Privacy and Confidentiality

Develop standards for identifying and mitigating privacy risks in advanced AI systems by convening AI model developers, deployers, regulators, academics, and non-profits to determine standard frameworks and practices of measuring privacy risks. Our goal is to help developers, regulators, and civil society groups confidently mitigate privacy risks, specifically in frontier and agentic AI development and deployment.

Purpose


Frontier and agentic AI deployment raise privacy risks that developers and deployers need to assess and mitigate. However, no standard framework exists for measuring how models and agents perform against them. The Privacy and Confidentiality Working Group builds that framework: standardized benchmarks and risk taxonomies that evaluate privacy risks and the tools designed to address them.

Models trained on large volumes of user-consented data can memorize sensitive information—financial, healthcare, or other personal data. We’re developing methods to reduce that recall across pre-training and post-training, cutting downstream harm at the source.

As AI shifts from chatbots to autonomous agents, the risk shifts too—from what a model knows to what it does. Agents acting on a user’s behalf, often through opaque tool-use chains or secondary data channels, can compromise privacy even when their direct responses are secure. We’re working to ensure agents follow data minimization principles, using only the data necessary to fulfill user intent.

Without shared standards, these risks will slow AI adoption for consumers and enterprises alike. Our goal is to give the industry the tools to measure, benchmark, and mitigate privacy risk—turning an open problem into a solvable one.

Deliverables


The working group addresses this gap through two initiatives:

1. Privacy and Confidentiality Risk Taxonomy

Our flagship initiative is developing a shared taxonomy for describing and measuring the types of privacy risks inherent to agentic AI deployments. 

2. Privacy Benchmarks for Agentic AI Systems

As we look ahead to 2027, we aim to develop concrete benchmarks that measure how well a given AI agent mitigates known privacy risks. 

Meeting Schedule

Thursdays Bi-weekly on Thursdays 11:30 AM to 12:30 PM ET

Get involved




Working Group Chairs

Vinh Nguyen

Senior Fellow for AI, Council on Foreign Relations

Vinh Nguyen is Senior Fellow for Artificial Intelligence at the Council on Foreign Relations, working to build trustworthy, scalable AI infrastructure that strengthens U.S. security and prosperity. Recruited at seventeen into the NSA’s elite Stokes Program, he became the youngest employee in agency history promoted to the senior executive ranks, later serving as the NSA’s first chief responsible AI officer and chief data scientist for operations. He also served on the National Intelligence Council as its most senior cyber analyst, advising the Director of National Intelligence on cyber threats and geopolitics. He is the founder of Aligned Intelligence Advisory, a board advisor to Identity Digital Innovation Labs, and a member of the National Academies’ Cyber Resilience Forum.

Kristie Chon Flynn

Google Data Protection Officer

Kristie is passionate about helping companies harness the power of data and technology by building and scaling products focused on driving brand loyalty, customer experience, and innovation grounded in digital responsibility. At Google, Kristie leads a global team that architects and scales data risk management products in an increasingly complex regulatory landscape. As Google’s Data Protection Officer, Kristie oversees Google’s data protection program. In addition, Kristie actively engages externally, sharing Google’s technical approach to data protection and fostering a culture of digital responsibility across the industry. Prior to Google, Kristie spearheaded PayPal’s data governance initiatives as Chief Privacy Officer. As the organization’s first dedicated data governance leader, Kristie developed the foundational principles and built a global team that scaled privacy through a robust platform. Serving as Chief Privacy Officer at HCL Technologies, Kristie advised B2B clients on data risk management across diverse sectors: healthcare, banking, and consumer products.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.