AI Memory Governance: 3 Gaps Harvey II Just Opened

AI memory governance concept showing a laptop screen with a glowing digital brain connected via data nodes to individual legal client matter folders by Cocha Technology.

Harvey launched its next generation platform on August 18, and the headline feature isn’t a smarter chatbot. It’s memory. Harvey II remembers how an individual lawyer drafts, which citation style they favor, the tone they use with opposing counsel versus the tone they use with a client. Then it carries that across Harvey, Word, and Outlook. Convenient, sure. But it also means your firm just picked up a new category of AI memory governance work, whether anyone budgeted for it or not.

I think the interesting part isn’t the feature itself. It’s what the feature quietly assumes about your firm’s existing policies, and how many of those policies were written before “memory” was something an AI tool could have.

What Harvey II Actually Changed

Three pieces matter here, and Harvey II AI governance conversations should probably start by naming them plainly rather than lumping them together as one launch.

Memory learns an individual lawyer’s preferences and applies them automatically across tools. Harvey says this data won’t be used to train its global models, and lawyers can review, edit, or turn it off. Rollout happens in stages: individual first, then matter level, then firm wide. That staging matters more than it sounds like it should.

Spaces organizes documents, tasks, and permissions around a specific matter, which is Harvey’s attempt at building ethical walls directly into the product rather than bolting them on after the fact. It’s a reasonable idea. Whether it actually holds up under the same scrutiny a firm applies to its document management system is a separate question.

Smarter Agents is the part that should get a CISO’s attention. These agents act on stored context without a human re-approving every step. That’s agentic AI, full stop, and it’s now sitting inside your document management workflow. Harvey built six months of testing around confidentiality and ethical walls before shipping this, according to the company. Testing is good. It’s not the same as your firm’s own risk sign off.

Why AI Memory Governance Is Suddenly Your Problem

Up to now, most legal AI governance conversations centered on one question: can we trust what the AI produced. Fair question. Still is. But Harvey II adds a second one that’s arguably harder to answer: what does this system now remember about us, and who else can see it.

That’s a genuine shift. A hallucinated citation is a bad output you catch and fix before it leaves the building. A memory that quietly carries a partner’s drafting habits, or a client’s deal terms, across a matter boundary it shouldn’t cross, is a different kind of problem. It doesn’t announce itself. You find out about it during a conflicts check, or worse, during discovery, months after the fact.

Firms already juggling ethical wall obligations know this tension well. Add persistent AI memory to it and the wall has to hold at the model layer too, not just the file system. AI memory governance, in other words, isn’t a nice to have policy add on anymore. It’s load bearing.

Three Gaps in Most Firms' AI Memory Governance Right Now

Here’s where I’d start looking, because these are the three places policies written a year ago simply don’t say anything.

Gap 1: Persistent Memory Across Matters

Most AI use policies address a single session. Prompt in, output out, done. Persistent memory breaks that model entirely. If Memory carries a lawyer’s habits or context from Matter A into Matter B, does your policy even contemplate that? For most firms, no, because the tool that would have triggered the question didn’t exist when the policy was drafted.

Gap 2: Consent and Disclosure

Clients rarely know an AI tool is retaining anything about their matter, let alone retaining it across time and across other matters that lawyer touches. Engagement letters written before this year almost certainly don’t cover it. That’s a gap worth closing before a client asks the question first, or before a malpractice carrier asks it for them.

Gap 3: Vendor Data Handling Assurances

Harvey says Memory data isn’t used for global model training. Good. Has your firm actually verified that, in writing, tied to your specific deployment, rather than trusting a blog post announcement? Agentic AI law firm risk assessments need to go deeper than a vendor’s marketing page. Ask for the data processing addendum. Ask where the memory data physically sits. Ask what happens to it when a matter closes.

The Bar Rules Haven't Caught Up, and That's Not an Excuse

ABA Model Rule 1.6 requires lawyers to make reasonable efforts to prevent unauthorized disclosure of client information. That rule was written long before persistent AI memory existed, and it still applies. Reasonable efforts, in a world where your legal AI tool remembers things across matters, probably means something different than it did two years ago.

The New York City Bar has already pushed for a nationwide AI rules framework built into the Model Rules, and other state bars are moving in the same direction, slowly. Waiting for a formal rule change before updating your own AI memory governance practices is a bet against the clock. Formal opinions tend to arrive after a firm has already had a problem, not before. Better to treat the reasonable efforts standard as already applying to Memory, Spaces, and Smarter Agents today, because that’s almost certainly how a disciplinary board or a malpractice carrier would read it if something went wrong.

How Other Legal AI Tools Handle This, and Why That's Not Enough

Harvey isn’t the only vendor building persistent context into legal AI. Thomson Reuters’ CoCounsel and other platforms are racing toward similar organizational intelligence features, because clients keep asking for continuity across sessions. That’s the market pressure driving all of this. Every vendor will eventually build some version of memory, because the alternative is a tool that forgets everything the moment you close the tab, which nobody wants either.

Here’s the thing though. Vendor assurances are not a substitute for your own AI memory governance framework. Each platform handles retention, training data exclusion, and matter level permissioning a little differently, and those differences matter enormously once you’re managing three or four AI tools across a firm instead of one. A policy built around “trust the vendor” doesn’t scale. A policy built around “verify, document, and audit” does.

A Practical Checklist for Closing the Gaps

Rollout moves from individual preferences to matter level to firm wide memory. That staged approach gives you a real window, not a huge one, to get ahead of it rather than react to it.

Start with your AI use policy language specifically. Add a section on persistent memory and cross matter data handling, naming Harvey II and any other agentic tools by name rather than describing AI generically. Update engagement letter language to disclose AI memory retention where it applies. Push your vendor management process to require written confirmation on training data use and retention windows, not just a sales conversation. Assign someone, by name, to own agentic AI law firm risk review going forward, because “IT will handle it” isn’t an answer a bar complaint accepts.

None of this is exotic work. It’s the same governance discipline law firms already apply to conflicts checks and information barriers. It just needs to extend to a new layer, one most firms haven’t built muscle memory for yet.

Where Cocha Technology Fits In

This is the kind of gap that’s easy to miss because nothing breaks on day one. Memory rolls out quietly, lawyers like the convenience, and the AI memory governance question sits unanswered until a conflicts issue or an audit forces it into the open.

We work with law firms on exactly this kind of AI agent security and readiness question, including where persistent memory and agentic features like Smarter Agents fit into an existing risk framework. If you want a clear read on where your firm actually stands before Harvey II’s Memory feature moves past the individual stage, our AI Readiness Assessment is the right place to start.

For more on the agentic AI risk question specifically, our guide on agentic AI security for law firms walks through the questions a CISO should be asking before any autonomous agent, Harvey’s or otherwise, gets access to firm systems. And if your firm is still working through a broader AI risk framework, our piece on the three laws of AI risk mitigation is a good starting point.

Permission sprawl is its own related headache, one we cover in our guide to permissions management, which matters just as much once Spaces starts governing who can see what inside a matter. Worth a look even if Harvey isn’t your firm’s tool of choice, since the underlying problem shows up everywhere.

Legal AI ethical walls used to be a document management problem. Now they’re an AI memory governance problem too. Better to sort that out on your own timeline than on Harvey’s rollout schedule.

Recent Posts

Have Any Question?

Call or email Cocha.  We can help with your cybersecurity needs!

About the Author:

Picture of Steve Combs

Steve Combs

Co-Founder & Managing Director, Cocha Technology

Steven is a fractional CIO/CISO with 30+ years of enterprise IT and security leadership. He has built AI governance frameworks for organizations with 1,700+ users, led enterprise Microsoft Copilot deployments, and conducted security assessments across law firms, energy companies, financial institutions, and PE-backed manufacturers.