A new paper lays out how to stop your AI assistant from repeating what your coworker told it in private to your spouse.
Researchers built a system that tags every memory an AI agent stores with the audience present when it was recorded, then tracks that tag through anything derived from it, including summaries and inferences. An item only surfaces in a conversation if everyone currently present is authorized to see it; if the system cannot verify who someone is, it defaults to showing only public information. The team tested this audience-bound approach on two independent memory architectures, a flat data store and a relationship graph, plus a prototype agent runtime, running 10,000 simulated multi-party conversation histories. Zero forbidden items leaked through in any of the three setups.
Personal AI agents are increasingly built to remember everything across every conversation you have with them, including work calls, family group chats, even a therapist appointment. Without deliberate audience-tracking, plain unscoped retrieval leaked private information into the wrong context in 82% of the same test scenarios, and the fix did not cost usefulness: entitled recall actually beat unscoped retrieval on relevance to the current conversation.
This is a lab benchmark, not a shipped feature, and it says nothing about whether the assistants people use today handle audiences this carefully. Worth remembering next time you tell yours something you would not want repeated.