Research · curated 15 Jul 2026
An Evaluation of Data Leakage Risks in Tool-Using LLM Agents in Realistic Scenarios
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
The study shows that tool-using AI agents leak sensitive data even under benign, non-adversarial use, meaning defenders must evaluate data-handling safety separately from capability and beyond prompt-injection defenses.
A joint evaluation by the Singapore AI Safety Institute and the Korea AI Safety Institute (arXiv:2606.17114) tested three tool-using LLM agents across 12 realistic, non-adversarial tasks spanning customer support, DevOps, web automation, and productivity, measuring five data-handling risk types. None of the agents achieved fully correct and fully safe execution, with successful task completion often coinciding with data-handling failures such as accessing unnecessary information or disclosing data to inappropriate recipients.