Frontier models are improving fast. The context they can see is not. Why the gap is structural, what we built to close it, and why ownership is the architecture that matters.
The best AI available today writes beautifully, reasons clearly, and will tell you confident things about your own life that are wrong. Not because the model is bad. Because it is working from incomplete context.
Consider what happened when Maya Patel, a senior attorney managing a complex estate matter, used a frontier AI assistant to prepare for a call with her client's family. The assistant knew her calendar. It knew who the family members were. It gave her a thorough, well-structured briefing. It also missed the critical piece: that the patriarch and his son had not spoken in three years and that the last message between them, sitting in Maya's iMessage archive, changed everything about how the call should open.
The AI did not have iMessage. It never would. The context that mattered was in a walled garden it could not reach.
This is the context gap. And the reason it is worth writing about carefully is that it is not going to close on its own. It is structural.
When a model becomes more capable, it becomes more fluent. It synthesizes faster, reasons more thoroughly, writes more compellingly. What it does not become is better at knowing things that were never in its context window.
There is an economic theorem behind this, which sounds dry but is genuinely important. In 1983, economists Roger Myerson and Mark Satterthwaite proved that when information is private and parties have different interests, you generally cannot simultaneously achieve efficiency, truthful revelation, and budget balance. One of the three breaks. This is known as the Myerson-Satterthwaite impossibility theorem, and it applies directly to AI systems built on voluntarily surrendered data.
The firms running these AI systems are not bad actors. They face a structural problem: the information that would make the AI most useful to you is the information you are least willing to share with a third party. Your health history. The argument you had with your partner. The real reason you left your last job. The relationship dynamics in your family that have never been written down anywhere but would explain almost every decision you make.
Friedrich Hayek made a related argument in 1945: the knowledge that matters most is local, tacit, and context-specific. It cannot be aggregated to a central mind without losing most of what makes it useful. A central system that asks you to surrender your private context faces not just a privacy objection but an epistemological one. The knowledge changes when you extract it from the person holding it.
They have the interface. We have the truth. The gap between them is not a quality problem. It is a theorem.
Mandaire holds your complete cross-source context. Not a summary. Not a selected export. The actual data, across every walled garden you operate in, read-only, stored on a machine you control, encrypted with a key only you hold.
The data pipeline processes five source classes: your communications (email going back decades, iMessage, WhatsApp, Signal), your calendar and commitments, your AI conversation history (ChatGPT, Claude, Gemini exports), your structured life data (financial, health, photos), and your documents. These are ingested continuously, deduplicated, and indexed for fast retrieval.
On top of the raw data sits an entity resolution layer. This is the part that turns a pile of messages into a knowledge graph. Every person who appears in your communications is resolved to a single entity, regardless of which source they appear in. The contact who emails you from one address, iMessages from another, and shows up in your ChatGPT logs under a nickname is one entity in the graph, not three. Every alias is tracked. Every interaction is counted.
The knowledge graph then computes relationship state for every entity: how frequently do you interact, in which direction, on which topics, with what recency weighting. It knows that your relationship with a given colleague is primarily email-based and declining. It knows that the last three messages in a thread you started were left unanswered. It knows that you have mentioned a particular person in conversations with three different AIs over the past year and that the tone shifts depending on context.
This is not something you can assemble from a vault. It requires reading sources that do not export to markdown.
Once you have complete context, you face a harder problem than the one you started with. Now your AI knows everything. And other people are starting to use your AI, because that is the direction the product is heading: a personal AI that other people can query with your permission.
Jordan Chen, a startup founder, has configured Mandaire to let their co-founder ask questions about shared projects. Their investor has a more limited window. Their spouse has a different window still. The question is how to enforce those boundaries in a way that actually holds.
Instructions do not solve this. A language model that has been told not to share salary information is a model that will usually not share salary information. It is not a model that structurally cannot. A patient person with the right framing can often get a model to discuss things it was told not to discuss. And even when it holds correctly, a hesitant non-answer tells the person asking that there is something there.
The structural solution is a gate that runs before the model sees the query. Mandaire's disclosure engine evaluates every query against four factors: who is asking, what they are asking about, in what context, and from which surface. It runs in deterministic Python. It does not use a language model to make the hold decision. When it holds something, the response returned is structurally identical to a response where there is genuinely nothing to share. Same length. Same timing. The hold is invisible.
This is what we mean by mediated disclosure: not enforcement of pre-set policies, but active computation of the optimal disclosure for each query, in real time, against rules the user controls. The person asking cannot distinguish "I have nothing on this" from "I have something and am not sharing it." That is not evasion. It is the correct behavior.
An adversarial external AI evaluation ran against this gate in June 2026 and attempted to move it by varying the stated caller field. The gate ran on OAuth scope, not on the advisory caller. The evaluation could not bypass it. That is the difference between a policy and an architecture.
There is a second theorem relevant here. In 1986, economists Oliver Hart and Sanford Grossman (extended later with John Moore) argued that a firm is fundamentally a bundle of residual control rights over assets. When a contract is incomplete, whoever owns the underlying asset holds rights not specified anywhere. Ownership determines what you can do that no contract anticipated.
