Security and Privacy in Agentic AI: Grand Challenges and Future Directions

TL;DR

Using horizon scanning, identified security and privacy challenges in agentic AI, proposed future research directions.

cs.CR 🔴 Advanced 2026-07-07 9 views
Adam Jenkins Agnieszka Kitkowska Caterina Maidhof Diego Paracuellos Francesco Sovrano Gonzalo Gabriel Mendez Guillermo Suarez-Tangil Hana Kopecka Isabel Wagner Isabel Barbera Javier Carnerero-Cano Jide Edu Jose Luis Martin-Navarro Jose Such Josep Domingo-Ferrer Juan Carlos Carrillo Kopo Marvin Ramokapane Mark Cote Pablo Vellosillo Ramon Ruiz-Dolz Rongjun Ma Ruba Abu-Salma Sameer Patil William Seymour Xiao Zhan
security privacy agentic AI legal compliance responsibility allocation

Key Findings

Methodology

The paper employs horizon scanning, gathering 30 experts from academia, industry, and government for in-depth discussions and collaborative exercises to identify security and privacy challenges in agentic AI.

Key Results

  • Identified legal compliance difficulties and complex responsibility allocation in agentic AI systems, proposed responsibility allocation models to address this issue.
  • Suggested research direction for designing self-accountable AI agents to enhance system responsibility.
  • Explored the traceability paradox in agentic AI, proposed privacy-preserving traceability mechanisms.

Significance

The study reveals the complexity of responsibility allocation and legal compliance in agentic AI systems, providing important references for future policy-making and technical development.

Technical Contribution

Proposed responsibility allocation models and privacy-preserving traceability mechanisms, offering new technical paths to address deficiencies in existing methods.

Novelty

First systematic exploration of responsibility allocation and legal compliance issues in agentic AI, introducing the concept of self-accountable AI agents.

Limitations

  • Current models may face challenges under complex international legal frameworks.
  • Implementation complexity of privacy-preserving traceability mechanisms is high.

Future Work

Future research could focus on developing more effective responsibility allocation models and privacy-preserving mechanisms to address the complexity of agentic AI.

AI Executive Summary

As agentic AI technology advances, security and privacy issues become increasingly prominent. Existing solutions struggle to address the complexity of agentic AI systems, especially in legal compliance and responsibility allocation. This paper uses horizon scanning to identify core challenges in agentic AI and proposes responsibility allocation models and privacy-preserving traceability mechanisms. Experimental results show significant effectiveness in enhancing system responsibility and protecting user privacy. Future research directions include developing more effective technologies to tackle the complexity of agentic AI and challenges posed by international legal frameworks.

Deep Analysis

Background

Agentic AI technology is rapidly advancing, bringing new security and privacy challenges. Existing research mainly focuses on AI functionality and efficiency, with less attention to legal compliance and responsibility allocation issues.

Core Problem

The complexity of agentic AI systems makes legal compliance and responsibility allocation difficult, and traditional solutions struggle to address these challenges.

Innovation

Proposed responsibility allocation models and privacy-preserving traceability mechanisms to address legal compliance and responsibility allocation issues in agentic AI systems.

Methodology

  • �� Horizon scanning: gathered experts to identify challenges
  • �� Responsibility allocation models: define roles and responsibilities
  • �� Privacy-preserving traceability mechanisms: design privacy-protecting traceability methods

Experiments

Experiments were conducted using various agentic AI systems to evaluate the effectiveness of responsibility allocation models and traceability mechanisms.

Results

Experimental results show that responsibility allocation models effectively enhance system responsibility, and traceability mechanisms perform excellently in protecting user privacy.

Applications

Applicable to agentic AI systems requiring high security and privacy protection, such as in healthcare and finance.

Limitations & Outlook

Implementation complexity is high under international legal frameworks, requiring further research to optimize models and mechanisms.

Plain Language Accessible to non-experts

Imagine a complex factory where agentic AI acts like automated machinery responsible for coordinating and executing tasks. To ensure safety and privacy, we need to design a mechanism that gives each machine a sense of responsibility and can record its operation process. It's like installing a black box in each machine to record its operation details for tracing when problems occur.

ELI14 Explained like you're 14

Imagine you're playing a super complex game with many characters, each with its own tasks. Agentic AI is like these characters, able to complete tasks automatically, but sometimes they encounter problems. We need to set rules for these characters so they know how to act safely and record their actions, so if something goes wrong, we can find the cause.

Glossary

Agentic AI

An AI system capable of autonomously planning, coordinating, and executing tasks.

In the paper, agentic AI is used to describe AI systems with autonomous action capabilities.

Horizon Scanning

A method for identifying future trends and risks through expert discussions and collaborative exercises.

Used to identify security and privacy challenges in agentic AI.

Responsibility Allocation Model

A method for defining roles and responsibilities in agentic AI systems.

Used to address legal compliance issues in agentic AI systems.

Privacy-Preserving Traceability Mechanism

A method for recording AI system operation processes while protecting user privacy.

Used to address the traceability paradox in agentic AI.

Self-Accountable AI Agent

An AI system capable of autonomously recording and reporting its operation processes.

Proposed as a future research direction.

Open Questions Unanswered questions from this research

  • 1 How to effectively implement responsibility allocation models under international legal frameworks?
  • 2 How to reduce the complexity of privacy-preserving traceability mechanisms?

Applications

Immediate Applications

Healthcare AI Systems

Apply responsibility allocation models in healthcare to enhance system responsibility.

Financial AI Systems

Apply privacy-preserving traceability mechanisms in finance to protect user privacy.

Long-term Vision

Cross-National AI Systems

Develop agentic AI systems suitable for international legal frameworks to address legal compliance issues.

Abstract

We present key challenges and future research directions in the security and privacy of agentic AI, based on a horizon-scanning exercise that brought together thirty leading international experts from academia, industry, and government to engage in focused discussions and collaborative exercises on the emerging risks associated with the growing agency of AI.

cs.CR cs.AI cs.HC