Cohere's North 2 gives agents a memory that persists across sessions, and Cohere has not said what that memory holds, how long it keeps it, or how you delete one person's share of it. If you run North on-premises or air-gapped because a regulator or a sovereignty rule told you to, that memory is a new store of employee and customer context sitting inside your perimeter. Get the scope, retention and deletion terms in writing before anyone turns it on. The token caps in the same release are the part you can use on day one.
Cohere announced North 2 on October 5, 2026, about 14 months after North reached general availability in August 2025 and less than three weeks after Cohere signed its merger agreement with Aleph Alpha on September 16. It is the release Cohere will pitch to banks, telcos and public bodies as the sovereign alternative to the US suites.
What Cohere Actually Shipped in North 2
North 2 is a rebuilt agent platform with five additions that matter to a buyer: an orchestration layer, memory, reusable skills, an app builder, and spend controls in North Admin.
Cohere's launch post describes an orchestration system that "manages complex, multi-step processes independently," plus skills (reusable capabilities agents call on), shared libraries, a drag-and-drop automation builder, and generation of decks, dashboards and lightweight apps. SiliconANGLE reports that the orchestrator escalates to a human when it needs to, and that agents built from simple prompts can be shared across a company.
Deployment options are the reason most buyers look at Cohere North at all. The launch post lists self-hosted, VPC, on-premises and hybrid, and SiliconANGLE adds fully air-gapped installations. Cohere cites SOC 2 Type 2, ISO 27001 and ISO 42001, content-filtering guardrails and per-agent autonomy policies. Connectors cover Slack, SharePoint, OneDrive, Outlook, Exchange, Jira, Linear, Notion and GitHub, with PitchBook, Crunchbase, S&P Global, FactSet and others listed as planned.
Named customers include LG CNS, Bell Cyber and CoreWeave, which Cohere presents as a customer support case study with a 90-day timeline. Cohere picked those references, and none comes with independently measured results.
Price is not published. Cohere told VentureBeat that pricing is "based on the scale and complexity of a customer's deployment, including infrastructure requirements, usage patterns, support and customization."
What North 2 Memory Stores, and What Cohere Has Not Said
Agent memory is a persistent store the agent writes to during one session and reads from in later ones, so it keeps context about users, projects and decisions instead of starting from a blank prompt each time. Cohere's whole public description is one line: "Agents that keep context across sessions, instead of starting cold every time," from the launch post.
The post gives no storage location, no retention period, no deletion mechanism and no admin control specific to memory. The North product page mentions persistent context and "audit-ready visibility," and is equally silent on retention. Paul Teyssier, Cohere's VP of Product AI, told VentureBeat that "memory lets context persist longer across sub-sessions and agents," and did not give a duration.
"Across sub-sessions and agents" is the phrase to read twice. If memory written by one agent can be read by another, the access boundary on that memory is no longer the user who created it. It is whatever scoping rule Cohere built, and Cohere has not published that rule.
To be fair to Cohere, this is a launch-day blog post, and the detail may sit in admin documentation customers can see. On-premises deployment also changes the question. If the memory store runs on your hardware, nothing leaves your building, and you can in principle find the table and drop rows. That is real, and it is why regulated buyers pick North. It still leaves you needing to know which table, keyed to which identity, with what written into it.
How Microsoft Answered the Same Questions
Microsoft's documentation for Microsoft 365 Copilot memory shows what a usable answer looks like, gaps included. Per Microsoft's own docs, memories are stored in a hidden folder in the user's Exchange mailbox, admins switch the feature off tenant-wide through the enhancedPersonalizationSetting Graph resource (on by default), and admins can find and delete memories through Purview eDiscovery.
The same page lists what Microsoft does not offer: no audit logging of memory actions, no way for admins to restrict what gets written to memory, and Purview retention policies that do not apply to Copilot memory. Saved memories persist until the user deletes them.
That is the level of detail to ask Cohere for. A buyer evaluating Copilot can at least read the limits and decide. A buyer evaluating North 2 cannot, yet. We covered what that Copilot gap costs during an incident in Copilot Memory Survives Your Password Reset.
Why Memory Is a Data Protection Problem
Memory turns an assistant that forgets into a system that keeps records about people, and records about people carry legal duties. Under GDPR Article 17, a data subject has the right to obtain erasure of their personal data "without undue delay." When a former customer or a departing employee files that request, your data protection officer has to find every copy, including whatever an agent decided to remember.
