HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

OpenAI’s ChatGPT Mac App Introduces ‘Computer History’ Feature That Tracks User Activity Across Apps

OpenAI’s ChatGPT Mac app now offers an opt‑in ‘Computer History’ skill that logs clicks, keystrokes and app switches to build a searchable timeline. The capability raises privacy‑by‑design questions for GDPR/CCPA compliance and requires documented consent and DSAR readiness.

LiveThreat™ Intelligence · 📅 August 14, 2026· 📰 zdnet.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
5 sector(s)
Actions
4 recommended
📰
Source
zdnet.com

OpenAI’s ChatGPT Mac App Introduces “Computer History” Feature That Tracks User Activity Across Apps

What Happened — OpenAI rolled out a new “Computer History” capability in the ChatGPT Mac application. When enabled, the feature records clicks, typing, keyboard shortcuts, app switches and website visits, building a timeline that can be queried by the model. The data is stored as “memories” and is not captured via screenshots, microphone, or system audio.

Why It Matters for Compliance & Audit Readiness

  • The feature creates a continuous stream of user‑level activity data, raising privacy‑by‑design questions under GDPR, CCPA and emerging state laws.
  • Organizations must demonstrate lawful basis, granular consent, and the ability to honor data‑subject requests for this type of behavioral data.
  • Continuous‑compliance programs need to capture evidence that such AI‑driven data collection is scoped, consented to, and auditable – exactly what Verisq’s CookiePLUS privacy suite helps document.

Who Is Affected – Enterprises that enable ChatGPT Pro, Business or Enterprise accounts on macOS, across sectors such as technology, professional services, finance, healthcare and education.

Recommended Actions

  • Conduct a privacy impact assessment (PIA) for the “Computer History” feature before enabling it.
  • Map the data‑collection flow to GDPR/CCPA consent controls and update your privacy policy to reflect the new processing activity.
  • Verify that your DSAR workflow can locate, retrieve, and delete the “memories” generated by the feature.
  • Log the configuration and consent decisions in your continuous‑compliance platform for audit evidence.

Source: ZDNet Security

Technical Notes – The feature leverages macOS accessibility APIs to capture interaction events (clicks, keystrokes, app switches). No screenshots, microphone or audio are recorded. Availability is currently limited to Pro, Business and Enterprise tiers, with rollout to the UK, Switzerland and the EEA pending. Source: OpenAI product page

📰 Original Source
https://www.zdnet.com/article/chatgpt-computer-history/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →