AI Moves Into the Workstation: What Computer History and Claude Cowork Mean for Your Governance
TokenShift Executive Note

Within four days, in mid-August 2026, OpenAI and Anthropic crossed the same line: their assistants no longer live in a chat window, they take up residence in the workstation itself. One records clicks and keystrokes to build a memory of your activity; the other acts directly in the browser, using the employee's own credentials. For an executive in a regulated European business, that shift changes the nature of the question: this is no longer a choice of tool, it is a governance decision about data, access rights and employment law.
Two announcements in one week, one direction of travel
On 13 August 2026, OpenAI launched Computer History in the ChatGPT macOS app. The feature records clicks, keyboard input, shortcuts and app switches through the Mac's accessibility layer, then turns that stream into text summaries that ChatGPT and Codex can work from. No screenshots, no microphone; but the memory files are stored locally as unencrypted text, according to The Next Web (2026). The feature is limited to the Pro, Business and Enterprise plans; OpenAI has not switched it on in the European Economic Area so far.
The day before, on 12 August, Anthropic turned the side panel of its Chrome extension into a full Claude Cowork session: the agent sees the page, clicks, navigates and fills in forms using the sessions the user already has open, and a task started in a tab carries on across desktop or mobile. One telling detail, noted by Engadget (2026): on Enterprise plans the feature is off by default, and administrators can restrict it to approved domains.
The shared logic is plain: an assistant's value comes from context, and context comes from watching real work. What used to be a website is becoming a component of your information system.
Why this belongs on the board's agenda, not just IT's
Three things push this up to the executive level. First, the data: an activity memory stored in the clear on a laptop holds fragments of client files, confidential projects and live negotiations. Second, access rights: an agent acting "with the user's logins" inherits every business permission that person holds, without any access review having anticipated it. Third, actual usage: depending on the scope measured, somewhere between 27% (Infosecurity Magazine, 2025) and 81% (UpGuard, 2025) of employees already use unapproved AI tools at work. These features will not wait for your sign-off to walk through the door.
One everyday scenario is enough to size the stakes. A management accountant at an insurer switches on the extension in her browser, where her password manager is already signed in. She asks the agent to prepare the monthly reconciliations: it opens the delegated-underwriter portal, downloads statements, pre-fills a report. No incident, no security alert; simply personal data processed by a software agent on a personal account — invisible to the GDPR record of processing, to the internal control plan and to audit.
That the vendors themselves are shipping guardrails (OpenAI holding back the EEA rollout, Anthropic defaulting to off) shows they are anticipating precisely these questions. It falls to the business to take them on.
Where the law stands on 1 September 2026
The GDPR applies right now, and it bites harder than many assume. The CNIL sets tight limits on monitoring employee activity: proportionality, prior notice, works council consultation. It has, for instance, ruled keystroke logging in remote working disproportionate, because it amounts to constant surveillance with no line drawn between work and personal data. An activity memory that an employee switches on for their own benefit is not employer surveillance; but the moment the employer supplies it, encourages it or tolerates it on company machines, the employer is a controller again — with an impact assessment, notice and consultation to follow.
On the AI Act, the actual timeline is worth stating precisely. Since 2 August 2026, the transparency obligations of Article 50 have applied. The penalty regime under Article 99 has applied since 2 August 2025: up to €35 million or 7% of worldwide turnover for prohibited practices. Regulation (EU) 2026/1744, the "AI Digital Omnibus", published in the Official Journal on 24 July 2026 and in force since 27 July, has by contrast pushed the Annex III high-risk obligations to 2 December 2027, and the Annex I ones to 2 August 2028 (Quantic Avocats, 2026). Annex III covers worker management, and Article 26 will require employers to inform employees and their representatives before putting such a system into service. Delayed does not mean dropped: the tools you let in today will have to be inventoried, documented and compliant by that date. Building the inventory now costs far less than reconstructing it under pressure.
Taking back control: a five-step approach
- Inventory what is already running. Browser extensions and desktop AI apps, pulled from your endpoint management tooling; compare what you find with what was declared. This is a baseline, not a trial.
- Decide category by category, using the native controls. Permitted on a corporate account, conditionally allowed, or blocked — using the mechanisms provided (off by default, approved-domain lists) rather than an internal memo nobody reads.
- Get it under contract. Enterprise plans, data processing agreement, data location, retention periods, no training on your data; plus one simple rule: no professional use on a personal account.
- Inform employees and consult the works council before any deployment that observes activity. It is a requirement of French employment law, it will be an AI Act obligation, and above all it is the condition for adoption: a tool that feels like a spy will be worked around.
- Check the results being claimed. Work published on arXiv in 2026 documents agents' "false success": tasks confidently marked complete without actually having been done; on one agent benchmark, the most lenient automated evaluation wrongly passed more than twice as many criteria as human annotators. Do not steer by the agent's own self-assessment: sample the output, have a human verify it, measure an error rate before scaling up.
Mistakes to avoid
- The ban by proclamation. Blocking with no inventory and no alternative pushes people straight to personal accounts; the shadow AI figures above are the empirical proof.
- The pilot run on personal accounts. Results you cannot reproduce, data already gone, nothing under contract: a pilot that cannot graduate to governed production is not a pilot, it is an organised leak.
- Reading the AI Act calendar too casually. Concluding from the Annex III delay that "nothing applies before late 2027": transparency has been in force since 2 August 2026, the penalty regime since 2 August 2025, and the GDPR never stopped applying.
- Trusting the agent's own report. A dashboard fed by the agent grading itself measures its fluency, not its reliability.
- The browser blind spot. Governing installed applications while overlooking extensions, at the very moment the browser is becoming agents' main surface for action.
Five observable signs that governance is working
You will know the system is working when you can read, every month: the share of your estate covered by the AI tool inventory (aim for over 95%); the gap between tools discovered and tools declared, and it should be narrowing; the share of AI usage on corporate rather than personal accounts; the median time from a request for a new tool to a decision (ten working days is a realistic target); and, for every system that observes activity, a dated works council notification, an impact assessment, and an error rate measured on a human-checked sample.
Where to start this week
Three concrete moves: ask your CIO for an inventory of the AI extensions and applications actually present on company machines; put an explicit decision on personal accounts and tool categories on the agenda of the next board meeting; and set the date for works council notification on the first governed deployment. Ambient AI is coming inside your walls either way; the only variable you control is whether it arrives governed.
TokenShift works with the executive teams of regulated businesses to take AI from pilot to governed production: governance, workflow redesign and AI Act compliance.
Sources: The Decoder (2026); The Next Web (2026); Anthropic (2026); Engadget (2026); CNIL, monitoring of employee activity; Quantic Avocats (2026); UpGuard via Cybersecurity Dive (2025); Infosecurity Magazine (2025); arXiv (2026), false success in agents; arXiv (2026), agent evaluation.