Oracle Releases Agent Memory and Deep Data Security for Its AI Database

Updated: 6 days ago
Title: Oracle Releases Agent Memory and Deep Data Security for Its AI Database
Date: 8 May 2026
Type: Blog
Author: SAASiQ (contact@saasiq.ai)
Word count: 1532 words
Reading time: 6 min
Published: 08-05-2026
Oracle made Deep Data Security available in Oracle AI Database 26ai on 1 May, and on 4 May its developer team released Oracle AI Agent Memory, a Python package that keeps an AI agent's working context and long-term memory in the database. Both ideas were first announced on 24 March, alongside prebuilt agents for Oracle's no-code Private Agent Factory and 22 Fusion Agentic Applications. OCI Enterprise AI, Oracle's cloud service for building and hosting agents, has been generally available since 31 March, and Oracle's monthly AI roundup on 8 May listed two new models for it.
What Oracle announced on 24 March
Oracle used its AI World Tour event in London on 24 March to announce a set of agent features for Oracle AI Database 26ai. The list included a Unified Memory Core for storing agent context, three prebuilt agents for Private Agent Factory, Deep Data Security, and a Private AI Services Container that runs AI models in a customer's own public cloud, private cloud or data centre, air-gapped sites included, so that data is not shared with a third party.
It also announced Trusted Answer Search, which uses AI Vector Search to match a question to a report someone has already built instead of having a model generate the answer, and Vectors on Ice, which lets the database read and index vectors held in Apache Iceberg tables in a data lake. A new Autonomous AI Vector Database went into limited availability on Oracle's free and developer tiers, with a one-click upgrade to the full Autonomous AI Database.
Oracle presented these features as an extension of its converged database. The announcement says the Unified Memory Core enables reasoning 'across vector, JSON, graph, relational, text, spatial, and columnar data in one converged engine', so an agent's context sits in the same system, under the same transactions and security, as the business data it works on.
Private Agent Factory
Private Agent Factory is older than the March announcement. Oracle introduced it alongside Oracle AI Database 26ai at AI World in October 2025, as a no-code tool for building agents and workflows on data held in the database. Users build agents on a canvas that connects MCP servers, documents, databases, prompts and a choice of LLM, with in-database AI through Select AI, and data can be loaded from files, Oracle databases, SharePoint, object storage and REST APIs.
It runs in containers under Podman on Oracle Linux 8 or macOS, according to Oracle's installation guide, and there is a one-click deployment from the OCI Marketplace. It needs an Oracle AI Database 26ai instance to hold its data. The models can be private or in the cloud: Oracle lists vLLM, Ollama, OpenAI, Google and the models in OCI Generative AI. Oracle says it comes at no additional cost to Oracle AI Database customers.
InfoWorld described the three new prebuilt agents on 25 March. The Database Knowledge Agent turns a question in plain language into a query that retrieves a specific fact, policy or record. The Structured Data Analysis Agent uses Python's pandas library on SQL tables or CSV files to produce charts, trends and flagged anomalies. The Deep Data Research Agent breaks a larger question into steps and works through web sources and document libraries.
Agent memory in the database
Oracle AI Agent Memory, published on PyPI as oracleagentmemory, is the developer release of the memory idea, announced on 4 May by Wojtek Pluta of Oracle's developer team. Short-term memory holds an active session as a thread, with summaries and 'context cards' covering recent turns, task state and progress so far. Long-term memory stores user preferences, learned rules and facts from earlier sessions and retrieves them with vector search, and an LLM decides automatically what to extract from each conversation.
The package is not tied to one agent framework. Oracle says LangGraph, the Claude Agent SDK, the OpenAI Agents SDK, Oracle's own WayFlow and plain Python can all use the same client against the same store. Tenants are kept apart at the storage layer, memories are scoped per user and per tenant with an audit trail, and individual records can be deleted for compliance purposes.
Oracle's post gives one cost figure, from its own demo. Over an eight-query conversation, summarising the thread once it reached 10,000 tokens used a mean of 121,268 tokens in total, about 60 per cent fewer than the 306,823 tokens used by sending the full history with every request. It is a single vendor demonstration.
