AI & Machine LearningResearch & Ethics

Agentic Data Flows: Privacy, Data Minimization, and PETs in Agentic Deployment

A Virtual Roundtable Series October 19, 2026 @ 9:30am - 11:00am ET

Overview

What are the governance challenges when AI agents share data, memory, and inferences with each other? We’ll explore that question in Agentic Data Flows: Privacy, Data Minimization, and PETs in Agentic Deployment, the first session of a new series on agentic data minimization from FPF’s Center for AI on Monday, October 19, 2026, from 9:30 to 11:00 am ET.

As AI agents move from pilots into real deployments, they cross system boundaries, carry what they learn from one session to the next, and hand data and inferences off to other agents. For privacy teams, regulators, and policymakers, that raises a pressing question: what happens to personal information between agents, and how do we keep it in bounds?

This series is part of FPF’s Research Coordination Network on Privacy-Enhancing Technologies, supported by the National Science Foundation and the U.S. Department of Energy, and is presented in collaboration with Working Paper.

In this virtual roundtable, we’ll cover:

  • Agents, privacy risk, and PETs. A level-set on what makes an agent different from earlier AI systems, and what current research and real-world deployments tell us about new privacy risks. With Andrew Gruen and Bennett Hillenbrand, Working Paper.
  • A map of agentic privacy risks. A walkthrough of 24 risks across five areas: data ingestion and processing; data aggregation, use, and sharing; inconsistent privacy practices across agents; the failure of legacy consent systems; and accountability and governance.
  • Deep dive: state sharing, cascading inferences, and boundary collapse. A presentation and fireside chat on inference contagion, memory persistence, and failures in deletion and propagation.

This discussion will be recorded, and the recording and a summary report will be published after the event.

Who should attend: Privacy and data protection professionals, AI governance and product teams, regulators and policymakers, researchers, and anyone working on responsible deployment of AI agents. No technical experience required.

Click here to see the full program agenda and speaker announcements.

This project is part of the Research Coordination Network (RCN) for Privacy-Preserving Data Sharing and Analytics, which is supported by the U.S. National Science Foundation (Award #2413978) and the Department of Energy (Award #DE-SC0024884).

Register

Agenda

Monday, October 19, 2026

Time

Event

Speakers

9:30 am –
9:50 am ET

Welcome and Opening Remarks
Agents, Privacy Risk, and PETs
  • Introducing the series. This is the first of four sessions on where PETs and AI meet. In the later sessions we will get into the technical primitives like confidential compute, secure enclaves, and cryptographic privacy protections.
  • Agents vs what came before. A quick level-set on what separates an agent from ordinary software. We will describe how it crosses system boundaries, it carries learning across sessions, and it hands data off to other agents.
  • Introducing the landscape. Before we get into standards or tools, we introduce a tour of what current research and actual deployments tell us about novel agentic privacy risk.
  • Bennett Hillenbrand, Adjunct Professor, Data Science and Public Policy, Georgetown University, McCourt School of Public Policy

9:50 am –
10:05 am ET

The Taxonomy

There are 24 agentic specific risks identified in the taxonomy, grouped into five parts:
  1. Data ingestion and processing
  2. Data aggregation, use, and sharing
  3. Inconsistent privacy practices across agents
  4. Failure of legacy consent systems
  5. Accountability and governance
Parts 1 and 2 are well understood risks, but have a new agentic spin. We’ll spend extra time on part 3 because that’s where privacy teams can actively develop learnings on agentic deployments, where some of the biggest novel risks are, and where they can make progress right now. This is the most immediate issue we’re seeing today. Parts 4 and 5 will come later, as they involve interactions between, and understanding of, parts 1-3.
  • Andrew Gruen, Senior Fellow, Future of Privacy Forum
  • Bennett Hillenbrand, Adjunct Professor, Data Science and Public Policy, Georgetown University, McCourt School of Public Policy

10:05 am –
10:30 am ET

A Deep Dive on State Sharing, Cascading Inferences, and Boundary Collapse

We’ll start from the chain-of-inference setup in part 3 and how it can lead to arbitrarily aggressive information sharing between agents (when it shouldn’t) and boundary collapse. We will go through a few use cases of multi-agent state sharing.

Part A: Technical mechanisms and agentic privacy 

  • Inference contagion. What happens if Agent A makes an uncertified, probabilistic inference (financial stress, an illness, etc.), passes it downstream, and Agent B treats it as a hard constraint?
  • Memory persistence. What happens if a persistent agent memory caches intermediate reasoning outside file-level permission domains, getting around the access controls that traditional databases rely on?
  • Deletion and propagation failures. What happens when a user revokes consent or asks for deletion, but downstream agents still hold cached memory or or derived inferences?
Part B: Privacy and enterprise realities 
  • Applying theory to enterprise risk. Connecting the risk model to real deployments in regulated workflows.
  • Auditability vs. minimization. How to capture audit trails and inference lineage across multi-agent loops without building a second, invasive surveillance log.
  • Vendor questions. Non-promotional. The technical questions privacy teams should be asking vendors about agent memory, tool-chain edge cases, and inference propagation to make sure their procurement efforts are privacy-aware.
  • Bennett Hillenbrand, Adjunct Professor, Data Science and Public Policy, Georgetown University, McCourt School of Public Policy
  • Speakers forthcoming!

10:30 am –
11:00 am ET

Moderated Discussion and Q&A

  • Discussion (15 min) Negotiating privacy limits between autonomous agents vs. setting policy at the protocol layer, and how to ask third-party vendors to include boundaries and inference controls.
  • Audience Q&A (10 min)
  • Wrap-up and next steps (5 min) What’s coming in the next PETs and AI sessions (including confidential compute) and how to get the working draft of the taxonomy.

 

Stacey Gray, Senior Director for Artificial Intelligence, Future of Privacy Forum