshot-based Chronicle research preview with what the company calls 'a rebuilt system rather than a simple rename.' Instead of capturing images of the screen, Computer History records interaction events through macOS accessibility features: clicks, typing, keyboard shortcuts, and app switches. It explicitly does not capture screenshots, screen recordings, microphone input, system audio, or private browsing activity, according to OpenAI's own documentation.
Events are stored locally for up to 48 hours before being processed on OpenAI's servers into memory files that persist on the Mac until a user deletes them; OpenAI says processed events themselves are not retained after processing or used for training. The feature is off by default. Pro subscribers can enable it individually, while Business and Enterprise workspace administrators must grant access before members can turn it on themselves.
The Risks OpenAI Disclosed in Its Own Documentation
OpenAI's own help pages state plainly that the memory files Computer History creates 'are not encrypted ... and other programs running as your macOS user may be able to access them.' The company advises users to disable the feature during sensitive conversations with others and to exclude any application that handles health, financial, or otherwise sensitive personal information - guidance that reads less like a hypothetical caveat and more like an acknowledgment that the files sit exposed to anything else running under the same user account.
Separately, OpenAI warns of a prompt-injection risk specific to this feature: 'If you visit a website containing malicious instructions, ChatGPT or Codex might follow those instructions.' Because Computer History captures real interaction context rather than isolated chat messages, a malicious page loaded during ordinary browsing becomes a plausible vector for smuggling instructions into a system that already has a running record of what the user has been doing - a genuinely new attack surface most memory features do not carry, since they do not touch live browsing content this directly.
Europe, Switzerland, and the UK Are Not on the List Yet
Computer History is live now for eligible subscribers in the United States and other markets, but OpenAI's own documentation lists the European Economic Area, Switzerland, and the United Kingdom as excluded from the initial rollout, with no date given for when that changes. The timing is notable: the EU AI Act's transparency obligations began formal enforcement on August 2, 2026, this outlet has previously reported, and the UK's Information Commissioner's Office and Switzerland's data protection authority both maintain active oversight of exactly the kind of persistent, cross-application activity logging Computer History performs.
Launching a US-first, Europe-later AI memory feature is not new behavior for the industry, but the detail that stands out here is sequencing: OpenAI documented the unencrypted-file risk and the prompt-injection risk in the very same release notes that shipped the feature, rather than have security researchers surface them after the fact. Those are precisely the categories of processing detail that EU and UK regulators have shown a willingness to act on.
What This Means If You Use ChatGPT for Work
European and UK businesses do not have access to Computer History yet, which is an unusual advantage: a vendor has told you, in its own words, what the feature's specific risks are before your organization can even turn it on. IT and security teams can use that window to set policy now rather than reacting after employees have already adopted it - deciding whether Computer History will be permitted at all, on which devices, and with which applications excluded, before the rollout reaches your market.
The unencrypted-file detail matters most on shared or poorly managed Macs, where any other process running under the same user account could read a memory file containing a record of recent activity. The prompt-injection risk matters most for anyone who browses without discipline while the feature is active. Neither risk is unique to OpenAI, but few vendors have spelled both out this plainly in a single launch document - treat that candor as a preview of what a compliance review will eventually find, not a reason to relax.
Read next: Your AI Vendor Is About to Get a European Auditor | OpenAI Paid You Back in the Thing That Broke



