Cohere North 2 Gives Agents Memory and Names No Retention Rule

Cohere North 2 gives agents memory that persists across sessions, but Cohere has published no scope, retention or deletion terms for it. The token caps in North Admin are usable now; memory should wait for written answers.

By Rajesh Beri·October 5, 2026·9 min read
Share:
A rack server in a locked, windowless data-centre cage with a single drawer pulled open, revealing rows of index cards filed inside, lit by cold overhead light.

Illustration generated using AI

Cohere's North 2 gives agents a memory that persists across sessions, and Cohere has not said what that memory holds, how long it keeps it, or how you delete one person's share of it. If you run North on-premises or air-gapped because a regulator or a sovereignty rule told you to, that memory is a new store of employee and customer context sitting inside your perimeter. Get the scope, retention and deletion terms in writing before anyone turns it on. The token caps in the same release are the part you can use on day one.

Cohere announced North 2 on October 5, 2026, about 14 months after North reached general availability in August 2025 and less than three weeks after Cohere signed its merger agreement with Aleph Alpha on September 16. It is the release Cohere will pitch to banks, telcos and public bodies as the sovereign alternative to the US suites.

What Cohere Actually Shipped in North 2

North 2 is a rebuilt agent platform with five additions that matter to a buyer: an orchestration layer, memory, reusable skills, an app builder, and spend controls in North Admin.

Cohere's launch post describes an orchestration system that "manages complex, multi-step processes independently," plus skills (reusable capabilities agents call on), shared libraries, a drag-and-drop automation builder, and generation of decks, dashboards and lightweight apps. SiliconANGLE reports that the orchestrator escalates to a human when it needs to, and that agents built from simple prompts can be shared across a company.

Deployment options are the reason most buyers look at Cohere North at all. The launch post lists self-hosted, VPC, on-premises and hybrid, and SiliconANGLE adds fully air-gapped installations. Cohere cites SOC 2 Type 2, ISO 27001 and ISO 42001, content-filtering guardrails and per-agent autonomy policies. Connectors cover Slack, SharePoint, OneDrive, Outlook, Exchange, Jira, Linear, Notion and GitHub, with PitchBook, Crunchbase, S&P Global, FactSet and others listed as planned.

Named customers include LG CNS, Bell Cyber and CoreWeave, which Cohere presents as a customer support case study with a 90-day timeline. Cohere picked those references, and none comes with independently measured results.

Price is not published. Cohere told VentureBeat that pricing is "based on the scale and complexity of a customer's deployment, including infrastructure requirements, usage patterns, support and customization."


What North 2 Memory Stores, and What Cohere Has Not Said

Agent memory is a persistent store the agent writes to during one session and reads from in later ones, so it keeps context about users, projects and decisions instead of starting from a blank prompt each time. Cohere's whole public description is one line: "Agents that keep context across sessions, instead of starting cold every time," from the launch post.

The post gives no storage location, no retention period, no deletion mechanism and no admin control specific to memory. The North product page mentions persistent context and "audit-ready visibility," and is equally silent on retention. Paul Teyssier, Cohere's VP of Product AI, told VentureBeat that "memory lets context persist longer across sub-sessions and agents," and did not give a duration.

"Across sub-sessions and agents" is the phrase to read twice. If memory written by one agent can be read by another, the access boundary on that memory is no longer the user who created it. It is whatever scoping rule Cohere built, and Cohere has not published that rule.

To be fair to Cohere, this is a launch-day blog post, and the detail may sit in admin documentation customers can see. On-premises deployment also changes the question. If the memory store runs on your hardware, nothing leaves your building, and you can in principle find the table and drop rows. That is real, and it is why regulated buyers pick North. It still leaves you needing to know which table, keyed to which identity, with what written into it.

How Microsoft Answered the Same Questions

Microsoft's documentation for Microsoft 365 Copilot memory shows what a usable answer looks like, gaps included. Per Microsoft's own docs, memories are stored in a hidden folder in the user's Exchange mailbox, admins switch the feature off tenant-wide through the enhancedPersonalizationSetting Graph resource (on by default), and admins can find and delete memories through Purview eDiscovery.

The same page lists what Microsoft does not offer: no audit logging of memory actions, no way for admins to restrict what gets written to memory, and Purview retention policies that do not apply to Copilot memory. Saved memories persist until the user deletes them.

That is the level of detail to ask Cohere for. A buyer evaluating Copilot can at least read the limits and decide. A buyer evaluating North 2 cannot, yet. We covered what that Copilot gap costs during an incident in Copilot Memory Survives Your Password Reset.

Why Memory Is a Data Protection Problem

Memory turns an assistant that forgets into a system that keeps records about people, and records about people carry legal duties. Under GDPR Article 17, a data subject has the right to obtain erasure of their personal data "without undue delay." When a former customer or a departing employee files that request, your data protection officer has to find every copy, including whatever an agent decided to remember.

Agent memory makes that hard in three ways. The agent chooses what to write, so nobody pre-approved the fields. Memory written from one employee's session may describe a customer, so it is keyed to the wrong person for a lookup. And if memory is shared across agents, one deletion has to reach several stores. We went through the build options in Zep vs Mem0 vs Postgres, where erasure was the deciding factor.

