Google Research Explores Privacy and Security for Autonomous AI Agents
Google Research has released a comprehensive report, "Open and Emergent Problems in Agentic Privacy and Security: A Contextual Angle," following a collaborative workshop held in late 2025. The report, developed by over 50 academic and industry leaders, explores the privacy and security challenges posed by increasingly autonomous AI agents powered by large language models (LLMs). These agents, designed to handle complex, multi-step tasks, present unique challenges due to their access to personal data and ability to take consequential actions.
The core issue highlighted in the report is the trade-off between agent capability and appropriate behavior. Unlike traditional software, agents operate with unstructured interfaces, probabilistic control flows, and autonomy, making traditional security methodologies inadequate. The report emphasizes the need for a contextual lens to ensure agents act appropriately within specific social norms and contexts.
To address these challenges, the report introduces the theory of Contextual Integrity (CI), which defines privacy as "appropriate information flow" according to established social norms. The report extends CI to contextual security, aiming to design systems that evaluate the social and contextual appropriateness of agent actions before execution. This involves creating machine-readable policies that are truly context-dependent, bridging the gap between high-level norms and low-level system permissions.
The report advocates for a multi-layered approach to agentic privacy and security, including system-level sandboxing, model-level reasoning, user-centric controls, multi-agent interactions, and ecosystem governance. It also proposes new approaches to safety evaluations that apply to highly autonomous, multi-agent systems, highlighting the need for standardized benchmarks.