[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84133-en":3,"doc-seo-84133-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84133,687197207057,"Sage","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Security and Privacy in Agentic AI: Grand Challenges and Future Directions","The paper presents the main security and privacy challenges and outlines future research directions for agentic AI systems. Drawing on a horizon-scanning exercise, the work gathers thirty international experts from academia, industry, and government to discuss emerging risks created by AI systems gaining greater agency. It highlights exposure created by expanded permissions, including prompt injection attacks, malicious application flooding, and sensitive data disclosure driven by anthropomorphic trust.","Security and Privacy in Agentic AI: Grand Challenges and Future Directions  \nAdam Jenkins, Agnieszka Kitkowska, Caterina Maidhof, Diego Paracuellos, Francesco Sovrano, Gonzalo Gabriel Mndez, Guillermo Suarez-Tangil, Hana Kopecka, Isabel Wagner, Isabel Barber, Javier Carnerero-Cano, Jide Edu, Jose Luis Martin-Navarro, Jose Such, Josep Domingo-Ferrer, Juan Carlos Carrillo, Kopo Marvin Ramokapane, Mark Cot, Pablo Vellosillo, Ramon Ruiz-Dolz, Rongjun Ma, Ruba Abu-Salma, Sameer Patil, William Seymour, and Xiao Zhan  \n~~ ~~ ✦ ~~ ~~  \narXiv :2607 .06608v 1 [ cs .CR] 7 Jul 2026  \nAbstract—We present key challenges and future research directions in the security and privacy of agentic AI, based on a horizon-scanning exercise that brought together thirty leading international experts from academia, industry, and government to engage in focused discussionsand collaborative exercises on the emerging risks associated with the growing agency of AI.  \n1 INTRODUCTION  \nSince the public release of ChatGPT in 2022, AI has advanced rapidly, giving rise to a wide range of applications. General-purpose AI models have become more capable and increasingly user-friendly, exemplified by systems such as ChatGPT [1], which broaden access to AI and encourage exploration of potentially beneficial AI applications. In addition, custom AI applications designed for specific tasks have opened new avenues [2], enabling users to tailor AI systems to their own needs and usage scenarios while integrating them with external tools. For example, users can connect AI to their personal calendars for task management. Beyond  \n• A. Jenkins, M. Cot´e, R. Abu-Salma and W. Seymour are with King’s College London, United Kingdom.  \n• A. Kitkowska is with the Department of Computer Science and Informatics, J¨onk¨oping University, Sweden.  \n• C. Maidhof, D. Paracuellos, H. Kopecka, R. Ma, G. G. M´endez, J. L. Martin-Navarro, J. C. Carrillo, P. Vellosillo and X. Zhan are with the Universitat Polit`ecnica de Val`encia, Spain.  \n• G. G. M´endez is also with Inria, Rennes, France.  \n• J. Carnerero-Cano is with IBM Research, Ireland.  \n• J. L. Martin-Navarro is also with Aalto University, Finland.  \n• J. Such is with INGENIO (CSIC–Universitat Polit`ecnica de Val`encia), Spain.  \n• G. Suarez-Tangil is with IMDEA Networks, Madrid, Spain.  \n• I. Wagner is with the University of Basel, Switzerland.  \n• I. Barber´a is with the Dutch Data Protection Authority (AP), The Hague, The Netherlands, and is also an Independent Researcher.  \n• J. Edu is with the University of Strathclyde, United Kingdom.  \n• J. Domingo-Ferrer is with the Department of Computer Engineering and Mathematics, CYBERCAT and ComSCIAM, Universitat Rovira i Virgili, Tarragona, Spain.  \n• K. M. Ramokapane is with the University of Bristol, United Kingdom.  \n• R. Ruiz-Dolz is with the University of Dundee, United Kingdom.  \n• S. Patil is with the Kahlert School of Computing, University of Utah, USA.  \n• F. Sovrano is with the Department of Informatics, Universit`a della Svizzera italiana (USI), Lugano, Switzerland.  \ncustomization, the growing agency granted to AI systems is enabling them to plan, coordinate, and execute increasingly complex workflows with reduced human oversight. The shift toward agentic AI is reflected in the rising popularity of autonomous systems such as OpenClaw [3], which illustrates that AI is moving from passive assistance toward proactive action.  \nThe advancement of agentic AI applications poses significant challenges for security and privacy research. As more permissions are granted to AI agents to provide them greater autonomy, users become increasingly exposed to security and privacy risks. Emerging threats include prompt injection attacks [4], flood of malicious applications on AI platforms [5], and disclosure of sensitive personal information to AI applications in exchange for convenience and ease of use, often driven by anthropomorphic trust [6] . These developments highlight the importance of","cbCaik5zRezqAG8h","https://ap.wps.com/l/cbCaik5zRezqAG8h","pdf",516487,4,1,12,"English","en",105,"# Introduction\n# Method","[{\"question\":\"What problem does the document address for agentic AI?\",\"answer\":\"It focuses on security and privacy risks that arise as AI systems gain increasing agency and autonomy, especially when users grant agents more permissions.\"},{\"question\":\"How were the key challenges and directions identified?\",\"answer\":\"The authors used a horizon-scanning exercise over three consecutive days, bringing together thirty experts from academia, industry, and government to conduct focused discussions and collaborative exercises.\"},{\"question\":\"What types of emerging threats are highlighted?\",\"answer\":\"The document highlights prompt injection attacks, the spread of malicious applications on AI platforms, and the disclosure of sensitive personal information to AI applications for convenience, often influenced by anthropomorphic trust.\"}]",1784193219,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"security-and-privacy-in-agentic-ai-grand-challenges-and-future-directions","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/security-and-privacy-in-agentic-ai-grand-challenges-and-future-directions/84133/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the document address for agentic AI?","Question",{"text":75,"@type":76},"It focuses on security and privacy risks that arise as AI systems gain increasing agency and autonomy, especially when users grant agents more permissions.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How were the key challenges and directions identified?",{"text":80,"@type":76},"The authors used a horizon-scanning exercise over three consecutive days, bringing together thirty experts from academia, industry, and government to conduct focused discussions and collaborative exercises.",{"name":82,"@type":73,"acceptedAnswer":83},"What types of emerging threats are highlighted?",{"text":84,"@type":76},"The document highlights prompt injection attacks, the spread of malicious applications on AI platforms, and the disclosure of sensitive personal information to AI applications for convenience, often influenced by anthropomorphic trust.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]