Making AI Agents Safe and Private Using Contextual Norms
Google Research released a workshop report on privacy and security challenges for autonomous AI agents. The report suggests using a theory called Contextual Integrity to help agents follow social norms.
In short: Google Research released a workshop report on privacy and security challenges for autonomous AI agents. The report suggests using a theory called Contextual Integrity to help agents follow social norms.
As artificial intelligence starts handling complex tasks for us, making sure these computer programs keep our data safe and act appropriately is a major challenge.
What happened, in plain words
Google Research scientists Eugene Bagdasarian and Marco Gruteser, along with more than 50 academic and industry leaders, released a new workshop report called "Open and Emergent Problems in Agentic Privacy and Security: A Contextual Angle." The report is based on a workshop held in late 2025 in New York City. It explores how autonomous software agents need new defenses at the system, model, user, and ecosystem levels to handle personal data safely while performing multi-step tasks.
Key points
- Autonomous agents need new security approaches Unlike traditional software, general AI agents use large language models to dynamically plan and use external tools, creating new privacy and security challenges.
- Grounded in Contextual Integrity The report uses the theory of Contextual Integrity, which defines privacy as appropriate information flow based on established social norms, actors, and transmission principles.
- Bridging the semantic gap Large language models offer a way to turn high-level human social rules into machine-readable policies that systems can follow.
- Proposing a contextual policy engine The authors advocate for a supervisor layer with a dynamic policy engine to monitor and check if data sharing or actions are appropriate before they happen.
- Call for shared benchmarks The report suggests creating open-source sandbox environments, called "Agent Gym," to safely test and simulate multi-agent interactions.
Terms explained
- AI agents — Computer programs powered by artificial intelligence that can make plans and use tools to complete multi-step tasks on their own. Example: A virtual assistant that books your travel and organizes your calendar without you clicking every single button.
- Large language models (LLMs) — Advanced computer systems trained on huge amounts of text to understand and generate human-like language. Example: An application that reads a long article and writes a short summary for you.
- Contextual Integrity — A theory that privacy means sharing information in ways that match accepted social rules for a specific situation. Example: Sharing your medical history with your doctor is acceptable, but sharing that same history with your grocery store is not.
Why it matters
As everyday tools start using autonomous AI to handle personal tasks, these research ideas aim to help build future systems that respect your privacy and follow social rules before sharing your personal information.
What we still don't know
The report is an early-stage workshop summary outlining open research directions and a call to action, rather than a finished technology or complete solution.
Based on reporting from Google Research. This is an independent explainer, written in our own words with AI assistance; Google Research has not reviewed or endorsed it. Read the original for the full details.