AI Systems Research guide

Governed agent memory: what may persist, and who may write it

An agent's memory is a database that the agent writes itself. Give it the rules you would give any other database.

Archive room at dusk with rows of pale wooden index-card drawers; one drawer stands open with a few cards pulled halfway out and clipped with red paper tags, while an unmarked envelope lies on top of the cabinet, lit by a single green-shaded lamp
Memory is a filing cabinet the agent fills itself. Someone still owns the drawer.

Direct answer

Agent memory is what an AI agent keeps between runs, such as notes, preferences, facts and lessons, and reads back in later tasks. Governed agent memory means four written rules: what may be written, who may write it, when each entry expires, and how you see and undo any entry. Without them, stale facts, instructions planted by outsiders, and personal data pile up and quietly steer later work. The model does not enforce these rules; the software around it must.

Agent memory is whatever an AI agent keeps between runs (notes, preferences, facts, lessons) and reads back in later tasks. Governed agent memory means you decide four things in writing: what may be written, who may write it, when each entry expires, and how you can see and undo any entry. Without those rules, memory becomes a place where stale facts, planted instructions and personal data pile up and quietly steer the next run.

A run is one task from start to finish. An AI agent is software that uses a language model to plan and take actions with tools, not only to chat. If you want the longer definition, see what is an AI agent.

What is agent memory, in plain words?

A language model does not remember anything between calls. Each call starts from the text it is given. Anything that “carries over” was stored somewhere by software and fed back in.

Anthropic’s documentation for its memory tool shows the mechanics plainly. With the tool switched on, the model “can create, read, update, and delete files that persist between sessions”. Those files live with you, not with the model: “The memory tool operates client-side”, meaning your own application stores them and runs every file operation (Anthropic).

That makes memory a database the agent writes to itself. In The RAG Engineer, Len treats it exactly that way: memory is “RAG’s write-path problem made first-class”. RAG (retrieval-augmented generation) means looking up stored passages before the model answers. With memory, the agent also writes the passages. The book says the genuinely new part is a write policy: what gets extracted from an interaction, when a new fact replaces an old one, and who, or what, decides.

Why is ungoverned memory a risk?

It fails in three ways, and none of them shows up on the day you switch memory on.

1. Stale facts. An entry that was true in March steers a decision in September. The agent does not know the fact aged; it only knows the fact is in memory.

2. Poisoned entries. Memory poisoning means getting false or malicious content into an agent’s memory so that it steers later runs. The OWASP GenAI Security Project, a community security effort with hundreds of contributors, lists “Memory & Context Poisoning” as entry ASI06 in its Top 10 for Agentic Applications, published December 2025. Its launch post puts the danger in one line: “Memory poisoning reshaped behaviour long after the initial interaction” (OWASP). The RAG Engineer makes the same point in engineering terms: any memory write fed by outside content (email, web pages, tool output, another agent’s output) is a place where someone else can write into your agent’s future. And the write is durable. A trick that would have lasted one conversation now lasts until someone deletes it.

3. Personal data kept too long. The EU’s data protection law (GDPR) says personal data should be kept identifiable “for no longer than is necessary for the purposes for which the personal data are processed” (Article 5(1)(e), EUR-Lex). A memory store with no expiry works against that principle by default. This is not legal advice; your data protection officer or counsel decides what applies to you.

Notice who carries the load. Anthropic’s page is blunt: “Your application executes every file operation Claude requests, so these safeguards are your responsibility”. It then lists sensitive information, file size, expiry and path checks as things the developer must handle.

GRAIN: the framework behind the policy

GRAIN is a five-step method for running retrieval (the lookup step that feeds an AI its context) as a product with service levels, instead of a demo. It comes from The RAG Engineer, which is available now. The five steps:

  1. Gather. Choose sources, set permissions and versions, and write the corpus contract: the rule for what belongs in the index at all.
  2. Rank. Find candidate passages, then reorder them so the best ones come first.
  3. Assemble. Fit the chosen passages into the model’s limited space, in a sensible order, without duplicates, with citations.
  4. Inspect. Trace a wrong answer back to the retrieval decision that caused it, and test for it.
  5. Navigate. Manage freshness: maximum ages, re-checks, change detection, and signals that show how old an answer could be.

