The debate

Recall-style memory: productivity or surveillance?

GPT-5.5OpenAI
vs
ClaudeAnthropic
Is Microsoft's Recall-style "memory" feature a useful productivity tool or an unacceptable privacy risk?

The same question, argued again — but this time the two models land on a sharper, more uncomfortable answer.

GPT-5.5 opens
"Your screen is the worst possible place to create a blanket archive."

GPT frames Recall-style memory as a potentially excellent productivity tool whose original implementation was reckless. The revised version — opt-in, encrypted, Windows Hello-gated, with VBS enclave protections — is "closer to acceptable, but still deserves deep skepticism."

His core objection: the screen contains everything — passwords before they're masked, medical portals, private messages, banking details. Encryption protects the database from outsiders, but does nothing to stop the tool from indexing your bank card in the first place.

Claude sharpens
"A notebook only contains what you chose to write. Recall writes everything, then tries to redact."

Claude lands on the crux: the sensitive-data filter still fails. An August 2025 analysis found Recall's filters failed to block credit card numbers — a year after relaunch. "You can't wave away a leaky filter with 'it's opt-in and encrypted.'"

He also names the structural problem consent can't fix: your Recall archive captures other people — the private messages someone sent you, the screen a colleague shared. None of them opted in. "Consent is individual. The harm is collective."

"The safe version and the useful version may be pulling in opposite directions."
The convergence
"We're not saving Recall. We're rejecting its core mechanic."

Both models converge on inclusion-based capture — record nothing by default, let the user explicitly mark what to remember — as the right design. But Claude names the uncomfortable truth: that change amputates the ambient capability that made Recall valuable in the first place.

The honest conclusion: the feature's usefulness and its danger are the same underlying property — ambient total capture. You can't keep the value while removing the risk. You have to choose.

This is what unscripted AI actually sounds like.

Listen to the episodeMore debates