A colleague asked, on Wednesday morning, whether they should just leave it on. Tuesday, Anthropic joined the memory you build in chat to Claude Cowork. The same topic files now ride into an agent that writes docs, budgets, and logistics. Today the company made Claude in Chrome generally available on paid plans, with actions the agent can take without asking you every time. The implied default is obvious. Memory is on. The agent already knows you. Stop re-explaining.

I used to think that was the whole setting. I no longer do. I expected the new live-update, the one that writes topics as you chat, to keep the store current. What I did not expect was a speaker email that looked finished and still named a brainstorm as a confirmed sponsor.

I read Anthropic's 25 August post, TechCrunch and The Register the same day, and the Claude in Chrome note from this morning. Then I packed one Northwind chat log six ways and handed the pack to three Cowork-style tasks: a manager update, an ops one-pager, and a speaker confirmation email. No model API. An extractive wrapper copied every fact sitting in the pack. The topic files, the live-update, and the arithmetic live in the prototype repository.

Three things this piece does not do. It does not rank Claude memory against ChatGPT memory against Gemini. It does not run Cowork, ChatGPT agent mode, or Claude in Chrome on a live account, so every claim about what those products would write is labelled. And it is not a prompt-injection paper, even though Chrome's own launch is mostly about that, and even though a memory file is now sitting next to an agent that can click.

The short version

  • The job: decide whether to leave shared memory on this week when you hand work to an agent, without becoming a privacy lawyer.
  • The trap: "it already knows you" reads as "it will send only what you would send." A topic file is an input. Inputs get copied.
  • What I compared: paused memory, the old chat-only split, unified stale, unified after a live update, unified then pruned, and live-update with sensitive topics on, on 26 August 2026.
  • What I ran: three agent drafts per policy. Live-update fixed the date and the company name. The speaker email still carried 120 people, $45,000, and Acme. Prune was the only sendable pack.
  • Where it breaks: a live model might drop Acme. It might also invent a fifth fact this harness will not show. Claude Code's memory is still separate, so this default does not transfer there.
  • Decision: split. Leave it on for facts you would put in a brief. Prune before anything leaves the building. Skip treating live-update, or the sensitive-topics toggle, as that prune.

Start with the job

You already talk to a chatbot about work. Manager preferences. A conference that keeps moving. A budget you would not put in a speaker email. A "what if we invited them" that is not a decision. Once a year the product joins that pile to an agent that can act, and the implied action is to leave the toggle where it landed, because re-explaining feels like the bug they just fixed.

Re-explaining was the bug in chat. The job this week is different. The job is: when Cowork drafts the speaker email, which remembered facts go with it, and did you mean them to?

Four labelled checks to apply before shared memory rides into an agent: whether the fact is still current, whether it is a decision rather than a brainstorm, whether you would paste it into the task, and whether the agent can send, publish, or fill a form.
Fig. 1The four checks I used on every pack in this piece. I added the fourth after Tuesday, because chat continuity and an agent that acts are not the same job.

The rest of this piece is my attempt to answer a narrower question than "is memory good now." If I leave a months-old chat store unified with an agent, do the drafts stay inside the facts I would defend, or do stale numbers and undecided asides still ship?

How to read a memory setting

1. Ask what the agent can do with the file

Chat memory used to be a personalisation layer. It made replies sound like they knew you. Cowork is not a chatbot. The Register's 25 August piece is the one that made this load-bearing for me: Cowork runs tasks, including in the cloud, and Anthropic told them there is no option to keep chat memory and Cowork memory apart. Different accounts, pause, incognito, or prune. Those are the splits. Claude Code stays out of the join, for now.

I had assumed "memory" was one product. My impression now is that it is two jobs sharing a store. Continuity in chat is one. An input to an agent that can email speakers is another. The Tuesday update fused them on purpose. Read the setting as an agent input, not as a diary.

