Claude memory crosses into Cowork — off by default for teams
Anthropic's Claude memory now carries from chat into cloud Cowork tasks. It's on by default for Free/Pro/Max and off for Team and Enterprise. Know which one you are.
Anthropic shipped Claude memory into Cowork today, and the interesting part is not the feature. It's the default. Memory is on out of the box for Free, Pro, and Max plans, and off by default for Team and Enterprise organizations, where only an Owner or Primary Owner can turn it on. Which means the personal account someone signed up with over lunch is already accumulating context about your business, and the paid org account your policy actually covers is not.
What actually happened
Per Anthropic's release notes dated August 25, the update is "Memory in Claude Cowork, editable topics, and a sensitive topics setting." What Claude picks up in a chat is now available when you hand it a task in Cowork running in the cloud, and what surfaces during that Cowork task carries back into chat. TechCrunch reports the system now writes topics to memory during a conversation rather than summarizing at the end, which is why the two surfaces stay in step.
The boundaries, from Anthropic's own documentation:
- Local Cowork sessions do not use memory. Cloud sessions do. Where the agent runs determines what it remembers.
- Sensitive topics are excluded by default — health, race, ethnicity, religious belief, politics, gender identity — with a new toggle to opt in.
- Some things are never stored at all: government ID numbers, financial account numbers, criminal history, immigration status. Claude tells you when it refuses to save something.
- Users read, edit, and delete their own memory under Settings > Memory. Admins cannot read individual users' memories — but memory data does land in organizational exports.
Why shared agent memory matters for your business
Your handoff just became a data flow. Research in chat, execution in Cowork used to be two separate contexts with a copy-paste between them. That copy-paste was a control point, and it's gone. Whatever your team pastes into a chat window — a client's margin structure, an unsigned quote, a vendor's rate card — is now standing context for an agent that takes actions.
"Off by default" is not the same as "handled." Team and Enterprise owners get to decide, which is the right design. It also means the decision is now sitting in somebody's queue unmade, while the shadow-IT personal accounts already defaulted to yes. Find out which accounts your people actually use before you write the policy.
Admins can't read it, but exports can. That asymmetry is worth understanding before an employee leaves, before a discovery request, before a client asks what your tooling retains about their account. Memory you cannot inspect day to day but can produce in bulk is a records-retention question, not a feature question.
Key takeaways
- Claude memory now carries between chat and cloud Cowork tasks in both directions
- On by default for Free, Pro, and Max; off by default for Team and Enterprise, where an Owner must enable it
- Cowork sessions running locally on a machine do not use memory — cloud sessions do
- Sensitive categories are excluded by default; IDs, financial account numbers, criminal history, and immigration status are never stored
- Admins can't read individual memories, but memory data appears in organizational exports
An agent that remembers is an agent with a retention policy — whether or not you wrote one. We map what your AI tooling stores, where it runs, and who can pull it back out, then wire the controls to match. See how we build agent systems, or tell us which accounts your team actually logs into.
Sources: Anthropic release notes, Anthropic Help Center, TechCrunch.
- #anthropic
- #claude-cowork
- #ai-agents
- #governance
- #data-privacy
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Thomson Reuters built its own model for $40M — data is the asset
Thomson Reuters trained a proprietary LLM on Westlaw and Reuters content for $40M and owns it outright. The lesson for operators isn't build-your-own — it's what you own.
Read itPerplexity Portable Computer: a local agent at zero token cost
Perplexity's Portable Computer runs its agent entirely on your own RTX GPU or DGX Spark — no billing credits per token, but a 24GB VRAM floor and a paid tier gate.
Read it