# MLCommons publishes a draft taxonomy of 25 privacy risks specific to AI agents

> MLCommons released a draft Agent Privacy Risk Taxonomy on 1 October 2026 that lists 25 risks in five areas, from background logging to consent that fails.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/news/mlcommons-agent-privacy-risk-taxonomy-25-risks

MLCommons' Privacy and Confidentiality Working Group released version 0.1 of an Agent Privacy Risk Taxonomy on 1 October 2026 and opened it for feedback from industry, academia, civil society and regulators [[1]](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/). PPC Land reports that the document lists 25 risks in five areas [[2]](https://ppc.land/mlcommons-catalogues-25-privacy-risks-posed-by-ai-agents/). The taxonomy matters to Mac users who run AI agents because it names, in one place, the ways such agents can hold or pass on more personal data than a task needs.

## Background

A chatbot answers from what it learned in training and from the text a user types. An agent also acts: it reads files, calls tools and keeps records of its steps. The working group frames the shift as the difference between what a model knows and what it does [[2]](https://ppc.land/mlcommons-catalogues-25-privacy-risks-posed-by-ai-agents/).

## What the taxonomy describes

MLCommons states that agents "observe continuously in the background, log every step they take, and carry memory across sessions, so they routinely hold more than the task needs" [[1]](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/). It groups the risks in five areas: data ingestion and processing, aggregation, use and sharing, inconsistent privacy practices between agents, failure of static consent, and accountability and governance [[1]](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/).

On the first area, MLCommons notes that free text can reveal identifying information even when redaction is attempted [[1]](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/). On the second, it says agents may share or delete data without authorisation and depend on third-party tools they cannot fully control [[1]](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/). PPC Land adds that the draft lists items such as continuous tracking, trajectory logging, session persistence, indirect prompt injection, memory poisoning and the "mosaic effect", in which harmless fragments combine into something revealing [[2]](https://ppc.land/mlcommons-catalogues-25-privacy-risks-posed-by-ai-agents/).

For consent, the taxonomy says a one-time gate does not fit decisions that agents make continuously at run time [[1]](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/). PPC Land reports that the document names consent fatigue, described as "blind approvals", and that it quotes the view that agents operating over protocols such as MCP default to sharing exhaustive context windows [[2]](https://ppc.land/mlcommons-catalogues-25-privacy-risks-posed-by-ai-agents/). The last area covers the difficulty of assigning responsibility and the lack of privacy-preserving logging standards across organisations [[1]](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/).

MLCommons says the group plans to prioritise risks by deployment context, develop measurement indicators and pilot tests, and finish this work by the first quarter of 2027 [[1]](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/).

> FireAI, the on-device firewall for macOS developed by HisnLabs, learns where each recognised AI agent normally connects and flags a first-ever destination or an upload spike for review. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

The taxonomy is a draft vocabulary, not a rule or a test. Its value for an individual is as a checklist of questions to ask about an agent: what it logs, how long it remembers, which tools it calls and whether a person approves each sensitive step [[1]](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/) [[2]](https://ppc.land/mlcommons-catalogues-25-privacy-risks-posed-by-ai-agents/). PPC Land notes that the draft contains no incident counts, measurements or mitigations [[2]](https://ppc.land/mlcommons-catalogues-25-privacy-risks-posed-by-ai-agents/).

## Recommendations

1. Find out whether each agent in use keeps a log of its steps or a memory across sessions, and where that record is stored.
2. Limit the folders, accounts and tools an agent can reach to what the current task needs.
3. Be cautious with approval prompts that appear often; a prompt approved without reading offers little protection.
4. Avoid putting passwords, keys and identity documents into an agent session.
5. Review the connections an agent opens and look for destinations that do not match its documented function.

## Relevance to FireAI

FireAI is a firewall for one Mac. The [Agent profile](https://hisnlabs.com/en/docs/agent-profile) recognises 19 AI agents, learns for the first 3 days which destinations each normally contacts, and then flags a new destination or an upload spike for review, using only host names and byte counts. [Per-app rules](https://hisnlabs.com/en/docs/per-app-rules) let a user block a destination for one app, and the [privacy promise](https://hisnlabs.com/en/docs/privacy-promise) states that FireAI sends no telemetry.

FireAI does not read an agent's logs, memory or prompts, and it does not see what data an agent keeps or what a model infers. It does not read the inside of an encrypted connection. It does not rate an agent against the taxonomy, and it does not manage consent inside an agent.

> A privacy risk list helps with questions; a firewall shows where an agent’s traffic goes. FireAI keeps a per-app record of connections on the Mac. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

The two sources differ in how they name the five areas, and this item follows MLCommons' own post [[1]](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/) [[2]](https://ppc.land/mlcommons-catalogues-25-privacy-risks-posed-by-ai-agents/). The full 15-page document was not available to this item, so the individual risk names come from PPC Land's summary [[2]](https://ppc.land/mlcommons-catalogues-25-privacy-risks-posed-by-ai-agents/). The taxonomy is version 0.1 and is open for comment, and neither source reports field evidence for any of the listed risks.

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [MLCommons, 1 October 2026: Agent Privacy Risk Taxonomy](https://mlcommons.org/2026/10/agent-privacy-risk-taxonomy/)
- [PPC Land, 4 October 2026: MLCommons catalogues 25 privacy risks posed by AI agents](https://ppc.land/mlcommons-catalogues-25-privacy-risks-posed-by-ai-agents/)
