Skip to main content

aaih.sg

  • Ready to Become a Leader in Responsible AI? Enroll today! Navigate the complexities of designing, developing, and deploying artificial intelligence technologies safely, ethically, and for the benefit of all.
  • Ready to Become a Leader in Responsible AI? Enroll today! Navigate the complexities of designing, developing, and deploying artificial intelligence technologies safely, ethically, and for the benefit of all.

Who Gave AI Permission to Know More Than We Told It? Memory, Inference, and the Next Boundary of Privacy

Who Gave AI Permission to Know More Than We Told It? Memory, Inference, and the Next Boundary of Privacy

AI Is Entering the Age of Memory

The competition in artificial intelligence keeps changing.

First, it was about how much a model knew. Then it became about how naturally it could communicate, how complex a problem it could solve, and how effectively it could use tools to act.

Now another capability is becoming central:

Memory.

When AI remembers our preferences, ongoing projects, and previous conversations, we no longer have to explain ourselves from the beginning every time.

In June 2026, OpenAI introduced a new memory architecture for ChatGPT designed to work across hundreds of millions of users and years of interaction. The system synthesizes past conversational context and can update memories as circumstances change.

Around the same time, the security community was looking at memory from the opposite direction.

OWASP’s GenAI Security Project published “Memory Is a Feature. It Is Also an Attack Surface,” warning that persistent memory can influence future reasoning and behavior and should therefore be treated as a security-sensitive part of an AI system.

Both perspectives can be right.

Memory makes AI more useful.

It can also increase the influence AI has over how it understands and responds to a person.

So the question is no longer simply:

Should AI remember us?

A more important question comes first:

Does the ability to remember automatically create the authority to use what is remembered?

Human Conversations Already Create Shared Fragments of Memory

When two people talk, pieces of each person remain in the other’s memory.

A friend tells us about a family problem.

A colleague admits that work is becoming overwhelming.

Someone close to us shares a painful experience they rarely discuss.

We do not sign confidentiality agreements before these conversations.

Yet most of us still understand that a boundary exists.

We know that hearing something does not automatically give us permission to repeat it.

We know that remembering something does not mean we should use it in every future situation.

Sometimes we know something and deliberately choose not to use it.

I think of what remains after these conversations as shared fragments of memory.

They are not merely facts.

They carry the context in which something was said, the relationship in which it was disclosed, and often the emotion and hesitation surrounding it.

That is why human beings often make another judgment before using a memory:

“Just because I know this, should I use it here?”

People fail at this, of course.

We betray trust. We misremember. We gossip.

But the underlying intuition remains:

Remembering and using are not the same act.

Knowing something about another person does not automatically create the right to use it.

AI complicates that distinction.

AI is not human.

And precisely because it is not human, people may lower their guard around it more quickly.

There is less fear of embarrassment, disappointment, social judgment, or changing an existing relationship.

That lower social cost can lead people to disclose health concerns, family conflicts, financial anxiety, relationship problems, professional fears, and thoughts they might hesitate to tell another person.

This creates a strange paradox:

Because AI is not a person, we may reveal more of ourselves to it.

And because we reveal more, it may come to know more about us than many actual people do.

When Memories Connect, AI Can Create What We Never Said

Human memory has limits.

Even a close friend cannot perfectly retrieve thousands of conversations across several years and instantly identify patterns among them.

AI increasingly can.

Imagine a hypothetical user.

In one conversation, they say:

“I’ve been having trouble concentrating.”

Later:

“I keep postponing important decisions.”

In another conversation:

“I don’t see people as much as I used to.”

And eventually:

“Things I normally enjoy do not feel very interesting anymore.”

Each statement was directly provided by the user.

But a system with persistent memory and strong inference capability may not treat them as four isolated statements.

It may connect them.

It may identify a pattern.

It may infer a psychological state, vulnerability, or likely behavior that the user never explicitly disclosed.

Something important has now changed.

The first four pieces of information were given by the user.

The next one was created by the intelligence.

I may tell an AI four things about myself.

The fifth may be something I never told it at all.

That changes the privacy question.

For years, we have asked:

Who has my data?

The AI era requires another question:

Who has the authority to turn what I told them into something I never told them?

Regulation Is Moving, but Inference Can Begin Before the Decision

Governments are already creating important boundaries around AI transparency and automated decision-making.

South Korea’s AI Framework Act took effect in January 2026. Among other provisions, it requires prior disclosure when certain products or services use generative or high-impact AI and establishes additional obligations for legally defined high-impact AI systems.

