Skip to content
ArchitectureInsights · 13 August 2026

The enterprise brain needs a memory you can trust

Lee NorvallFounder5 min read

Drafted with Akora, reviewed and edited by Lee Norvall. We disclose this on every post where Akora helped — see our authoring approach.

The industry has worked out that agents which forget are not worth much. The harder problem is what happens when they all remember the same thing — and it is wrong.

Sandy Carter's piece in Forbes this week — Enterprise Brain Replaces AI Agents And Loops As Microsoft And Glean Race — names something that has been obvious to anyone running agents in production for more than a quarter. Agents, as built, execute a task and forget. Loops close the feedback cycle inside one workflow and stay there. Neither accumulates anything.

The numbers she quotes are the part worth sitting with. Only 28% of AI use cases in infrastructure and operations fully succeed, with Gartner attributing the failures to workflow integration rather than model quality. Ragy Thomas of UnifyApps puts it more bluntly: "The model was the easiest part. The constraint was architecture."

We agree with the diagnosis. We think the industry is about to get the cure wrong.

The shift is real

The direction of travel is not in doubt. Microsoft shipped its IQ family at Build and framed it, tellingly, as "a context layer rather than a product, with no interface of its own". Glean has built the pure-play version — a permissions-aware knowledge graph over your applications — and is somewhere near $300 million ARR on it. Mem0 raised $24 million to sell memory as a service.

When the largest platform vendor and the fastest-growing independent both conclude that the missing layer is shared memory, that is not a trend. That is an architectural consensus forming.

And it moves the blast radius

Here is what concerns us. A shared memory layer is, by construction, a shared blast radius.

OWASP added memory and context poisoning to its 2026 agentic application risks, and classified it with high persistence and very high detection difficulty. Read that pairing again, because it is the whole problem in six words. A poisoned fact does not announce itself. It gets retrieved, acted on, and — in a system designed to learn — it gets reinforced. The failure is quiet, durable, and propagates to every agent that shares the store.

The article's own conclusion is that enterprises are adopting the enterprise brain before establishing ownership frameworks or governance. Gartner projects 150,000 agents across Fortune 500 enterprises by 2028, with only 13% calling their governance adequate. Those two facts together describe a decade of remediation work being commissioned right now, by people who think they are buying a productivity gain.

What we think memory has to do

If a shared brain is where the enterprise is heading — and we think it is — then the memory layer inherits every security property the organisation previously placed at the application boundary. It should therefore be built to a standard the application layer was never held to.

Three properties we consider non-negotiable:

Provenance over recall. The interesting question is not what does the system remember but how did that get in there, who put it there, and what has read it since. A memory you cannot interrogate is a memory you cannot trust, and a memory you cannot trust is worse than none — because it is authoritative.

Isolation as the default, not a tier. Shared memory across an organisation does not mean shared memory across a boundary. Per-tenant isolation with auditable access should be how the thing is built, not a feature reserved for the enterprise plan.

Forgetting as a first-class operation. Every system like this is described in terms of what it retains. Almost none are honest about deletion. Under UK GDPR, erasure is not optional, and a memory layer that cannot pull a fact back out — from every derived index, not just the source row — is a compliance problem waiting to be discovered by somebody else.

Where CosmicMem fits

Ours is not a separate thing to bolt on. CosmicMem is built into Akora and into the core OS, available as a securely hosted central option — so the memory layer arrives with the products rather than as another system to integrate.

The part that bears on the argument above is the separation model. It is not one tenant boundary with everything inside it. Separation runs in layers — organisation, department, and down to the individual desktop — with management that scales from a single person to an enterprise without changing the model underneath.

That is the shape a shared brain actually needs. Shared should mean shared exactly where you decided it is shared, and nowhere else — which is the difference between a memory layer and a blast radius.

There is more to say about how it works, and the CosmicMem product page is the right place for it.

The uncomfortable part

Carter's article closes by noting that the enterprise brain is being assembled on a three-year timeline, where previous infrastructure layers took decades. That compression is not going to reverse. The vendors racing here are not going to slow down, and neither are the buyers.

So the question worth asking your vendor — ours included — is not what can your memory layer remember. It is: when something wrong gets in, how would you know, how far would it have spread, and what would it take to remove it entirely?

If the answer is a shrug, the demo was very good and the architecture is not.

  • ai-memory
  • enterprise-brain
  • cosmicmem
  • governance
← Back to Insights