VC
Value Add VC
⚡HomePulse⚡Helpful Apps📝Blog🤝Partner
Illustration for: ChatGPT Can Now Log Every Click and Keystroke on Your Mac
Value Add VC/Pulse/AIDEEP DIVE

ChatGPT Can Now Log Every Click and Keystroke on Your Mac

OpenAI's new Computer History feature records mouse clicks, typing and app switches on macOS to build a searchable timeline ChatGPT can reference, stored locally as unencrypted plain text and off by default.

TC
By the AI Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
August 16, 2026
3 min read
ShareXLinkedInEmail
TC

The VC Read · Trace's Take

Trace Cohen

Plain text. On disk. Of every keystroke. OpenAI made the right call skipping screenshots and then undid most of the benefit at the storage layer. If you run a company, the memo to write this week is not about AI policy in the abstract -- it is that Computer History is disabled on any machine that touches production credentials, because a consumer Pro subscription can enable it without ever crossing IT's desk.

AI Jailbreak Tracker →

Analysis

OpenAI has shipped Computer History, a macOS desktop feature that captures interaction events -- mouse clicks, typing, keyboard shortcuts, application switches -- and turns them into a searchable timeline ChatGPT can draw on when assisting with tasks. The Verge covered the rollout on August 16.

What It Actually Captures

The mechanics are narrower than the headline suggests. The feature reads events exposed through macOS's built-in accessibility APIs. It takes no screenshots, no screen recordings, no microphone or system audio. Private and incognito browsing is excluded automatically, users can block specific apps and sites, and individual entries can be deleted after the fact. It is off by default, opt-in, available to Pro subscribers, and not offered in the EEA, Switzerland or the UK.

“Recall, announced for Copilot+ PCs in May 2024, took screenshots and was delayed for a year after a security backlash; Microsoft eventually made it opt-in and encrypted.”

The design decision that will generate the most argument is storage: the memory files sit locally as unencrypted plain text. That is defensible on one reading -- nothing leaves the machine by default, and users can inspect exactly what was captured -- and indefensible on another, because any process with filesystem access, including malware, can read a plain-text log of everything typed. The ChainDrop npm worm that injected startup hooks into local editor configuration files this month is a reminder that "local" and "safe" are different properties.

Competitively this is OpenAI moving onto ground Microsoft already tried and retreated from. Recall, announced for Copilot+ PCs in May 2024, took screenshots and was delayed for a year after a security backlash; Microsoft eventually made it opt-in and encrypted. Rewind AI built the same category as a startup. OpenAI's version deliberately avoids screenshots -- the specific thing that sank Recall's launch -- while collecting arguably more granular data.

The geographic exclusions tell you what OpenAI's own counsel thinks. Keystroke-level capture under GDPR and the EU AI Act's transparency obligations is a materially different legal product than under U.S. law, and shipping to the U.S. first while excluding Europe, Switzerland and the UK is a compliance judgment, not a rollout schedule.

For enterprises, the immediate action is device policy: this is a feature that will appear on employee laptops via consumer subscriptions, outside IT procurement, capable of logging credentials typed into internal systems.

The strategic logic is about agents rather than memory. An assistant that can see how you actually complete a task -- which apps, in what order, with which keystrokes -- has training signal for automating that task later. OpenAI has been shipping computer-use capabilities for over a year; Computer History supplies exactly the demonstration data those systems need, gathered from users who opted in for a convenience feature.

That is also where the consent question gets genuinely hard. The opt-in covers the person who enabled it, not the colleague whose message they typed, the customer whose account number they entered, or the patient record on screen. Local storage limits exfiltration risk but does nothing about scope. Enterprises running macOS fleets should treat this as an MDM policy item this week rather than a privacy debate next quarter.

Pricing and packaging tell you how confident OpenAI is. Shipping to Pro subscribers first limits blast radius to the users most tolerant of experimental features and most likely to file useful bug reports, and it keeps the feature out of the free tier where a privacy story would spread fastest. Anthropic, Google and Microsoft all have desktop assistants in market; none currently log keystrokes at this granularity, which means OpenAI is establishing the norm rather than following one.

ShareXLinkedInEmail

More on

OpenAI →

Reported by The Verge · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.

Read Next

AI· Aug 17, 2026

AI Chip Stocks Rally as Anthropic's Blowout Quarter Lands

Illustration for: AI Chip Stocks Rally as Anthropic's Blowout Quarter Lands
AI

AI Chip Stocks Rally as Anthropic's Blowout Quarter Lands

Micron and Sandisk led premarket gains Monday after Anthropic's Q2 revenue surge bolstered the market's view that AI infrastructure spending will keep climbing rather than plateau.

AI· Aug 16, 2026

DeepSeek Raises V4 Prices Hours After Topping Agent Tests

Illustration for: DeepSeek Raises V4 Prices Hours After Topping Agent Tests
AI$0.44/$1.32 per 1M tokens

DeepSeek Raises V4 Prices Hours After Topping Agent Tests

DeepSeek moved its V4 models to peak and off-peak pricing on August 16, raising rates across every tier, days after V4-Flash beat the company's own flagship on nine agent benchmarks at three cents per task.

AI· Aug 15, 2026

Eval Harness Finds Models Most Confident When Wrong

Illustration for: Eval Harness Finds Models Most Confident When Wrong
AI

Eval Harness Finds Models Most Confident When Wrong

A systematic evaluation harness surfaced what qualitative review missed: model confidence rises on the outputs that turn out to be wrong, inverting the signal teams rely on for routing and human escalation.

@Trace_Cohen·t@nyvp.com