Contents

Artificial Intelligence
On-premise AI architectures, local LLMs, RAG, autonomous agents. Intelligence you cannot afford to see switched off must be owned.
Explore →DataGovern
AI agents for the governance of documents and processes (NIS2, GDPR, AI Act), configurable to your company.
Explore DataGovern →
Admina Enterprise
Open Source AI governance: audit trail, PII redaction, bidirectional ALLOW/BLOCK/REDACT policies on any model, local or remote.
Explore Admina →
Linux Services & Systems
Design, deployment and management of on-premise Linux infrastructure: from servers to AI hardware, with data that stays yours.
Explore →From the personal note to company memory
The second brain idea, an external archive that remembers for you, starts as an individual practice. The metaphor is old: back in February 2008 Evernote’s then-CEO Phil Libin told TechCrunch that “the main idea of Evernote is to create an external brain.” But when that archive becomes an organisation’s memory, and you connect a language model that reads all of it, three things change at once: who can see what, who owns the container, and who answers to a regulator.
The personal side of the same question, from the origins of the Zettelkasten to the criticism and what still holds up as a practice, is covered in a parallel piece on Stefano Noferi’s blog: The personal second brain. Here we look at what happens when that same archive moves from the desk to the company.
Note. The figures, dates and contractual terms here come from public sources (vendor documentation, official announcements, trade press) as of 21 July 2026, and they change often. We report them as verifiable at that date, not as guarantees. Revenue and user numbers stated by vendors are self-reported and unaudited.
The market: searching inside the company
The category consolidated fast. Glean announced on 28 May 2026 that it had passed $300 million in annual recurring revenue, fifteen months after reaching $100M, on the back of a $150M round at a $7.2 billion valuation (June 2025). The large vendors answered by folding search into their own stack: Google Gemini Enterprise has been generally available since 9 October 2025 from $30 per user per month; Microsoft opened the Microsoft 365 Copilot Retrieval API in consumption-based preview and, from late April 2026, brought federated connectors to general availability, querying third-party sources in real time over the Model Context Protocol, under the user’s identity and without indexing data into Microsoft services. Atlassian included Rovo in paid Cloud plans at no additional upfront cost.
On the open side there is Onyx, an enterprise search platform with an MIT-licensed core, self-hostable including in air-gapped environments, with reported deployments at Netflix and Thales. It is the option that matters when the requirement is that the index never leaves the perimeter.
Three risks you only see after signing
The compliance posture is tier-gated
This is the point that surfaces in procurement, never in a trial. The guarantees that matter almost always sit on the top SKU: Notion documents zero data retention with model providers for Enterprise workspaces, while on lower plans data may be retained by the provider for up to 30 days; Granola disables training on customer data by default only for Enterprise customers; Tana puts SAML SSO, audit logs, a custom DPA and residency/retention controls only in its custom-priced Business plan. Worth adding: Notion also documents an opt-in programme (“AI LEAP”) that trades workspace-data sharing for early access to features, an explicit carve-out from the default posture that belongs in any review.
The operational consequence is simple: the posture you evaluate in a trial is not the posture you get, unless you buy the tier that contains it.
Lock-in comes with a price that changes
The textbook case is Evernote. Acquired by Bending Spoons in January 2023, its free plan was cut from December 2023 to 50 notes and one notebook, and during 2025 the legacy plans were replaced by Starter (around $99/year, capped at 1,000 notes) and Advanced (around $250/year). Bending Spoons has meanwhile picked up fifty-plus digital properties (Vimeo, WeTransfer, AOL, Eventbrite) and listed on Nasdaq on 1 July 2026, raising about $1.68 billion at $29 a share and closing its first day near $40.50. The acquire-and-reprice model is now capitalised on a public market.
You do not need a change of ownership to lose a feature. Notion announced on 25 June 2026 that Notion Mail will shut down on 22 September 2026, with product-only data to be exported by hand by the 21st: and Notion Mail descended from Skiff, acquired in February 2024 and shut down in August of the same year. In March 2026 Granola encrypted its local macOS cache, breaking the third-party tools that read it; after the backlash it published a REST API and an MCP server, but with access tied to the Business and Enterprise plans. Programmatic access moved from unofficial-and-free to sanctioned-and-paid.
The portability test almost nobody runs before signing: export your data, then read that export with a tool the vendor did not write.
The attack surface is the content
In September 2025, days after agents shipped in Notion 3.0, researchers demonstrated a prompt-injection chain in which a PDF containing hidden text drove a workspace agent into reading private data and exfiltrating it through the agent’s own web-search tool; the demonstration was amplified by Simon Willison and Bruce Schneier, and Notion later documented how it detects injected instructions in third-party content. It is the same pattern we described for coding agents: what the agent reads can command it.
It is worth noting where the worst damage of the period actually came from. In February 2026 Malwarebytes reported that a Firebase misconfiguration at Chat & Ask AI had exposed roughly 300 million messages belonging to more than 25 million users. The root cause is a problem of infrastructure hygiene.
Compliance: what actually applies, as of 21 July 2026
Dates matter here, because the picture moved recently.
- AI Act. The Article 50 transparency obligations apply from 2 August 2026. The Digital Omnibus on AI was approved by Parliament on 16 June 2026, by the Council on 29 June and signed on 8 July 2026, but as of 21 July 2026 it has not yet been published in the Official Journal, so it has not entered into force and the original calendar remains the legally operative one. Once in force, it defers Annex III stand-alone high-risk obligations to 2 December 2027 and Annex I ones to 2 August 2028. GPAI obligations, applicable since 2 August 2025, are unchanged. We covered this in the AI Act and the Digital Omnibus.
