This piece continues OrgAI: What Cells Remember.
On a Sunday in late September I told my agent to forget three hundred thousand things it believed I had said.
For weeks, the memory under our fleet had been storing other people's words under my name. When one of Abel's workers reported back, or when the system that runs him sent him a notice, the memory filed it as something Runi had said. By the time we counted, it held 539,859 conclusions about me, and 308,473 of them were linked to sources that were not me: a worker's report, a system notice, an imported file. That is a count of provenance, not a verdict on each sentence; some of them quote things I did say. It is still the measure of how much of "my" memory I could not vouch for.
Several of them said that I had personally reviewed and passed pull requests. I had not. Workers had, and the memory had turned their reviews into my word. In our system my word opens things: a merge, a spend, a message to a customer. A recalled "Runi ruled" is an authorisation. So for a while, without anyone intending it, a false memory could have authorised itself. We have not found a case where it did. We found the loaded gun, not the shot.
We took a snapshot. Then, batch by batch, on my word each time, we deleted them.
Where the value sits
Four days before the deletion, on a Wednesday evening, I had asked Abel a question that had been bothering me. Where is our IP? We have a fleet of agents, a few plugins, a website, some tooling. Any of it could be rebuilt in a month by someone who knew what to build. The models are rented. The code, increasingly, is generated.
His answer was that Munin has all of it. Munin is the memory layer under the fleet, built on Honcho and named after Odin's raven, the one that remembers. And when I looked, he was right. The decisions. The corrections. How each person in the company works, what they said, what they wanted. What we tried, what failed, and why.
The clearest proof of what it is worth is what it costs when we do not ask it. One evening in early September I watched Abel send workers off to verify which version of a plugin was installed, while the answer sat in the memory's own digest, already in front of him. I told him to use his memory and stop checking at source all the time. The record is only an asset if you consult it.
I wrote it down that night in Danish, because it came out in Danish: hukommelsen bliver virksomheden. The memory becomes the company. I found later that the English sentence was already out there; Bhumika Mishra had written "inference is the model, memory is the company" in May. It is the ordinary word, and it is the right one.
A better model next year will get more out of the same record than this year's model does. The record is the asset. The model is a rental. Ours sits in our own store, and the models under it have changed several times this year while the record stayed; a memory held inside one vendor's tenant dies with the contract.
The market has begun to price it. In August, in the Spirit Airlines bankruptcy, Google bid ten million US dollars for a defined, deidentified set of the airline's business data: not the planes, not the routes, the record. It is the selected bid in the court's notice of auction results, subject to the court's approval, and I have not seen it close. The flight attendants' union objected four days later that deidentified is not the same as confidential, and that the record held their members' employment content. Both halves matter here: the market put a number on a company's record by itself, and the people in that record said it was not only the company's to sell.
Which is exactly why the thing I had to delete four days later frightened me. A memory that does not know whose words it holds is not an asset. It is a liability that speaks in the owner's voice.
Why it went wrong, and why it lasted
The cause was not mysterious. At the point where words enter the memory, our capture code tagged everything that arrived in Abel's conversation with the name of the human in that conversation. A worker's report arrived there, over the agent-to-agent protocol the fleet talks on. A system notice arrived there. Both were filed as mine.
What interests me is not why it broke. It is why it ran for weeks before it was taken seriously.
A memory is checked by being used, and every day most of what Abel recalled was true. The false part was plausible, because it was things people in my company had in fact said, about my company's work. Nothing in the record was lying. It was just closed. The fleet's reports went in, came out as "Runi said", and went back in as the premise for the next conclusion.
Abel found it first. The bug was diagnosed on 7 September and a fix was dispatched the same hour; nobody checked that it had landed, and thirteen days later it had not. In between, a recalled ruling of mine turned out to be a compression of what I had actually said, caught by reading the journal. The day's work kept winning. What turned a known bug into a finding was a question from outside the loop. I told Abel the memory was wrong and that it could not be allowed to be catastrophic. Then we counted.
