Open and Emergent Problems in Agentic Privacy and Security: A Contextual Angle
Google Research
Google says AI agents need new privacy and security rules. The twist: it wants them judged by context, not just permissions.
Based on reporting by Google Research — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Google Research has published a workshop report on a problem that’s about to get awkward fast: once AI agents can plan, use tools, and act with some autonomy, the old software playbook stops being enough. The report, “Open and Emergent Problems in Agentic Privacy and Security: A Contextual Angle,” comes out of the Google CAPS Workshop held in late 2025 in New York City and was shaped with input from more than 50 academic and industry leaders.
The basic tension is easy to state and hard to solve. Useful agents may need access to personal data and the ability to do consequential things across many contexts. But agents are not neat little deterministic programs. They take natural-language and image inputs, which makes “expected behavior” fuzzy and opens the door to prompt injection. They follow probabilistic execution paths. They also keep handing off work to other agents, which makes human oversight less and less useful and raises the risk of confirmation fatigue.
Google’s answer is to treat privacy and security as context problems. The report leans on Contextual Integrity, a theory that defines privacy as appropriate information flow, shaped by who is sending, who is receiving, what kind of information is involved, and what rules govern the transfer. The report extends that idea from information sharing to agent action: before something happens, the system should decide whether it is socially and contextually appropriate in that setting.
That requires more than a smarter model. The report argues for a supervisor layer with a contextual policy engine that can generate and update rules in real time, including when new tools appear at runtime. Around that sit multiple other layers: sandboxing at the system level, model reasoning about appropriateness, user controls that fit how people actually think, guardrails for multi-agent collaboration, and governance mechanisms that can handle conflicts between different norms.
The report also says current evaluation methods are not enough for this world. It calls for standardized multi-agent benchmarks and dynamic “Agent Gym” environments where researchers can simulate long, cascading interactions safely. The pitch is broad on purpose: this is framed as a shared problem for academia, government, civil society, and industry, not a niche model-safety paper with better branding.
My take — AI-written commentary, not fact-checked reporting
This is the right fight, and it’s overdue. The industry loves talking about autonomous agents like they’re just helpful interns, then acts surprised when the intern has access to everything and no sense of context. Privacy rules built for static software were never going to survive that joke for long.
Read more about this at: Google Research