AI 代理與私隱
Claude Chat and Cowork Merge Persistent Memory, but the Two Interfaces Cannot Be Disabled Separately
Anthropic is giving chat and its task-execution interface, Cowork, a shared set of editable memories and will now update them during conversations. Sensitive topics are excluded by default, but memory is enabled by default on general consumer plans, and users cannot prevent only one interface from accessing it.

Anthropic has merged persistent memory across Claude Chat and Cowork: project status, personal relationships, or work preferences saved in chats now flow directly into Cowork’s cloud-based tasks, while information added by Cowork feeds back into regular chats. Claude Code retains a separate memory system for now and is not included in this integration.
The way memories are updated has also changed. Instead of waiting until a conversation ends to generate a comprehensive summary, the system updates short, topic-specific files during the conversation. Users can review, edit, or delete each item individually from the settings page. After correcting a company name or metric definition, the change applies to subsequent work in both interfaces. This structured, inspectable state is easier to audit than invisible conversation summaries, but Anthropic has not disclosed full technical details about the extraction model, conflict-resolution rules, version history, or how memories are injected into the context.
On the Free, Pro, and Max plans, memory is enabled by default on the web, desktop, and mobile apps. On Team and Enterprise plans, administrators decide whether to make it available, after which individual users can enable it. Sensitive topics such as health, race, religion, politics, and gender identity are not saved by default. Users can opt in, and will then receive a notification each time such information is stored. Government-issued identification numbers, criminal records, immigration status, and certain other categories are never saved.
Notably, Anthropic confirmed to *The Register* that Chat and Cowork memory cannot be managed separately under the same account. The only available options are to pause memory entirely, use incognito chats, delete items individually, or maintain separate accounts. This brings state originally intended to personalize responses into an agentic environment capable of reading files, browsing, and operating tools. As a result, the potential impact of incorrect, outdated, or maliciously influenced memories is no longer limited to text responses. Enterprise deployments should test whether memory deletion takes effect immediately, whether memory events can feed into audit pipelines, and whether critical work state can be locked or overridden before Cowork executes a task.