A new arXiv paper studies memorization in foundation-model agents as a deployment-time issue, not only a property of model weights. Long-lived agents increasingly remember users across interactions, which creates new privacy and utility tradeoffs.
The authors model this as a frontier between personalization recall and adversarial extraction risk, while testing how memory summaries, retrieval breadth, and deletion choices shape behavior.
That framing is useful because agent memory is becoming a product feature. The paper suggests teams need to evaluate how memory is stored, retrieved, and deleted, not just whether the base model memorized training data.