From Sanskriti Khandelwal | Product & Market Analysis
AI Memory at Work: What Persists, Who Can Delete It, and Where It Lives
On this page
An employee pastes a client's salary figures into an assistant, regrets it, and deletes the chat. At 3 of the 4 major enterprise assistants, that deletion does not remove what the assistant remembered from it. AI memory is now a separate store with its own lifecycle, and most retention policies written in 2024 and 2025 do not mention it.
Key takeaways
- Deleting a chat does not delete the memory it created at ChatGPT, Claude or Microsoft Copilot. All three vendors document that saved memories outlive their source conversation and must be removed separately.
- Gemini for Google Workspace has no cross-chat memory today. Google states its Personal Intelligence memory is not available on Business, Enterprise or Education accounts, so Workspace retention is about conversation history only.
- Microsoft says Purview retention policies do not apply to Copilot memory. A three-month deletion policy on Copilot chats leaves saved memories in place until the user removes them.
- Claude is the only vendor where the admin off switch deletes memory. Anthropic states that turning memory off at organisation level permanently deletes every user's memory entries immediately.
What AI memory means in an enterprise workspace
AI memory is any information an assistant stores from one conversation and applies to a later one without being asked. That is different from chat history, which is the record of the conversations themselves. The distinction is the whole subject of this post.
Vendors now ship two kinds of memory. Explicit or saved memories are discrete facts the assistant writes down, such as "prefers British spelling" or "works on the Acme account". Inferred memory draws on past chats at answer time, either by summarising them or by searching them.
Both kinds create a copy of user content that sits outside the conversation it came from. Your retention schedule, your legal hold and your deletion procedure were all written around conversations. Memory is the part they miss.
The vendor-wide view of how long conversation data is kept is covered in the ranking of AI vendor data retention policies. This post looks only at the memory layer, because it behaves differently enough to need its own rules.
AI memory controls compared across four vendors
The table below is built only from each vendor's own admin and privacy documentation, read on 9 October 2026. Where a document is silent, the cell says so rather than guessing.
| Question | ChatGPT Enterprise | Claude Team and Enterprise | Gemini for Workspace | Microsoft Copilot |
|---|---|---|---|---|
| Cross-chat memory on work accounts | Yes. Saved memories plus reference chat history | Yes. Topic entries, separate per project, plus past-chat search | No. Personal Intelligence is not offered on work accounts | Yes. Saved memories, chat-history details, custom instructions. In preview |
| Default state | Set by role in workspace settings | Off for each member until they turn it on | Not applicable | On by default |
| Admin can switch it off | Yes, by workspace role | Yes, organisation-wide | Not applicable | Yes, through Microsoft Graph |
| Admin switch-off deletes memory | Not stated | Yes, immediately and permanently | Not applicable | No for saved memories. Chat-history details deleted after 30 days |
| Deleting the source chat removes the memory | No. Delete both | No | Not applicable | No for saved memories |
| Admin access to memory content | Compliance API includes memories | Owners cannot view memories. Included in conversation exports | Not applicable | eDiscovery search, export and delete |
| Covered by org retention rules | Not stated for memory | Follows chat retention policy. Unavailable with custom retention | Conversation retention 3, 18 or 36 months | No. Purview retention does not apply |
| Stored in a chosen region | Saved memories in scope for data residency. Improved memory not supported | Not documented for the Claude app | Not documented for the Gemini app | Exchange mailbox, under existing Microsoft 365 commitments |
Sources: OpenAI Help Center, Anthropic support and privacy centres, Google Workspace Admin Help, Microsoft Learn. All read 9 October 2026. OpenAI pages were read through search-index extracts because the help centre refused direct automated access, which is the weakest sourcing in this table.
Read across the rows rather than down the columns. No two vendors give the same answer to the same question, which means a single "AI memory policy" cannot be a single sentence. It has to be a short table of its own, one row per tool you have approved.
