The first time your AI assistant remembers something you forgot you told it, it is a genuinely lovely little moment. It recalls your kid's name, the project you mentioned three weeks ago, the way you like your drafts. You feel known. (It is the same warm feeling as a good bartender, and roughly as commercially innocent, which is to say not at all.)
That feeling is the first-order effect, and it is the part everyone is talking about. Memory makes the tool more useful. Less repeating yourself, more context, better answers. Wonderful. Now do the thing this newsletter is built to do and look one step downstream, because the second-order effect is where the actual game is being played.
Memory is becoming the switching cost. Quietly, while everyone argues about which model scored higher on which benchmark (a debate I already told you isn’t needed in Why your best model loses to a worse one), the real moat is being poured, and it is made of everything the system now remembers about you.
Think about why you do not switch banks. It is not the interest rate, which is usually worse than the place down the street. It is that your whole financial life is wired into this one, the auto-pays, the history, the muscle memory, and the sheer dread of moving it all. That dread is a switching cost, and it is worth more to your bank than any feature. (The metric is customer retention and it’s as important as customer aquisition) Agent memory is that same dread, rebuilt for the thing you will soon route most of your thinking through. The accumulated context becomes a gravity well. Leaving does not feel like changing vendors. It feels like onboarding a brilliant new hire who has total amnesia about your entire business, and who you now have to re-teach from zero. Most people will simply never do it.
This is the second-order game in one sentence: whoever owns the memory owns the customer. The model can be matched in a quarter. The memory cannot, because it is yours, accrued one conversation at a time, and that is precisely what makes it the durable lock-in the model never was. From model lock-in to memory lock-in. The frontier labs know this, which is why "memory" shipped across ChatGPT and every serious assistant the moment it plausibly could, framed entirely as convenience. (Convenience is almost always how a moat introduces itself. Nobody opens with "we would like to make leaving painful.")
Here is where I put on the advisory hat (I wish it was as cool as a Pope hat, but alas), because there is a leadership decision hiding inside the delight of "it just works", and the window to make it deliberately is closing. Follow the control point. In any value chain, find the spot where control quietly concentrates, and you find who actually holds the power five years out. With agents, that point is moving off the model and onto the memory layer, the accumulated, proprietary context. So the question for any leader is uncomfortable and specific; as your people pour your company's institutional knowledge into someone else's agent, one helpful conversation at a time, who owns that memory? Where does it live? Can you export it, or is it hostage? If you switched providers tomorrow, do you walk away with the accumulated context, or does it stay in their cloud, now training their understanding of your business and quietly underwriting their pricing power over you?
One fast moving proof point of this is how developers and companies adopted Cursor precisely to "stay free" by wiring coding practice to a tool rather than to any one model. You can swap the intelligence engine underneath the moment a better one appears. Smart. Model-agnostic by design. The trouble is that the thing Cursor was quietly accumulating was never the model choice. It was Cursor's memory of how code actually builds, one commit and one conversation at a time. Then in June, SpaceX bought the company holding all of it. That accumulated coding memory now lives under the same roof as a frontier model (xAI, also part of SpaceX now) with every reason to learn from it. (Coding is the path to the self-improvement promised land after all)
The companies who thought they were abstracting away from any single model spent two years pouring their assets into an abstraction layer, which a model owner then simply walked in and purchased. They got (and so far still have) their model-agnosticism. Many companies would (rightfully) say their code is the proprietary asset, not the coding method so maybe IP didn't go out the door but, they also handed the memory of how coding really works to the exact place they were trying not to depend on. (those companies still own their code IP, but $60B for the memory of workflows is a pretty strong value argument to me.)
Most organizations have not asked this yet about AI. They are governing the model choice (maybe), and the data inputs (sometimes), and they are completely ignoring the layer that is becoming the actual asset. It is the data-and-governance problem, except the data in question is being generated by your own enthusiastic adoption, which makes it the easiest kind of exposure to miss. The more useful the assistant, the faster the moat fills, and the moat is not necessarily yours.
So the move is not to ban memory, which would be both impossible and dumb (the convenience is real and your people will route around you to get it, see: every shadow-AI/shadow-technology story ever). The move is to put memory ownership on your governance map now, while it is still cheap to decide. Treat accumulated agent context as a first-class corporate asset, the way you eventually learned to treat your customer data. Ask vendors the portability question before you are dependent, not after. Decide which memory is so strategic it should live in infrastructure you control rather than rent. Boring questions, asked early, that determine whether you are the one with the gravity well or the one stuck inside someone else's.
That is the whole shape of the second-order game, and agent memory is just the clearest current example of it (with agent orchestration ecosystems coming up fast): the first-order effect is a feature everyone celebrates, and the second-order effect is a power structure almost nobody is governing until it has already set.
So the next time your assistant charms you by remembering something you forgot, enjoy it, and then ask the leader's version of the question. If everything we are teaching this thing is becoming the most valuable and least portable asset we own, whose asset is it actually becoming?
Someone forwarded you trouble.
They clearly think you can handle it. Trouble Worth Making is where I work out loud on how to stop bolting AI onto a pre-AI company and actually rebuild the operating model underneath it. One issue every week or two, no filler, the occasional uncomfortable question.
If the person who sent this has good taste (obviously, they do), subscribe here and get the next one straight from the source.

