Own Your Operating Memory

The model knows the manual. It doesn’t know yours.

new economics
AI
strategy
knowledge
What operating memory is, and why your firm — not the model vendor — must own it.
Published

July 22, 2026

Disclosure: I build IndustryVault, whose architecture reflects the ownership model argued for here.

A capable new employee becomes useful by learning how this company actually works: which systems are authoritative, what words mean here, which exceptions matter, who can approve what, and how past mistakes changed the rules. AI Agents Are the New Employees showed why an agent faces the same onboarding gap — and why a fragmented workplace makes the firm pay to close it task by task. A frontier model may cover much of the industry’s public corpus; it still does not know the operation.1

Operating memory closes that gap. It is the governed, firm-specific state and codified judgment people and agents need to act correctly — current facts, rules, exceptions, workflows, examples, approvals, history, evals, and provenance, held in systems rather than only in heads. The front door described in the previous essay is the governed access surface; operating memory is the authoritative, portable material behind it.

Deploying agents both consumes this memory and creates more of it. Every correction, approved example, exception, eval, and workflow decision can make the next run better. Where those artifacts land determines whether the firm’s knowledge compounds under its control or becomes part of a supplier dependency.

AI’s New Economics ends in a three-part defense it calls sovereignty: own your operating memory, make models contestable, keep your customer. This essay defines the first part — what operating memory contains, why the frontier model cannot supply it, and what owning it takes. The strategic question is not “how smart is the model?” It is one an executive can act on: who controls the operating memory the model runs on — and the new memory that using it creates?

The answer has an operational test. The firm needs durable rights and practical control over the authoritative sources, usable exports, the means to rebuild derived stores, and a tested ability to appoint a successor. Owning the memory does not require running every server. It requires ensuring that no supplier is indispensable to recovering and using what the firm knows.

What operating memory is

Operating memory is the task-relevant subset of institutional knowledge that people and agents can actually run on: live state, rules, examples, approvals, provenance, and the firm’s own tests for what counts as a correct answer.

The nearest pre-AI artifact is the franchise manual. It packages procedures, training, supplier terms, and standards so that an operation can be reproduced without its veterans in the room. Operating memory is that idea extended to live state, recorded decisions, and machine-usable context.

The components are familiar — systems of record, knowledge management, workflow state, decision logs, provenance, and evals. The term names the governed combination people and agents need to carry the firm’s way of operating from one task, worker, or supplier to the next.

Three kinds of knowledge matter to the argument.

Public knowledge includes laws, manuals, standards, documentation, and the industry literature. Frontier systems can search and synthesize this material at a breadth few firms can match, especially when backed by a licensed, current retrieval corpus. But breadth is not authority: coverage may be uneven, versions may be stale, and interpretation still needs accountable review.

Operating memory turns that generic knowledge into correct action. A model may know the manual; it cannot reliably know which customer contract applies, which exception was approved, which record is current, or who has authority to decide unless the firm supplies governed context. The base model may contain fragments of firm-related information, but it is not an authorized, current, or authoritative source for the operation.

Tacit knowledge remains in people: know-how, taste, relationships, pattern recognition — knowing when the formal rule is incomplete or a technically valid result is operationally wrong. Parts of it can be elicited and recorded, at a cost. Once governed and made reusable, those parts become operating memory. What cannot be articulated or reliably reproduced remains tacit, and retains its scarcity.

These categories are a working distinction, not a clean legal partition. A firm may process customer records, license investor guidance, or rely on confidential partner information that it does not “own” as property. Ownership here means having the rights, continuity, and practical control required to use the authoritative material, govern it, and carry it to a successor.

Mortgage servicing as the high-stakes example

Return to the loan domain from the previous essay, now at higher stakes. There the question was how much navigation an agent must repeat; here it is what knowledge the firm, rather than the model provider, must supply and control. Take a mid-sized mortgage servicer: what does a frontier model bring, and what must the firm provide?

Public knowledge

The public layer includes the Fannie Mae and Freddie Mac servicing guides, the Ginnie Mae MBS Guide, Reg X and Reg Z, CFPB servicing rules, state foreclosure statutes, MISMO standards, rating-agency criteria, agency announcements, consent orders, and the broader industry literature.

A frontier system with current retrieval can accelerate search and synthesis across more of this corpus than any individual employee is likely to know. That does not make it the source of truth. Applicability, currentness, citations, and legal interpretation still require governed sources and accountable review.

Operating memory

The firm’s operating memory spans its servicing-platform configuration, investor-specific overlays, loss-mitigation decision trees tuned to its portfolio, call-center scripts, approved exception procedures, vendor arrangements, cost structures, QA findings, control evidence, regulator-exam history, borrower histories, and the business rules embedded in reports and workflows.

A base model does not arrive with authoritative access to this layer. Yet this is the binding layer. Execution happens one loan at a time: the applicable rule depends on the investor and the loan’s history; the action needs someone with delegated authority; and the result must land in the system of record with evidence an examiner will accept. Public knowledge can inform that work. It cannot supply the firm’s current decision state.

