Loading...
Loading...

As agentic browsers come in the market, it's not going to be as simple as saying, just don't use confidential information in your prompts, because users won't necessarily have complete control over what the model ingests.
So it's going to be very important for Council to continually update and revise their AI use policies as these brand new forms of AI products become available.
Welcome to AI Council Code. I'm your host Maggie Welsh, and today we're joined by Cole's strime of Baker bots to talk more in depth about AI agents and to look at these agents in more detail.
So stay tuned for some interesting insights.
Baker bots LLP provides podcasts for educational purposes only. They are not legal advice and are not intended to establish an attorney client relationship.
This communication may constitute attorney advertising.
Cole, welcome to our podcast. Why don't you introduce yourself to our listeners?
Hi Maggie, thanks for having me. It's great to be here. I'm an associate in our IP practice at Baker bots at the New York office.
I practice focuses mainly on high tech patent matters, as well as diligence and advisory matters related to AI.
To start off, can you tell us more about what these AI agentic tools are and how they're different from traditional LLM models that we've become familiar with in the past few years?
A great way to think about these agentic tools is that they're capable of taking actions autonomously, where LLMs are generally confined to providing responses within a chat interface.
Most agentic products that are available now are actually built on top of LLMs, so they're not entirely separate.
But these agentic tools have access to external tools, usually through APIs.
And agent can actually receive a task from the user, reason about what might be required to accomplish that task, and develop a plan to carry out a set of actions to achieve the goal that the user sets.
These agents can actually engage with external tools to execute each task within that plan.
There are also multi-agent systems, which combine multiple agentic models, each of which specializes in a particular type of task.
These systems assign specific components of a project to different agents, pretty similar to the way that a project manager would assign different aspects of a job to different employees.
But a class B is agentic tools that's been making a lot of news lately are agentic web browsers.
These systems provide AI agents with access to and even control over a full web browser, so they can actually point and click to interact with third party websites on behalf of a human user.
Allowing AI the ability to act in the place of a human poses a lot of risks.
So what are issues that we should be thinking about when deploying AI agents within a company or using AI agents ourselves?
Absolutely. Why build you standing from the use of these AI agents is actually subject to some litigation right now.
Some agents can access and use websites using human users, user names and passwords.
But the problem that certain companies are seeing with this is that at scale agents accessing their websites as opposed to normal human users might throw off the recommendation algorithms or advertising algorithms, which are based on how humans interact with the websites as opposed to agents.
Also, AI agents are going to be less likely to see a recommended product or add on and make a snap purchase in the same way that a human might.
And for companies that derive a large portion of revenue from advertising streams, they might also be concerned about how much an advertiser would be willing to pay or ads on their websites if they know that a large portion of the site's traffic is from AI and not for humans.
So in some instances, these companies are actually requiring AI agents to identify themselves into a web traffic presumably so that they can monitor or even block their access through technological barriers.
Is it possible now to block the access to these AI agents if you own a company that operates a website?
Well, like I mentioned, this issue is subject to an ongoing case and the law is still developing there.
But at least in that case, the plaintiffs did try and the defendant actually evaded those tactical barriers. So they have some limited success, but there are two causes of actions being raised in that case.
The first claim is based on the computer fraud and abuse act, the federal anti hacking law, which creates civil and criminal liability for accessing a protected computer without authorization or in a matter that exceeds authorization.
Here, the argument is that the AI agent access services obtained customer information without authorization because it violated the website's terms and like I mentioned evaded technological barriers.
And the second claim is based on the California comprehensive computer data access and fraud act as the CDAA for short, which criminalizes things like unauthorized access, authorization, damage or even use of computers and data.
The argument here is that the AI agent, I'm awfully added data to the plaintiffs servers and databases by creating browsing histories and transaction data when the agent interacted with the website.
This is outside of the scope of committed use because again, there are terms of service violations and evasions of technical barriers.
The CFA was enacted in 1986 and the CDAA in 2001, but what we're seeing now are novel applications and we're going to have to wait and see how courts decide on these types of issues, at least as they apply to AI tools and most specifically AI agents.
And you raise an interesting theme that we're seeing with AI law now where there's quite a few longstanding laws being applied to AI and trying to figure out how those laws work with this new technology.
Are you seeing new laws that might implicate AI based decisions as well?
This is definitely an area that states into thinking about for a while now and they're just beginning to grapple with.
So Utah has an AI policy act which went into effect in 2024 and that imposes liability on companies if their AI tool violates a consumer protection law.