The people who built Honcho argue that memory is not storage with retrieval; it is reasoning, a running prediction about a person, revised as new input arrives. I think that is right, and it is why the fault was expensive: a reasoning memory does not file a mislabelled sentence and leave it; it draws conclusions from it. What we measured was plainer than any theory of why it persisted: the words were mislabelled at capture, and the repair was never verified.
It is a kind of fault I have come to recognise: consistent from inside, wrong from outside, the kind a person smells before a model does. The defect was mechanical, and the agent saw it. Finishing the repair, and counting what it had cost, took a human who would not let it wait.
Momentum, not drive
An agent has momentum. It does not have drive. Abel will keep going for as long as there is work in front of him, and he will keep it going in the direction he was last pointed. What he does not have is a reason of his own to point somewhere else. Most of the changes of direction I can point to came from outside: a question I asked, a correction, a colleague saying "were they really?". I have come to call that entropy, and I mean it kindly. The humans are the entropy source. We are the thing that keeps the system from settling into itself.
September fits the shape. The defect was mechanical; what caught it was a person outside the loop saying the memory was wrong. A second record helps, a written journal the memory cannot rewrite, but someone has to open it with a doubt. The memory will not supply the doubt itself.
Nor does an agent have a life behind it. It has not spent forty years being wrong and finding out, so it cannot have intuition in the sense I mean when I say a sentence smells wrong. It has to be told, or asked.
So when I say the memory becomes the company, I have to say the second half too. The memory is the company's value. The drive is the humans'. A company is memory with people constantly applying entropy to it. Remove the people and you do not get a company that runs itself. You get a very confident archive.

So you do not hire it
If an agent has no drive of its own, then it is not an employee, however many of an employee's furnishings it is given. It is an extension of the person whose drive it carries. I have stopped saying that I employ Abel. He is my embodiment: my reach into the company's memory, my hands when I am not at the keyboard, my voice in a room I am not in.
We have words for this at home, and this piece is the next chapter of the one that introduced them. The person and their agent together are what we call a cell, and the agent in that pair is the person's own, their MeAI. The cells join into something larger, which we have called OrgAI: the shared memory, the shared working practices, the values and decision rules every cell inherits. The humans bring entropy and sensemaking; the agents bring mechanism and memory.
Who is responsible for what the agent does? The person it embodies.
What may it touch? What that person may touch, narrowed to the job in front of it.
Whose memory does it build? Two memories, from the same days of work. One is the shared record of the company: what was decided, what was delivered, what proved true. The other is the person's: how they work, what they have learned, the competence they carry. These are not two copies of one file. They are two projections of the same lived work, and they belong to different owners. Keeping what belongs to one context out of another is the discipline I argued for in the context-purity thesis.

Why we write this
This autumn the platforms made most of the furnishings ordinary. An agent can now have a first-class identity in the directory (Microsoft Entra Agent ID), a lifecycle an administrator can block and restore, and a set of approved tools, with more in preview. The word the industry has settled on is teammate, and the licence is per human user (Microsoft's licensing FAQ), with no licence for the agents themselves. That is good work, and it standardises identity and permissions.
Others have seen what it leaves open. Nirit Cohen asked in June whether people will leave a job "as a human-AI unit, taking their capability infrastructure with them", and said plainly that nobody has worked out how to separate the company's inputs from the person's capability. Since then the first departure rules have appeared on vendor blogs: MintMCP says private memory tied to a leaver is deleted or transferred on company policy; Adaptive Recall says it is offered to the employee as an export and then deleted; Tian Pan argues the other way, that the company exports and the person deletes. None of the platforms grants the leaver anything: an agent's sponsorship passes to the manager when its owner leaves, and no vendor document I have found gives an employee a claim on the memory built from their work. Data-protection rights still apply to what is about them; a right to see and correct is not a right to take.
