Google Research has published a workshop report on the privacy and security challenges posed by increasingly autonomous AI agents. The report, produced with more than 50 academic and industry participants at the Contextual Agent Privacy and Security workshop in New York in late 2025, argues that agents cannot be secured with traditional software methods. It identifies three distinguishing characteristics: unstructured interfaces that invite prompt injection, probabilistic control flows that evade standard testing, and autonomy that makes user oversight impractical.

To address these issues, the authors draw on Contextual Integrity, a theory that defines privacy as the appropriateness of information flow according to social norms. They propose extending this idea to contextual security, so agents evaluate whether an action is socially appropriate before executing it. A key contribution is the idea of a contextual policy engine, a supervisor component that generates and enforces context-specific policies in real time, bridging the gap between high-level norms and low-level permissions.

While the report is a research agenda rather than a product roadmap, it frames a multi-layered set of open problems across system, model, user, and ecosystem levels. The authors argue that LLMs finally make machine-readable, context-dependent policy feasible, but significant work remains.