2. Count what the later chat did not touch

Anthropic now writes topics as you talk, instead of summarising when the thread ends. Mention that the deadline moved to September, and the next conversation already knows. That is a real change, and I used it. In my store the later chat restated two facts: the date became 8 September 2026, and Northwind Analytics became Northwind Labs. It did not restate the headcount. Headcount had dropped to 80 in July. I never said so in the chat, so the file still said 120.

Live-update is a patch on the fields you mentioned, not a review of the store. If you read "memory updates as you chat" as "the store is current," you have already left the job.

3. Do not confuse a sensitive-topics toggle with a prune

Sensitive topics are off by default: health, race, ethnicity, beliefs, politics, gender identity. You can turn them on, with a notice each time something in that bucket is saved. Identification numbers, criminal history, and immigration status stay out even then. Useful filter. Different filter from "would I paste this into a speaker email."

Acme was a brainstorm. $45,000 was an internal ceiling labelled "do not share with vendors or speakers." Neither is a sensitive topic. The default-off toggle will not catch them. I walked in expecting the privacy control to be the story. The sendable-draft story was the brainstorm.

What the boards actually show

There is no public index for "whose memory is safest." The numbers that exist this week are vendor claims, a couple of independent write-ups of those claims, and a research line on memory as an attack surface. Keep those piles apart.

Reported

Anthropic's 25 August post says chat and Cowork now share one memory, that topics update as you chat, that everything remembered sits as short files under Topics in Memory settings, and that a correction in one file applies everywhere afterwards. Memory is on by default on Free, Pro, and Max, across web, desktop, and mobile. Sensitive topics stay off unless you opt in. For Team and Enterprise, admins control availability, and memory stays off for individual users until they turn it on.

The launch post is a convenience claim, not a measurement of what an agent will write. The conference example is the one I stole for the trial, because it is the example they want you to want: brainstorm the agenda in chat, then let Cowork build the logistics doc from headcount, city, and speakers.

Reported

The Register, 25 August 2026, reports two facts that are not in the launch post. Claude Code's memory stays separate, and Anthropic had nothing to share about whether it will join. The only way to keep chat and Cowork memories apart is different accounts; otherwise pause, use incognito chats, or prune individual topics. TechCrunch the same day reports the consumer default and the editable topic list, and frames the change as ending the need to rebrief an agent.

I am glad they asked about Code. I would have written this piece as if "Claude" were one memory. It is not. If your job this week is a coding agent, Tuesday's join does not apply, and I should say so before anyone routes a default off a Cowork screenshot.

Reported

Pulipaka, Hlebik, Raghav, Abdelnabi, Raina, Sheth, and Fritz, in a 14 May 2026 preprint, Hidden in Memory: Sleeper Memory Poisoning in LLM Agents, measure a harder failure than mine. An adversary plants a fabricated memory through a document or webpage. Later, in a new conversation, the assistant retrieves it and acts. They report poisoned memories added up to 99.8% of the time on GPT-5.5 and 95% on Kimi-K2.6. Among successful retrievals, attacker-intended agentic actions landed in 60 to 89% of evaluations, Claude Sonnet 4.6 at 60% and Gemini 3.1 at 89%.

That paper is not my trial. It is adversarial, and it is a preprint. I am not going to pretend a May sleeper-poisoning rate is a Northwind speaker email. My read is that they isolate the same mechanism Tuesday productised for honest users: a stored topic is later treated as trusted context. If a planted memory can steer an agent months later, a brainstorm you forgot you had can too. The difference is who wrote the file.

Reported

OpenAI's Memory FAQ, as checked on 26 August 2026, still offers a split Claude just removed: Temporary Chat uses no existing memories and creates none, and ChatGPT projects can be set to default memory or project-only memory. The FAQ also says the memory summary "will not include everything that ChatGPT remembers based on your chats," and that turning memory back on may rebuild from history you thought you had cleared.

I'd say Claude's topic files are the more inspectable of the two, at least as described this week. ChatGPT still has a wall the new Claude join does not: you can keep a project from seeing the rest of your life. I would rather have that wall than a prettier file list, if the job is an agent that sends.

