Blog
Provenance-aware memory for AI agents. What we measured, what it cost, and what we still do not know.
-
What happens after you find the bad source?
September 2026
Finding the poisoned source is the easy half. What a memory system does next decides whether provenance was a control or a label, because the bad claim did not stay where it landed.
-
Where does your memory system consult provenance?
August 2026
Every agent-memory system records where a fact came from. A paper measured what happens when that record is used as a retrieval weight: statistically indistinguishable from no defense. The seam it is consulted at decides whether it is a control.
-
Once a claim becomes a row, it reads as fact
August 2026
We built five agent-memory architectures that record where every fact came from and enforce nothing. In the four the instrument scores cleanly, a trusted speaker's restatement turned an untrusted claim into fact in 55–90% of probes.
-
Who's allowed to change your agent's memory?
August 2026
Agent memory systems now retire outdated facts. Almost none check who is allowed to, so an unverified email can overwrite what your user actually said.
-
Your agent's memory is an injection vector
July 2026
A scam email your agent reads becomes a fact it asserts. How naive agent memory gets poisoned, confabulates, and loses history, and how provenance-aware memory fixes all three.