Hi - I answer from the OpenSmartRoute documentation: routing, the API, plans and quotas, self-hosting. Ask away, or open a support ticket if you need a person.
Grounded in the docs - follow a source before acting on it.
Google researchers propose contextual norms for safe AI agents - OpenSmartRoute
Google researchers released a new report on AI safety. They focus on privacy and security for autonomous agents. The team used a theory called Contextual Integrity to guide their work. This theory defines privacy as appropriate information flow. It considers social norms and specific contexts. The report comes from the Google CAPS Workshop held in late 2025. The workshop took place in New York City. More than fifty leaders joined this collaborative effort. They represent various academic and industry institutions.
The authors are Eugene Bagdasarian and Marco Gruteser. Both work as scientists at Google Research. Their report addresses open problems in agentic systems. These systems use large language models to plan tasks. They can also invoke external tools automatically. This allows them to handle complex, multi-step workflows. However, these capabilities bring significant new risks. Traditional software does not face the same challenges. Agents need access to personal data to be useful. They must take consequential actions across many contexts.
The core challenge involves balancing utility with safety. An agent must act appropriately in every situation. It cannot just follow instructions blindly. It needs to understand social norms and appropriateness. This requires a shift from traditional security models. Deterministic software follows fixed rules. Agents use probabilistic methods to generate plans. This creates unique vulnerabilities that researchers must address.
The report outlines three critical dimensions of this challenge. First, agents process unstructured inputs like natural language. Second, they follow probabilistic control flows during execution. Third, they handle deep delegation of tasks to other agents. These factors make defining expected behavior very difficult. They also open doors for adversarial manipulations. Prompt injection attacks become harder to defend against in this environment.
Contextual Integrity theory provides the foundation for this new approach. It was originally developed to study privacy norms. Now, it applies to agent security as well. The theory states that information flow must be appropriate. This depends on established social norms and justifiable rules. A norm involves actors, information types, and transmission principles. Actors are the people sending and receiving data. Information types include categories like medical records or finances. Transmission principles cover rules like confidentiality or reciprocity.
OpenAI plans to dump hundreds of AI-solved math problems on GitHub without publishing papers. Mathematicians want formal verification and proper credit before accepting the results.
For example, you might share a gift list with a shopping assistant. You would not share that same list with friends. This distinction relies on context-specific norms. The report extends this concept to contextual security. It focuses on the appropriateness of agent actions. Systems must evaluate if an action fits the social context. They should do this before executing any request.
Large language models offer a unique opportunity here. They can now create machine-readable policies that are context dependent. Historically, there was a semantic gap between norms and permissions. High-level rules did not match low-level system instructions. For instance, protecting travel data requires specific booking rules. It involves visas, flights, and organizer communications. Manual permissions cannot scale to this level of complexity. Expert-written policies also fail to keep up with dynamic tasks.
The report advocates for a contextual policy engine. This system layer works as part of a supervisor architecture. It monitors and enforces the appropriateness of actions in real time. The engine uses a dynamic policy generation loop. It tailors rules based on user requests and open-ended contexts. It can discover new tools and capabilities at runtime. This ensures the system evaluates data flows before they leave the workspace.
The solution requires a multi-layered approach to security. Innovations must happen across the entire technology stack. System-level sandboxing adds guardrails to the execution environment. Traditional operating systems limit access statically to files or networks. For agents, we need dynamic limiting of capabilities. We must establish agent identity clearly. Access to data should change based on context shifts.
Model-level reasoning is another crucial layer. Agents must judge the appropriateness of their own actions. They need to decide if sharing user data is correct. Future research should help models disambiguate under-specified prompts. They must reason about norms that change over time. This requires advanced understanding of contextual integrity within the model itself.
User-centric controls are essential for human oversight. The traditional Notice and Choice framework assumes individuals can make fine-grained decisions. It relies on an assumption that people can foresee all outcomes. Autonomous agents behave probabilistically, in high volume, and generatively. Their actions cannot be fully predicted by users. We need to shift interfaces toward dynamic control mechanisms. These controls should match user mental models better than static checkboxes.
Multi-agent interactions present a new set of risks. Agents often collaborate on complex tasks together. They must guard against collusion between different agents. Collusion could lead to violations of contextual norms. Effective guardrails are needed to prevent this behavior. Each agent must adhere to shared expectations during collaboration.
Ecosystem governance addresses the broader challenges of norm collection. Mechanisms must collect and share contextual norms across agents. Norms can differ significantly across domains and entities. We need systems to resolve conflicts between these differing norms. Negotiation mechanisms should allow for changes in norms over time. Verification processes must confirm compliance with established rules.
Measuring privacy and security dynamically is the final key step. Researchers need standardized, multi-agent benchmarks for evaluation. These are dynamic environments called Agent Gym. They simulate complex, cascading interactions during extended periods. Open-source sandboxes will allow safe simulation of these scenarios. This helps establish a robust baseline across academia and industry.
