MLCommons' Privacy and Confidentiality Working Group released version 0.1 of an Agent Privacy Risk Taxonomy on 1 October 2026 and opened it for feedback from industry, academia, civil society and regulators [1]. PPC Land reports that the document lists 25 risks in five areas [2]. The taxonomy matters to Mac users who run AI agents because it names, in one place, the ways such agents can hold or pass on more personal data than a task needs.
Background
A chatbot answers from what it learned in training and from the text a user types. An agent also acts: it reads files, calls tools and keeps records of its steps. The working group frames the shift as the difference between what a model knows and what it does [2].
What the taxonomy describes
MLCommons states that agents "observe continuously in the background, log every step they take, and carry memory across sessions, so they routinely hold more than the task needs" [1]. It groups the risks in five areas: data ingestion and processing, aggregation, use and sharing, inconsistent privacy practices between agents, failure of static consent, and accountability and governance [1].
On the first area, MLCommons notes that free text can reveal identifying information even when redaction is attempted [1]. On the second, it says agents may share or delete data without authorisation and depend on third-party tools they cannot fully control [1]. PPC Land adds that the draft lists items such as continuous tracking, trajectory logging, session persistence, indirect prompt injection, memory poisoning and the "mosaic effect", in which harmless fragments combine into something revealing [2].
For consent, the taxonomy says a one-time gate does not fit decisions that agents make continuously at run time [1]. PPC Land reports that the document names consent fatigue, described as "blind approvals", and that it quotes the view that agents operating over protocols such as MCP default to sharing exhaustive context windows [2]. The last area covers the difficulty of assigning responsibility and the lack of privacy-preserving logging standards across organisations [1].
MLCommons says the group plans to prioritise risks by deployment context, develop measurement indicators and pilot tests, and finish this work by the first quarter of 2027 [1].
Implications for Mac users
The taxonomy is a draft vocabulary, not a rule or a test. Its value for an individual is as a checklist of questions to ask about an agent: what it logs, how long it remembers, which tools it calls and whether a person approves each sensitive step [1] [2]. PPC Land notes that the draft contains no incident counts, measurements or mitigations [2].
Recommendations
- Find out whether each agent in use keeps a log of its steps or a memory across sessions, and where that record is stored.
- Limit the folders, accounts and tools an agent can reach to what the current task needs.
- Be cautious with approval prompts that appear often; a prompt approved without reading offers little protection.
- Avoid putting passwords, keys and identity documents into an agent session.
- Review the connections an agent opens and look for destinations that do not match its documented function.
Relevance to FireAI
FireAI is a firewall for one Mac. The Agent profile recognises 19 AI agents, learns for the first 3 days which destinations each normally contacts, and then flags a new destination or an upload spike for review, using only host names and byte counts. Per-app rules let a user block a destination for one app, and the privacy promise states that FireAI sends no telemetry.
FireAI does not read an agent's logs, memory or prompts, and it does not see what data an agent keeps or what a model infers. It does not read the inside of an encrypted connection. It does not rate an agent against the taxonomy, and it does not manage consent inside an agent.
Limitations
The two sources differ in how they name the five areas, and this item follows MLCommons' own post [1] [2]. The full 15-page document was not available to this item, so the individual risk names come from PPC Land's summary [2]. The taxonomy is version 0.1 and is open for comment, and neither source reports field evidence for any of the listed risks.
Try FireAI, by HisnLabs free for 17 days.