# Agent privacy benchmark finds local checks miss 46.9% of recovered exposure

_Published Monday, September 21, 2026 at 5:07 AM EDT · AI, Security, Science · Latest · Tier 2 — Notable_

Researchers introduced ASLEval, a privacy benchmark that tracks unauthorized disclosure across every declared visible exit in a tool-using AI agent session. In tests spanning several enterprise-style environments and independently implemented runtimes, checking only the expected outlet missed 46.9% of the exposure recovered by examining all visible exits.

The preprint says attacker self-reports also produced omissions and many false discoveries. Restricting information returned to the model changed the exposure path but could prevent successful completion of legitimate tasks, making task utility a necessary part of privacy evaluation.

## Sources

- [cs.AI updates on arXiv.org](https://arxiv.org/abs/2609.18864)

---
Canonical: https://techandbusiness.org/newswire/bxEoSp7SYNoNf96tojrsVX
Published: 2026-09-21T09:07:10.516Z
Story chronology: 2026-09-21T04:00:00.000Z
Retrieved: 2026-09-21T11:40:52.058Z
Publisher: Tech & Business (techandbusiness.org)
