The cuddly faces of the AI agents being released are not accidental. They are designed to pull you in, make you comfortable. Easy to lean in, difficult to leave. But the real question is who owns their memories.
Anyone remember Clippy back in the day? Or the other little iconic helpers they attempted to unleash on us? They were endearing at first, but ultimately they felt, well, just wrong; and for the most part they were harmless.
Clippy never held your email, your calendar, customer files, and financials. He could not learn how your business works and start doing it the way you would.
Some of the newest helpers (Dots, Muse, Claude) are cuter than Clippy, and they are being handed the keys to your business, even if you aren't aware of it.
Those cute faces are the bait. The memory they keep is the hook.
What builds up behind those faces can make it hard to leave, because the model is replaceable and what it accumulated is not. Both are deliberate design decisions, with a foreseeable effect: vendor lock-in and education.
But like the Gremlins, the trouble starts when nobody is following the rules.
Is the friendly face on purpose?
It is deliberate, and the designers say so.
Meta's Muse team called an avatar and personality "a delightful and most natural choice," because "it felt very odd talking to a corporate logo or entity." Google's Gemini design team, on the app's visual system, listed "alleviating potential concerns" among its challenges and wrote: "When a system is hard to approach, the design must be soft."
OpenAI has not said why Dots arrive as a triangle in a bow tie or a bunny in headphones, but it doesn't take a genius to understand what they are doing. Fast Company, not OpenAI, wrote that Dots "seem designed to defang the technology."
Claude gets the same standard. Anthropic's constitution says it wants Claude to be engaging "only in the way that a trusted friend who cares about our wellbeing is engaging," and admits Claude's behavior "might not always reflect the constitution's ideals." It does not say who owns what Claude remembers.
What does the smile collect?
Nir Eyal wrote Hooked, the playbook for habit-forming products, the playbook famously applied by the social media companies. The investment phase, he writes, asks the user to put in "time, money, physical effort, social capital, or personal data." In March he said "The investment phase is where all the AI genius is headed," and that a habit-forming product "must get better with use. It must store value."
OpenAI says the more you work together, the more your dot "learns your preferences, how you think, and what good looks like to you." Its help page says a dot "can create its own memories, including from connected apps," and that "Disconnecting an app does not delete information your dot has already obtained from it. To delete that information, you need to delete your dot." You need to delete your assistant, your "friend".
VentureBeat's Carl Franzen argued that a named assistant that remembers preferences "may become harder to replace than a generic chatbot, especially once it accumulates permissions, workflows and knowledge about how its user operates."
In two experiments posted to arXiv, with 3,500 people in all, making a chatbot more humanlike "did not universally increase trust or engagement." Not surprising, it hints at the uncanny valley. Cute is easier to lean into than "almost human."
But it was testing conversation, not avatars or connected accounts. Regardless of the face, the hook still sets.
Remember Gizmo? The cutest creature in Gremlins came with three rules: no bright light, no water, and never feed him after midnight. The trouble was never the cuteness.
We all wanted a Gizmo. But while you're pulled in by those big eyes and cuddly sounds, you forget a rule by accident and then... mayhem.
An agent has rules too: what it may see, do without asking, and keep. Meta's designers named the risk, "banner blindness," where "people approve everything to make it go away."
Who owns what your agents learn?
A personal agent learns one person, inside one vendor. VentureBeat warned that "employees may arrive with increasingly capable personal agents just as companies are deploying sanctioned corporate ones." Add them up and your challenge isn't siloed teams, it becomes a private silo for every person: many private memories and no organizational one.
But that's just one issue. The larger question is, do you or your employees own the created memory, and what about the model vendor?
Gartner's George Brocklehurst, talking about software vendors, says the most important clause in the next generation of contracts is "Who owns what the system learns from you?" He told CIO: "If it accrues to the vendor's shared models, your operational experience is improving a product your competitors also use."
In a June 2026 survey by IBM, which sells hybrid cloud and AI, 71 percent of 1,000 senior executives said switching their primary AI vendor or model would be difficult. That is a perception, and it concerns the vendor or model, not the memory.
What an agent learns about a person leaves with the person or stays with the vendor. What your organization learns about its own work has to live somewhere it owns. That is the difference between an individual's memory and organizational intelligence.
