i
News
News · 2026-10-05

Google Research wants AI agents judged by the context of their actions

@neuronium_ai @neuronium_ai

Google Research is making a case for judging AI agents by the context they act in, not just by the data they handle. A report prepared by more than 50 researchers and industry specialists argues that privacy and security controls must account for who is involved, what information is at stake and what an agent is about to do. The proposal is a response to systems that plan on the fly, use outside tools and carry out long tasks with less direct oversight.

Cover: Google Research wants AI agents judged by the context of their actions

Why agents strain old safeguards

The report grew out of a Google CAPS workshop held in New York in late 2025. Its authors say agents create three problems for conventional software defenses:

Instructions arrive as ordinary text and images, making expected behavior harder to define and attacks such as prompt injection harder to prevent.
Agents generate plans probabilistically, so the same task can produce different action sequences that are difficult to secure with standard testing.
Long-running tasks and delegation to other agents reduce user oversight. Asking for confirmation too often can lead to “confirmation fatigue.”

The tension is practical: agents may need access to personal information and permission to take consequential actions to be useful. The more flexible they become, the less well a fixed list of permissions describes what they should be allowed to do.

Source: research.google

Privacy depends on the situation

The report uses contextual integrity, a theory that treats privacy as appropriate information sharing under justified social norms—not merely secrecy or control over data. Those norms depend on who is sharing information with whom, whose information it is, what kind of information is involved and the terms of its transfer, such as confidentiality or reciprocity.

A person might share a gift list with a virtual shopping assistant but not with family or friends. The authors extend the idea beyond information flows: an agent’s actions, too, should be judged for whether they fit the social situation.

That shifts the question from whether an agent has permission in general to whether a particular action is appropriate in context. The report’s example is a request to protect someone’s data while arranging a conference trip. A system would need to translate that broad instruction into specific rules for booking travel, applying for a visa and communicating with organizers.

From norms to enforceable rules

The authors argue that large language models make it possible to create machine-readable rules that account for context. They propose adding a contextual policy engine to the system’s oversight layer. It would monitor actions, restrict them when needed and update rules as a user’s request or working context changes, including when the agent discovers new tools and capabilities. Before sending data, the system could check whether that transfer is appropriate.

The engine is one part of a broader set of safeguards:

System-level sandboxes that dynamically grant or revoke access to data and tools, and establish an agent’s identity.
Model-level reasoning that helps agents judge whether actions are appropriate, clarify underspecified requests and account for changing norms.
User controls that are dynamic, contextual and personalized, rather than relying only on separate notices and choices.
Constraints on collaboration between agents to prevent collusion and violations of contextual norms.
Ecosystem-wide mechanisms for sharing norms, resolving conflicts, coordinating changes and checking compliance.

Source: research.google

The hard part is proving it works

The report also calls for standardized, multi-user benchmarks in dynamic “Agent Gym” environments. Open-source sandboxes, the authors say, could let researchers safely simulate complex, long-running interactions and build a shared basis for evaluating privacy, security and reliability.

I think the policy engine is the report’s most concrete proposal—and also where its hardest unanswered question sits. The report describes rules that can change with context, but does not establish how systems should resolve disagreements over what counts as an appropriate norm, or how reliably an agent can recognize a situation before acting. Without answers to those questions, contextual safeguards risk becoming another layer of rules whose limits are hardest to see precisely when an agent is operating on its own.

Daily AI news

Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.

Only what matters — every day

Follow on X