So this has been the week of Apple Intelligence, obviously. Every tech site on my RSS list (yes, I still use an RSS reader, don't @ me) has run some version of the same WWDC recap since Monday, and I don't have much to add to that pile that you haven't already read three times over. What I do want to talk about is a smaller story that happened basically in Apple's shadow this week, because I think it's actually the more interesting AI-on-your-computer story of June: Microsoft backing off Recall.
Quick recap if you missed it. Recall was the headline feature of the whole "Copilot+ PC" push Microsoft announced back at Build in May, the pitch being that your PC takes a screenshot of basically everything you do, every few seconds, then runs it all through on-device AI so you can later type something like "that recipe site I looked at last Tuesday" and it just finds it for you. Neat trick, in theory. Creepy as hell in practice, and it took security researchers about five minutes to explain why.
The problem, as people like Kevin Beaumont laid out pretty clearly, wasn't the concept, it was the implementation. All those screenshots were getting dumped into a local database in plain text, unencrypted, sitting right there on disk. Anyone with local access, or any halfway competent piece of malware, could scoop up months of your screen history, passwords typed into forms, private messages, whatever you'd been doing, in one go. Somebody literally built a proof-of-concept tool nicknamed TotalRecall just to demonstrate how trivial it was to extract.
Microsoft's first response, earlier this month, was to say okay fine, we'll encrypt the database and gate it behind Windows Hello. And then this week, on the 13th, they went further and said Recall won't ship on by default at all. You'll have to opt in. It's also not going out broadly with new Copilot+ machines on the original June 18 date anymore, it's rolling out to Windows Insiders first so they can keep poking at it before the general public gets it.
I think this is the right call, and I also think it's a little bit funny that it took this much public pressure to get there. This is exactly the kind of feature that should never have made it past an internal security review with "always-on, unencrypted, plaintext" as the actual shipped behavior. Not a beta caveat, not a footnote, the default state of a feature Microsoft was putting front and center in its marketing.
Here's my actual complaint though, and it's not really about the encryption bug. It's about the base assumption baked into Recall in the first place, which is that constant passive surveillance of your own screen is a good trade for a slightly better search bar. I don't want a permanent, indexed archive of everything I've ever looked at sitting on my hard drive, encrypted or not, because encrypted-at-rest doesn't mean much once you've unlocked your laptop for the day. I already don't love how much of my life autocomplete and browser history quietly remember. Adding a full-fidelity photographic memory of my desktop on top of that isn't a feature I asked for, it's a feature somebody in a product meeting decided I needed, and I get to opt out only because enough security researchers made noise this week.
Fixing the encryption is a patch. It doesn't answer whether this should exist by default on the millions of PCs Microsoft is about to sell, in offices where IT departments haven't audited it yet, on machines used by people who share their login with a partner or a kid. Off-by-default buys Microsoft time to figure that out, or at least to let this be your decision instead of theirs. I'd rather they took the extra months and actually rebuilt trust in it than shipped it quietly re-enabled in some cumulative update six months from now, which, if I'm honest, is the outcome I'd bet on.
Meanwhile I'm sitting here with a laptop that still runs on the assumption that if I want to remember something, I write it on a sticky note. Genuinely lower attack surface than an AI screenshot database, and it's stuck to my monitor bezel right now reminding me to renew my domain before it lapses again like it did in 2019.