Deep Data Security goes live
Deep Data Security became available in Oracle AI Database 26ai on 1 May. It moves per-user access rules into the database. The identity of the end user, and of any agent acting for them, is passed to the database at runtime, and policies written in SQL decide which rows, columns and individual cells come back, with sensitive values masked.
Oracle's reasoning is about agents that write their own SQL. Most business applications connect through one privileged account and filter results in their own code, which works because their queries are written in advance and can be checked. An agent inherits that connection but generates new queries, and a prompt can steer it into asking for data its user should not see. With the policy held in the database, the same rule applies whichever agent, application or SQL tool sends the query. Deep Data Security is a 26ai feature, and databases on 19c keep the older tools for this, Virtual Private Database and Real Application Security.
How agents reach the database
The Model Context Protocol is the open standard AI assistants use to find and call tools, and two Oracle MCP servers were available at the start of May. The first, in the SQLcl command-line tool since July 2025, runs on a developer's own machine with that person's database credentials.
The second is built into Autonomous AI Database. Since 23 December 2025 each Autonomous AI Database on Serverless infrastructure, on 19c or 26ai, has had its own managed MCP server, included with the database, according to Oracle's release notes. It exposes the tools a customer defines with Select AI Agent, shows each user only the tools they are authorised to use, and applies the database's existing roles, access control lists, auditing and Virtual Private Database policies. Oracle listed it in the 24 March announcement as a way for outside agents to reach the database without custom integration code.
OCI Enterprise AI and its models
OCI Enterprise AI is the cloud service. Oracle announced it on 24 March and the release notes date general availability to 31 March, in nine regions: Chicago, Ashburn, Phoenix, Frankfurt, London, Osaka, Hyderabad, São Paulo and Riyadh. Its Responses API is compatible with OpenAI's, so existing OpenAI SDKs work against it, and it includes file search, a code interpreter, function calling and calls to remote MCP servers, with short- and long-term memory for conversations.
Work is organised into projects, each with its own conversations, files, memory and data-retention settings. The service also hosts agent applications built with open-source frameworks or as MCP servers, on public or private endpoints, and has an NL2SQL feature that reads a customer's schema and turns questions in plain language into SQL.
xAI's Grok 4.3, a reasoning model with a one-million-token context window, was added to OCI Generative AI on 1 May. Oracle's roundup on 8 May also listed NVIDIA's Nemotron 3 Nano Omni, an open model that reasons across video, audio, images and text. The same roundup noted Oracle's 1 May agreement with the Pentagon to deploy its AI on classified networks, using its ten cloud regions for US government customers. Oracle was one of eight companies to sign such an agreement that day.
Agents inside Fusion Applications
For Fusion customers the agents come inside the applications. Oracle announced 22 Fusion Agentic Applications on 24 March, available immediately across ERP, HCM, supply chain and CX. Each is a coordinated team of AI agents built into Fusion, working with the application's own data, workflows, approval hierarchies and permissions. The examples Oracle gave included a Collectors Workspace for cash collection, a Workforce Operations application for scheduling approvals and a Cross-Sell Program Workspace for sales teams.
On 9 April Oracle published two more announcements, one describing 12 agentic applications for finance and supply chain, among them a Sourcing Command Center, a Warehouse Operations Workspace and a Maintenance Operations Workspace, and one describing eight for HR. Oracle says the agents inherit the role-based access controls and data permissions already set up in Fusion. It also added an Agentic Applications Builder to AI Agent Studio, so customers can assemble their own from Oracle, partner and external agents.
What needs 26ai
SAASiQ's view is that the database release a customer runs decides how much of this it can use now, because Private Agent Factory and Deep Data Security both need Oracle AI Database 26ai, while the Autonomous AI Database MCP server also works on 19c.
Oracle's April Release Update for 26ai, 23.26.2, reached Linux on 1 May, and on 30 April the database team advised customers to move to 19c or 26ai with the April updates applied. The first of Oracle's new monthly security patch updates is due on 28 May.
SAASiQ - Intelligent Solutions for SaaS ©


