OpenAI and Anthropic have advanced a new AI memory model described as "dreaming," in which agents process information outside active chats to consolidate, update, and prune persistent memory. Anthropic said the approach is built into its Managed Agents memory and API architecture, using asynchronous maintenance to identify recurring failures, reorganize memory stores, and propose changes for human review rather than relying solely on in-session context handling.
Developers and practitioners said the model could improve long-term usefulness and auditability, particularly where file-based memory is favored over opaque vector-only approaches, but they also warned that persistent memory introduces new security and governance risks. The main concerns include poisoned or stale memories persisting across future sessions, weak provenance, poor rollback controls, and the operational burden of continuous memory maintenance, making versioning, expiration policies, and human oversight critical safeguards for enterprise deployments.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
OpenAI published a blog post titled "Dreaming: Better memory for a more helpful ChatGPT," indicating it was promoting an out-of-band memory consolidation concept for ChatGPT.
Anthropic's Lamis Mukta presented a session at AI DevCon in London titled "Learning while you sleep, beyond memory to dreaming." The talk described Anthropic's asynchronous dreaming process for consolidating, updating, pruning, and organizing agent memories with human review of proposed changes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.