🛡 Google: a new security architecture for agents

Google Research published a report on the findings of the CAPS Workshop (November 2025, 50+ researchers). LLM agents break conventional security: plans in natural language are vulnerable to prompt injection, and delegation causes consent fatigue.

🌍 Static permissions and confirmation dialogs do not scale to LLM agents: the report proposes dynamic contextual policy engines — a security layer separate from the planner.

👤 Endless “allow?” prompts create consent fatigue. Instead — an engine that pre-evaluates whether an action is appropriate in context: a shopping list goes to the shopping assistant, not to relatives.

Source 1: https://research.google/blog/open-and-emergent-problems-in-agentic-privacy-and-security-a-contextual-angle/ Source 2: https://research.google/pubs/open-and-emergent-problems-in-agentic-privacy-and-security-a-contextual-angle/