
Shared AI Agent Memory Across All Users: The Real Implications of a Public AI Memory Pool
Sharing memory across every user of a public AI is three different architectures wearing one name: a private per-user layer, an attributed shared layer, and a de-attributed wisdom layer. Raw pooling without those boundaries produces 57-71% cross-user contamination from benign interactions alone, and 80-99% memory-poisoning success under attack. That is the short answer, and it is deliberately unflattering to the idea. The longer answer is more useful: cross-user sharing genuinely works where local experience is scarce, the failure mode nobody budgets for is not forgetting but confidently remembering somebody else’s local convention, and the security model changes so completely that standard prompt-injection controls do not catch it. This guide walks through what the 2026 research actually measured, what it costs, and the design rules that hold up when one memory pool serves an entire user base. ...