Mer. Set 30th, 2026
Un portatile con documenti di attività in chiaro e un occhio esterno: la memoria locale esposta ad altri programmi.

A program that records clicks, keystrokes, applications and websites, and keeps the result in unencrypted text files on your own disk, already has a well established technical name. Ship it with a product page and a toggle in settings, and it is called Computer History, the new ChatGPT feature for macOS, and the output becomes memory the assistant can consult.

Credit where it is due, because the design is not careless. The feature is off by default. It requires the separate Memories feature to be switched on, and it is available only through the ChatGPT desktop application for macOS: Pro users can enable it themselves, while Business and Enterprise environments need administrator approval. It does not capture screenshots or record audio, and private browsing is always excluded. It leans on macOS accessibility features rather than a driver of its own. Raw interaction files stay on the machine and are deleted after 48 hours.

That is a serious privacy engineering effort. It is also not where the problem lives.

The files that stay

The 48 hour deletion applies to the raw event data. The memories built from it are plain text Markdown documents, stored locally, and they remain until somebody deletes them by hand. They are not encrypted.

OpenAI states the two consequences itself, which is both commendable and damning. First, other programs running under the same macOS user account may be able to read those files. Second, giving a model this much running context increases the chance of prompt injection: visit a site carrying malicious instructions, the company warns, and ChatGPT or Codex might follow them.

Read that second one slowly. The assistant now holds a written record of your working day, and a web page you open can attempt to give that assistant orders. The attack surface is no longer your session. It is your memory of the session, and it is legible to whatever else is running as you.

A ready made map

Mark Beare, of Malwarebytes Labs, warns that these files could hand infostealers a ready made map of a person’s workday. That is precisely the right frame, because infostealers are not an exotic threat. They are the commodity malware of the decade, and their entire job is to sweep readable files out of a user profile and ship them somewhere. Handing them a curated, chronological, plain language summary of what somebody did all day is not a new category of risk. It is a quality upgrade to an existing one.

Ed Gaile, principal solution architect at Appfire, put the feature in domestic terms: a coworker sitting next to you all day, writing down every click and every keystroke, and keeping the notes in a folder on your computer. It is not a villain origin story. It is a very literal description of what the feature does, and it suggests the only test that matters in an organisation. If you would have to defend that log in a room, a client memo, a personnel note, a spreadsheet with real numbers, you have your answer about the work machine. Try proposing the same arrangement in an employment contract and see how far the analogy travels.

What ends up in the folder

For a company this is not a philosophical question. A detailed, unencrypted chronology of what an employee does on their computer is a high value target on its own terms. Client names. Unreleased projects. Fragments of communications. The shape of an approval chain, which is the single most useful thing an attacker can learn before attempting fraud. Reconnaissance that would normally take weeks inside a network, pre-written, in the first person, in a folder.

The feature is unavailable in the European Economic Area, Switzerland and the United Kingdom. Nobody should read that as a compliment to European regulation. It is an answer to it, and a fairly eloquent one: a capability whose compliance position in those jurisdictions was evidently not worth arguing.

It does not follow that European companies can file this under someone else’s problem. Groups with staff, subsidiaries or contractors in the United States and other markets have the same laptops, the same client data and the same shared drives. The data crosses the border even when the feature does not.

The one control point, and how it gets wasted

On Business and Enterprise plans, administrator approval is required before individual users can opt in, and approval alone does not switch the feature on for anybody. That is a genuine control point, and it is the only one.

Which means it has to be presided over as a decision: explicit, documented, consistent with existing endpoint policy, and revisited. Not a request cleared between two tickets by whoever was on rota. An organisation that grants that approval without a written rationale has not made a risk decision, it has skipped one, and it will discover which when it has to reconstruct events.

The compliance side is heavier still. Continuous recording of a worker’s activity raises questions of proportionality and of remote monitoring that, in a European context, run through the GDPR and through national employment law. None of that is satisfied by a toggle, a tooltip or a line in an acceptable use policy that nobody has read since onboarding.

The pattern here is the one worth naming, because it will recur with every assistant that ships next quarter. The capability is real, the documentation is honest, the risks are disclosed by the vendor, and the entire weight of deciding whether the trade is acceptable has been moved onto the person least equipped to evaluate it and most tempted by the convenience. That is not a security failure. It is a design choice about who carries the consequences, and it has been made in favour of the party writing the release notes.

Raffaele Di Marzio

All my “insane” books on cybersecurity and governance are here 👇 https://cyberium.limited/bookshelf.html