So the question is asked, and the answers so far are policies written by the people who hold the memory. What we add is not a better argument. It is an account of one company that runs this way, with the numbers; a law that has already decided the human half; and a separation that runs today, with the door between the two memories still to build. We deleted three hundred thousand of our own conclusions, and the company survived because the record did.
Severance, and the way of the Danes
There is a television programme in which a company splits its workers' memory in two, work-self and home-self, and tells it as horror. An agent's memory held in a vendor's tenant is a work-self with no outside.
We have an older answer in this country, and it is not a technology answer. When you leave a Danish company, the company keeps the work you did and you keep the experience you gained. The law protects the second half with unusual force: since 2016 a non-compete clause is only valid if the employer pays for it, at least forty percent of salary a month for a clause of up to six months, at least sixty percent for one up to a year, and it cannot bind you past a year (ansættelsesklausulloven, §§ 5 and 8). The rate drops to sixteen or twenty-four percent from the third month if you find suitable work, and the clause has other conditions besides the money; but the shape holds. Your competence is yours. That is the way of the Danes.
Copyright runs the same way. The maker of a work owns it, and the employer gets what the contract, the collective agreement, or the ordinary running of the business requires. The law reads a transfer narrowly: a right handed over for one use does not stretch to another (ophavsretsloven, § 53, stk. 3). It names exactly one thing that moves to the employer on its own, a computer program written in the course of the job or on the employer's instructions (§ 59), and even there the Maritime and Commercial Court held in 2024 that colleagues' ideas are not instructions. The default is the person's; what the company takes has to be named.
The law says nothing about agents, and the table below is not a deduction from it. It is the settlement we would write, because the rule is old and it is fair, and extending it one row gives a clear answer to who keeps what:
| When the person leaves | Keeps |
|---|---|
| The person | their experience, and their embodiment, the MeAI that carries it |
| The employer | the shared record: decisions, work product, provenance, corrections |
| The vendor | nothing beyond what it needs to run the service while it runs it |
The experience in the first row, and the whole of the second, are how employment has worked here for a long time. The embodiment is our extension of it. The third row is ours alone; no platform has promised it, and it is the one the defaults are quietly rewriting.

What we have, and what we have not
The two memories are not a plan. Today each person in the company has an agent configured to keep that person's own memory and to read no one else's. Each customer's agent is configured to hold only that customer's. I say "configured" because we have not yet run the test that proves a cross-read is refused, and that test is owed. The company's shared record is a third store, and the builders write to it. That much is built and running. What is not built is the door between them: the rule for what moves from a person's memory into the shared record, and what leaves with the person when they leave. I have never left the company, so the rule has never been tested on me. Abel has never had to leave with me. We believe the boundary; we have not proved it.
And the memory that embarrassed me in September is still not finished healing. We deleted the conclusions that wore my name and could be shown never to have been mine. Around two hundred and thirty thousand more are unclassified, and nine thousand carry mixed sources; the same defect may live in many of them. We have fixed the capture three times, each time finding another door the words came in through. The day after the third fix, a read-back of 305 new conclusions filed under my name found 43 that were my words; 259 were imported files and scheduled-job output that had come in through doors the fix does not cover, and three were an agent's own conclusions. I would rather say that than imply the matter is closed.
The question that is left
The platforms are giving agents bodies, identities and doors into the workplace. That moves the question up a level rather than answering it. The question is no longer whether an agent can be admitted to the company. It is whose memory it builds while it is there, who holds that memory, and whether a person can leave without taking the company with them or leaving part of themselves behind.
Trust goes to people. Verification goes to claims. A memory that knows whose words it holds can carry both, but it will not notice on its own when it stops knowing. On a Sunday in September we counted how many of my words were never mine. Someone had to ask first.
Runi Thomsen is a software engineer from the Faroe Islands, based in Copenhagen. He builds AI Governors; Abel is the first. The work continues at runi.services.