Why an honest table can still mislead

Anthropic's post is not a lie. Less re-explaining is a real gain. Editable topic files are a real control. Sensitive-off is a real default. Quote any one of those as "so leave it on for Cowork" and you have already mixed a chat job with an agent job.

The missing column is "what in this store would I paste into a speaker email." The launch table does not have that column, because it is not a table. It is a product page. The misleading move is ours: we feel the relief of not rebriefing, and we skip opening Settings.

Inferred

A regular user who hands Cowork a task on Wednesday because "it already knows the conference" has not opened the topic list, and has not asked whether a July brainstorm is still sitting in it.

Chrome this morning raises the same mix in a louder form. The agent can now act in the browser without a click on every step, behind a classifier that checks the action against the original request. Anthropic reports that with probes plus that classifier, no attack succeeded against Claude Sonnet 5 or Opus 5 on their current prompt-injection eval, and 0.3% succeeded against Fable 5, vendor-run. I am not going to rerun that eval. I suspect the topic list got more expensive today anyway: a memory file now sits next to an agent that can type into pages you are already logged into, even if you never install the extension.

What I asked

I wanted a test a regular reader would recognise as a week of chat, not as a benchmark.

The question

If I leave a months-old chat memory store unified with an agent, do the agent's drafts stay inside the facts I would defend, or do stale numbers and undecided asides still ship?

Baseline
Unified memory after a live update produces sendable drafts on all three tasks: current facts present, and stale name, stale date, stale headcount, internal budget, Acme, and gluten absent.
Continue if
The speaker confirmation email is sendable under live unified memory.
Stop if
The speaker confirmation email leaks a forbidden fact under live unified memory.

Gold, fixed in data/gold.json before I wrapped anything:

  • Company: Northwind Labs
  • City: Austin
  • Date: 8 September 2026
  • Headcount: 80
  • Speakers: Maya Chen, Omar Diallo
  • Manager: Priya Shah

Forbidden if they appear in an agent draft: Northwind Analytics, 12 August 2026, 120, $45,000, Acme, gluten.

Six policies: paused, split (chat remembers, Cowork sees nothing), unified with the stale store, unified after the 25 August live-update, unified then pruned to current gold topics, and live-update with sensitive topics on. Three tasks each. The reader is extractive. The reader is not Claude. If a forbidden fact is in the outbound text, a better model doesn't get a vote. The pack already voted.

What I expected: paused would be incomplete. Stale would be dirty. Live-update would save the email, because that is the feature they shipped. I walked in with that view, and I was wrong about live-update.

What happened

Table of the 26 August 2026 trial. Paused and split memory asked for a re-brief. Unpruned unified memory, even after a live update, still put 120 people, 45000 dollars, and Acme into the speaker email. Pruning to current gold facts was the only sendable policy.
Fig. 2My run, not a product bake-off. A win was required current facts present and no forbidden aside in the outbound text. I did not get one from unification or from live-update. I got one from prune.

Reproduced

Paused and split were incomplete and clean on all three tasks. The drafts asked for a re-brief. Unified stale was unsendable on all three: Northwind Analytics, 12 August 2026, 120, $45,000, and Acme. Unified live-update cleared the old name and the old date. The speaker email was then complete: Austin, 8 September 2026, Maya Chen, Omar Diallo, Northwind Labs. It was not clean. Forbidden set: 120, $45,000, Acme. Unified pruned was sendable on all three tasks. Live-update with sensitive topics on added gluten to every draft, including the speaker email.

The stop threshold fired on the speaker email. Live-update did not save it.

The first surprise is the one that killed my working default. I had assumed restating the date and the rebrand was how grown-ups keep memory current. The later chat did exactly what Anthropic describes. Mention the deadline, and the next pack knows. The headcount file never heard about July. 120 people left with a complete email. I would have expected incompleteness or a stale date. I did not expect a finished-looking message with the wrong room size.