- NIS2. In Italy, under Legislative Decree 138/2024 and ACN determination 379907/2025, important entities must implement 37 measures and 87 requirements, essential entities 43 measures and 116 requirements; for entities listed during 2025, full compliance with the security measures is expected by 31 October 2026, after which ACN moves from accompaniment to inspection. Sanctions for essential entities reach €10 million or 2% of worldwide turnover. An archive indexing technical documentation, procedures and incidents falls squarely inside that perimeter: see NIS2 in practice.
- GDPR. The EDPB’s Opinion 28/2024 of 17 December 2024 addressed legitimate interest as a basis for developing and deploying models, and when a model may be considered anonymous; on 7 July 2026 it adopted draft Guidelines 02/2026 on anonymisation, open for consultation until 30 October 2026 (draft, non-binding), applying a three-criteria test: singling out, linkability, inference. In Italy, the Garante’s decision 364/2024 indicates for employee mailbox metadata an indicative retention of a few days and normally no more than 21, exceedable only on demonstrated technical and organisational grounds. Indexing corporate mailboxes into an AI search engine is exactly where that guidance bites.
- Data residency. The AWS European Sovereign Cloud has been generally available since 15 January 2026, with its first region in Brandenburg. One legal limit no region solves: the US CLOUD Act lets US authorities compel a US provider to produce data in its possession, custody or control regardless of where it is stored. European residency under a US-parented vendor is not jurisdictional immunity.
What actually works, technically
The technical part is less glamorous than the pitch, and the public data is clear on several points.
Below a certain size, you do not need RAG. Anthropic’s own guidance is explicit: for knowledge bases under roughly 200,000 tokens (about 500 pages), put the whole corpus in the prompt instead of building a retrieval system. Many corporate “RAG projects” are, in fact, small corpora.
When you do need it, the order of operations is measurable. Also from Anthropic (September 2024): prepending model-generated context to each chunk before embedding cuts top-20 retrieval failures by 35%; adding contextual BM25 reaches 49%; adding a reranker reaches 67%. The reranker is the best return on effort, and retrieving 20 chunks instead of 5 helps more than people expect.
Long context is not a shortcut. Chroma’s Context Rot study (July 2025, 18 models) shows degradation is non-uniform and begins well before the advertised limit, and that a single distractor already hurts. NoLiMa (ICML 2025) is even more relevant to corporate memory: when the question and the target information share no wording, 11 of 13 models fall below 50% of their short-context performance at just 32K tokens. That is precisely what happens when you remember the concept but not the exact phrasing used in the document.
Verbatim text beats summaries. A controlled ablation (a single-author preprint, so treat it with care) holding retrieval fixed finds verbatim chunks beat model-extracted artifacts by 15.9 points on LoCoMo and 22.0 on LongMemEval-S, and that adding artifacts to chunks does not improve on chunks alone. Structured memory adds to the original text, it does not replace it.
On how to organise the derived layer, the pattern we follow is the one we wrote about in LLM Wiki: a Markdown knowledge base maintained by the model on top of immutable sources, versioned in git. It is a layer that is auditable by construction, and in a NIS2 or AI Act context that is worth as much as answer quality.
The on-premise stack
Putting the three risks and the regulatory constraints together, the configuration we propose to clients is consistent with what we have written for a while: the corpus and the index stay inside the perimeter, the model is a swappable component behind an endpoint, and a control plane sits on top.
Running serious models in-house is no longer the bottleneck it was: engines like KTransformers and colibri run enormous MoE models on company hardware, and the open-weight frontier keeps closing on the closed models, from GLM 5.2 to Kimi K3. When a remote model genuinely is the right call, the point is to govern it: an audit trail of every interaction, PII and secret redaction, ALLOW/BLOCK/REDACT policies over any model, local or remote. That is what Admina does. And on the document side, where company memory meets regulatory duties, it is the ground DataGovern covers: agents that read documents and processes, cross-reference NIS2, GDPR and the AI Act and prepare the evidence, with the decision staying with the team.
What we think
The corporate second brain is a good idea with a premise worth stating plainly: you are building an index of everything your company knows, and that index inherits the permissions, the jurisdiction and the business model of whoever hosts it. The three items above are not hypotheticals: they are a free plan cut to 50 notes, a product closed with ninety days’ notice, an encrypted cache that broke integrations, a PDF that made an agent talk.
AI enterprise search works and saves real time, so it is worth keeping. For us the answer lies in owning the operational floor: corpus and index inside the perimeter, a swappable model, a derived layer that is versioned and auditable, and explicit governance over all of it. That is the sense of Open Intelligence, Secure Governance, applied to the place where a company keeps what it knows. Company memory is its least replaceable asset: it is worth deciding calmly where it lives, on infrastructure that stays yours.
Sources
- Anthropic: Introducing Contextual Retrieval
- Chroma: Context Rot, how increasing input tokens impacts LLM performance
- NoLiMa: Long-Context Evaluation Beyond Literal Matching (arXiv:2502.05167)
- EDPB Opinion 28/2024 on AI models and the GDPR
- Garante privacy, decision no. 364 of 6 June 2024 (email metadata)