Deleting the chat does not delete the memory
This is the finding that should change your deletion procedure. Three of the four vendors document that a saved memory survives the deletion of the conversation that produced it.
ChatGPT: delete the memory and the chat, separately
OpenAI's Memory FAQ tells users that removing remembered information means deleting the saved memory and also the chat where it was first shared. It adds that OpenAI may keep logs of deleted saved memories for up to 30 days for safety and debugging. Turning off reference chat history schedules remembered information for deletion within the same 30-day window.
The practical consequence is a two-step deletion. A user who deletes only the chat has left the fact in memory. A user who deletes only the memory has left it in the chat, where reference chat history can find it again.
Claude: memory entries outlive expired chats
Anthropic rebuilt Claude's memory on 10 July 2026, replacing a daily summary with individual topic entries. Under the old system, deleted conversations dropped out of the summary within 24 hours. Under the new one, Anthropic's support article states that memory entries generated from a deleted or expired conversation are not removed.
That reversal matters if your security team approved Claude memory in late 2025. The behaviour they reviewed no longer exists. A user must now delete individual topic entries, or reset memory entirely, to remove what a deleted chat taught the assistant.
Copilot: saved memories stay, inferred details fade
Microsoft separates the two memory types cleanly. Saved memories are retained until the user explicitly deletes them in Settings, and deleting a chat does not remove them. Details inferred from chat history behave better: once every chat mentioning a fact is deleted, traces of it are removed within 7 days.
So Copilot gives you a predictable clock for inferred memory and no clock at all for saved memory. That asymmetry is the right design in my view, and it is also the one most likely to surprise an employee.
What the admin off switch actually does to AI memory
Every vendor offering memory gives admins a way to turn it off. They do not mean the same thing by "off", and the difference decides whether switching off is a reversible pause or a destructive act.
Claude treats off as delete
Anthropic's documentation for Team and Enterprise owners is blunt. Turning memory off at organisation level deletes all existing memory entries for all users immediately and permanently. The change is logged, though individual member edits to their own memories are not.
This is the strongest privacy guarantee in the group and also the most dangerous button in it. An owner testing the setting on a Friday afternoon can erase months of context for every employee, with no undo. I would require a second approver before anyone touches it.
Copilot treats off as pause
Microsoft's Enhanced personalization control is on by default and is configured through Microsoft Graph. Turning it off stops Copilot applying saved memories and custom instructions, but Microsoft states it does not remove them. Only chat-history details are deleted, after 30 days.
So a Copilot admin who switches memory off to "clear" it has done no such thing for saved memories. They are still sitting in each user's mailbox, waiting for the control to be turned back on. Microsoft also states that admins cannot restrict what type of information is added to memory.
OpenAI's workspace settings let admins enable shared memory and improved memory per role, with improved memory switching on by default for eligible workspaces after early access unless an admin opts out. What switching off does to memories already saved is not stated in the material available for this post, so ask before you assume.
AI memory sits outside the retention policy you already set
Most organisations that deployed an assistant set a conversation retention period. Memory is where that period quietly stops applying.
Microsoft is the clearest case because it says so directly. Its Learn page states that retention policies and labels configured in Purview do not apply to Copilot memory, and that no admin control enforces retention specifically for memory. A three-month deletion rule on Copilot chats leaves memories untouched.
Microsoft's roadmap item RM569612 targeted September 2026 for Purview retention of Copilot memory, aimed at preserving historical versions of memory items for investigations. The Learn page, updated 2 September 2026, still describes the old behaviour. Treat the roadmap as intent until your tenant shows the setting.
Anthropic takes the opposite route. Memory follows your chat retention policy, but memory is not available at all to organisations with HIPAA, public-sector or custom data retention agreements. If you negotiated a custom retention window, you have already opted out of Claude memory, whether or not anyone noticed.
Google avoids the problem by not shipping memory on work accounts. Its Gemini app conversation history is kept for 3, 18 or 36 months, with 18 as the default, and only admins can change it. With history switched off, Google may still hold conversations for up to 72 hours to provide the service.
