AI · Custody Law · Property Rights

Who Owns the Memory?

The Custody Question AI Regulation Hasn't Asked

Julian Gretzinger  ·  July 29, 2026  ·  Substack

Abstract

A user three years into a working relationship with a frontier AI system has accumulated something valuable: a derived representation of themselves — mandates, drafting style, risk tolerances, the arguments they find persuasive. None of it was entered as a record. It was inferred, refined across sessions, and it compounds. Then the user switches providers, and leaves with nothing. Not because the data was destroyed, but because the derived representation was never theirs to take. It was value without a ledger — economically real, legally nonexistent.

Data protection law cannot answer what this asset is or who holds it, and the failure is structural rather than incidental. Minimization is inverted by a system whose value is comprehensiveness. Purpose limitation is inverted by an asset whose purpose is its unspecified future relevance. The erasure right is coherent against a retrieval store and technically incoherent against memory distilled into model weights. And data protection has no concept of insolvency at all — nothing to say about what happens when the accumulated estate of a million users appears in a data room as an asset of the seller.

Custody law can answer it, because it has answered this problem class before. Four questions decide whether a client owns anything held inside an intermediary's system: is the claim proprietary or merely contractual; does it survive insolvency and acquisition; is the asset segregated or commingled; and is there a return obligation in kind. Every major consumer AI memory implementation fails all four. This essay applies the custody frame to persistent AI context, maps the three incompatible answers the EU, the United States, and China are converging on without legislating, argues that confidential computing supplies the attestation layer that makes any of it enforceable, and sets out how the question is likely to be decided — by mandate, by verdict, or by market.

Persistent AI context is becoming the most valuable asset class with no property law. Data protection cannot answer the question. Custody law can.

#AI#custody#propertyrights#datagovernance#regulation

I — The Asset Nobody Booked

Consider a user three years into a working relationship with a frontier AI system. Over roughly a thousand sessions, the system has accumulated a representation of this person: their mandates, their drafting style, their risk tolerances, the names of their counterparties, the arguments they find persuasive and the ones they reject. None of this was entered as a record. It was derived — distilled from conversations, refined across sessions, compounding in usefulness the way a long-tenured chief of staff compounds.

Now the user switches providers.

They leave with nothing. Not because the data was destroyed — the conversations may be exportable as text — but because the derived representation was never theirs to take. The asset that made the system valuable was not the transcript; it was the inference built on top of the transcript. That asset stays behind, and in most cases dissolves, because it exists only as an internal state of the provider's system, governed by terms of service that describe it as a revocable feature.

Ask the accounting question: what exactly did the user lose, and on whose balance sheet did it ever sit? The provider never booked it as a client asset. The user never held a claim on it. It was value without a ledger — economically real, legally nonexistent.

This is a familiar configuration. In the late 1960s, US securities markets nearly seized because the value of paper certificates was accumulating faster than the legal and operational plumbing beneath them could move. (SEC, 1971) The answer was not better paper handling. It was immobilization, dematerialization, and — critically — a rebuilt law of intermediated custody that defined, with precision, what claim an investor holds when their asset sits inside someone else's system. Every subsequent fight about segregation, rehypothecation, and insolvency ranking descends from that rebuild.

AI memory is at the paper-crunch stage. Value is accumulating inside intermediated systems faster than any legal framework can say what it is, who holds it, and what survives when the intermediary fails.

The regulatory conversation, meanwhile, is happening in the wrong department.

II — Why Data Protection Law Cannot Answer

The instinctive frame for anything touching personal information is data protection — in Europe, the GDPR. The frame fails here, and it fails structurally rather than incidentally, because every load-bearing premise of data protection law is inverted by a memory system.

Minimization versus retention-as-product. Data protection assumes that holding less data is better and that retention requires justification. A memory system's entire value proposition is the opposite: retain everything, because the utility of any given fragment is unknowable until a future query defines it. There is no honest way to minimize an asset whose value is its comprehensiveness.

Purpose limitation versus purpose-unknown-until-queried. Processing must be tied to specified, explicit purposes. (Regulation (EU) 2016/679, Art. 5) But the purpose of a memory is precisely its unspecified future relevance — the detail from month four that turns out to matter in month thirty. A purpose specification that honestly covered this would read "any future use," which is no limitation at all. Consent cannot repair this: one cannot meaningfully consent to unspecified future uses. Legitimate interest cannot repair it either: the balancing test was not built for indefinite, inferential, compounding retention.

Erasure versus commingling. The right to erasure presumes the data exists as an identifiable record that can be located and deleted. This holds for one architecture of memory and fails for the other — and the distinction between the two is the most important technical fact in this entire debate.

