Security & AI news

AI agent privacy and security · By FireAI Security & Research Team · Published

Google Research argues that AI agents need privacy and security defined by context, not by secrecy alone

Google Research published a report on 5 October 2026 from a workshop of over 50 experts: agents need contextual integrity, sandboxing and user controls.

Levels and the FireAI radar-lab mascot, illustrating a Google Research report on privacy and security for AI agents based on contextual integrity.

Google Research published a report on 5 October 2026, written by Eugene Bagdasarian and Marco Gruteser, that sets out open problems in the privacy and security of AI agents [1]. It draws on the company’s Contextual Agent Privacy and Security workshop, held in New York City in late 2025 with more than 50 academic and industry contributors [1]. The report matters to Mac users because desktop agents increasingly hold personal data and can take actions on it.

Background

Traditional software privacy often treats data as something to keep secret. An agent has to read personal data and act on it to be useful, so secrecy alone does not describe the problem. The report states that, for an agent to be useful, it “may need to have access to personal data and the ability to take consequential actions” across contexts [1].

What the report describes

The authors name three features that distinguish agents from earlier software: unstructured interfaces and input ambiguity, where natural language makes prompt injection possible; probabilistic control flows, where generative planning produces unpredictable execution paths; and autonomy and delegation, where long tasks create the risk of confirmation fatigue [1].

The report builds on contextual integrity, a theory that defines privacy as appropriate information flow, judged by the actors involved, the type of information and the transmission principles [1]. It extends the idea to “contextual security”, which asks whether an agent’s action is appropriate in the situation before the action runs [1].

The proposed response has several layers: system-level sandboxing with dynamic capability limits, model-level reasoning about whether an action is appropriate, dynamic and user-centred controls, guardrails across multiple agents to prevent collusion, ecosystem governance to standardise norms, and dynamic safety evaluations [1].

Implications for Mac users

The report is a research agenda, not a product or a standard. For an individual, it supports a practical stance: judge an agent by whether each action fits the task, and limit what it can reach, since a mistaken or manipulated instruction acts with the agent’s permissions [1]. The attention to confirmation fatigue suggests that approval prompts alone are a weak control when they appear constantly.

Recommendations

  1. Give each agent only the folders, accounts and tools that the current task needs.
  2. Treat text an agent reads from the web, mail or documents as untrusted input that can contain instructions.
  3. Read approval prompts for consequential actions rather than approving them by habit.
  4. Prefer agents that run inside a sandbox with limits you can change.
  5. Watch the network connections of agents you run, and investigate destinations that do not match the task.

Relevance to FireAI

FireAI covers one layer the report discusses: observing what leaves the Mac. The Agent profile recognises 19 AI agents, learns for the first 3 days which destinations each normally contacts and flags a first-ever destination or an upload spike for review, using only host names and byte counts. The kill switch and per-app rules let the user stop or restrict an app’s connections.

FireAI does not judge whether an agent’s action is contextually appropriate, and it does not sandbox an agent or limit the files it reads. It does not read prompts, memory or the inside of an encrypted connection, and it does not implement contextual integrity.

Limitations

This item relies on one page, Google Research’s own post, and no second outlet was fetched. The post states problems and directions; it does not report measurements or incidents [1]. The company that publishes the report also builds agents, which is a context readers may weigh.

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. Google Research, 5 October 2026: Open and emergent problems in agentic privacy and security, a contextual angle