Two camps, and this one has lawyers on both sides.
Team Lock It Down: an agent should hold as little of your personal data as possible. Every field of PII is a liability — a breach surface, a compliance headache, a subpoena waiting to happen. Data minimization is the first principle of security for a reason. The only data that's safe in a breach is the data you never collected. Give an LLM your family's IDs and you've built a honeypot you can prompt-inject.
Team Know Me: a personal agent that isn't allowed to know your life is a butler forbidden from learning your address. The entire value is the context. You know your wife's phone number, your kids' ID numbers, your doctors, who you owe a call. Strip all of that out and "personal agent" is a lie — you've got a search box with a personality.
Both are right. And the way the fight is usually framed hides the question that actually matters.
Because the argument sounds like it's about whether an agent should hold your private life. It isn't. It's about where it holds it, and who controls that place. Once you separate those, the debate stops being a standoff and becomes a design decision.
Why this is now a real question
Three things turned a privacy preference into an engineering fork in 2026.
Agents got good enough to actually be personal. For years "personal AI" meant a chatbot with your name in the system prompt. Now agents can act across your life — your calendar, your inbox, your accounts. The digital-clone dream got concrete. And a clone, by definition, is made of private knowledge. You can't build one out of public facts.
Agents don't just know now — they act. A chatbot that knows your contacts is a privacy question. An agent that knows your contacts and can email them is a different risk class entirely. The blast radius of "what it holds" is now multiplied by "what it can do," and most people only budget for the first.
The "where" became a legal and technical fact, not a vibe. Regulation made deletion a right, not a courtesy — and weights can't honor it. Research on training-data extraction (Carlini and colleagues) showed models memorize and can be coaxed to cough up what they were trained on. Meanwhile prompt injection sits at the top of the OWASP LLM risk list — the channel by which a clever input turns your helpful agent into an exfiltration tool. So where personal data lives, and whether you can delete it, stopped being philosophy.
Steelman: lock it down
You can't leak what you don't hold. Every system gets breached eventually — that's not pessimism, it's actuarial. Minimization is the only security property that survives a breach intact, because it's the absence of a target. The most defensible byte of personal data is the one that was never collected.
Concentrated personal data is the perfect target. An agent that knows your finances, your health, your family's identities, and your relationship graph is the single most valuable thing an attacker could ask for — and you've parked it behind a model that can be talked into things. We spent decades learning not to build honeypots. An over-eager personal agent is a honeypot with an API.
Other people never consented. Your data is your call. But a "know me" agent inevitably holds them too — your wife's number, your kids' records, a client's secret. They didn't sign up for your convenience. Scope creep in personal AI isn't just your risk; it's a surveillance surface pointed at everyone near you, built one helpful capture at a time.
Steelman: know me
Identity is made of private knowledge. Take away everything confidential a clone of you would hold and what remains isn't you — it's a polite stranger wearing your face. The specifics you'd never post publicly are the self. An agent forbidden from them can imitate you but never stand in for you.
The value lives in the specifics. Generic competence is a commodity now — every model gives decent generic help. The only durable reason your agent beats the default is that it knows your situation: the project, the history, the argument you had Tuesday. Usefulness scales almost exactly with how much it's allowed to know. Cripple the knowing and you've paid for a worse version of the free thing.
You already trust concentrated stores of your secrets. Your phone holds all of it. Your password manager holds the literal keys. Your own memory is an unencrypted, un-auditable store you can't even back up. The honest objection was never "an agent must not hold this." It's "I don't trust this agent, on this infrastructure." That's a trust problem — and trust problems have engineering answers.
Where I actually land
The taboo is mis-stated, and the mis-statement is doing real damage. "Agents shouldn't hold personal data" smuggles two different claims into one sentence: holding it, and holding it somewhere you don't control. The first is how you build something that's actually yours. The second is the thing to be afraid of. Collapse them and you'll either cripple your agent or kid yourself about a rented one.
The real axis isn't privacy versus personalization. It's ownership — the locus of control over where your life is stored. A clone is allowed to know you. It just has to keep that knowledge on substrate you own, encrypted, scoped to what it needs, revocable on demand, and auditable — and (the through-line from last issue) in a memory layer you can delete, not baked into weights that can't forget. Apple's bet on on-device processing and a controlled private compute path is the same instinct dressed in hardware: keep the intimate stuff where the user, not the vendor, holds the keys.
The question was never whether your agent should know your secrets. It's whether you still own the place it keeps them.
So the rule is context-dependent, the way it always is here:
A third-party, cloud-hosted, general-purpose agent? Minimize hard. Lock it down. You don't control the substrate, you can't guarantee deletion, and you can't see who else has access. Treat every field you hand it as potentially public.
Your own clone, on infrastructure you control? Let it know you — with the controls. Encryption, least privilege, revocability, a memory you can wipe, and an audit trail. The knowing is the point; ownership is what earns you the right to it.
The mistake is mixing them up: pouring your life into a rented cloud agent as if it were your private clone, or crippling your own owned clone as if it were a stranger.
And one edge that stays hard even when you own everything: data about other people. Total recall for yourself can be fine. Total recall for your wife and kids, who never opted in, is not your unilateral call. Default to minimize for everyone but yourself — that's the one place where Team Lock It Down is right no matter whose basement the server is in.
What I'd ask any team (or yourself)
Whose data is this — mine or someone else's? Your own data on your own substrate is your decision. Data about your family, your clients, your contacts is theirs. Different bar. Default to minimize or ask.
Where does it physically live, and who could breach or subpoena it? Your device? A vendor's cloud? Can you name every party with access right now? If you can't, you've already lost the thread.
Can you delete it — completely and on demand? Weights can't forget; a memory store can. If there's no erase button that actually erases, you don't own the data — you're just holding the liability.
What can the agent do with it, not just know? Read-only memory is one risk tier. An agent that can act on your accounts and message your contacts is another. Scope the actions, not only the data.
Would you be calm if this exact store leaked tomorrow? If the honest answer is no, the question isn't whether to hold the data — it's whether you've earned the right to yet, by putting the ownership and controls in place first.
A small confession
I want the clone. The real one — the agent that knows my wife's number without me typing it, remembers my kids' details, knows who I owe a call and what we fought about last week. Not a chatbot with my name on it. The actual thing.
And what stops me isn't capability anymore. The models are ready. What stops me is that I can't yet promise that knowledge stays mine. To let an agent hold my family's life is to become the person responsible for never leaking it — and that responsibility is heavier than the feature is shiny. It's easy to want total recall for myself. It's harder to look at my kids' data sitting in a store and be sure I've earned the right to keep it there.
I'm not going to pretend I've resolved it. I'm building toward the clone, and I'm holding the brake at the same time — not because the knowing is wrong, but because ownership is a thing you have to build before you're allowed to want it. I want Luke to know me. I'm just making sure that when he does, I still own the place he keeps it.
Next time: every debate so far has been about what an AI should do, hold, or become. The next one goes underneath all of it — whether a machine that only predicts the next token can understand the world at all, or whether real intelligence needs a different kind of mind entirely. LLMs vs world models. Don't pick a side.