Why Memory Is a Security Problem

A persistent memory store is also the one place a prompt injection can survive the end of a session. In September 2024, researcher Johann Rehberger showed that a malicious website or image could plant instructions in ChatGPT's long-term memory on macOS that kept exfiltrating chats in later conversations, TechSpot reported. OpenAI first closed his report as a safety issue, then shipped a partial fix.

The 2026 version is worse. The MemGhost paper, posted to arXiv on July 6, 2026, used a single email to make an agent write a false fact into durable memory and hide that it had done so, according to The Hacker News. It succeeded in 87.5% of background-mode runs against OpenClaw on GPT-5.4, and input filters missed it nine times in ten. The researchers' mitigations were concrete: confirm before writes reach durable memory, log every memory change, and keep email-reading agents away from memory-writing tools.

North 2 connects to Outlook and Exchange out of the box. HiddenLayer CTO Jacob Rideout told VentureBeat that the company uses North for agent workflows over untrusted data sources. So the questions are whether North 2 logs memory writes, whether an admin can require confirmation, and whether an agent that reads inbound email can write to shared memory. SiliconANGLE says North screens for prompt injection; nobody has published how well.


The Token Caps Are the Part You Can Use Now

North Admin's spend controls are specific and immediately useful. The launch post lists "granular cost controls, rate limits, user quotas, and org-wide caps," with consumption tiers set by request and token rates for users and groups. VentureBeat adds usage tracking broken down by model, user and department, and alert thresholds that warn teams before a cap bites.

On self-hosted North your cost is the GPUs you already bought, so a cap works as a capacity allocation: it stops one runaway agent loop from starving the rest of the cluster. That makes per-agent caps more valuable on-premises than in a SaaS product, where the bill is the only damage.

The caps do not fix the pricing opacity. Without a published price, you cannot model what a tier costs. Ask for the price per unit the caps are measured in.

What the Aleph Alpha Merger Adds to the Question

The merger raises the stakes on getting terms in writing now. The deal still needs regulatory clearance, and the combined company would carry a reported $20 billion valuation, up from Cohere's $7 billion in September 2025, with dual headquarters in Berlin and Toronto and a €500 million commitment from Schwarz Group. SiliconANGLE notes the deal keeps the Cohere name on the combined company.

That commits to a company name, and nothing in it binds how memory behaves. Products get merged after deals like this, and memory behaviour is the kind of default that changes in a platform consolidation. Our exit-clause analysis covers what a change-of-control clause should say. Background on the deal itself is in our merger coverage.

What to Do Before You Enable North 2 Memory

This Week:

  1. Ask your Cohere account team, in writing, five questions: where memory is stored in your deployment, what an agent is allowed to write to it, how long entries live by default, whether memory is shared across agents or users, and how an admin deletes everything about one named person.
  2. Confirm whether memory can be switched off org-wide and per agent, and whether it ships on or off by default after upgrade. Keep it off until the answers come back.
  3. Set North Admin caps per agent, not only per user, on any agent that loops or runs on a schedule.

This Month:

  1. Have your DPO run a mock erasure request against a test tenant with memory enabled, and record how long it takes and what it misses.
  2. Have your red team plant an instruction in an inbound email to an agent with Exchange access, and check whether it lands in memory and whether a log shows it.
  3. Benchmark one workflow with memory on and off. Memory can make answers worse; see our MemTrapBench write-up.

Before Renewal:

  1. Put memory retention, scope, deletion and audit logging into the order form or DPA, not a help-centre page.
  2. Ask for published unit pricing behind the consumption tiers, and add a change-of-control clause that covers memory defaults.

The Bottom Line

Memory is becoming standard across agent platforms. Google already meters memory and bills revisions as storage, and Microsoft documents its gaps. Cohere has shipped the feature to the buyers who most need to explain where their data goes, and has not yet told them. On-premises control means you can answer the question yourself, provided Cohere tells you where to look. Send the five questions to your account team before the upgrade window opens.

Continue Reading

Share:

Frequently Asked Questions

What is new in Cohere North 2?

North 2, announced October 5, 2026, adds a rebuilt orchestration layer, cross-session agent memory, reusable skills, an app and automation builder, and North Admin spend controls with user quotas, rate limits, consumption tiers and org-wide token caps. It runs self-hosted, in a VPC, on-premises, air-gapped or hybrid.

How long does Cohere North 2 agent memory retain data?

Cohere has not published a retention period. The launch post says only that agents keep context across sessions, and Cohere's VP of Product AI told VentureBeat memory persists across sub-sessions and agents without giving a duration. Ask for retention, scope and deletion terms in writing before enabling it.

How much does Cohere North 2 cost?

Cohere does not publish North 2 pricing. It told VentureBeat pricing is based on the scale and complexity of a deployment, including infrastructure, usage patterns, support and customization.

Why is agent memory a GDPR concern?

Memory stores context about people that the agent chose to write, often keyed to the employee whose session created it rather than the customer it describes. GDPR Article 17 requires erasure without undue delay, so you need to know where memory lives and how to delete everything about one named person.

Can prompt injection poison agent memory?

Yes. Johann Rehberger showed in 2024 that a malicious web page could plant persistent instructions in ChatGPT memory, and the 2026 MemGhost paper planted false memories through a single email in 87.5% of background-mode runs against OpenClaw on GPT-5.4. Log memory writes and keep email-reading agents away from memory tools.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →