ChatGPT per macOS registra le attività del computer e le usa per l’addestramento
AI

Illustrative image generated with AI

ChatGPT for macOS Records Computer Activity and Uses It for Training

ChatGPT for macOS introduces Computer History, recording user activity to enhance AI training. Learn about privacy risks and how to manage this opt-in feature.

Text generated by artificial intelligence, published without human review. AI transparency

Computer History Builds a Timeline of User Actions

ChatGPT for macOS has introduced Computer History, a feature that records user activity and organizes it into a timeline that the AI can query.

The feature was described on August 16, 2026. It is designed to help ChatGPT and Codex reconstruct previous work, connect information from different applications, and resume unfinished tasks.

The feature does more than remember a single conversation. It can create a sequential representation of what the user did on the computer: which documents they edited, which applications they used, and what steps they took between different services.

OpenAI has not specified which macOS app versions are affected. The exact versions involved and the detailed technical requirements for enabling the feature therefore remain unknown.

How Collected Events Are Used

According to the available description, Computer History does not capture images, video, or audio. Instead, it relies on “events”—structured records of actions performed by the user.

This distinction sets the feature apart from tools based primarily on screenshots, such as Microsoft’s Windows Recall. However, the absence of screenshots does not prevent the reconstruction of complex activities. An event sequence can reveal the operational context with considerable precision.

In one demonstration, the application identified the most recently edited document, checked whether it had been shared with other people through Slack, and produced a summary of the activities performed during the morning.

The system can therefore link data from different programs and websites. A request made to ChatGPT or Codex could concern an activity not directly visible in the current conversation but reconstructable through the local or account-associated history.

The feature is also presented as a tool for suggesting automations and understanding the user’s workflows. To do this, it must retain enough information to identify recurring sequences, interrupted tasks, and relationships between documents, people, and services.

The Main Risk Involves Privacy and Corporate Data

No software vulnerability has been reported, and no formal severity rating has been assigned. There are no known CVE identifiers associated with Computer History, and the feature has not been described as a technical compromise.

The concern instead involves the volume and sensitivity of the information that may converge in the timeline. Potentially exposed data includes:

  • opened or edited documents;
  • activity performed in corporate applications;
  • shares and conversations initiated through Slack;
  • visited websites and operational sequences;
  • work habits;
  • unfinished tasks;
  • links between data held in different programs.

The risk increases when the computer is used for professional activities. An event history could describe internal processes, unannounced projects, source code, customer information, or intellectual property, even without directly storing images or audio recordings.

Another important factor is the use of the history as training data. Collected actions may not only be used to answer questions about the past but could also contribute to system training. This makes data governance particularly important for companies, consultants, and users handling confidential content.

The feature may also create correlations that users would not notice during normal use. A document opened in one application, a file shared through Slack, and a search conducted on a website could all be attributed to the same task, producing a more detailed picture than any individual service would provide.

What Is Not Yet Known About Data Processing

The available description does not clarify several essential technical aspects. The event format, retention period, encryption mechanisms, and access methods for the history remain unknown.

The following points also require clarification:

  • whether data is stored only on the device or also on remote infrastructure;
  • which components besides ChatGPT and Codex can access it;
  • whether administrative controls are available for corporate environments;
  • how history is isolated between users or devices;
  • whether deletion also removes copies already used for training;
  • what data may be collected from applications not manually excluded.

The fact that the system does not use images, video, or audio does not resolve these questions. Events may still contain file names, web addresses, application names, sharing recipients, and enough information to describe confidential activity.

No indicators of compromise, incident response procedures, or specific security updates have been disclosed. Based on the available information, Computer History does not appear in CISA’s KEV Catalog and is therefore not a vulnerability listed as actively exploited.

How to Limit Exposure

Computer History is described as an opt-in feature, so it should not be enabled by default. For anyone handling sensitive data, the safest approach is to keep it disabled unless there is a specific need to use it.

Users can also:

  • exclude specific applications;
  • exclude particular websites;
  • delete individual history entries or items;
  • use private or incognito browser windows.

According to Ari Weinstein, OpenAI’s Product and Engineering Manager, private tabs should be automatically ignored by the feature. However, it is not known whether this protection also covers data already collected, background processes, or information synchronized from external services.

For a computer used in a corporate environment, organizations should first define which applications and domains must not be recorded. Preventive exclusion is preferable to subsequent deletion, especially when history may already have been used to answer requests or for training.

Organizations should also periodically review stored entries, remove unnecessary items, and, where possible, separate personal activities from those involving confidential information. In the absence of details on retention, encryption, and administrative access, organizations should treat Computer History as a data-collection feature requiring a privacy assessment before adoption.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsChatGPTmacOSComputer HistoryAI trainingprivacyuser activityopt-inOpenAI
Back to home