Where AI memory lives, and which region it sits in
Location answers two separate questions: which system holds memory, and in which country that system sits. The vendors answer the first far better than the second.
Microsoft gives the most concrete answer. Copilot memories sit in a hidden folder in each user's Exchange mailbox, so they inherit mailbox encryption and Customer Lockbox. Microsoft's privacy page states that Copilot is covered by the EU Data Boundary, though it also notes that models from Anthropic as a subprocessor are currently excluded from it.
OpenAI's data residency article lists ChatGPT memory among the features stored at rest in the selected region, for new workspaces. The same article says improved memory is not supported under data residency, while standard saved memories remain available. If residency is a hard requirement, the newer memory mode is the one you give up.
Anthropic's regional compliance page offers residency in Europe, the United States, Canada and Asia-Pacific, but every route it names runs through AWS Bedrock, Google Cloud Vertex or Microsoft Foundry. It does not describe residency for the Claude app itself, and it does not mention memory. Google's Workspace pages are similarly silent on where Gemini app data is stored.
The broader question of keeping AI workloads inside EU and Indian borders is worked through in the analysis of AI data residency for the EU and India. For memory specifically, the honest summary is that two vendors document it and two do not.
Where this comparison is weakest
This post compares documentation, not behaviour. Nobody here tested whether a deleted Copilot memory is gone in 7 days, or whether a Claude switch-off really clears every backup. Vendor documentation is a commitment you can hold a vendor to. It is not proof.
The OpenAI column rests on thinner sourcing
OpenAI's help centre refused automated access during research for this post. Its memory and data residency statements here come from search-index extracts of OpenAI's own pages, not from a page opened directly. The wording matches across several extracts, but treat that column as one tier below the others and check the live articles before relying on it.
The documents move faster than the policies
Anthropic replaced its memory architecture in July 2026 and flipped Team and Enterprise defaults in August. Microsoft labels memory a preview with a pending retention feature. A comparison like this one has a shelf life of months. That is an argument for a quarterly review, and also a fair argument against building a policy on any single row.
There is also a reasonable counter-view on the whole subject. Memory is user content that users can see and edit, and most of it is mundane: preferred formats, project names, writing tone. A security team could fairly decide that the risk is smaller than the friction of governing it. I disagree for regulated data, but for a 40-person agency writing marketing copy, that position is defensible.
An AI memory policy you can set this quarter
Your memory policy needs three decisions per approved tool: whether memory is on, who can delete it, and what happens when someone leaves. Each decision maps to a setting the vendor documents.
| Area | Weak version | Version that works |
|---|---|---|
| Deletion instruction to staff | "Delete the chat if you share something sensitive" | "Delete the saved memory, then the chat, then check memory again" |
| Admin switch | Any admin can toggle memory | Two-person approval for Claude switch-off, which is destructive |
| Retention | One period covering "AI data" | Separate rows for conversations and memory, per tool |
| Leavers | Account disabled | Memory exported or searched before the account is removed |
| Where the gap is conceded | Not addressed | Copilot saved memories have no admin retention control yet, and the policy says so |
Decide memory per data class, not per tool
Turn memory off for teams that handle regulated or client-confidential data, and leave it on where the content is low risk. Every vendor that ships memory supports some form of scoped control, whether by role, group or organisation. The way permissions travel through connected tools is covered in the comparison of Glean and Copilot permission handling.
Write the contract clause before the renewal
Ask each vendor to state in writing whether memory is covered by your retention commitment and your residency commitment. Put the answer into the data processing agreement, using the structure in the guide to AI clauses in a data processing agreement. If memory is excluded, that is fine, as long as it is excluded on paper.
Unmanaged personal accounts sit outside all of this, since none of these admin controls reach them. That exposure is measured in the analysis of AI use on personal accounts. Wider admin differences between the three main enterprise plans are compared in the review of ChatGPT, Claude and Gemini enterprise governance.
Frequently asked questions
Does deleting a ChatGPT chat delete its memory?