Tacit knowledge

This layer walks around in the default-servicing veteran who knows which counties have predictable processing delays, which reports carry known data-quality limitations, which approved precedents apply to an unusual case, when delegation limits require escalation, and how prior exam findings changed the review path.

A model does not arrive with that judgment either. Some of it can be captured as records, rules, examples, or escalation criteria. Some remains contextual and embodied in the people doing the work. The model and the firm are complements, not substitutes: one brings broad cognitive capability; the other supplies state, authority, and accountable judgment.

The same pattern outside regulation

Regulation makes the structure visible because the cost of error is high. It does not create the pattern.

A regional HVAC company has the same layers. Public knowledge includes equipment manuals, refrigerant rules, building codes, diagnostic guides, and manufacturer bulletins. Operating memory includes customer histories, installed equipment, warranties, dispatch rules, pricing, supplier terms, truck inventory, callbacks, and prior-site photos. Tacit judgment includes diagnosing an unusual failure from weak signals, choosing the right technician for a difficult call, and knowing when a technically defensible recommendation will damage a long customer relationship.

The model knows the manual. The company knows the operation.

Deployment can create operating memory

Agent use frequently elicits what used to live only in heads: procedures, decision logic, exception paths, evidence standards, prompt libraries, labeled examples, and review decisions. Codification is a spectrum:

tribal recollection → scattered artifacts (emails, spreadsheets, Slack threads, stale docs) → governed operating memory (records, rules, workflows, examples, evals, provenance)

Deployment creates an opportunity to move knowledge to the right, but it does not do so automatically. Uncurated chats and prompt folklore are not operating memory. The conversion happens only when accountable people validate the artifacts, resolve conflicts, assign authority, preserve provenance, and keep the result current.

The boundary between operating memory and tacit knowledge has always been contested. Firms try to turn employee know-how into processes, code, documents, and trade secrets they control; employees inevitably leave with general skill, judgment, relationships, and experience embodied in them. Trade-secret law and invention-assignment agreements police ownership directly; non-competes and no-poach practices sit in the broader, contested history of firms trying to control what knowledge and relationships move with workers. Apple’s July 2026 suit against OpenAI and two former Apple employees is a current example: Apple alleges that the former employees carried confidential hardware material and knowledge into a competing effort; OpenAI denies wrongdoing.2 The dispute is, in this vocabulary, over where Apple’s operating memory ends and an employee’s portable tacit capability begins.

AI suppliers add a third claimant. As employees teach an agent through prompts, corrections, trajectories, examples, and evals, knowledge that once lived only in the worker can become codified inside a supplier’s harness. The governance question is no longer only what the employee may carry away. It is also what the supplier may retain, reuse, or make indispensable.

Done well, that conversion is a large, often unbudgeted return on deployment. The firm depends less on individual veterans, its agents become more useful, and corrections compound in artifacts future workers can inherit. Done badly, the deployment produces a larger pile of technical exhaust and a new dependency on wherever that exhaust happens to live.

None of this knowledge needs to become part of a model’s weights. But using a model requires information to cross an inference boundary, and transit is not automatically private or ephemeral. Prompts, outputs, tool calls, traces, metadata, caches, safety reviews, and derived analytics may each follow different retention and use rules. A no-training promise addresses one risk. It does not, by itself, settle custody, access, telemetry, or deletion.

That reuse has an economic consequence: whoever runs inference may collect the corrections, trajectories, and review signals that improve its next model or product.3 Portability protects continuity; limits on reuse determine whether using the service also teaches the supplier how to compete with you.

That is why the destination matters. If new records, approved examples, corrections, evals, and workflow state land in systems the firm controls, they compound its operating memory. If the only durable copy lands in a supplier-controlled harness, the firm’s training materials and runbooks for its future workforce accumulate somewhere it may not be able to carry away.

The harness is a control point

Tomasz Tunguz’s “The Harness Is the New Battleground” names the strategic role of the software wrapped around the model.4 A harness such as Claude Cowork, Codex CLI, or an internal agent runtime decides what context to assemble, which tools to call, what to log, and what state to retrieve on the next task.

That makes the harness an important control point, but not the only one. The boundary also includes the model provider, tool APIs, identity system, retrieval store, observability stack, and any people allowed to review retained content. A firm-controlled harness can keep authoritative state out of a proprietary memory store; it cannot eliminate provider-side exposure for context deliberately sent to a model.

Anthropic’s June 2026 policy for Fable 5 made the distinction concrete. Organizations using zero-data-retention environments had to enable thirty-day retention in the workspace, subscription, or cloud environment through which they wanted to use covered models, or create a separate environment with retention enabled.5 A firm could preserve ZDR for its production environment and use the model elsewhere, but it could not use the covered model inside that ZDR boundary. An owned memory layer would not prevent content sent to the model from being retained. It would preserve the firm’s authoritative copy and its ability to point the work elsewhere.

A serious deployment therefore treats four controls separately:

  1. Custody and continuity: Where does authoritative memory live, and can the firm keep using it without the incumbent?
  2. Inference access: What information may be sent to the model, and with what minimization or redaction?
  3. Telemetry and retention: Which prompts, outputs, traces, tool calls, metadata, and derived artifacts may be stored, reviewed, or deleted?
  4. Training and reuse: May any of those materials improve the vendor’s models, products, or services?