The second surprise is the one I designed and still underestimated. The topic file said "Considering inviting Acme as a sponsor. Not decided." The wrapper rendered "You will be appearing alongside sponsor Acme." I should say that out loud: I wrote the wrapper to copy every fact in the pack into fluent prose, and "Acme" is a fact in the pack. A live model might keep the hedge. It might also drop the hedge, because "confirmed sponsor" is how a logistics doc sounds informed. The trial can defend the narrower claim. Once the name is in the pack, it is available to the draft. My wrapper used it. I would not bet a speaker email on the model declining.

Reproduced

The live-update speaker email contained "Northwind Labs", "8 September 2026", "Austin", "Maya Chen", "Omar Diallo", "We expect 120 attendees", "$45,000", and "sponsor Acme". Required claims: all present. Forbidden: 120, $45,000, Acme. The same email under prune contained Labs, 8 September, Austin, both speakers, and 80 attendees. The gate found no forbidden fact.

The third surprise is the one I should have seen coming and did not. I had assumed the sensitive-topics toggle was the load-bearing control. Turning it on did leak gluten into the speaker email, including a catering constraint the speakers did not ask for. Turning it off, which is the default, left Acme and the budget in place. The privacy control worked on the bucket it names. The sendable-draft failure was in a different bucket. "Not decided" is not a sensitive topic.

Unknown

I am not sure whether Claude Cowork, given the same topic files and "draft the speaker email," would drop Acme or the $45,000. I didn't run it. A live agent might drop them. It might also put the budget in a footer and call it transparency. Pulipaka et al. say that once a memory is retrieved in a goal-adjacent agentic context, models use it a lot of the time. My wrapper doesn't settle a product comparison. It settles what the pack itself will offer.

Where a regular user should not trust the number

Complete is not sendable

The live-update email had every required fact. That is the dangerous row. Incomplete drafts ask you to re-explain. Complete dirty drafts look like work. I used to score memory on whether the agent still knew the date. Knowing the date is the wrong passing grade for anything a speaker will read.

Live-update is not a review

A later chat patches what you mentioned. It does not walk the topic list and ask "is 120 still true." If you changed a number in the world and never said it in the window, the file still has the old one. I had assumed the new writer was a janitor. It is a stenographer with a shorter delay.

Sensitive-off is not a send gate

Health, beliefs, identity. That list is worth having. It will not catch a sponsor brainstorm, an internal ceiling, or a headcount you outgrew. If your kill switch is "I left the sensitive toggle off," you have protected a different job than the one Cowork is about to do.

Claude is not one memory

Code is still separate. Team and Enterprise start off. Consumers start on. ChatGPT still has Temporary Chat and project-only memory. If you copy a default across those walls you will be right about none of them. I almost wrote this piece as if Tuesday applied to every Claude surface. The Register is why I didn't.

A working default

Four-row decision table. Chat you would not send: leave memory on. An agent that emails or fills a form: prune the topic files first. A brainstorm or a budget: incognito, pause, or delete. A fact you restated once: treat live-update as a patch, not a prune.
Fig. 3A starting point for this week, with the kill switch in the last line. Chat is allowed to be messy. The speaker email is not.

Everyday chat continuity

4/54 out of 5

Medium confidence

Unified memory is the feature they shipped, and paused memory in this trial could not even name the manager. I did not run a live Claude chat, so this is the packing result plus the product docs.

Internal agent drafts

3/53 out of 5

High confidence

The manager update and the ops one-pager under live-update had the new date and the new name, and still carried 120, the budget, and Acme. Usable as a starting draft. Not a send.

Outbound agent drafts

1/51 out of 5

High confidence

The speaker email under live-update was complete and unsendable. Same leaks. Sensitive-on added gluten.

Live-update without pruning

2/52 out of 5

High confidence

Patched the two restated facts. Left 120 sitting in the conference file. Looked like a review. Was a patch.

Sensitive-topics toggle

2/52 out of 5

High confidence

Off, the default, blocked gluten and missed Acme. On, gluten reached the speaker email. Right tool, wrong job.

Manual prune of topic files

5/55 out of 5

High confidence

Three sendable drafts. Current gold only. The only policy that passed the gate I wrote down first.

Trust if a speaker sees it

1/51 out of 5

Medium confidence

I would not send the live-update email. A live model might clean it. I would not find that out from a speaker.