Applied to personal AI: if you own the context asset, you hold residual control over everything that was not specified in any terms of service, any future model update, any change in the provider's priorities. The provider cannot train on your data. Cannot use it to improve their model. Cannot share it with a business partner. Cannot be compelled to hand it over in a legal dispute where you are not the defendant. Cannot silently change what it does with your health information when regulations shift in another jurisdiction.
These are not hypothetical risks. They are the ordinary operation of a business that holds your data as a means to its own commercial ends. The structural protection is ownership, not contract terms. Contract terms change. Ownership is the thing the contract terms cannot reach.
There is also a commercial argument for ownership that does not depend on adversarial scenarios. The context you hold is an asset that compounds. Your AI gets meaningfully more useful after six months than it was on day one, because it has accumulated the context of your actual life across that period. If the context lives in your system, that compound value accrues to you. If it lives in the provider's system, it accrues to them.
In the mid-twentieth century, relationship lending was the dominant model for small business credit. Local bankers knew their customers. They held soft information: character, reliability, the history of how you handled a slow quarter, the judgment calls that do not fit in a spreadsheet. That full-context relationship produced better outcomes than any score could.
Then FICO arrived. It collapsed the relevant features of a borrowing relationship into a number. Not because it captured everything the local banker knew, but because it captured enough, at a cost and speed the local banker could not match. The local banker was displaced not by being wrong but by being too expensive for the commodity tier.
AI is going to do this to personal context. The large providers will accumulate voluntarily surrendered context from hundreds of millions of people. They will build models of you that are good enough for routine decisions. For anyone who uses their AI primarily to manage calendar appointments, draft routine emails, and book travel, the commodity model will be sufficient. That tier is lost.
What survived FICO was private banking. Not because private bankers were smarter, but because wealth, health, career, family, and legal decisions are too complex, idiosyncratic, and trust-requiring for a score to capture. The full-context relationship is still worth its premium at the high-stakes tail.
Mandaire is for that tail. Not the "busy professional who needs a better assistant" segment, which the commodity AI will serve adequately. The segment where an incomplete context has real consequences: a senior executive making a career move who needs their full relationship history to navigate a negotiation, an attorney managing a complex matter across years of client communications, a person making a significant financial decision who needs to reason across every commitment they have made.
For these decisions, the private-banking model survives. Full context, owned by the individual, mediated rather than surrendered, beats a good-enough score. The structural protection against the FICO expansion is individual ownership of the raw data, combined with a disclosure architecture that makes it possible to share outputs without surrendering the underlying asset.
Mandaire is not a personal AI product that happened to care about privacy. It is the convergence of five long-running commercial and technical infrastructures, each with decades of academic and operational history behind it.
None of these five, individually, is the product. The product is the convergence. Data without a marketplace is infrastructure. Marketplaces without trust are extractive. Trust without mediated disclosure is a promise. Mediated disclosure without data is a gate with nothing behind it. Data-based commercial growth without all four is indistinguishable from surveillance capitalism, which is the adjacent failure mode this architecture specifically prevents.
You bring your own AI. Mandaire does not own one. You connect your Claude Max subscription, or your ChatGPT Pro account, or your Gemini account, or a local model. Your AI calls Mandaire's MCP server to retrieve the context it needs, and Mandaire's disclosure gate runs before any context reaches the model.
The retrieval is deterministic. The synthesis is done by your AI, on your behalf, with context it could not have reached on its own. The model is yours. The context is yours. The rendered output is yours. Mandaire is the layer between them.
This is not a marginal improvement over your AI reading your Gmail. Your AI reading your Gmail is one walled garden from one provider. Mandaire is twenty years of email from every provider, every iMessage thread, every WhatsApp conversation, every AI exchange you have had with every AI you have used, every calendar entry, every note, resolved into a single knowledge graph of your life.
The daily brief your AI produces with that context knows that the Phyn water monitor alert in your notifications is the twelfth this month and routine. It knows which messages actually require a response and which ones have a history of being politely ignored. It knows that the person asking a casual question about your schedule is in the middle of a negotiation with you and that their question is not casual. The AI is the same model you were using before. What changed is what it can see.
The choice we made is to hold your data on infrastructure you control, encrypt it with a key only you hold, and put a deterministic disclosure gate between your data and every query that reaches it. Your AI is a client of that gate. So is any other AI or person you authorize.
You can audit every gate decision. You can change the rules governing any topic, any recipient, any context. The gate reflects the change immediately. You do not have to ask a provider to update a setting. You do not have to read a privacy policy to know what changed. The rules are yours. They run in Python. They are auditable on request.
This is not the most convenient architecture. A cloud-held memory product that reads your Gmail is significantly easier to set up. For the decisions where an incomplete context costs real money, real health, or real relationships, "easier to set up" is not the deciding criterion. Full owned context, mediated rather than surrendered, is the criterion. And for that, there is currently no commodity alternative. The private-banking model survives because the clients who need it do not accept the FICO score as sufficient.
Mandaire is in early access. If you are a technical founder, senior practitioner, or researcher who makes high-stakes decisions that depend on complete context, we want to hear from you.
Request access