Filed at birth, never inferred later
The memory is written with its class, principal, tenant, and AI-specific notice declared in the record itself — not in a policy PDF nobody can query.
Agents accumulate memory — preferences, histories, identities — and then act on it. The question that decides liability is never what the memory says. It is whether it may be used for this action, right now, on this legal basis. AgentMemorySDK makes that a filed, answerable question.
Regulators already treat agent memory as personal data — Singapore's PDPC guidance validated exactly this lifecycle. Each stage below is a decision with an evidence trail, so a deletion request or an audit is a query, not an archaeology dig.
The memory is written with its class, principal, tenant, and AI-specific notice declared in the record itself — not in a policy PDF nobody can query.
Legal basis and purpose scope attach where the data lives. When the basis changes, the record knows before the agent does.
Training, fine-tuning, inference, and action are four different questions with four different answers: ALLOW, DENY, REQUIRE_CONSENT, REQUIRE_MINIMISATION — decided when it matters, not audited after.
Sealed, tenant-scoped, replayable. The answer to "which memories did the agent act on, and was it allowed?" is one lookup.
Withdrawal routes through the same governed path as use — the erasure itself seals evidence, closing the file the way it was opened.
Honest scope: the SDK governs whether a memory may be used for an action. It does not verify the truth of what the memory contains, and it claims no regulation it has not mapped.
KYC, support, healthcare, finance — teams whose agents hold people's data get access first. Replies come from a person at [email protected].