Agent memory makes that hard in three ways. The agent chooses what to write, so nobody pre-approved the fields. Memory written from one employee's session may describe a customer, so it is keyed to the wrong person for a lookup. And if memory is shared across agents, one deletion has to reach several stores. We went through the build options in Zep vs Mem0 vs Postgres, where erasure was the deciding factor.
Why Memory Is a Security Problem
A persistent memory store is also the one place a prompt injection can survive the end of a session. In September 2024, researcher Johann Rehberger showed that a malicious website or image could plant instructions in ChatGPT's long-term memory on macOS that kept exfiltrating chats in later conversations, TechSpot reported. OpenAI first closed his report as a safety issue, then shipped a partial fix.
The 2026 version is worse. The MemGhost paper, posted to arXiv on July 6, 2026, used a single email to make an agent write a false fact into durable memory and hide that it had done so, according to The Hacker News. It succeeded in 87.5% of background-mode runs against OpenClaw on GPT-5.4, and input filters missed it nine times in ten. The researchers' mitigations were concrete: confirm before writes reach durable memory, log every memory change, and keep email-reading agents away from memory-writing tools.
North 2 connects to Outlook and Exchange out of the box. HiddenLayer CTO Jacob Rideout told VentureBeat that the company uses North for agent workflows over untrusted data sources. So the questions are whether North 2 logs memory writes, whether an admin can require confirmation, and whether an agent that reads inbound email can write to shared memory. SiliconANGLE says North screens for prompt injection; nobody has published how well.
The Token Caps Are the Part You Can Use Now
North Admin's spend controls are specific and immediately useful. The launch post lists "granular cost controls, rate limits, user quotas, and org-wide caps," with consumption tiers set by request and token rates for users and groups. VentureBeat adds usage tracking broken down by model, user and department, and alert thresholds that warn teams before a cap bites.
On self-hosted North your cost is the GPUs you already bought, so a cap works as a capacity allocation: it stops one runaway agent loop from starving the rest of the cluster. That makes per-agent caps more valuable on-premises than in a SaaS product, where the bill is the only damage.
The caps do not fix the pricing opacity. Without a published price, you cannot model what a tier costs. Ask for the price per unit the caps are measured in.
What the Aleph Alpha Merger Adds to the Question
The merger raises the stakes on getting terms in writing now. The deal still needs regulatory clearance, and the combined company would carry a reported $20 billion valuation, up from Cohere's $7 billion in September 2025, with dual headquarters in Berlin and Toronto and a €500 million commitment from Schwarz Group. SiliconANGLE notes the deal keeps the Cohere name on the combined company.
That commits to a company name, and nothing in it binds how memory behaves. Products get merged after deals like this, and memory behaviour is the kind of default that changes in a platform consolidation. Our exit-clause analysis covers what a change-of-control clause should say. Background on the deal itself is in our merger coverage.
What to Do Before You Enable North 2 Memory
This Week:
- Ask your Cohere account team, in writing, five questions: where memory is stored in your deployment, what an agent is allowed to write to it, how long entries live by default, whether memory is shared across agents or users, and how an admin deletes everything about one named person.
- Confirm whether memory can be switched off org-wide and per agent, and whether it ships on or off by default after upgrade. Keep it off until the answers come back.
- Set North Admin caps per agent, not only per user, on any agent that loops or runs on a schedule.
This Month:
- Have your DPO run a mock erasure request against a test tenant with memory enabled, and record how long it takes and what it misses.
- Have your red team plant an instruction in an inbound email to an agent with Exchange access, and check whether it lands in memory and whether a log shows it.
- Benchmark one workflow with memory on and off. Memory can make answers worse; see our MemTrapBench write-up.
Before Renewal:
- Put memory retention, scope, deletion and audit logging into the order form or DPA, not a help-centre page.
- Ask for published unit pricing behind the consumption tiers, and add a change-of-control clause that covers memory defaults.
The Bottom Line
Memory is becoming standard across agent platforms. Google already meters memory and bills revisions as storage, and Microsoft documents its gaps. Cohere has shipped the feature to the buyers who most need to explain where their data goes, and has not yet told them. On-premises control means you can answer the question yourself, provided Cohere tells you where to look. Send the five questions to your account team before the upgrade window opens.
Continue Reading
- Zep vs Mem0 vs Postgres: Buy the Memory Store Last
- Copilot Memory Survives Your Password Reset. Go Purge It.
- Agent Memory Cost 14 Points at Best. Test With It Off.
- Google Bills Agent Memory Now. Revisions Count as Storage.
- 7 OpenAI Alternatives. Only 3 Clear a Sovereignty Rule.
- AI Vendor Security Review: 6 Questions That Change the Answer