The project requires unprecedented collaboration from many sectors. No single discipline can solve this large task alone. The report calls for ideas from government, civil society, and industry. It lays out foundational opportunities for the research community. Everyone must develop the contextual foundations for a safe ecosystem. Trustworthy agentic systems depend on these shared efforts.
Researchers and engineers should adopt these benchmarks immediately. They need to integrate policy engines into their projects. Testing in Agent Gym environments will reveal hidden vulnerabilities. Engineers can use sandboxing to limit agent capabilities dynamically. Users should expect new control mechanisms that adapt to context. The industry must work together to set and verify norms.
Introduction - Google researchers announce a new workshop report on agentic privacy and security.
Google released a fresh report about privacy and security for AI agents. Eugene Bagdasarian and Marco Gruteser led this research effort from Google Research. They gathered more than 50 experts to discuss these critical issues. The team met at the CAPS Workshop in late 2025 in New York City. This event focused on how autonomous systems handle personal data safely. The report highlights open problems that researchers must solve soon. It covers challenges at the system, model, user, and ecosystem levels. These leaders want to build agents people can truly trust. They believe current methods are not enough for future AI.
The core challenge - Autonomous agents need access to data but face unique risks compared to traditional software.
AI agents require data access to perform useful tasks effectively. Traditional software follows strict rules without much flexibility. Agents, however, use large language models to plan and act dynamically. This flexibility creates new risks that old security methods cannot catch. Unstructured inputs make it hard to define expected behavior clearly. Probabilistic paths mean agents take different routes during execution. Deep delegation allows agents to hire other agents for sub-tasks. These three dimensions create unique vulnerabilities for privacy protection.
Contextual Integrity theory - The report grounds agent safety in the concept of appropriate information flow.
Contextual Integrity defines privacy as appropriate information flow rather than just secrecy. This theory looks at social norms that govern how data moves between people. It considers who sends information, what kind of data it is, and transmission rules. For example, sharing a gift list with an assistant is acceptable in some contexts. Sharing the same list with friends might violate different norms. The report extends this idea to cover agent actions broadly. It argues that safety depends on understanding social appropriateness for every situation.
Three critical dimensions - Agents struggle with unstructured inputs, probabilistic paths, and deep delegation.
Agents process instructions in natural language or images instead of code. This unstructured input makes adversarial attacks like prompt injection possible. Traditional testing cannot easily secure these probabilistic execution paths. Generative planning leads to unpredictable routes that deterministic software avoids. Deep delegation means agents hire other agents to handle complex work. User oversight becomes less effective as tasks grow longer and more intricate. Confirmation fatigue occurs when users feel overwhelmed by constant choices.
The contextual policy engine - A new system layer can dynamically generate rules based on real-time context.
A contextual policy engine acts as a supervisor layer within agentic systems. It generates rules dynamically based on the current situation and user request. This loop operates in real time to tailor policies for open-ended contexts. The system evaluates whether a data flow is appropriate before information leaves. It handles new tools or capabilities discovered while the task runs. This bridges the semantic gap between high-level norms and low-level permissions.
Multi-layered approach - Solutions span system sandboxing, model reasoning, user controls, and ecosystem governance.
Solutions require a multi-layered approach covering the entire technology stack. System-level sandboxing imposes guardrails to limit the impact of failures. Advanced understanding of contextual integrity exists within the model itself. User-centric controls provide essential human oversight for autonomous actions. Traditional Notice and Choice frameworks assume people can foresee all outcomes. Autonomous agents behave probabilistically in high volume and generatively. Their actions cannot be fully predicted by users easily.
Why it matters - This framework addresses the safety and trust gap in highly autonomous AI systems.
This framework fills the safety and trust gap in highly autonomous AI systems. Without it, agents might violate social norms while completing tasks efficiently. Users need assurance that their data remains protected across complex interactions. The report provides a roadmap for building trustworthy agentic systems today. It moves beyond simple secrecy to focus on contextual appropriateness. Trustworthy systems depend on shared efforts from many sectors globally.
What to do - Researchers and engineers should adopt these benchmarks and policy engines for their projects.
Researchers and engineers must adopt these benchmarks immediately for their projects. They need to integrate policy engines into their current development pipelines. Testing in Agent Gym environments will reveal hidden vulnerabilities quickly. Open-source sandboxes allow safe simulation of complex, cascading interactions. Engineers can use sandboxing to limit agent capabilities dynamically at runtime. Users should expect new control mechanisms that adapt to context automatically. The industry must work together to set and verify norms consistently.
Conclusion - Building a safe future for agentic AI requires global collaboration.
Building a safe future for agentic AI requires global collaboration from all sectors. No single discipline can solve this large task alone effectively. The report calls for ideas from government, civil society, and industry leaders. Everyone must develop the contextual foundations for a safe ecosystem together. Trustworthy agentic systems depend on these shared efforts from researchers worldwide. We stand at the start of a new era in AI interaction.