Atlassian uses cookies to improve your browsing experience, perform analytics and research, and conduct advertising. Accept all cookies to indicate that you agree to our use of cookies on your device.
Atlassian uses cookies to improve your browsing experience, perform analytics and research, and conduct advertising. Accept all cookies to indicate that you agree to our use of cookies on your device. Atlassian cookies and tracking notice, (opens new window)
Recordings: you can find them in LFX calendar (along with transcripts). We no longer manually add the links here.
Attendees:
@Wenjing Chu
@Neil Thomson
@Nicky Hickman
@Drummond Reed
@Steven Milstein
@Jim St.Clair
Agenda Items and Notes (including all relevant links)
Time
Agenda Item
Lead
Notes
5 mins
Welcome & antitrust notice
Introduction of new members
Agenda review
Recording with transcription is now automatic
Chairs
Antitrust Policy Notice:Attendees are reminded to adhere to the meeting agenda and not participate in activities prohibited under antitrust and competition laws.
ToIP Policy: Only members of ToIP who have signed the necessary agreements are permitted to participate in this activity beyond an observer role.
This continues the topic @Wenjing Chu brought to the WG’s attention to broad the scope of our work from protecting strictly “data” to also restricting behavior and other aspects of somewhat autonomous agents
Last week’s notes:
PyTorch conference + Open Agent Summit
@Wenjing Chu attended in SF. RL is being researched for the next stage of LLM which has different “governance” approaches, from data management to behavior management, goals management
@Wenjing Chu introduced the difference between observable behavior of an LLM vs. internal processing structure of LLM. The latter is much more difficult to observe or govern than the tokens in and out or chain of thoughts outputs.
Let’s continue this line of discussion …
Understanding the problems
@Wenjing Chu summarized last week’s discussion
@Neil Thomson specific to the services/role - what info not to disclosed at all per context. no caching. micro-sharing. in this case, we are advancing a better “best practice”, collaboratively. it’s also a good way to minimize exposure/risk for the service providers.
Moving as much personal info as possible to the endpoint/customer. including derivatives e.g. models.
@Wenjing Chu pointed out that the SP can still build a detailed model about a customer without strict PII
@Wenjing Chu “relationship management” does require retaining information that may not be strictly limited to today’s goals but for potential tomorrow’s goals… for a “long term” relationships.
@Jim St.Clair policy control - but wenjing and others pointed out policy complexity and execution/enforcement difficulty. Nicky pointed out policy coherence research. AI to help. https://arxiv.org/html/2508.06799v2
beyond AI assisted policy - maybe risk management.
This is a good example of “AI for trust” in our WG’s mission. @Nicky Hickman
@Drummond Reed pointed out “guardian agents” related work/startups. – Andor.
@Neil Thomson a “middle man” to neutral management.
Planning future work
etc.
15 mins
Atlas and other browser based Agents, such as the Atlas Agentic mode.
@Wenjing Chu
If time allows
Understanding the “browser based” agents and their security and privacy vulnerabilities
if the local execution is no longer safe, then all agent behavior is suspect.
@Steven Milstein will user notice? @Wenjing Chu yes/maybe, but autonomous agents can do a lot of damage bc it’s autonomous for quite a while before the user notices.
0 mins
Action Items
All
List action items to follow up
AIMWG in Google Drive is still under Tech Stack WFG - needed to elevate AIM to WG level
There seems to be problems at the moment - so wait until it settles.