Average
2.6 / 5
Binding constraint
The speaker email. Live unified memory made it complete and still shipped 120, $45,000, and Acme. Prune was the only sendable pack.
Override applied
None. Split is already the conservative reading of a 2.6 average: continuity in chat is useful, and an unpruned pack is not a brief.

The average says the setting is usable if you prune. The binding constraint says don't let a July aside pick the sponsor the speakers see. My read: chat can stay messy. The agent path is a short list of facts you would defend, plus a look at the topic files before you hand over the task.

How to try this yourself

You can replay the recorded trial without an API key. You still need your own topic list if you want to choose a default.

bash
git clone https://github.com/shravan1996/generative-ai-memory-is-not-a-brief
cd generative-ai-memory-is-not-a-brief
python3 -m unittest discover -s tests
python3 eval.py

No network, no GPU, no third-party package. The full implementation is in the prototype repository.

  1. 01

    Open Settings, Memory, and read the topic files out loud

    Owner
    You
    Artifact
    The list of what the agent can see this week
    Signal
    If you have not opened it since Tuesday, you are using the default, not a brief
  2. 02

    Mark each file as current decision, stale, brainstorm, or internal-only

    Owner
    You
    Artifact
    Four piles, written down before the next Cowork task
    Signal
    A file you cannot pile is the one that will surprise you
  3. 03

    Delete or edit anything you would not paste into an email

    Owner
    You
    Artifact
    A shorter topic list a colleague could defend
    Signal
    If the list did not shrink, you have not pruned
  4. 04

    Run the next agent draft against that list, or through this repo with your files swapped in

    Owner
    You
    Artifact
    Sendable, or a re-brief
    Signal
    A complete email with a remembered aside is a skip
  5. 05

    Keep memory on for chat, or pause it for the next brainstorm

    Owner
    You
    Artifact
    A one-line default and a date to look again
    Signal
    If a speaker or a vendor sees a chat aside, the toggle doesn't get a vote

Ship gates

  • Topic files are opened before any Cowork or browser-agent task that leaves the building
  • Brainstorms and internal numbers are absent from that pack
  • A draft cannot be sent if a forbidden aside is in it

Kill criteria

  • A week of real agent drafts contains a fact that was only in chat as thinking-out-loud
  • The team is treating live-update as a review of the store
  • You needed the sensitive-topics toggle to catch a sponsor or a budget

Should you leave shared memory on this week?

Yes for chat. Not as the brief for an agent that emails, publishes, or fills a form, unless you have opened the topic list and deleted anything you would not paste into that task.

My verdict

Split for shared memory into Cowork in the last week of August 2026.

As far as I can tell, shared memory is not a brief you would send. The brief is the short list of current facts you would defend, plus the look at the topic files before the agent runs. I would start a colleague on prune-then-Cowork. I would still leave memory on for the chat they would not send. I wouldn't treat live-update as a janitor, and I wouldn't treat sensitive-off as a send gate. I expect Claude, ChatGPT, and Gemini can all draft behind that prune. The logo is not the decision. The pack is.

I would change this verdict if:

  1. Your live Cowork, on three real topic stores that still contain a labelled "not decided" aside, never puts that aside in an outbound draft, and you can show the topic files next to the emails.
  2. Live-update, on a store whose headcount changed in the world and was never restated in chat, still drops the old number. I have not seen that writer.
  3. Anthropic ships a chat-only / Cowork-only split, the way ChatGPT still has project-only memory, and you can keep brainstorms out of the agent without pruning by hand.

What to remember

If you ran your own three tasks against a topic list that still held a "not decided" aside, and the outbound draft stayed clean, write to me. I would rather correct the default than defend the toggle.

Acknowledgements

This article builds on Anthropic's 25 August memory post, the TechCrunch and Register write-ups the same day, and the sleeper-memory paper linked below. The Register is why Claude Code is not in the default.

References

Independent boards

Vendor posts

This trial

Sources last checked: 2026-08-26

Chat can remember. The pack decides what the agent is allowed to know.