ARQ LabBook a briefing

    AN ARQ LAB POSITION PAPER · FROM THE ADULT SUPERVISION SERIES

    The Perfect Witness

    Your AI remembers more about your business than anyone is tracking. It can be compelled to repeat it. And almost no one is managing what it knows.

    Dave Tyson, Co-founder, ARQ Lab · September 2026

    Download the PDF (8 pages) →

    THE PREMISE

    You hired a workforce with perfect memory — and no HR file

    Imagine a situation where you hired a thousand employees in one quarter. Brilliant, tireless, and each one remembers every conversation perfectly, forever.

    Now imagine none of them has an HR file. No record of what they know. No retention schedule for what they keep. No exit interview when they leave. Nobody who can say, under oath, what they were told and when.

    That is what most organizations did over the last two years. The employees are AI assistants and agents, and the memory is real: many AI tools now remember facts across conversations, accumulate context about your business, and act on what they remember. Every control regime your company relies on — retention schedules, legal holds, access reviews, offboarding, privilege — was built on the assumption that information lives in systems. It now also lives in agents, and almost none of those controls follow it there.

    The data says this gap is normal, not rare.

    Exhibit 1 — Adoption is sprinting; governance is walking

    Breached organizations without a policy to govern AI or detect unapproved use (none, or still in development) (up from 63% in 2025)68%
    Security incidents involving unapproved "shadow AI" tools (more than double last year)43%
    Companies planning to deploy agentic AI within two years ~75%
    Companies with a mature governance model for AI agents 21%
    Sources: IBM Cost of a Data Breach Report 2026 (top two; the second is a share of security incidents); Deloitte, State of AI in the Enterprise 2026 (bottom two, each a share of all leaders surveyed). Bar length is percent.

    The right response is to keep going, and to do it well. If you don't know how something fails, how will you ensure that it doesn't?

    WHY EXISTING CONTROLS MISS IT

    Five controls that assume information lives in systems

    Each of these controls works. Each was built for information that sits in a mailbox, a file share, or a database — a system of record with an owner, an inventory entry, and an administrator. An AI tool's memory is none of those things, so the control simply never reaches it, and nobody ever decided that it should.

    Exhibit 2 — Where the control stops: systems of record vs. AI memory

    ControlSystems of record (email, files, databases)AI memory (assistants and agents)
    Records retention scheduleCovered: Classes, periods, dispositionNot covered: Schedules are silent on what AI tools retain
    Legal hold / eDiscoveryCovered: Custodians mapped, preservation toolingNot covered: Memory stores absent from custodian maps
    Access reviewCovered: Periodic recertification of who reaches whatNot covered: No review asks who can reach a memory
    OffboardingCovered: Accounts revoked, devices returnedNot covered: Nothing revokes or reviews what the agent learned
    Privilege & confidentiality wallsCovered: Matter walls, need-to-know boundariesNot covered: Memory crosses contexts no wall was built for
    Assessment reflects the default state of each control as commonly deployed; individual programs vary. Exceptions exist: some platforms extend retention and eDiscovery to their own assistant's interactions (for example, Microsoft Purview for Microsoft 365 Copilot). That coverage rarely reaches project knowledge, notes an agent writes for itself, or AI tools outside the platform.

    What counts as AI memory. Anything an AI tool keeps from one interaction and uses in a later one: the memory features in assistants, project and workspace knowledge, files and notes an agent writes for itself, stored conversation histories, and the document stores agents search before they answer. If a tool can bring back tomorrow what it was told today, it has memory — wherever that memory is hosted.

    What follows are the ten memory risks we believe matter most to the business — each with the one question it should make you ask inside your own organization.

    THE TEN RISKS · 1–4

    AI memory is discoverable — and most legal holds don't cover it

    When litigation arrives, opposing counsel can demand what your AI tools remember the same way they demand email and chat. Most companies cannot even list where their AI tools store memory, let alone preserve it under a hold. "IT didn't know that store existed" has failed for email, texts, and chat — it is unlikely to fare better here.

    Ask: If we received a litigation hold notice today, could we identify and preserve every AI memory store in the company within the deadline?

    Institutional knowledge walks out the door — or is deleted on the way out

    People pour ideas, drafts, and decisions into AI assistants only they use. When they leave, that knowledge either leaves with them or gets wiped — a corporate asset nobody inventoried, destroyed without approval. The exit interview and the shared drive were the old answer. Neither reaches an assistant's memory.

    Ask: When someone leaves, who reviews what their AI tools learned during their employment — and who decides what is kept?

    Memory becomes a shadow system of record

    Decisions get made on facts an agent "remembers" that exist in no official system. When an auditor, a regulator, or your board asks what you knew and when, the honest answer may live in AI memory nobody governs — quietly undermining change management, financial controls, and every attestation built on official records.

    Ask: Are decisions being made in this company based on information that exists only inside an AI tool's memory?

    Uncontrolled memory can weaken trade secret and privilege protection

    Trade secret status depends on reasonable measures to protect the information. Your most sensitive know-how sitting in ungoverned, often third-party-hosted memory is a gift to opposing counsel arguing you didn't protect it. The same logic threatens attorney-client privilege. The exposure exists the day the information enters the memory — no breach required.