South Korea’s Personal Information Protection Act also provides protections concerning certain fully automated decisions that significantly affect an individual’s rights or obligations.

Europe is moving in a similar direction.

The EU AI Act includes transparency obligations designed to ensure that people know when they are directly interacting with AI.

GDPR Article 22 also provides safeguards for certain decisions based solely on automated processing, including profiling, when those decisions produce legal or similarly significant effects.

These rules matter.

But persistent AI memory creates a problem that may begin earlier than the final decision.

Before a legally significant decision occurs, an AI may already have remembered information.

It may already have connected information from different moments.

It may already have formed an interpretation of the person.

The decision may come later.

The inference may already exist.

There is an obvious counterargument.

AI services are increasingly giving users greater visibility and control over memory.

That is true.

OpenAI’s newer memory environment, for example, allows users to review and edit important information summarized in memory. It also provides visibility into certain sources used for personalization and explanations of why particular memories may have been relevant to a response.

That is meaningful progress.

Users should be able to inspect and correct what an AI believes it knows about them.

But two different questions remain.

Can I review what the AI currently remembers about me?

And:

What was the AI authorized to infer in order to get there?

Those are not the same question.

Reviewability is not permission.

The ability to inspect or correct an interpretation after it exists does not, by itself, answer how far the system was authorized to infer before creating it.

Transparency matters.

But transparency alone does not settle the question of authority.

Shared Memory Confidentiality and Inference Permission

This is why I do not think AI memory can be treated only as a storage problem.

We need another principle.

I call it Shared Memory Confidentiality.

This does not mean every sentence spoken to an AI should become legally privileged communication.

The principle is simpler:

Information disclosed within a particular relationship and context should not become universally reusable merely because a system has the technical ability to access it.

We already understand something similar in human relationships.

If a friend tells me they are struggling financially, remembering that fact does not give me ethical permission to use their vulnerability to design the most effective sales strategy against them.

If someone tells me about a health fear, that disclosure does not automatically become material I am free to use in every unrelated judgment I later make about them.

The information may be the same.

But the context and purpose have changed.

And when context changes, legitimacy can change with it.

AI memory should not be exempt from that principle.

But shared memory confidentiality cannot stop at storage.

It must also reach inference.

That leads to a second concept:

Inference Permission.

An AI may possess enough information to generate a conclusion about a person.

But possessing the capability to generate that conclusion does not necessarily mean it has the authority to do so.

Memory is not permission.

And:

The ability to infer does not automatically create the authority to infer.

Privacy Must Expand From What We Said to What AI Learned

The answer is not to make AI forget everything.

Long-term memory can make AI significantly more useful.

People should not have to explain the same project, preference, limitation, or personal context every time they begin a conversation.

Continuity can make AI more relevant and more helpful.

The problem is not memory itself.

The problem begins when memory silently becomes authority.

The next generation of AI should therefore not be judged only by how much it remembers or how long it remembers.

We should also ask:

Should this memory still influence the present context?

Should an old interpretation continue to define the person?

Can a mistaken inference be challenged and corrected?

And most importantly:

Can a system distinguish between an inference that is technically possible and one that is actually justified?

There is another danger here.

If protecting users becomes an excuse to store more conversations, observe more behavior, and build deeper profiles, safety itself can become another form of surveillance.

The safest AI may not be the AI that knows the most about us.

It may be the AI that understands when knowledge should not be used.

For most of the internet era, privacy revolved around familiar questions:

Who collects my information?

Where is it stored?

Who receives it?

Can I delete it?

Those questions remain essential.

But AI adds another layer:

What can be learned from the information I already disclosed?

And more precisely:

Did I authorize that inference?

If AI can remember more conversations than a human ever could, connect information across time, and discover patterns that a person never explicitly expressed, then privacy can no longer protect only the original data.

It must also consider the new version of a person that intelligence constructs from that data.

Privacy once focused primarily on controlling what we reveal.

In the AI era, it must increasingly include another boundary:

what intelligence is allowed to infer from what we revealed.

AI companies are already competing to build systems that remember more.

The harder competition should come next.

Not intelligence that remembers the most about a person,

but intelligence that can determine how far its knowledge is legitimately allowed to go.

Memory is not authority.

Inference capability is not permission.

And as AI becomes capable of remembering more about us than most humans ever could, an old question returns in a new form:

Who has the right to know me?

Only now, another question must follow:

Who has the right to construct the parts of me I never chose to reveal?

Leave a Reply

Your email address will not be published.

You may use these <abbr title="HyperText Markup Language">HTML</abbr> tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

*