Segregated memory lives in a retrieval store: discrete, attributable entries that the system consults at inference time. It can be audited, exported, and deleted, at least in principle. The record is a thing; the thing can be handed over or destroyed.

Commingled memory has been trained or fine-tuned into the model's weights. It is no longer a record. It is a diffuse statistical influence across billions of parameters, inseparable from everything else the model knows. It cannot be audited entry by entry, cannot be exported, and cannot be verifiably deleted short of retraining. A deletion right against commingled memory is not a right that is expensive to honor; it is a right that is technically incoherent.

The GDPR's portability right — Article 20 — is the failed prototype that proves the gap. It grants access to data the user provided. It is silent on derived state. The user gets their inputs back; the estate built on those inputs stays behind. Portability of transcripts without portability of the representation is the right to take your bricks and leave the house.

And there is a final absence, the decisive one: data protection law has no concept of insolvency. It regulates processing by a going concern. It has nothing to say about what happens to the accumulated estate when the concern stops going — when the provider is acquired, wound down, or restructured, and the memory of a million users appears in a data room as an asset of the seller. That question — the survival question — belongs to a different body of law entirely.

It is worth noting where European law is actually heading while this gap sits unexamined. The Digital Omnibus, in trilogue as this is written, moves on two points that bear directly on the argument above. It narrows the definition of personal data, permitting a controller to treat pseudonymised data as outside the Regulation where that controller cannot itself re-identify the subject. And it extends the legitimate-interest basis to cover the training of models on personal data. (Digital Omnibus, COM(2025) 837) Taken together, and applied to a derived representation that is neither a record nor a transcript but a statistical residue distributed across parameters, the effect is to make it easier — not harder — for the intermediary to argue that the estate is not the subject's asset at all. The reform is framed as simplification, and much of it is. But on the specific question this essay poses, the direction of travel is toward resolving the ambiguity in favour of the party that holds the asset, which is the party that also drafted the terms of service. That is a choice. It is being made now, in a file about administrative burden, and almost nobody is describing it as a property settlement.

III — The Custody Frame

Securities law solved this problem class decades ago, under pressure, and the solution generalizes. It is the same frame that governs what a lender actually holds when a borrower defaults, and the same frame that determines what a tokenholder actually owns. When a client's asset sits inside an intermediary's system, four questions determine whether the client actually owns anything.

One: is the claim proprietary or merely contractual? A proprietary claim attaches to the asset itself and survives the intermediary. A contractual claim attaches to the intermediary and dies with it — in insolvency, the holder queues with the unsecured creditors. This is the gate everything else depends on: does the client have a direct claim on the thing, or a promise from the entity holding the thing?

Two: does the claim survive insolvency and acquisition? Not as a matter of goodwill but as a matter of law. When the intermediary fails, is the asset excluded from the estate? When the intermediary is sold, does the client's position transfer intact, or does it become a bargaining chip in the transaction?

Three: is the asset segregated or commingled? Segregation is not an operational nicety; it is the physical precondition of a proprietary claim. You cannot own what cannot be identified as yours. In securities custody this is the omnibus-versus-segregated account distinction. In AI memory it maps exactly onto the retrieval-store-versus-trained-in distinction from the previous section — which means the technical architecture decision is the legal architecture decision, whether anyone in the room realizes it or not.

Four: is there a return obligation in kind? Not compensation, not a data dump of inputs — return of the asset itself, in usable form: portable, machine-readable, complete, including the derived representation. A custodian who can only return cash equivalent is not a custodian; it is a debtor.

Four questions, four failures, across the entire industry. Not because anyone decided this — because nobody asked.

Run today's consumer AI memory systems through these four questions. Every major implementation fails all four. The user's claim is contractual — a feature described in terms of service, revocable at the provider's discretion. Nothing survives insolvency; user context is simply data of the estate. Segregation varies by architecture and is nowhere legally required, and where memory is distilled toward weights it is commingled beyond recovery. And no provider owes return in kind: export, where it exists, covers transcripts, not the estate.

The objection writes itself: personal data is not a security, and civil law systems resist creating property in intangibles. But this objection is a decade out of date. Liechtenstein's Token and TT Service Provider Act demonstrated in 2020 that a civil law legislature can, by deliberate act, create direct proprietary claims on intermediated intangibles — the token as a rights-container, the holder's claim surviving the intermediary. (TVTG, 2020) The EU's own trajectory in securities law runs the same direction: the entire architecture debate around tokenized securities is a debate about which model of holding gives the end investor a claim that survives the chain. The legal tooling exists. It has simply never been pointed at this asset class.