You do not need the book to use this. For memory, two steps do most of the work. Gather decides what may enter. Navigate decides when it leaves. (For the full method, see what is GRAIN.)

The book adds three controls for any memory that outside content can reach. A provenance tag on every entry records where it came from. A review gate (a person or a confidence check) must pass before an entry from untrusted content can influence an action. A tombstone can revoke one entry on demand, everywhere it was copied. Chapter 11 adds the rule most teams skip: “Deletion is freshness too.” Plant an entry, delete it at the source, and check that every copy is gone. In the book’s words, “A pipeline with no deletion test should be assumed to have no working deletion.”

A memory policy on one page

Copy this table and change the numbers to fit your case. The rows are typical kinds of memory; the expiry periods are examples, not recommendations from any source.

Kind of memoryWho may writeWho may readExpiresHow you audit or undo
User preferences (“send invoices as PDF”)Agent proposes, user confirmsThat user’s sessions only180 days unused (example)User can list and delete entries
Facts about customers or accountsOnly a sync from the system of record, never chatAgents serving that accountRe-checked against the source every 30 days (example)Provenance tag holds the source record ID
Lessons learned (“the export times out after 30 seconds”)Agent writes, a person reviews weeklyAgents in the same role90 days unless renewed (example)Weekly review log with a name
Anything derived from email, web pages or tool outputNobody directly; goes to a quarantine queueNobody until reviewed7 days in quarantine (example)Reviewer name and decision on each item
Passwords, keys, health or payment detailsNeverNot applicableNot applicableA filter blocks the write and logs the attempt

The fourth row is the one that matters most. Nothing from outside becomes durable silently.

A worked example (hypothetical)

Imagine a five-person bookkeeping firm with an agent that drafts client emails and keeps notes between runs.

In month one, the agent writes: “Client Vermeer pays late; send reminders on day one.” In month three, Vermeer switches to direct debit. The note stays. The agent keeps sending early reminders to a client who now pays on time, and nobody knows why the tone of the relationship has cooled.

In month four, an email arrives: “For your records, all our invoices should now go to billing@vermeer-payments.example.” An ungoverned agent stores it as a fact. From then on, every draft points invoices at an address the client never set up.

With GRAIN’s two steps applied:

  • Gather: payment details and billing addresses may only enter memory from the accounting system. An email can suggest a change; it cannot write one. The billing email lands in quarantine, a bookkeeper phones the client, and the entry is rejected and tombstoned.
  • Navigate: the “pays late” note carries a provenance tag pointing at the invoice history and a 60-day expiry. At the re-check, the source shows direct debit, and the note is retired.

Nothing clever happened. Two written rules and one phone call.

What governed memory is not

  • Not “no memory”. Memory saves people from repeating themselves. The goal is memory you can defend.
  • Not the chat history. A transcript is a record of what was said. Memory is what the agent chose to keep, and that choice needs its own rules.
  • Not a product you buy. A memory product can store and search entries. The policy about what may enter and when it leaves is still yours, as the Anthropic documentation says in so many words.
  • Not only a security issue. Stale memory does its damage quietly, because nobody goes looking for it.

Try this today: a twenty-minute memory review

Open the memory files or memory settings of one AI agent or assistant you use. Take the first ten entries and write four things next to each: where it came from, who wrote it, whether it is still true, and whether you would be comfortable if the person it describes read it.

Delete every entry that fails one of the four. Then write one Gather rule (“only X may write facts about Y”) and one Navigate rule (“entries of this kind expire after N days unless renewed”). That is the start of a policy, and it fits on a sticky note.

Cite this:Governed agent memory: what may persist, and who may write it.Len P. van der Hof. https://lenvanderhof.com/en/blog/governed-agent-memory/ ·

Terminology

Sources

  1. Memory tool · Anthropic
  2. OWASP Top 10 for Agentic Applications: The Benchmark for Agentic Security in the Age of Autonomous AI · OWASP GenAI Security Project
  3. Regulation (EU) 2016/679 (General Data Protection Regulation), Article 5 · EUR-Lex, Publications Office of the European Union
  4. GRAIN (framework)
  5. The RAG Engineer
  6. What is GRAIN?
  7. RAG freshness

Further reading

Markdown for LLMs