The Problem With AI “Memory”
A feature that remembers everything you said sounds convenient right up until you remember who else can read it.
“Memory” is the feature everyone asked for and few thought through. The pitch is lovely: the assistant remembers your preferences, your projects, your writing style, the fact that you are vegetarian and allergic to long emails, so you never have to repeat yourself. In practice, it is one of the most consequential privacy decisions in consumer AI, dressed up as a convenience toggle, and most people flipped it on without reading past the word “remember.”
Convenience and surveillance are the same feature
The uncomfortable truth is that there is no version of persistent memory that is not also a growing personal record. For the assistant to remember your details, it has to store your details. The thing that makes it feel like it knows you is a file — structured or otherwise — accumulating what you have told it, and inferring more from what you did not. The warmth and the dossier are not two features. They are one feature seen from two angles.
The profile that shapes what you are shown
A stored model of who you are does not sit there inertly; it starts to shape the responses you get. That is the entire selling point — a memory-enabled assistant tailors its answers to what it believes about you. But tailoring cuts both ways. Once the system has decided you are a particular sort of person, with particular views and particular tastes, it begins to give you the version of the world it thinks you want, and you lose the ability to know what it would have said to someone it had profiled differently. The personalisation that feels like being understood is also, quietly, a narrowing.
We have seen this film before, with recommendation feeds that learned our preferences and then fed them back to us until the preferences hardened into a cage. A memory-driven assistant risks the same dynamic applied to information and advice rather than entertainment — a system that increasingly tells you what fits the profile it has built, in a voice of neutral helpfulness that hides the fact that a version of you is doing the steering. The more it remembers, the more it reflects you back at yourself, and the harder it becomes to use the tool to genuinely think against your own grain. Forgetting, it turns out, is part of what keeps a source honest.
You cannot easily see what it decided about you
The deeper problem is opacity. Memory does not only store the facts you deliberately offered. It stores inferences — patterns it noticed, conclusions it drew, categories it filed you under. And the interface for inspecting all of this is, at best, partial. You can often see some saved notes; you can rarely see the full shape of what the system has concluded about your habits, your mood, your politics, your health, your finances, based on months of you thinking out loud.
This matters because people talk to chatbots with a strange candour. The blank, non-judgemental box invites disclosure — worries, symptoms, relationship problems, half-formed plans — that people would never put in an email. Memory turns that candour into a persistent profile. The thing you found comforting about the anonymity is quietly undermined by the thing that remembers.
The record outlives the moment
Context collapses over time. A question you asked during a frightening week, a subject you researched out of one-off curiosity, an opinion you were trying on and discarded — memory can flatten all of these into apparently stable facts about who you are. The system does not know that you were joking, venting, or looking something up on behalf of someone else. It just knows you said it, and now it remembers, and it will helpfully bring it up later.
And then there is everyone else who can reach it
A stored profile is a target. It can be subject to a data request, exposed in a breach, retained after you thought you had deleted the account, or used — depending on the settings we complained about elsewhere — to improve the very models it was built from. The more the assistant remembers, the higher the stakes of every one of those failure modes. A chatbot that forgets each conversation is a low-value target. A chatbot that has quietly assembled a year of your inner monologue is not.
Using memory without being used by it
Memory is not evil, and for some genuinely useful cases — remembering your formatting preferences, your recurring project context — it is a real quality-of-life improvement. The point is to treat it as the significant choice it is, rather than the harmless toggle it is presented as:
- Know whether it is on. For several products it defaults on. Check.
- Read what it has stored, where you are allowed to, and delete what you did not mean to donate.
- Keep the sensitive stuff out of the box entirely — the health worries, the financial specifics, the details about other people who never agreed to be remembered.
- Turn it off for the anonymous, one-off questions where the whole value was that nothing was being kept.
The inference problem is worse than the storage problem
People worry about memory storing the facts they typed. The sharper concern is the facts it derives that they never typed at all. A system with a running record of your questions can infer a great deal you never stated: your rough location from what you ask about, your health from your worries, your income bracket from your spending questions, your politics from the framing of your queries, a mental-health picture from your tone at 2am. None of this was disclosed. All of it can be inferred, stored as a working model of you, and used to shape what you are shown — and you cannot delete an inference you do not know exists.
This is the part the tidy “view your saved memories” screen conceals. It shows you the explicit notes; it does not show you the profile assembled from the pattern of everything you have ever asked. The gap between what a system has visibly saved and what it has effectively learned about you is enormous, and it is precisely the invisible part that is most sensitive and least controllable. You are auditing the tip and reassured, while the mass of it sits below the waterline, unlabelled and un-deletable.
Intimacy as a retention strategy
It is worth being clear-eyed about why memory is pushed so hard. An assistant that knows you is an assistant that is painful to leave. Every preference it has learned, every bit of context it holds, is a small switching cost — start again with a competitor and you must rebuild the relationship from scratch. Memory is not only a convenience feature; it is a moat, quietly converting your accumulated disclosures into lock-in. The more it remembers, the more it costs you to walk away, which is a benefit to the vendor dressed as a benefit to you.
That reframing is not cynical; it is just following the incentive. A feature that happens to make the product both stickier and more data-rich, while feeling to the user like warmth and personalisation, is a feature a subscription business will build whether or not it is in your interest — because it is squarely in theirs. The intimacy is real in effect and instrumental in purpose, and knowing which is which is the difference between using the feature and being used by it.
Consent that cannot keep up with context
Even a diligent user who reads every setting faces a problem no toggle solves: you cannot meaningfully consent to how a fact about you will be used in a future you cannot foresee. You tell the assistant something during a frightening week, in a particular mood, for a particular reason. Memory strips away that context and preserves the fact as a stable, decontextualised truth about who you are — available to be surfaced, acted on, or inferred from, months later, in situations you never imagined when you said it. The consent you gave was to a moment. The retention is forever, and the two do not match.
This is why “you agreed to memory” is a weak defence for what the feature actually does. Agreeing that an assistant may remember your preferences is not the same as agreeing that a year of your unguarded thinking may be assembled into a durable profile, mined for inferences you never volunteered, and used to shape what you are shown. The granularity of real consent — this fact, for this purpose, for this long — is exactly what a persistent, inferential memory cannot offer, because its whole value comes from retaining and connecting things you did not deliberately decide to give it. A feature built on remembering everything cannot, by construction, ask permission for each thing it remembers. So it asks once, vaguely, at the start, and calls a year of accumulation covered by a single tick.
The feature is sold on intimacy — an assistant that finally knows you. It is worth remembering that intimacy, in software, is another word for data retention. Enjoy the convenience with your eyes open, and decide for yourself what you would rather it forget.
Finally someone said it. I cancelled my sub last week for exactly this reason.