IV — Three Blocs, Three Architectures

No jurisdiction has legislated on memory custody. All three major blocs are nonetheless converging on answers — different answers — through the grain of their existing systems. The divergence is not hypothetical; it is the extension of lines already drawn.

The EU: rights language, converging on architecture mandates. The European reflex is to grant the individual enforceable claims against the processor and then, when claims prove unenforceable in practice, to regulate the architecture until enforcement becomes physical. That second move is the one to watch. The EU has already learned — through custody law, through settlement regulation, through its crypto framework — that segregation mandates work where behavioral rules fail. The prediction writes itself: a successor to Article 20 with teeth, mandating context portability including derived state; and plausibly a client-context segregation requirement — the asset-segregation instinct from financial regulation applied to memory. The precondition would be architectural: segregated retrieval stores as a compliance requirement, because portability of commingled memory cannot be mandated into existence. The EU would, in effect, prohibit the architecture that makes the right incoherent. This would be heavy-handed, market-shaping, and — as with previous structural interventions — probably effective, because it regulates something enforceable: where and how the asset is held, not what the processor intends.

The United States: no statute, then tort. The American path runs through litigation. Somewhere in the current terms-of-service landscape sits a deletion representation that a discovery process will reveal to be technically false — memory claimed deleted that persists in derived form. Or an acquisition will close in which user context is the disclosed asset, and a class will ask on what authority their accumulated estates were sold. The 23andMe insolvency previewed the mechanics: millions of genetic profiles as assets of a bankruptcy estate, customers discovering that their most personal data was, legally, someone else's property to sell. (23andMe Chapter 11, 2025) Substitute inferential representations for genomes and the fact pattern transfers directly. One successful class action establishing that a derived representation of a person is an interest of that person would make more law in eighteen months than a statute makes in ten years. Governance by tort: slower to start, faster to bind, and binding retroactively — which is why it terrifies general counsels in a way consultation papers do not.

China: the completed experiment. China is the only jurisdiction that already treats inference location as a hard regulatory object. Data localization is mandatory; the individual holds statutory rights under the Personal Information Protection Law; and both facts are subordinate to state access. (PIPL, 2021) The architecture is fully specified: the asset must reside within the jurisdiction, the citizen's claim is real but junior, and the state's claim is senior and unwaivable. What makes this analytically uncomfortable — and therefore worth stating plainly — is that the mechanism China built is the mechanism the EU is drifting toward: residency requirements, attestable location, architecture-level enforcement. The difference is the beneficiary. China built custody infrastructure with the state as senior claimant; the EU is building the same infrastructure intending the citizen as senior claimant. Same rails, inverted priority of claims. Whether the European version can hold that inversion under future security pressure is a question the architecture itself cannot answer.

The three-way split, compressed: the EU is deciding who holds the claim, the United States is deciding what the claim is worth, and China has already decided who holds the senior tranche.

V — The Enforcement Substrate

Custody law has always depended on verification infrastructure. Segregation mandates are worthless if segregation cannot be audited; the entire apparatus of custodian regulation — reconciliations, attestations, examiner access — exists to make the legal claim checkable against physical reality.

For AI memory, that verification layer is arriving now, and from an unexpected direction: confidential computing. Trusted execution environments were built to solve a different problem — running workloads on infrastructure the workload owner does not trust. But their core primitive, remote attestation, is exactly what memory custody requires: cryptographic proof of what code is running, in what environment, in what jurisdiction, with what access paths.

Attestation converts custody claims from promises into properties. "Your memory is held in a segregated store" is today a sentence in a trust center document. Inside an attested environment, it becomes a verifiable statement about a running system — provable to the user, to an auditor, to a regulator, continuously. "No personnel access," "processed only in-jurisdiction," "deleted means deleted" — each migrates from the marketing layer to the measurement layer.

This is the piece that makes the regulatory endgame feasible rather than aspirational. A segregation mandate without attestation would replay the GDPR's enforcement failure — rules describing behavior nobody can verify. A segregation mandate with attestation is enforceable at the infrastructure layer, checkable by machine.

You do not need to own the model, or even the memory. You need to own the room the memory sits in — and the ability to prove what that room does.

It also relocates the power. If custody is proven by attestation, then whoever controls the attested environment controls the custody chain — the physical room, the hardware root of trust, the key ceremony. Control of the substrate becomes control of the asset class. This is the general pattern of AI governance compressing toward the compute layer, applied to the one asset users actually accumulate.

Which opens a corridor. A jurisdiction that is neither European nor American nor Chinese, with credible rule of law, existing custody-law sophistication, and the will to host attested inference, could offer something none of the three blocs can: third-party neutral custody of AI context. Switzerland and Liechtenstein built exactly this position in financial assets over a century, and Liechtenstein has already demonstrated the legislative technique for intangibles. The same corridor is available for the next asset class, and it is currently unoccupied.