No. OpenAI's Memory FAQ says that to remove remembered information you must delete the saved memory and also the chat where you first shared it. OpenAI may keep logs of deleted saved memories for up to 30 days for safety and debugging. If reference chat history is switched off, remembered information is scheduled for deletion within 30 days, while the original chats stay unless deleted.
Can Claude Enterprise admins see what Claude remembers about users?
No. Anthropic states that owners cannot view or edit an individual user's memories. Memory entries are, however, included in standard conversation history exports and are retained under the organisation's chat retention policy. Owners can switch memory on or off for the whole organisation, and switching it off permanently deletes every member's memory entries immediately. Those owner switch actions are logged.
Does Gemini for Google Workspace have memory of past chats?
Not on work accounts. Google states that its Personal Intelligence features, including memory of past Gemini chats, are not available on Workspace Business, Enterprise or Education accounts. Workspace admins control conversation history instead, with retention options of 3, 18 or 36 months and a default of 18 months. If an organisation uses Google Vault for Gemini, Vault retention rules apply even after users delete conversations.
Where is Microsoft 365 Copilot memory stored?
Microsoft states that Copilot memories, including saved memories, details inferred from chat history and custom instructions, are stored in a hidden folder in the user's Exchange mailbox. They therefore follow mailbox security policies such as encryption at rest and Customer Lockbox. Admins can find saved and inferred memories with eDiscovery, though Purview retention policies do not currently apply to them.
Is AI memory covered by data residency commitments?
It depends on the vendor. OpenAI lists ChatGPT memory as in scope for data residency on new workspaces, but says improved memory is not supported there. Microsoft stores Copilot memory in the Exchange mailbox under existing Microsoft 365 commitments. Anthropic documents residency for Claude through cloud platforms only, and Google's Workspace pages do not address Gemini app storage location.
How do I make sure an AI assistant forgets sensitive information?
Delete in two places, not one. Remove the saved memory or memory entry first, then delete every chat where the information appeared, then check the memory list again. On Copilot, inferred details clear within 7 days of the last source chat being deleted. On Claude, deleting a chat does not remove memory entries, so delete the entry itself or reset memory.
Where to start
Open the admin console for each assistant you have approved and write down one thing: is memory on, and for whom. Most teams that do this find at least one tool where the answer is "on, by default, for everyone", which is Copilot's documented default.
Then change one sentence in your staff guidance. Replace "delete the chat" with "delete the memory, then the chat". It costs nothing, it is accurate for three of the four vendors, and it closes the most common gap this research found.
Related on governance
Memory is one layer of the retention question. The other layers are ranked in AI data retention policies, ranked by what they promise.
References
- Anthropic, Using Claude's chat search and memory to build on previous context, support article, read 9 October 2026. Used for memory architecture, owner controls, deletion behaviour and plan exclusions.
- Anthropic, Regional compliance, read 9 October 2026. Used for residency regions and cloud platform routes.
- Microsoft Learn, Copilot personalization and memory, updated 2 September 2026. Used for storage location, admin control, retention and eDiscovery.
- Microsoft Learn, Data, privacy and security for Microsoft Copilot, updated October 2026. Used for EU Data Boundary statements.
- Google Workspace Admin Help, Manage Gemini in Workspace conversation history settings, updated 7 October 2026. Used for deletion and auto-deletion controls.
- Google Workspace Admin Help, Generative AI in Google Workspace Privacy Hub, updated 6 October 2026. Used for Personal Intelligence availability and training statements.
- OpenAI Help Center, Memory FAQ, read through search-index extracts, October 2026. Used for deletion steps and 30-day windows.
- OpenAI Help Center, Data residency and inference residency for ChatGPT, read through search-index extracts, October 2026. Used for memory residency scope.
Weakest point in the source base: the OpenAI rows could not be checked against a directly opened page, and Microsoft's memory feature is labelled preview with a retention change on its roadmap. Re-verify every row before a renewal or audit.
Related reading