Google Research Publishes Workshop Report on Agentic Privacy and Security
Google Research has released a comprehensive workshop report exploring foundational privacy and security challenges in autonomous AI agents using Contextual Integrity.

The computing landscape is shifting rapidly toward general and increasingly autonomous agents. Powered by large language models that generate plans dynamically and invoke external tools, these systems can handle complex tasks on behalf of users. However, ensuring these agents act appropriately while maintaining their capability remains a major hurdle. Google Research recently shared a workshop report titled "Open and Emergent Problems in Agentic Privacy and Security: A Contextual Angle," following a late 2025 gathering in New York City that brought together more than 50 academic and industry leaders.
The report outlines foundational privacy and security obstacles that require coordinated defenses spanning system, model, user, and ecosystem levels. Unlike traditional deterministic software, autonomous agents introduce distinct characteristics: unstructured interfaces and input ambiguity, probabilistic control flows stemming from generative planning, and high levels of autonomy and delegation that can overwhelm traditional user oversight with confirmation fatigue.
The Contextual Lens and Policy Engines
To build trustworthy agents, the research points to the theory of Contextual Integrity (CI). This framework defines privacy as appropriate information flow according to established social norms, characterized by actors, information types, and transmission principles. The report extends this concept to contextual security, evaluating the appropriateness of agent actions.
Traditionally, a semantic gap has existed between high-level contextual norms and low-level system permissions. The report argues that language models can bridge this gap by enabling machine-readable policies. Researchers propose complementing model and user advances with a contextual policy engine within a supervisor layer. This engine utilizes a dynamic policy generation loop to evaluate data flows and actions in real time before information leaves the user's workspace.
Multi-Layered Defenses Across the Stack
Addressing agentic security requires innovation across multiple layers of the technology stack:
- System-level sandboxing: Dynamically limiting capabilities, establishing agent identity, and authorizing data access based on changing contexts.
- Model-level reasoning: Enabling models to disambiguate prompts and reason about appropriateness under shifting norms.
- User-centric controls: Moving away from traditional static notice-and-choice frameworks toward dynamic, contextual mechanisms.
- Multi-agent interactions: Establishing guardrails to prevent collaborating agents from violating contextual norms.
- Ecosystem governance: Developing mechanisms to resolve norm conflicts and verify compliance across domains.
To evaluate these systems, the report suggests dynamic, standardized multi-agent benchmarks, such as "Agent Gym" environments, to simulate complex interactions safely.
What it means for developers
Developers building applications with autonomous agents face new paradigms where traditional static permissions and deterministic testing fall short. As the industry moves toward contextual policy engines and runtime supervision, developers will need to integrate dynamic guardrails that evaluate actions based on social norms and data contexts. For those building and testing these next-generation applications, developers can try top AI models cheaply through one API at https://apixoai.online.
The report serves as a call to action for the broader research and development community across academia, government, and industry to establish robust foundations for safe and privacy-respecting agentic ecosystems.
Source: Open and Emergent Problems in Agentic Privacy and Security: A Contextual Angle — Google Research. Written by the Apixo team from that report.
One key for Claude, GPT, GLM, DeepSeek and more. Pay per token with crypto.
Get your API key

