Google Research workshop report maps open problems in agentic AI privacy and security

Google Research workshop report maps open problems in agentic AI privacy and security

On October 5, 2026, Eugene Bagdasarian (Research Scientist) and Marco Gruteser (Principal Scientist) of Google Research published a post presenting a workshop report titled "Open and Emergent Problems in Agentic Privacy and Security: A Contextual Angle". The report is the product of the Google Contextual Agent Privacy and Security (CAPS) Workshop, held in late 2025 in New York City, which brought together more than 50 academic and industry leaders from numerous institutions.

The starting point is that computing is shifting toward general, increasingly autonomous agents. Driven by large language models that can generate plans on the fly and call external tools, they could handle complex multi-step tasks for users. The catch, according to the authors, is that a useful agent may need access to personal data and the ability to take consequential actions across many contexts. That, together with agents' behavioral flexibility, calls for approaches meaningfully different from those used for traditional deterministic software. The post says agents differ from such software in three critical dimensions, and that these create challenges the research community must tackle together. It announces the three dimensions but the text does not list them.

The report is grounded in the theory of Contextual Integrity (CI). CI defines privacy not just as secrecy or control but as "appropriate information flow" according to established and justifiable social norms. A context-specific informational norm is defined by three things: its actors (who sends and receives information about whom), the types of information (categories such as medical or financial records), and transmission principles (the rules governing the flow, such as confidentiality or reciprocity). The post's example: you might share a gift shopping list with a virtual shopping assistant, but not with your family and friends. The report extends and generalizes CI from information sharing to what it calls contextual security, meaning the appropriateness of an agent's actions. The aim is to design systems that evaluate whether an action is socially and contextually appropriate before executing it.

The authors argue that, for the first time since CI was developed, LLMs offer a chance to create machine-readable policy that is truly context dependent. Historically there has been a semantic gap between high-level contextual norms and low-level system permissions. Their example is a request like "protect my data while organizing my travel for a conference", which needs specific instructions on what user information is appropriate to share when booking flights, applying for visas and communicating with organizers. They say manual permissions or expert-written policies cannot scale to a future where agents autonomously perform multiple complex, long-running tasks. As language models begin to understand CI, they argue, the gap can be bridged.

The report's central proposal is to complement advances at the model and user-interaction levels with a contextual policy engine that forms part of a supervisor layer, monitoring and enforcing the appropriateness of actions. The engine includes a dynamic policy generation loop that can operate in real time, tailoring policies to the user's request and to open-ended, dynamic contexts, including new tools and capabilities discovered at runtime. This would let the system judge whether a requested data flow is appropriate before any information leaves the user's workspace. Together with model-level and user-level advances, this makes for a multi-layered approach; the report outlines opportunities for innovation across the stack, though the post's list of those opportunities is not reproduced in the text.

The report also calls for new safety evaluations suited to highly autonomous, multi-agent systems. It highlights the need for standardized multi-agent benchmarks, described as dynamic "Agent Gym" environments where researchers can safely simulate complex, cascading interactions over extended periods. These open-source sandboxes would establish a shared privacy, security and safety baseline across academia and industry.

The post closes by calling the effort ambitious and too large for any single discipline, organization or sector. It describes the report as a call to action for academia, government, civil society and industry. Lillian Tsai is credited as co-primary author and Sarah de Haas with coordinating the workshop, report writing and the blog post. Kassem Fawaz, Stefan Mellem, Helen Nissenbaum and Nina Taft contributed to conceptualization and writing across several sections and guided the writing process. Bagdasarian is also an Assistant Professor at the University of Massachusetts Amherst.

Key facts

  • Google Research published a workshop report on agentic privacy and security on October 5, 2026, from the CAPS Workshop held in late 2025 in New York City with more than 50 academic and industry participants.
  • It builds on Contextual Integrity, which defines privacy as appropriate information flow, and extends the idea from information sharing to contextual security, the appropriateness of agent actions.
  • The main proposal is a contextual policy engine in a supervisor layer, with a real-time policy generation loop, that would check a requested data flow before information leaves the user's workspace.
  • The authors argue that manual permissions and expert-written policies cannot scale to autonomous, long-running agents, and that LLMs that begin to understand CI could close the gap between social norms and system permissions.
  • The report calls for standardized multi-agent benchmarks, described as open-source "Agent Gym" sandboxes, and for coordinated defenses at the system, model, user and ecosystem levels.

Why it matters

Agents that book travel, share documents and call tools need access to personal data and the power to act. The post argues that this makes privacy and security a different problem from the one traditional deterministic software poses. Its answer is to frame both as questions of context: who is sharing what, with whom, under which rules. The report also stretches Contextual Integrity, an existing privacy theory, beyond data sharing to the appropriateness of actions. It is a research agenda from a large workshop, so its value is in naming the open problems and the shared direction, not in a new result.

Who it affects

The report addresses researchers and practitioners across academia, government, civil society and industry, whom the authors call on to collaborate. In practice it speaks most directly to people designing agent platforms, permission systems and safety evaluations, and to users who would delegate personal data and tasks to agents. The workshop itself drew more than 50 participants from numerous institutions.

How to use it

There is nothing to install: this is a set of research directions, and the post invites readers to read the full technical report. The ideas can serve as a framework for thinking about agent design. A norm can be described by its actors, the types of information involved and the transmission principles. A supervisor layer with a policy engine could evaluate a requested data flow before anything leaves the user's workspace. The proposed "Agent Gym" sandboxes are meant as a shared testing ground for multi-agent privacy, security and safety, though they are proposed, not said to exist yet.

How solid is it

This is a first-party post from Google Research, written by two of the report's contributors, and it summarizes a collaborative workshop report with named co-primary and section authors. It reports no experimental results, benchmarks, measurements or attack data. Its central claims are framed as arguments and advocacy: the authors "argue" the semantic gap can be bridged as language models begin to understand CI, and the report "advocates" for the policy engine. Treat it as an informed position, not as evidence that the approach works.

Risks and caveats

The contextual policy engine is a proposed research direction. The post does not say it is built, deployed or shipped in any Google product, and gives no timescale or roadmap. The three dimensions in which agents differ from traditional software, and the list of opportunities across the stack, are announced in the post but not spelled out in its text, so the detail sits in the full report. The "Agent Gym" environments are also still a proposal. The approach depends on language models actually understanding contextual norms, which the authors present as something that is beginning to happen, not as something shown.

“To be useful, AI agents must understand and be constrained by contextual behavioral norms to ensure they act appropriately.”

— Eugene Bagdasarian and Marco Gruteser, Google Research