AI News selected for Professionals and Decision Makers
Primary Research Stream

Janus: a Playground for User-Involved Agentic Permission Management

06:00 · July 3, 2026 · arXiv cs.AI RSS

Janus: a Playground for User-Involved Agentic Permission Management

AI agents that autonomously execute tool calls on a user's behalf raise pressing questions about permission management: what role could users play, and what role should they play? Despite many proposed approaches, the user's role in agentic permission management remains under explored. We introduce Janus, a playground system for implementing and evaluating user-involved agentic permission management designs. Janus consists of two components: Janus-Core, a modular agentic system supporting a diverse spectrum of permission management designs, and Janus-Harness, an automated evaluation framework. Grounded in a conceptual model that identifies key design axes for user involvement, we implement six permission assistants spanning the design space and evaluate them across three scenarios and three synthetic responders. We demonstrate that user input is critical and can significantly strengthen privacy and security, that AI augmentation of user decisions can help reduce cognitive load, and that realistic user behavior including permission fatigue must be accounted for in system design. No single design performs optimally across all contexts, motivating a more principled and context-sensitive approach to deploying permission assistants in agentic systems. Janus is publicly available to support future investigation into this dimension of agentic system design.

Summary

Janus is a research playground for exploring how users can participate in runtime permission decisions for AI agents that autonomously invoke tools on their behalf. The system addresses the tension between the principle of complete mediation—every access must be checked—and the practical limits of user attention when agents handle open-ended tasks such as email management that routinely encounter ambiguous or potentially malicious inputs.

The framework consists of two parts. Janus-Core provides a modular agentic architecture that lets researchers plug in different permission assistants along several design axes, including the degree of user involvement, the use of persistent policies versus runtime prompts, and the extent of AI assistance in summarizing or recommending decisions. Janus-Harness supplies an automated evaluation harness that runs controlled experiments across multiple task scenarios and synthetic user responders, allowing repeatable comparison of privacy, security, and usability outcomes.

Using this infrastructure, the authors implemented six distinct permission assistants that cover a range of involvement strategies. Evaluation across three scenarios showed that incorporating user input measurably improves resistance to inappropriate tool calls, while AI augmentation of those decisions can lower cognitive load. At the same time, the experiments confirmed that realistic user behaviors such as permission fatigue quickly degrade the effectiveness of designs that rely on frequent prompts, and that no single configuration performs best in every context.

The work therefore argues for context-sensitive permission systems rather than one-size-fits-all solutions and releases Janus publicly to support further investigation into user-involved agentic security.

Why it matters

This research is highly relevant to the Dutch AI market's strong emphasis on ethical, transparent, and privacy-compliant AI. By providing an open-source framework to test agentic permission management, it offers Dutch researchers and developers practical tools to align autonomous agents with strict EU data protection and AI regulations.

More in this beat
ai-agentsai-privacy-compliancehuman-oversight-frameworksJanusmodel-security-controlspermission-managementprivacy-by-designtrustworthy-ai-practices
The Security-Privacy Imperative in the Age of AI Attacks

14:00 · July 19, 2026

The Security-Privacy Imperative in the Age of AI Attacks

Directly addresses AI security risks and privacy compliance under GDPR for EU-based professionals; offers actionable guidance on privacy-by-design techniques applicable to Dutch AI deployments and regulatory contexts.

Relevance 85 · Audience 90

A Theory of Least Autonomy in AI

06:00 · July 14, 2026

A Theory of Least Autonomy in AI

This theoretical framework directly supports the Dutch and EU focus on secure, ethical, and transparent AI by providing rigorous methods to audit and constrain autonomous AI agents. It offers advanced researchers actionable mathematical models to prevent dangerous capability composition in enterprise AI deployments.

Relevance 85 · Audience 95

Idiobionics: The Unification of Privacy and Intelligent Robotic Prostheses

06:00 · July 11, 2026

Idiobionics: The Unification of Privacy and Intelligent Robotic Prostheses

The article aligns strongly with the Dutch AI market's focus on ethical, transparent AI and healthcare innovation. It provides primary research on privacy vulnerabilities in AI-driven medical devices, which is highly pertinent for Dutch researchers navigating EU data protection standards (GDPR) and the AI Act.

Relevance 85 · Audience 95

InfoQ Opens AI Security & Privacy Engineering Cohort for Regulated Industries

14:00 · July 6, 2026

InfoQ Opens AI Security & Privacy Engineering Cohort for Regulated Industries

This article is highly relevant as it offers actionable training for security and privacy professionals dealing with AI in regulated environments. The curriculum directly addresses EU-relevant compliance and privacy needs, such as handling sensitive data and applying privacy threat modeling frameworks.

Relevance 85 · Audience 95

MosaicLeaks: Can your research agent keep a secret?

20:13 · June 18, 2026

MosaicLeaks: Can your research agent keep a secret?

Directly addresses production challenges for ML Engineers building agents: privacy leakage via queries, balancing accuracy vs. data exposure, and sample-efficient RL training. Strong quantitative benchmarks and actionable training recipe. EU GDPR relevance for Dutch enterprises handling sensitive data.

Relevance 78 · Audience 85

Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network

17:33 · June 18, 2026

Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network

This article is highly relevant for security and privacy professionals as it addresses a critical vulnerability in AI access management and data governance. For Dutch enterprises, mitigating the risks of unmonitored AI agents is essential for protecting intellectual property and ensuring compliance with strict EU data protection regulations like the GDPR and the AI Act.

Relevance 85 · Audience 95

How we contain Claude across products

02:00 · May 25, 2026

How we contain Claude across products

Highly actionable for Product Teams and Builders: provides concrete implementation patterns, risk trade-offs, and lessons on agent security that directly apply to building safe AI products. Addresses limitations, prompt injection, and oversight fatigue with measurable outcomes.

Relevance 85 · Audience 90

Stability AI’s Annual Integrity Transparency Report

02:00 · September 17, 2025

Stability AI’s Annual Integrity Transparency Report

This report is highly relevant for Dutch product teams and builders as it details the safety mechanisms, API filters, and C2PA provenance standards implemented in Stability AI models. Understanding these safeguards is crucial for building compliant, ethical AI applications that align with stringent EU and Dutch regulations.

Relevance 85 · Audience 80

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

16:36 · August 20, 2026

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

This article highlights a critical data exfiltration vulnerability in LLMs via context injection, which is highly relevant for security professionals defending AI systems. Understanding this attack vector is essential for Dutch enterprises to ensure GDPR compliance and protect user privacy when deploying AI chatbots.

Relevance 85 · Audience 95

Army Cyber training AI agents in cyber ‘work roles’ alongside human counterparts

15:57 · August 20, 2026

Army Cyber training AI agents in cyber ‘work roles’ alongside human counterparts

This article provides critical insights into how a leading NATO ally is operationalizing agentic AI in cyber warfare, directly informing Dutch and European doctrine developers and defense technologists. It highlights practical human-machine teaming models and ethical guardrails that align with the Netherlands' focus on responsible military AI.

Relevance 85 · Audience 95