Harvey, the legal AI vendor used by law firms and in-house legal departments, announced Harvey II in a post on its own blog, describing an agent architecture built to carry context and memory between tasks instead of starting each one cold. The change targets a specific cost lawyers already know: getting an agent caught up on a matter before it can do any real work. That framing is itself an admission, since it concedes the prior version of Harvey’s agents could not retain context on their own, a gap Harvey says limited how much substantive work it could safely hand off.
The system has two separate parts. The first, which Harvey calls a Space, holds a matter’s files, the parties involved, the assigned tasks and the permissions that apply, so an agent opening inside that Space inherits deal history without a lawyer re-supplying it by hand. The second is a memory layer that tracks an individual lawyer’s habits, such as how they format a summary or which citation style they prefer, and that profile carries across Harvey’s own product, Microsoft Word and Outlook. Harvey says users can view, edit or disable what the system remembers, and that this memory is not used to train its models.
Harvey is pairing that memory system with a new proprietary model, Harvey Tenet, described as the company’s first model post-trained specifically for legal reasoning rather than a general-purpose model adapted to law. Harvey claims Tenet reaches frontier-level scores on unnamed legal benchmarks while matching top general-purpose models at what it calls open-source-level cost. The announcement does not name those benchmarks, does not publish scores and does not compare Tenet against a named competitor’s model. Harvey’s own blog post is the only source for all of these claims. No independent evaluation accompanies the launch.
The harder question is what persistent memory means for confidentiality. Legal work runs on matter separation: a firm’s ethical walls exist specifically to stop information from one client’s file reaching another client’s team, and privilege can be lost if confidential material crosses that line. Harvey’s post says client data never moves between Spaces and that permissions sync from a firm’s existing systems, which speaks to document leakage across matters. What the post does not say is whether the memory layer, which is scoped to a lawyer rather than to a matter, could carry substantive detail from one client’s work into how it drafts for another. Harvey describes memory as learning from a user’s “edits and corrections,” a category broad enough to include more than formatting habits, and the announcement is silent on whether that layer sits behind the same ethical-wall controls as a Space.
Before letting an agent carry memory across clients, a firm would need Harvey to state, in writing, whether memory is scoped per matter or per user, whether it falls under the same access controls as Spaces, and whether outside counsel guidelines and malpractice carriers have reviewed cross-matter learning by a single lawyer’s agent profile. None of that appears in this announcement.
Firms already running Harvey should treat Spaces and memory as two separate risk categories. Document isolation at the matter level looks addressed on paper, but individual memory persistence has not been tested against conflicts-of-interest and ethical-wall obligations that predate any vendor’s product design.
Harvey described Harvey II and Harvey Tenet in a post on its own blog, harvey.ai, reviewed August 19, 2026.