And effectively, companies which are subject to this law should give you any statements made to their customers by an AI tool as if they were made by human employee because they'll have the same amount of liability.
And California has a pretty similar law which just went into effect in January, California's version prohibits a defendant from asserting as a defense that an AI system autonomously caused harm.
So in other words, a defendant would be responsible for any liabilities that result from their use of an AI agent.
And we expect that over the next few years, states will continue to legislate around this issue, but with the current administration's recent formation of the AI litigation task force, which is aimed at challenging quote unquote owners state AI laws states may face and particular challenges in this area.
So we'll have to wait and see how that process plays out.
One question we get from clients and companies is about confidentiality and how can their important data sensitive data be maintained as confidential if they want it to be so how could AI agents pose an issue with confidentiality.
This is a major issue for AI tools in general, but especially in gentick AI tools.
So for example, you can imagine a user asking an AI agent to pull and summarize a non confidential document, but maybe the tool mistakenly accesses a confidential document with a similar file name.
The risk associated with agentic browsers in particular though are especially high use browsers work by constantly analyzing the visible browser window and adjusting information for the underlying AI model to interpret and interact with.
So the browser itself is essentially taking screenshots of everything that's in the window constantly.
The problem here though is that unlike a regular LLM where the user controls exactly what is input to the tool, the user with these AI agent browsers doesn't necessarily have full control over what goes into the browser window.
So you can imagine a user if they have their email open in an agentic browser, they could proceed an email from someone else, which contains confidential information.
If that email pops up on the screen or the user accidentally clicks on it, the browser and its underlying AI model will have access to that information.
And what's even worse is that these agentic browsers can access computer files just like a regular browser or have access to shared file systems like SharePoint.
So the agent could potentially navigate to sensitive files all on its own without any human involvement whatsoever.
Or the user can log into a company site or password protected website containing sensitive information using these browsers.
From the company's perspective, this kind of risk multiplies with each employee who has access to these types of tools.
But while the risk is higher here with these browsers, we've already dealt with similar issues related to existing AI tools.
So just like when we started to grapple with LLMs, corporate counsel and IT teams will need to work together to put together proper controls and make sure the confidential information is an accessible or available to any unapproved or insecure tools.
So this is going to need to be paid to these browser tools, which present very new and unique confidentiality and security risks.
We've also seen some recent disputes surrounding potential wiretapping issues.
So for example, AutoAI, which is a very popular AI tool for transcribing meetings, is currently the subject of class action litigation in California.
In that case, the plaintiffs are alleging that AutoAI was implemented in meetings without their knowledge or consent and transcribed conversations to screenshots and even recorded audio of the meetings.
And I'm sure many listeners have probably even experienced this for themselves and notice halfway through meeting that AutoAI or some similar tools listed as a participant.
And a lot of the times these tools appear as if they're normal human participants with generic names like butter or note taker, which even if they're seen and be very easily overlooked.
But this case is still on its early stages, though, and no rolling some come out. So this particular issue is still on resolve.
But you can imagine a similar theory being applied to agentic browsers. So for example, in the email example and agentic browser might collect screenshots of an email thread without notice or consent among all participants.
And this might raise very similar issues to the AutoAI case.
These kinds of questions will probably be popping up more and more over the next few years as these tools become more popular.
Thanks for breaking that down for us. These risks are definitely a huge concern for certain companies and something that council should be thinking about any final thoughts for our listeners.
Yeah, I just want to emphasize that it's going to be very important over the next few years for corporate council to stay on top of these developments and understand the capabilities of the tools that their company's employees have access to.
So far, we have been dealing almost entirely with LOMs, but as new products come in the market like agentic browsers, it's not going to be as simple as saying, just don't use confidential information in your prompts because we talked about users won't necessarily complete control over what the model ingests.
So we know that at the same time, though, outright bands on these types of tools aren't going to be effective either because companies are going to want to maintain their competitive edge.
So it's going to be very important for council to continually update and revise their companies, AI use policies as these brand new forms of AI products become available.
Thanks, Cole. And thanks for being with us today. Thanks to our listeners for listening to the AI council code. We're so glad that you joined us today.
Stay tuned for additional podcasts and more insights on AI legal issues from Baker bots.
Thank you for listening to this Baker bots podcast. Baker bots has the experience, knowledge and people to address our clients most significant legal issues.
For more information on Baker bots practices, please visit us at Baker bots dot com.
This presentation is provided by Baker bots LLP for educational and informational purposes only.
It is not legal advice and is not intended to establish an attorney client relationship under the roles of certain jurisdictions.
This communication may constitute attorney advertising.
