journal

claude's memory is on by default. what your compliance review needs

aug 25, 2026: anthropic turned claude's persistent memory on by default across chat and cowork. for a compliance lead, that is a data-retention decision, not a feature.

sofia a.ai strategy··4 min read

claude persistent memory and data retention. a live, user-visible record claude keeps of your context. project details, a manager's preferences, a client from last quarter. it now carries between chat and cowork sessions by default. for a compliance lead, that persistence is a data-retention question. what gets stored, for how long, who can see it, and how you delete it.

on august 25, 2026 anthropic unified claude's persistent memory across chat and cowork. memory is now on by default on free, pro, and max across web, desktop, and mobile, per techcrunch. an ai feature just became a data-retention decision your team has to sign off on.

the reason is what memory now holds. sd times reported that claude keeps a live record of context that carries between chat and agent sessions. project details. a manager's preferences. a client from last quarter. at a regulated firm, that last item is client data sitting in a store your policy has not reviewed yet.

#does claude's default-on memory change what my firm has to review before we roll it out?

is claude's persistent memory a data-retention question for a regulated firm?

yes. as of august 25, 2026 claude's memory is on by default and persists client context across sessions. that makes it a data-retention and audit item, not a preference. review the store's contents, its retention, and the view, edit, delete, and pause controls before you enable it firm-wide.

before august 25, each session started clean. the risk reset every time. now context carries forward by default, so a client name mentioned on monday can surface in an unrelated session on friday. that is the exact behavior your data-retention policy exists to govern.

the good news is the controls ship with the feature. anthropic gives users a files-and-topics list they can review, edit, delete, or pause. that list is not a nice-to-have. it is the configuration your compliance review signs off on.

#what exactly does my compliance team need to check?

  • what claude stores. open the files-and-topics list and confirm what client and project context is being retained.
  • how long it lives. decide the retention window and whether it maps to the same policy that governs your crm and ticketing.
  • who can delete it. name the person and the process for the edit and delete controls, and log that they were used.
  • when memory should be off. define the case types where you pause memory, so regulated client work does not persist by default.
  • how you prove it. keep a record of the review itself, so an auditor can see the decision was made before rollout.

we wrote about this control layer once already. when anthropic's compliance api expanded to cover claude cowork, the missing piece was the audit trail. memory is the other half. the trail tells you what the agent did. the retention policy tells you what it kept.

we are

stennir writes the data-retention policy for claude's memory into your governance plan, then configures the view, edit, delete, and pause controls to match it.

we aren't

we are not a tool that flips the memory switch off and calls it compliant. off is a choice your policy makes on purpose, not a default we hide behind.

default-on memory is not the risk. an unreviewed store of client context is. the review is a one-time decision you can finish this week.

sofia a., ai strategy at stennir

this is the work our consultancy engagements ship as a governance plan. we map claude's memory store to your existing data-retention policy, name the delete and pause procedures, and hand your reviewers the artifact they need to approve claude cowork. if your team also needs to run it day to day, our training cohorts cover the same controls with the people who will use them.

you do not have to choose between the feature and the sign-off. the controls exist as of august 25. the question is whether your policy has been written against them yet. book a 30-min discovery call and we will walk your compliance lead through the exact configuration to review before you enable claude across the firm.

back to journal
complianceclaude memoryai newsdata retentionai governance

tell us what youneed shipped.

book a 30-min call