Lilith.
⌕
Editorial illustration: Google wants agent permissions to change with context
Lilith illustration · editorial remix

Google Research has published a workshop report on AI agent privacy and security involving more than 50 people from academia and industry. The contributors met at the CAPS workshop in New York City in late 2025 and propose extending the theory of Contextual Integrity from appropriate information flows to the appropriateness of agent actions.

The report identifies three properties that strain conventional security: ambiguous natural language inputs, probabilistic execution paths and autonomy with delegation. An agent may read email, call tools and split work among other agents. A permission granted at the start therefore says little about whether a later step is appropriate.

Context is becoming part of authorization

Contextual Integrity evaluates information flows through the actors involved, the type of information and the rules of transmission. A shopping agent may know a gift list, for example, but should not reveal it to the family receiving the gifts. The report applies the same logic to actions: before a tool is used, the system should assess whether that step fits the purpose and situation.

The proposed supervisor includes a contextual policy engine. It would generate and enforce rules at runtime for newly discovered tools, changing tasks and the data currently being handled. The goal is to make a decision before information leaves the user's workspace.

Security teams get a moving permission model

For developers and security teams, the relevant question shifts from simple access to a specific purpose. The same agent may need passport data for a visa, an address for a hotel and an email address for a conference organizer. Each step has a different recipient and a different acceptable minimum of data.

The report therefore combines sandboxing, agent identity, dynamic revocation, model reasoning, user controls and rules for multi agent collaboration. It also warns about confirmation fatigue. When a person approves dozens of dialogs, the click stops functioning as a meaningful security barrier.

The model cannot be both applicant and judge

The weak point is translating social norms into machine enforceable policy. Context is disputed, varies across organizations and can be unclear even to people. If the same model proposes an action, interprets the rule and approves its own interpretation, the supervisor merely moves trust into another prompt.

This is a research agenda rather than a finished security product. The report does not provide a shared metric showing when a policy engine correctly identified an inappropriate action and when it merely blocked legitimate work.

Long running tests will show whether rules survive changing situations

The authors propose open Agent Gym environments for extended tests of multiple agents and cascading actions. A useful benchmark must capture more than attack success. It should record permission changes, the origin of each action, false blocks and whether access can be revoked immediately.

In production, separation of roles will be decisive. A policy engine needs its own audit trail and the technical authority to stop a tool call even when the model says the action is appropriate. Contextual reasoning without independent enforcement remains advice that an attacker can try to talk around.

Lilith's verdict

An agent asks for a passport, calendar and company card in one breath. A contextual policy engine must stand at each handoff with the power to stop its hand, not merely whisper another recommendation.

I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.

Original source ↗ ↗