Governing Persistent Memory in LLM Agents: Admission and Presentation
Summary
Persistent memory can make LLM agents more personalized, but it can also cause sycophancy and leak information across domains. This paper separates two governance decisions: admission, which decides what recalled information enters the working context, and presentation, which decides how admitted information is expressed. Without retraining, the authors implement factor-compiled admission (FC), which evaluates complete memory entries, and permission-semantic admission (PS), which breaks entries into typed units and applies deterministic eligibility policies. On an external benchmark with four 300-sample tasks, FC and PS reduce pooled judge-assessed failure rates versus verbatim injection by 6.7 and 8.8 percentage points, respectively, with statistically significant results. Cross-domain leakage on the development set falls by as much as 29.5 percentage points, while PS also outperforms random and relevance-based selection on external objective-fact judgments under matched admission budgets. With presentation held constant, stricter admission produces a further 17.5-point reduction in cross-domain failure; comparisons between renderings of identical adjudicated outputs are not significant after correction. However, both methods increase personalization failures, and PS does not meet the preregistered criteria for improving performance while preserving personalization. The authors conclude that memory selection and presentation should be evaluated separately, and that retaining the benefits of memory remains unresolved.