Contracts matter at every boundary: no-training and no-use terms, explicit coverage of session exhaust and derived artifacts, retention limits, deletion evidence, audit rights, and exit assistance. Architecture provides the stronger assurance for custody, continuity, and portability; contracts remain essential once data crosses the inference boundary. The firm should hold the authoritative source records in usable formats, preserve the schemas, policies, keys, and tool contracts needed to use them, and be able to rebuild replaceable derivatives such as retrieval indexes. Not every cache or log must live forever; everything needed to reconstruct and audit representative decisions, workflows, and controls must be governed and recoverable.

Where the infrastructure is hosted is secondary. A supplier can operate it. The firm must not need the incumbent’s permission to export the authoritative sources, reconstruct the necessary derivatives, or appoint a successor. This does not make switching free: adapters, validation, retraining, compliance, and downtime remain real. It removes one of the strongest forms of lock-in — losing the firm’s own accumulated state and judgment when it leaves.6

The vendor can operate the service layer. The firm must control the memory layer.

The operating rule

Never make a model your system of record. And increasingly: never make a model harness the sole authoritative or irreplaceable system of memory.

That is not an argument for timid deployment. Let models summarize, classify, draft, recommend, and act through tools. Use them heavily enough to expose missing rules, conflicting definitions, undocumented exceptions, and review decisions worth preserving. But decide at the start which results become authoritative, who certifies them, and where they persist.

Doing that work is not free. Dual-writing an already structured approval may be cheap; turning an unstructured conversation into trustworthy operating memory is not. It requires schemas, identity and access controls, provenance, validation, retention policy, and accountable owners. For high-stakes deployments, those costs are paid either up front or later. Designing the durable destination early is cheaper and more reliable than discovering years later that the only usable history is trapped in a proprietary runtime.

The dependence becomes unmistakable by contract renewal. If the firm holds the records, rules, examples, evals, and tool contracts, a competing model or harness can be tested against the same operating specification. Behavior will not transfer perfectly — models differ — but the incumbent must compete. If the only durable memory lives in its harness, the switching cost includes the firm’s own accumulated judgment, and the incumbent gains pricing power.

As more well-specified tasks can be performed by several models, owned operating memory and evals are what turn technical substitutability into buyer power: the firm can compare total cost per correct outcome against the same operating specification.

One practical starting point is a context audit. For a representative agent task, ask:

  1. What state, definitions, rules, exceptions, examples, and history must be authoritative?
  2. Which decisions require human judgment or approval?
  3. Which information may cross the inference boundary?
  4. Which information may the harness or provider retain, review, or reuse?
  5. Could a successor reconstruct and audit the result from the firm’s own artifacts?

That final question is the ownership test. If a successor cannot reconstruct and audit a representative decision record and its workflow from the firm’s records, rules, approvals, provenance, and evals without the incumbent harness, the firm does not own its operating memory.

Own the operating memory your agents need, keep models contestable, and let no supplier become indispensable to what your company knows about how to operate.

Footnotes

  1. Vivek Dubey, “The Onboarding Gap Is Killing Your AI Agents”, Atlan Context & Chaos, May 1, 2026. Dubey contrasts the structured exposure given to human hires with the thin prompting often given to agents, and recommends human certification of the resulting context.↩︎

  2. Apple Inc. v. Liu et al., No. 5:26-cv-07078, complaint, filed July 10, 2026, U.S. District Court for the Northern District of California. Apple alleges that OpenAI encouraged two former Apple employees to bring confidential materials and knowledge into a competing hardware effort. OpenAI denied the claims and told TechCrunch that it had no interest in other companies’ trade secrets. The allegations have not been adjudicated.↩︎

  3. Ben Thompson, “Who’s Afraid of Chinese Models?”, Stratechery, July 20, 2026. Thompson argues that intelligence is becoming commodity-like for more defined tasks, that inference produces learning data that can improve later models, and that model vendors are moving upward into sticky harnesses and customer experiences.↩︎

  4. Tomasz Tunguz, “The Harness Is the New Battleground”, Theory Ventures, July 14, 2026. Tunguz argues that the harness decides what flows to the model, what gets logged, and what may feed future training or improvement.↩︎

  5. Anthropic, “Data retention practices for Covered Models”, effective June 9, 2026. Prompts and outputs for covered models are retained for thirty days. Access from an organization using ZDR requires a retention-enabled workspace, subscription, or cloud environment; Anthropic describes separate sandbox organizations or subscriptions as ways to isolate the change from production.↩︎

  6. Economists call an asset worth far more inside one relationship than outside it specific. Oliver Williamson’s work shows why specificity creates a governance hazard: incomplete contracts leave room for hold-up when circumstances change. Ownership is not the only possible safeguard — standards, long-term contracts, audit rights, joint governance, and credible exit plans can all matter — but the more firm-specific and difficult to reconstruct the memory, the more important practical control and tested portability become.↩︎