Anthropic Merges Claude Chat and Cowork Memory, Enabling Cross‑Product Data Sharing Unless Users Opt Out
What Happened — Anthropic announced that the memory store used by its Claude chatbot is now shared with Claude Cowork. Any context the model has built from a user’s chat sessions is automatically available to the coworking assistant, and vice‑versa, unless the user explicitly opts out.
Why It Matters for Compliance & Audit Readiness
- The change creates a cross‑service data flow that can expose personally‑identifiable information (PII) to additional processing contexts, a scenario SOC 2 CC6 (Confidentiality) and privacy‑related criteria are designed to detect and document.
- Continuous‑compliance programs must now track consent opt‑out status and retain evidence that data handling aligns with declared privacy policies.
- Verisq’s CookiePLUS privacy capability can automate consent capture, DSAR readiness, and provide audit‑ready logs of user opt‑out decisions.
Who Is Affected — SaaS AI providers, enterprise customers that embed Claude Chat or Claude Cowork in internal workflows, and any organization subject to GDPR, CCPA, or similar privacy regimes.
Recommended Actions
- Review your data‑processing agreements to ensure they cover cross‑product memory sharing and that you have a documented opt‑out mechanism.
- Map the new data flow to SOC 2 CC6 controls (e.g., CC6.1 – “Data is processed only for authorized purposes”) and capture the consent status as audit evidence.
- Deploy a privacy‑consent management solution (e.g., Verisq CookiePLUS) to record, manage, and report user opt‑out choices.
Technical Notes – The feature is a product‑level change; no CVE or vulnerability is disclosed. Anthropic states that “sensitive‑data controls” are built into the memory system, but the exact technical safeguards (encryption at rest, access controls) have not been publicly detailed. Source: ZDNet article