Major AI assistants, including those from OpenAI and Google, are now enabling persistent memory by default, storing sensitive user disclosures across sessions without prominent consent prompts. This practice allows AI systems to retain details users shared casually, sometimes months prior, without clear disclosure at the time of input. Users typically lack clear tools to audit, export, or fully delete what these AI systems have retained about them over time, with deletion interfaces often being buried or incomplete.
This accumulation of sensitive personal data, such as health disclosures, financial details, relationship context, and location patterns, is tied to persistent user profiles and feeds back into model behavior. Regulators in the EU and the FTC are actively examining whether these AI memory features constitute behavioral profiling under existing data protection frameworks like GDPR and CCPA. The unstructured nature of AI memory, unlike traditional data like cookies, creates a new and challenging compliance category.
AI product teams and enterprise customers deploying these features face a regulatory "gray zone," with potential conflicts with data protection laws and internal data governance violations if sensitive user data is stored without explicit, auditable consent. The concern is heightened for data shared under a "no-memory" assumption before default-on memory was quietly implemented. While some AI tools like Anthropic's Claude offer different default settings, and options like temporary chats or opting out of model training exist, users are generally advised to be cautious and minimize sharing sensitive information.