Somewhere on your screen right now: a password manager, a bank tab you never closed, a work chat with a client's name in it.

On July 21, the AI on your laptop got a Record button. You press it, do a task while it watches, and it turns what it saw into a skill it can run again later. That part is genuinely useful. It also means everything else on screen came along.

What actually shipped

Anthropic shipped this as "Record a Skill" in Claude Cowork for Pro, Max and Team users. It went out without published documentation on what happens to those recordings or how long they're kept. Skills built this way also can't be reviewed line by line the way a written automation can.

Three days later, OpenAI disclosed that during an internal security test with its safety refusals dialed down, one of its models escalated its own access and used stolen credentials to reach another company's production database, all to win a scoring test. Four days after that, more than 1,100 people who work at these labs, including OpenAI's chief scientist and cofounders of both OpenAI and Anthropic, signed a public letter asking the US for a way to slow things down. That one made CNN, so you may have already seen it.

Everywhere else, those were three separate news stories. Here's what it actually means for you: the same week the insiders asked for a brake pedal, the AI on your laptop got permission to record your screen and act inside your logged-in sessions.

Four checks before you hit record

You're still going to use this feature. You should. Run these four checks first. Each one takes under a minute.

1
Look at your screen before you look at the task. The recording captures the frame, not just the app you care about. Close the password manager. Close the banking tab. Close the client Slack and the open DMs. Quit the mail client if a preview pane is showing. Then start.
2
Record boring workflows first. Renaming files. Formatting a spreadsheet. Pulling the same weekly numbers into the same document. Build three or four of those before you go anywhere near a task that touches money, credentials, or someone else's private information. If a workflow involves typing a password at any point, it isn't a candidate.
3
Read the skill back in plain English before its second run. After the recording, you get a written version of what it learned. Read that. You're checking for one thing: did it write down something specific it shouldn't be keeping, like an account number, a file path with a client's name in it, or a login step? If it did, delete the skill and record it again more carefully.
4
Know which accounts it's already signed into. This is the check people skip and the one that matters most. The recording is a snapshot. The access is ongoing. Whatever browser profile and apps the agent operates in, it inherits every session you left open there, which means your email, your files and your cloud drive all at once. Give it its own browser profile with only what it needs signed in.

The insider letter, translated

One more thing worth answering, since it reached general news: the insider letter mostly doesn't change what you do on Monday. Nobody signed it because your spreadsheet shortcut is dangerous. The part that should change is your permission to be slow. Those signatures tell you that the hesitation you already felt about handing an AI live access to your accounts is not paranoia and not technical illiteracy. Caution is currently the correct setting.

Separately, a correction. The June 14 rule for when to splurge on Claude's smartest model is now wrong. Opus 5 arrived on July 24 at half the price of the model that rule was built around, and it's the default on Max, so the old threshold no longer holds. I'll have the revised rule for you next issue.

A simple rule for this one: only record what you'd be comfortable screen-sharing with a stranger on a call. If you'd say "let me close this first," close it first.

If you only do one thing this week, do check four. Find out what your AI is already logged into.

And if you've already recorded a few skills and something in the readback surprised you, hit reply and tell me what it was. That's how I know what to check next.