A consultant has worked with the same assistant for months. He no longer explains what he does, which sector his clients are in, or how he structures a report. That is the point, and it works well.
Then, in a conversation about an entirely different client, a detail surfaces that he mentioned about the first client three months ago. Nobody did anything wrong. The switch was simply on.
Memory is not the conversation
The distinction first, because this is where assessments most often go wrong.
The context window is the working space of one conversation. When the conversation ends, that space is empty. What was in it remains in your history, but the model does not carry it into the next exchange.
Memory is a separate facility. The assistant extracts facts that look worth keeping and stores them as discrete notes: your role, your preferences, what you are working on, how you like to be addressed. On a new conversation, those notes are supplied alongside your first message.
Two systems, two retention periods, two switches.
Three owners of the same switch
The user. On consumer accounts you manage it. The major assistants offer a view of what has been remembered, and you can remove entries from it. The default is usually on.
The administrator. In enterprise tenants the control moves. The organisation can disable memory for everyone, enable it for everyone, or configure it per group. It is one of those settings that survives a rollout on its default value simply because nobody went looking for it.
The vendor. The third owner and the least visible. Assistants embedded in your workspace pull in context automatically: recent documents, your calendar, the thread you are reading. Technically that is not memory, because nothing is stored as a note, and to the user it feels identical. The assistant knows things you never told it. See how AI tools reach files you never uploaded.
Why this is more than a setting
Three consequences that turn up in practice.
Errors get repeated. If the assistant stored a wrong assumption (a role you do not hold, a client you no longer serve), it returns in every conversation and is treated as given. Harder to catch than a one-off mistake, because no source is attached to it.
Third-party data lands in it. Memory is meant for facts about you. In practice it also retains what you mention often, and that means client names, matters and cases. That is processing personal data belonging to someone who was never part of the conversation.
Context leaks between contexts. What you say in one role can surface in a conversation held in another. For anyone serving multiple clients, that is not a theoretical objection.
What to do
For an organisation:
- Set the memory control deliberately rather than leaving it on its default. Both choices are defensible; not choosing is not.
- Treat memory as a distinct processing operation in your DPIA, with its own purpose and retention.
- Explain what happens. People who know something is being retained behave differently toward it.
For yourself, if it is on:
Read the memory list once a month. Not because something alarming is in there, but because it shows you what the assistant believes it knows. It is usually a clarifying list, and it is the only way to remove a wrong assumption before it gets repeated fifty times.
How remembering works per tool and how to manage it at each provider is covered in how AI memory works.
Which leaves the honest summary: the question is not whether an assistant remembers, because it does. The question is who owns that switch and whether anyone has ever looked at it. In most organisations the answer to the second is still no.