Request a scoping call Contact
← Research

Agent memory is a new system of record, and it arrived as a feature flag

Persistent agent memory creates retained records that can affect later decisions. Define what may be stored, how its source and scope are preserved, and how entries are corrected or erased before expanding its use.

Architecture / Conceptual study
Make the connections explicit.
  1. Applications
  2. Interfaces
  3. Records

Trace the interfaces between applications and records before changing a system.

Persistent memory can make an assistant more useful by retaining context across sessions. Enabling it also creates or expands a store of information. The platform owner and data protection lead should assess that store before a successful convenience pilot becomes routine use.

A conversational interface can obscure the data lifecycle. Retained entries may describe a person, reproduce information from another system or record an interpretation that later turns use as a fact. The design needs a named owner, permitted fields, source references, access boundaries and retention rules.

Treat persistent agent memory as a governed information store. Assess the obligations associated with the information actually retained, and specify how its controls survive summarisation and reuse. A model-written paraphrase can remain personal or sensitive data even when it no longer resembles the original record.

A context window is a cache. Memory is a store.

Long context and persistent memory describe different properties. The Horizon Gap, an August 2026 survey, distinguishes model context capacity from system-level persistence across steps or sessions. The distinction helps locate the retained records. It does not establish that a context-only service stores nothing: request logs, caches and provider retention require their own assessment.

Retained data is the category that carries obligations. Under the General Data Protection Regulation, Article 5(1)(e) requires that personal data be kept in a form permitting identification for no longer than is necessary, Article 15 gives a person the right to know what is held about them, Article 16 the right to have it rectified, and Article 17 the right to have it erased. None of those articles contains an exception for data an organisation did not realise it was storing.

Where the controls go missing

The following are failure modes to check in a particular memory design, rather than properties shared by every product.

Unstructured writes complicate classification. A free-text memory entry may contain a name, health detail, salary or statement about another person. Define permitted content and inspect whether the write path enforces it. A structured record can still contain sensitive information, but its schema gives the organisation a clearer place to attach controls.

Derived entries need source links. When a memory paraphrases a document without preserving its identity and version, correction and erasure become difficult to propagate. Store the relationship at write time. Test whether correcting or deleting a source reaches its derived memories and records any lawful retention exception.

Retrieval needs a current permission check. Scope entries to the relevant user, team or tenant and preserve the restrictions attached to their sources. A partition key alone does not establish that every person in that partition may receive the information. Test access after source permissions change.

Relevance and retention answer separate questions. Relevance scoring decides which memories are useful to retrieve. A retention policy decides which may continue to exist. Verify deletion and expiry behaviour rather than inferring it from an entry disappearing from answers.

The six phases of the memory lifecycle set out in the April 2026 survey of long-term memory security, and what each one decides Fig. 01
  1. 01 Write The model decides what is worth keeping. Check schema, source scope and classification.
  2. 02 Store Where provenance, versioning and a retention rule would have to be attached.
  3. 03 Retrieve The entry re-enters context, carrying whatever scope it was given at write time.
  4. 04 Execute Check whether source status and uncertainty survive reuse.
  5. 05 Share and propagate The entry reaches another user, another agent or another tenant.
  6. 06 Forget and roll back Erasure and correction, which are only possible if the earlier phases recorded enough.

The six phases come from a survey of long-term memory security in agent systems, submitted in April 2026 and revised in September. The authors argue that provenance, versioning and retention controls need to begin at storage, rather than being added solely to retrieval or execution.

Storage-time controls preserve information that a later retrieval filter cannot reconstruct.

The storage design determines which evidence a later review can recover. A retrieval filter can suppress an entry, but cannot reconstruct an origin or correction relationship that the write path never recorded. Policy needs corresponding controls in that path.

What to decide before the toggle moves

There is a fifth property that belongs with the four above and sits awkwardly in a checklist, which is that a memory entry can simply be wrong. It is a model’s summary of a conversation, which means it can be a confident misreading, and once written it is read back as established fact on every subsequent turn. A correction right has a technical meaning here that it does not have for a database row. Somebody has to be able to find the entry, show it to the person it describes, and replace it.

Design the write and storage controls before expanding the population. Retrofitting source relationships becomes harder as unlabelled entries accumulate, and the original context may no longer be available. A pilot should demonstrate correction, erasure and permission changes as well as improved conversational continuity.

What this does not tell you

This is not legal advice and it is not an assessment of your estate. Whether a particular memory store holds personal data, which lawful basis applies, and how storage limitation applies to a derived paraphrase rather than to a copy are questions for your counsel, decided against the text of the regulation. The ICO’s work on agentic AI is the place to watch for the UK regulator’s settled position, and check the publication status at the time of the decision.

The research cited here is research about memory systems and their failure modes. It is not a measurement of how common these failures are across enterprise deployments, and this article does not offer one either. We do not certify anyone, and no review we run makes an organisation “compliant” with anything. What an architecture review can establish is narrower — where a property is applied in a running system, where it is lost, and which team owns the layer it is lost at.

Before enabling memory more widely, the platform owner should show the data protection lead the actual write, retrieval and deletion paths. Agree what may be retained and how the organisation will account for it. Expand the feature only when the operational benefit and the information controls have both been tested.

Filed under · Architecture · Agents · Memory · Data Inference Institute · 02 Oct 2026 (updated)

Bring us the question

Reading this because it is on your desk right now?

That is the conversation we are best at. Thirty minutes, a written summary, no obligation.