HomeIntelligenceBrief
BREACH BRIEF🟡 Medium ThreatIntel

Anthropic Merges Claude Chat and Cowork Memory, Enabling Cross‑Product Data Sharing Unless Users Opt Out

Anthropic now shares the memory store between Claude Chat and Claude Cowork, making prior conversation context available across both services unless a user opts out. This creates a privacy‑risk scenario that SOC 2 and privacy‑compliance programs must track and evidence.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 zdnet.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
zdnet.com

Anthropic Merges Claude Chat and Cowork Memory, Enabling Cross‑Product Data Sharing Unless Users Opt Out

What Happened — Anthropic announced that the memory store used by its Claude chatbot is now shared with Claude Cowork. Any context the model has built from a user’s chat sessions is automatically available to the coworking assistant, and vice‑versa, unless the user explicitly opts out.

Why It Matters for Compliance & Audit Readiness

  • The change creates a cross‑service data flow that can expose personally‑identifiable information (PII) to additional processing contexts, a scenario SOC 2 CC6 (Confidentiality) and privacy‑related criteria are designed to detect and document.
  • Continuous‑compliance programs must now track consent opt‑out status and retain evidence that data handling aligns with declared privacy policies.
  • Verisq’s CookiePLUS privacy capability can automate consent capture, DSAR readiness, and provide audit‑ready logs of user opt‑out decisions.

Who Is Affected — SaaS AI providers, enterprise customers that embed Claude Chat or Claude Cowork in internal workflows, and any organization subject to GDPR, CCPA, or similar privacy regimes.

Recommended Actions

  • Review your data‑processing agreements to ensure they cover cross‑product memory sharing and that you have a documented opt‑out mechanism.
  • Map the new data flow to SOC 2 CC6 controls (e.g., CC6.1 – “Data is processed only for authorized purposes”) and capture the consent status as audit evidence.
  • Deploy a privacy‑consent management solution (e.g., Verisq CookiePLUS) to record, manage, and report user opt‑out choices.

Technical Notes – The feature is a product‑level change; no CVE or vulnerability is disclosed. Anthropic states that “sensitive‑data controls” are built into the memory system, but the exact technical safeguards (encryption at rest, access controls) have not been publicly detailed. Source: ZDNet article

📰 Original Source
https://www.zdnet.com/article/anthropic-claude-and-cowork-share-memories-now-unless-you-opt-out/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →