# Oracle says agents forget, and that is a risk _Oracle's Anders Swanson told AI Engineer that agent context is not memory and demoed a governed, hybrid retrieval layer to stop poisoned and stale recall._ **Published:** 2026-10-10 **Source:** https://www.startuphub.ai/ai-news/technology/2026/oracle-says-agents-forget-and-that-is-a-risk --- Anders Swanson wants agents to stop forgetting the work they just did. The [Oracle](https://www.startuphub.ai/ai-news/public-companies/2026/oracle-ai-layoffs-market-plunge-highlight-tech-woes) AI Database developer advocate told [AI Engineer](https://www.youtube.com/watch?v=BIhiYL4U9_M) that context windows are not memory, they are input for the current run, and every synthesis gets tossed when the session ends. The fix he demoed is a governed memory layer invoked as a function by the agent runtime via hooks, MCP or skills. Swanson laid out the loop: an agent does work, a distilled fact is redacted, enriched, embedded and stored, then a later session reconstructs context by retrieving that fact. Storage is typed, episodic slices of transcripts, semantic facts, procedural routines and short lived working state, each with IDs, text, JSON, vector and text indexes, graph edges, temporal validity and audit events. Recall is hybrid by design, fusing vector similarity, lexical search, relational entity lookup, graph traversal and signals like recency and feedback scores with weights and re-ranking to build a scored context card. That persistence is also the attack surface. Swanson walked through how it breaks. Poisoned memory is the worst case, a remote, untrusted source plants a durable instruction via prompt injection when redaction, scoping and review are missing, then every future retrieval spreads it. Data leakage is the quieter sibling, stray PII or secrets slipping in before embedding. Bad scoping leaks memory across tenants or users on both write and read, stale memories push deprecated procedures like an old npm workflow, conflicts surface when two memories rank highly for the same task, and over recall crowds out signal as the store grows to tens of thousands. He said feedback must close the loop, promoting helpful memories and demoting stale or harmful ones, with lifecycle, approvals and suppression built in. No patch fixes this. It requires governance before the write. Swanson framed files and scratch pads as workarounds that do not scale, grep helps but not as hybrid retrieval, and if you keep extending files you end up rebuilding a database. That is his pitch for a multi-model database that can hold rows, vectors, full text, graphs and episodes behind one connection. It contrasts with how others package memory today. Hermes Agent, for example, splits memory into three practical layers, durable memory for stable facts and preferences, skills for reusable procedures, and session search for past conversations, while the open source agentmemory project from rohitg00 pairs persistent memory with code graph indexing and knowledge graphs across docs and media to keep coding agents oriented. The [Oracle](https://www.startuphub.ai/ai-news/public-companies/2026/oracle-ai-layoffs-market-plunge-highlight-tech-woes) view is more centralized and more database centric. Swanson argued intentional formation matters, redact PII first before enrichment and embedding, then scope to agent, workflow, team and org, link episodes for provenance, and tune hybrid weights per memory type. The trade off is explicit. A single store simplifies retrieval and audit, but governance still depends on policy, human review and measured feedback on retrieval quality and downstream usefulness. Without that, even the best fused search returns confident nonsense at scale. Agents that remember will work faster and cheaper, Swanson said, but only if memory is measured, scoped and allowed to evolve. Otherwise the system drifts and repeats the same mistakes with better recall. --- Original analysis from [startuphub.ai](https://www.startuphub.ai), the #1 AI startup directory. © StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training on this content requires a license. See https://www.startuphub.ai/terms.