The AI portability trap

Written by
Isabella Vahdati

Anyone who has used an LLM will have a working understanding of ‘context’. Context is what the model has to work with; it decides whether what comes back is useful. But as the heavily overused saying goes: garbage in, garbage out. Shopify's Tobi Lütke popularised the phrase context engineering in June 2025, calling it the work of giving a model everything it needs to have a fair chance at the task (Simon Willison). OpenAI's own documentation describes context engineering as "shaping what the model knows at any given moment” (OpenAI Cookbook).

Context needs to continuously evolve. It gets better the longer it has been watching one person do one kind of work. It adapts to your individual ways of working and your desired outputs to deliver what you need, reliably.

Arjun Karanam, co-founder of Trajectory, made this point in a talk for Sequoia last month. Models get smarter every week but they don’t gain experience: however capable they are, "it's their first day on the job" (BigGo). His example is Fields Medal winning mathematician, Terence Tao: if he joined an accounting firm, he would be a novice - but he would quickly become an expert. Agents have the IQ but none of the adaptation. In the talk, Arjun Karanam finished with "Every company should own its own experience layer that never stops evolving" (StartupHub).

This problem becomes trickier when we think about the movement of people. Picture this scenario:

A marketing lead resigns after three years. On her last day she loses access to the tenancy (the company's own account and instance of the tool) where she built everything: the agent that drafts campaign briefs in the house voice, the project with four years of customer research loaded into it, the eleven prompts she rewrote until the output stopped needing edits, the approval sequence she set up with legal for anything mentioning a competitor. Her replacement inherits none of it either. On Monday she opens a fresh account at the new job and starts again.

The experience layer in this example splits into two things with different owners:

  • The skill layer is the prompts, the workflows, the accumulated sense of what a good output looks like and how to get one. This belongs to the employee.
  • The context layer is the customer records, the transcripts, the pricing, the board papers and the source code, and that belongs to the firm.

The tools keep both in the same account inside the same tenancy, so the skill layer cannot leave without dragging the context layer along with it. The real fault line runs through skills, memory and workflows at once, and where each of those boundaries actually sits, what counts as portable craft versus what stays locked to the employer's systems, is not yet settled for any of the three.

None of this is unreasonable. Your employer owns the work you do in the role, and it follows without much of a stretch that they own the systems you built to do it. The law says the same thing almost everywhere. In the US the work-made-for-hire doctrine treats the employer as the author of whatever an employee creates in the course of employment (Klemchuk), and UK law arrives in the same place, with section 11(2) of the CDPA making the employer first owner unless the contract says otherwise (Freshfields). Continental author's-rights systems leave the right with the creator, but the employment contract licenses it to the employer anyway, and for software the economic rights vest in the employer outright (Orrick). A prompt library is better protected as a trade secret than as copyright in any case, which lands it with the employer too. The data portability rules do not help the employee either, GDPR Article 20 covers what you gave the controller and not what it worked out about you, and inside an enterprise tenancy the controller is your employer (GDPR Local).

Perhaps this further enhances the rise of the freelancer, who keeps their own tenancy and compounds across engagements rather than resetting at each one. But where do the rules stand there? Carta's practitioners report that AI clauses in NDAs went from rare to common in a short period, and that the compromise forming in the market is a tier restriction rather than a ban: prohibit public and consumer generative AI, permit controlled enterprise-grade systems where confidential data is not shared externally or used for training (Carta). Layerz makes the same distinction from the practitioner side, arguing that three separate restrictions get collapsed into a blanket belief that AI is off limits, when the typical clause constrains which data, on which tier, with whose consent (Layerz). Some counsel go further and want separate written authorisation before confidential information enters even a private or enterprise deployment (Gallagher & Kennedy). Clients will take AI, but (understandably) not a setup that they can't check.

This is also relevant for the consumer market. Every major AI assistant shipped cross-session memory through the first half of 2026, and none of it works across vendors, because each one built memory to keep you in its own product rather than as a record your own (MemoryLake). A category of independent tools has grown into that gap. MemoryRouter sells a single vault behind an MCP endpoint that ChatGPT, Claude and coding agents all read (MemoryRouter). Echo does cross-platform memory across ChatGPT, Claude, Gemini and Cursor (Echo). MemVerge launched MemoryBox in August, keeping everything on the user's own device (PR Newswire). Nimble takes the same local-first approach on macOS. Egoist has a user-owned context store that apps request scoped and revocable passes against, with receipts showing which app read what. All of them solve one problem well, which is that a person should not have to explain themselves twice.

At work it runs the other way. The consumer products assume one person, one vault and one owner, and the whole promise is that everything follows you everywhere. Almost none of that survives contact with a job, as most of the material is not yours to move. There are other parties whose permission you need, and their interests conflict with each other. And what you want is close to the opposite of total recall: a context layer scoped to one engagement, sealed off from the others and probably gone at the end, with a skill layer above it that does travel.

A few companies are working the professional end of it. Shakers (Brighteye portco), sits between more than 600 companies and the freelancers working for them, and certifies its builders not only on what they can do but on how transparent they are in their use of AI and agents, backed by ISO 27001 and its own framework of guarantees. Shakers plays the role of the intermediary to its clients, certifying the transparency of agent use.

We do not envisage a world in which freelancers are not using AI to enhance their outputs. The problem is not what they can do, it is what they can show. A freelancer can already show quite a lot: which vendor and which tier they are on, a team or enterprise subscription with contractual commitments on training and retention, a signed data processing agreement, and in regulated professions a supervisory body and indemnity cover behind all of it. Cyber Essentials or ISO 27001 if the engagement is worth the cost. What none of that tells a client is whether their material is sealed off from the last client's inside the freelancer's own workspace, or whether it is really gone when the work ends. This is challenging to certify.

There is a loss on both sides that none of this reaches. What she built is closer to a working copy of how she thinks than to a document, and a copy like that is only worth something to someone who can read it. Without a proper handover nobody ends up with the workflows. When the marketing lead leaves, her replacement probably has little idea what her workflows do or why they were built that way, so they get rebuilt or abandoned. She rebuilds them too, from memory, at the new job. The employer is left with artefacts it cannot use and she spends time redoing work she has already done. If you are building here, we would like to talk.

I’m building what’s next

Share your deck and a few lines about what you’re building.

Submit a pitch
I have a question

For partnerships, media and general enquiries, we’d love to hear from you.

general enquiries