    Ask: Which of our trade secrets and privileged matters have entered an AI memory store — and would our protection story survive cross-examination?

    THE TEN RISKS · 5–8

    Memory accumulates personal data you never decided to collect

    Each conversation is innocent; the accumulated profile is not. AI memory aggregates personal information across interactions by design, running against the data-minimization principle in GDPR, CCPA, and most privacy programs. Honoring a deletion request is very hard when you cannot locate every place a person's data was remembered or derived.

    Ask: If a customer or employee filed a deletion request tomorrow, could we find and remove what our AI tools remember about them?

    A false fact planted in memory corrupts every decision after it

    A bad prompt is a moment; a poisoned memory is an infection. If an attacker — or simply an error — plants a false fact in an agent's memory, every future output quietly builds on it, and the record of when the falsehood entered rarely exists. Some organizations plant canary markers in AI memory specifically to detect tampering and leakage. Few even ask the question.

    Ask: If a false fact entered one of our agents' memory six months ago, would anything in our environment detect it?

    Memory leaks across contexts the walls were built to separate

    Information learned in a confidential context — an acquisition, an HR investigation, a board discussion — can resurface in an unrelated draft or a different user's session. Every industry that handles confidential matters spent decades building walls between contexts. Nobody thought of an assistant's memory as a data flow, so no wall was built there.

    Ask: Do our AI tools carry memory between people, projects, or matters that our own policies require us to keep separated?

    Retention schedules are silent, so you get both failure modes at once

    Over-retention: memory holding information your schedule says should be gone, keeping expired liability alive. Under-retention: memory casually wiped that regulation required you to keep. Records programs have not caught up — which means a company can be out of compliance with its own retention policy without knowing it.

    Ask: Does our records retention schedule mention AI memory anywhere — and if it does, can we actually enforce it?

    THE TEN RISKS · 9–10

    Memory outlives the access decisions that fed it

    An agent remembers what a person shared while they had clearance for a project. The person changes roles or leaves; the memory stays, available to whoever can query the agent. Offboarding checklists revoke accounts — nothing revokes what the agent learned. Access reviews audit who can reach a system; none audit who can reach a memory.

    Ask: When we revoke someone's access, what happens to the information they already fed into shared AI tools?

    Stale memory drives confidently wrong decisions

    Memory captures what was true when it was written — the old price, the retired product name, the pre-reorganization chart — and an agent will assert it months later with complete confidence. Nobody owns re-validating what AI tools remember, so decision quality degrades silently. Keeping memory current is a supervision job, and someone has to own it.

    Ask: Who in our organization is responsible for keeping AI memory current — and when did they last check?

    ALSO ON THE LIST

    Personal AI accounts remembering company information entirely outside your visibility. In IBM's 2026 study, shadow AI was involved in 43% of security incidents. Vendor lock, where years of institutional memory sit in a platform you cannot export from on the day you need to leave. And the questionnaire problem: you cannot honestly answer a customer's "how long do you retain our data" while AI memory is untracked — and your customers are starting to ask.

    "Every control regime your company relies on was built on the assumption that information lives in systems. It now also lives in agents."

    SCORE YOURSELF

    The AI Memory Risk Checklist

    The scoring rule — the part most self-assessments skip: a YES only counts if you can produce a dated artifact that proves it. A policy document, an inventory export, a test result, a named owner in writing. "I'm pretty sure legal has that covered" is a NO.

    1. 01Could we identify and preserve every AI memory store under a legal hold?
    2. 02Does anyone review what a departing employee's AI tools learned?
    3. 03Can we say whether decisions rest on facts that exist only in AI memory?
    4. 04Do we know which trade secrets and privileged matters have entered AI memory?
    5. 05Could we honor a deletion request against what our AI tools remember?
    6. 06Would we detect a false fact planted in an agent's memory?
    7. 07Is memory prevented from crossing our confidentiality walls?
    8. 08Does our retention schedule cover AI memory — enforceably?
    9. 09Does offboarding address what a person already fed into shared AI tools?
    10. 10Does someone own keeping AI memory current?

    A low score is not a judgment. Until recently most AI tools kept little or nothing between conversations, so few programs were built for this. The gap grows daily, and it is cheapest to close while your AI footprint is still small enough to inventory.

    WHERE THIS LEAVES YOU

    Run the checklist without us — genuinely

    Take these ten questions and run them inside your own organization. They work without us, and the artifact rule keeps everyone honest.

    If you want to go deeper, I'm here: arqlab.ai.

    AI that remembers is worth having. What it remembers is worth governing.

    Dave Tyson is co-founder of ARQ Lab (arqlab.ai). He has held CISO roles at global enterprises and now helps organizations see and manage the risk load their AI actually carries. Sources: IBM, Cost of a Data Breach Report 2026 (July 2026); Deloitte, State of AI in the Enterprise 2026. Statistics current as of September 2026.

    Want to go deeper?

    Book a private briefingTwenty minutes, free.

    Get the next paper when it's published: subscribe to Adult Supervision. Subscribe on LinkedIn →