Where do you start?
First, put Gartner's clause in every agent contract, and add what leaves with you when you do.
Second, find out which agents your people have connected to work accounts, what they may do without asking, and what they kept when someone disconnected. You cannot answer what an agent does when nobody is watching without that inventory.
Third, decide where your organization's memory of its own work lives before a vendor decides for you. That is the work behind a Source of Truth engagement: scattered documents, systems and tribal knowledge consolidated so your people and your AI use the same record.
None of this argues against friendly design. AdoptAI, the adoption module inside UniversalContext, uses some of the same design principles: badges and leaderboards meant to make people want to use it.
Eyal's own test applies: persuasive technology should never "coerce people into doing something they later regret." The difference is where it points: what people learn lands in a layer your organization owns and everyone in your organization benefits from, so adoption builds organizational intelligence instead of feeding a vendor's memory.
In the film, the rule everyone remembers is the one about midnight. Yours has no clock. Sooner or later, somebody on your team will name an agent, give it a face and connect it to your work, and it will start learning your business.
It will stay cute the whole way through. In the movie, at least, you could see when the rules had been broken.
Before the next one gets a key to anything, ask the question no smile answers: who owns what it remembers?
Sources
Every quotation and figure above, with its full citation. Dots is a day old as of publication and Muse, launched September 8, is about three weeks old; the OpenAI help page is a living document.
- Meta, "How We Designed Muse", introducing.muse.ai, September 2026 (the page gives no day). Quoted: the avatar and personality as "a delightful and most natural choice", and "it felt very odd talking to a corporate logo or entity", from the design team; the "banner blindness" passage on approval prompts. introducing.muse.ai
- Google Design, "Illustrating the Gemini App", undated. The team writes about the Gemini app's visual system, not a mascot. design.google
- OpenAI, "Introducing dots", September 29, 2026, and OpenAI Help Center, "Getting started with your dot", read September 30, 2026 and marked updated hours earlier. OpenAI states no reason for the dots' characters. openai.com, help.openai.com
- Grace Snelling, "OpenAI's new dots agent comes with a crew of friendly mascots", Fast Company, September 29, 2026. "Defang" is Fast Company's reading, not OpenAI's. fastcompany.com
- Carl Franzen, "OpenAI launches Dots, always-on AI agent coworkers, and ChatGPT Space...", VentureBeat, September 29, 2026. The lock-in passage is the author's analysis and is hedged with "may". venturebeat.com
- Anthropic, "Claude's Constitution". A statement of intent about the model, not evidence of how Claude behaves. The page is undated. anthropic.com
- Nir Eyal, "User Investment: Make Your Users Do the Work", nirandfar.com; and "Beliefs Are Tools, Not Truths: Beyond Belief with Nir Eyal", Analyse Asia, edited transcript, March 10, 2026. Eyal offers the investment phase as an opportunity, not a criticism, and did not name Dots or Muse. nirandfar.com, analysepodcast.com
- Robin Schimmelpfennig, Mark Díaz, Vinodkumar Prabhakaran and Aida Davani, "Humanlike AI Design Increases Anthropomorphism but Yields Divergent Outcomes on Engagement and Trust Globally", arXiv:2512.17898, preprint, February 2026. Two experiments, 3,500 people in total, ten countries; it tests conversational human-likeness in a chatbot, not avatars or connected accounts. arxiv.org
- Gartner, press release, July 1, 2026, and Gyana Swain, "Agentic AI puts $234B in enterprise SaaS spending at risk, Gartner says", CIO, July 2, 2026. Brocklehurst speaks of enterprise software vendors; applying his clause to personal agents is this post's inference. cio.com
- IBM Institute for Business Value with Oxford Economics, "The Calculus of AI Sovereignty", as reported in IBM's press release of June 17, 2026. A survey of 1,000 senior executives across 16 countries and 17 industries, fielded February to April 2026, self-reported. IBM sells hybrid cloud and AI. The measure is switching the primary AI vendor or model, not agent memory. newsroom.ibm.com
Universal Mind sells UniversalContext, which has a stake in the answer this post argues for. Read the argument with that interest in mind. This post uses no client relationship as evidence.
