Control over AI
Blog
AI data leakage 7 min read

Who decides what an AI assistant remembers?

Memory became a setting, and settings have owners. Sometimes you, sometimes your administrator, sometimes the vendor deciding for both of you.

Someone reviewing an assistant's memory settings
Quick answer

On most assistants memory is on by default and the user manages it: you can view the stored facts, edit them and delete them. In enterprise tenants that control moves to the administrator, who can disable memory organisation-wide or mandate it. And with assistants embedded in your workspace, the vendor decides what gets pulled in as context regardless of what you deliberately asked it to remember. So the question is not whether AI remembers, but who owns the switch and whether anyone has looked at it.

01

Memory across conversations is separate from the context window within one

02

On consumer accounts the user manages it, usually with memory on by default

03

In enterprise tenants the control moves to the administrator

04

Context pulled in automatically is not memory and feels identical

05

Review what has been remembered, because errors get repeated

A consultant has worked with the same assistant for months. He no longer explains what he does, which sector his clients are in, or how he structures a report. That is the point, and it works well.

Then, in a conversation about an entirely different client, a detail surfaces that he mentioned about the first client three months ago. Nobody did anything wrong. The switch was simply on.

Memory is not the conversation

The distinction first, because this is where assessments most often go wrong.

The context window is the working space of one conversation. When the conversation ends, that space is empty. What was in it remains in your history, but the model does not carry it into the next exchange.

Memory is a separate facility. The assistant extracts facts that look worth keeping and stores them as discrete notes: your role, your preferences, what you are working on, how you like to be addressed. On a new conversation, those notes are supplied alongside your first message.

Two systems, two retention periods, two switches.

Three owners of the same switch

The user. On consumer accounts you manage it. The major assistants offer a view of what has been remembered, and you can remove entries from it. The default is usually on.

The administrator. In enterprise tenants the control moves. The organisation can disable memory for everyone, enable it for everyone, or configure it per group. It is one of those settings that survives a rollout on its default value simply because nobody went looking for it.

The vendor. The third owner and the least visible. Assistants embedded in your workspace pull in context automatically: recent documents, your calendar, the thread you are reading. Technically that is not memory, because nothing is stored as a note, and to the user it feels identical. The assistant knows things you never told it. See how AI tools reach files you never uploaded.

Why this is more than a setting

Three consequences that turn up in practice.

Errors get repeated. If the assistant stored a wrong assumption (a role you do not hold, a client you no longer serve), it returns in every conversation and is treated as given. Harder to catch than a one-off mistake, because no source is attached to it.

Third-party data lands in it. Memory is meant for facts about you. In practice it also retains what you mention often, and that means client names, matters and cases. That is processing personal data belonging to someone who was never part of the conversation.

Context leaks between contexts. What you say in one role can surface in a conversation held in another. For anyone serving multiple clients, that is not a theoretical objection.

What to do

For an organisation:

  1. Set the memory control deliberately rather than leaving it on its default. Both choices are defensible; not choosing is not.
  2. Treat memory as a distinct processing operation in your DPIA, with its own purpose and retention.
  3. Explain what happens. People who know something is being retained behave differently toward it.

For yourself, if it is on:

Read the memory list once a month. Not because something alarming is in there, but because it shows you what the assistant believes it knows. It is usually a clarifying list, and it is the only way to remove a wrong assumption before it gets repeated fifty times.

How remembering works per tool and how to manage it at each provider is covered in how AI memory works.

Which leaves the honest summary: the question is not whether an assistant remembers, because it does. The question is who owns that switch and whether anyone has ever looked at it. In most organisations the answer to the second is still no.

FAQ

Common questions

What is the difference between memory and the context window?

The context window is the working space of one conversation and empties when it ends. Memory is a separate facility holding facts between conversations, so the assistant still knows in a new chat what you told it before.

Can I see what an assistant has remembered about me?

At the major assistants, yes. There is usually a settings view listing the stored facts, which you can edit or delete. Reviewing that periodically is more useful than switching memory off entirely.

Can my administrator turn memory off?

In enterprise tenants, usually yes. It becomes an organisational setting rather than a personal preference. During a rollout it is one of the first switches to set deliberately rather than leave on its default.

What happens to incorrect memories?

They get repeated. If the assistant stored a wrong assumption about your role or your client, it returns in every subsequent conversation and gets treated as established fact. That is why review matters more than people expect.

Is memory a processing operation under the GDPR?

Yes. Data about a person is stored for later use, with a purpose and a retention period. If third-party personal data ends up in there, such as a client name you mention often, that is processing your organisation is accountable for.