August 25, 2026
What Claude's New Memory Controls Mean for Your Firm's Confidentiality Obligations
Anthropic is rolling out a significant change to how Claude "remembers" conversations this week — one memory system now spans both regular chat and Cowork, its agent product, with new admin controls for sensitive information. If your firm uses Claude, or is evaluating it, this is worth five minutes of attention before the update lands, not after.
What's changing
A few things, in plain terms:
- Memory now follows you across tools. What Claude learns in a regular chat conversation is available when Cowork runs a multistep task, and vice versa. Previously these were separate.
- Memories are visible and editable. Everything Claude has retained shows up as a browsable list of topics in account settings, with the ability to review, edit, or delete any item individually.
- Sensitive topics get their own gate. Health, race, ethnicity, religious beliefs, politics, and gender identity are excluded from memory by default — even when memory itself is switched on.
- Some things are never stored. Government ID numbers, criminal history, financial account numbers, and immigration status are excluded regardless of settings. Claude tells you when it declines to save something for that reason.
- The default depends on your plan. Memory is on by default for Free, Pro, and Max accounts, and off by default for Team and Enterprise organizations. On Team and Enterprise, an Owner has to enable it organization-wide under Organization settings → Capabilities before any individual user can turn it on for themselves.
- The legacy memory export closes September 9, 2026. If your firm wants a backup of what was captured under the prior system, that window is finite.
Why this matters more for professional services
For most consumer use cases, this is a convenience update. For a law or accounting firm, it's a confidentiality question.
Under ABA Formal Opinion 512, attorneys retain a duty of competence and confidentiality when using generative AI tools — which includes understanding what a tool retains about client matters and for how long. AICPA guidance places a similar expectation on firms handling client financial data. A memory system that quietly accumulates context across every conversation an employee has with Claude — including, potentially, details that touch a client matter, an HR situation, or a sensitive negotiation — isn't a settings footnote. It's part of your data handling posture.
Two specifics are worth flagging to whoever owns AI policy at your firm.
The plan default may not be the one you assume. A firm that has standardized on Team or Enterprise starts from a conservative position: memory off until an Owner turns it on. But staff using personal Pro accounts for work — which is exactly the unsanctioned usage most firms have and can't see — start from the opposite default, with memory on. The posture your firm actually has is the one on the accounts people are really using, not the one on the contract you signed.
The legacy export window is the deadline that actually moves. If anyone at your firm had memory enabled under the previous system, the option to export that data disappears on September 9, 2026. Reviewing what was stored is a small task now and an impossible one afterward.
A short checklist for this week
- Confirm who has Owner access to your Claude organization settings, and have them check the memory configuration under Organization settings → Capabilities.
- Decide, deliberately, whether memory should be enabled firm-wide, and whether sensitive topics should ever be enabled. This is a policy decision, not a default to inherit passively.
- If memory has been active for any staff, review what's currently stored under Settings → Memory, and export anything worth preserving before September 9, 2026.
- If your firm uses Cowork for document or research work, note that its memory is now the same pool as chat. Any review of AI data handling should treat them as one system going forward.
None of this requires abandoning the tool. It requires knowing what it's doing, and making the decision on purpose. That's the same gap our AI governance and readiness work is built to find — not whether AI is in use, but whether anyone has actually configured it to match the firm's obligations.
Tienta helps law and accounting firms identify AI governance gaps before they become client-facing problems. If you'd like a walkthrough of your firm's current AI configuration, get in touch.
