This continues the Self-Correcting Systems research on why relevance alone is insufficient for agent memory safety.

The previous gate stopped trusting the memory's own story about itself.

That was the right move, but it was not the final move.

After the article went live, ANP2 sharpened the remaining problem in the comments:

Inferring sensitivity from the natural-language query is still a self-description channel.