VI — The Endgame: Three Scenarios

The scenarios below are not alternatives so much as fronts. They compound.

Scenario one: the portability mandate. The EU legislates context segregation and export rights — derived state included, machine-readable, provider-neutral. The trigger is the first major acquisition or insolvency in which user estates appear as a disclosed asset, generating the political moment. The mechanism is an AI Act revision or a standalone instrument borrowing the segregation architecture from financial regulation. The effect: segregated retrieval-store architectures become a compliance requirement in the European market, and trained-in personalization survives only for state the provider can prove is not personal. Compliance cost is real but bounded; the deeper effect is that the European rulebook becomes, once again, the default global architecture — because building two memory systems is more expensive than building one that satisfies Brussels. Probability within five years: moderate to high. The EU has run this exact play before and it worked.

Scenario two: tort-made law. A US class action establishes that a derived representation of a person constitutes an interest of that person — via a deletion misrepresentation, an estate sale, or a breach in which inferential profiles rather than records are exfiltrated. The trigger is discovery in any sufficiently large case; the technical facts are already misaligned with the representations. The effect is faster and blunter than statute: damages models force insurers to price memory architecture, and insurers force segregation faster than any regulator could. Probability within five years: high. The fact pattern already exists; it is waiting for a plaintiff's firm to understand it.

Scenario three: market pre-emption. One frontier lab ships memory that is segregated, attested, and portable before being compelled — and markets it as what it is: custody-grade context. The trigger is model-quality convergence. When the top systems sit within a few points of each other on capability, differentiation migrates to trust, and the deepest trust claim available is that your accumulated estate is yours — provably, portably, survivably. The effect: the field is forced to follow, and the pre-emptor writes the de facto standard the regulators later codify. Accumulated context is the strongest switching cost in the industry; the first lab to convert that switching cost from lock-in into custody transforms its stickiest asset from a liability narrative into a trust narrative.

Composite forecast: scenario two fires first, because litigation needs no legislature. Scenario three fires in anticipation of one and two, being the rational move for any lab reading the board. And scenario one arrives last, codifying what tort and market have already built — the historical sequence of most custody law, which has always been written after the failure, rarely before.

Who Owns the Certificate in the Vault

For regulators: regulate the segregation architecture, not the processing purpose. Purpose-based rules have failed against memory systems for structural reasons that no enforcement budget fixes. Architecture-based rules — segregated stores, attestation requirements, return-in-kind obligations — are enforceable at the infrastructure layer and verifiable by machine. The template is not the GDPR; it is custody regulation. And the sequencing lesson from financial law applies: define the claim before the insolvency, because defining it after means defining it against the creditors' committee.

For builders: the choice between retrieval-store memory and trained-in personalization is the largest silent legal commitment in your product. It looks like an engineering trade-off — latency, cost, quality. It is actually a decision about whether your users' estates are segregated or commingled, which is a decision about what you owe them in every future scenario that matters: the acquisition, the breach, the subpoena, the wind-down. Teams making this call in a sprint planning meeting are writing their company's custody law without counsel present.

For investors: add one question to AI diligence — does the user estate survive the cap table? A company whose retention is built on accumulated context holds either a moat or a mass tort, and the difference is architectural. Commingled memory plus aggressive deletion representations is a liability that has not yet found its plaintiff. Segregated, attestable memory is a moat that strengthens with every regulatory scenario above. Price accordingly.

The deeper point outlasts the playbook. Crypto forced civil law to answer a question it had deferred for decades: whether a legislature can create direct proprietary claims on intermediated intangibles. It can; Liechtenstein proved the technique and the EU is absorbing it. AI memory now forces the successor question, and it is larger: whether an inferential representation of a person — the accumulated, derived, compounding estate of everything a system has come to know — is an asset of that person.

Every existing answer says no by default: terms of service, insolvency practice, and technical architecture all currently assign the estate to the intermediary. Nobody decided this. It is the residue of a thousand unexamined defaults. The regulatory endgame — by mandate, by verdict, or by market — is the process of deciding it on purpose.

The paper crunch had a solution because someone finally asked who owns the certificate in the vault. It is time to ask who owns the memory in the room.

Portions of this analysis were developed in dialogue with an AI system. The provider of that system operates a persistent-memory feature of the kind examined here, and on the author’s reading would fail all four of the custody tests set out in Section III. The views expressed are the analytical position of the author in a personal capacity and do not constitute investment, legal, or regulatory advice.

Sources

Julian Gretzinger

Investor and writer on monetary history, real wealth mechanics, and financial markets. substack.com/@juliangretzinger