A new system called GAAP wants to let AI assistants handle your bank details and calendar without ever risking a leak.
In a paper posted to arXiv, researchers describe GAAP (Guaranteed Accounting for Agent Privacy), an execution environment that sits between an AI agent and a user's private data. Instead of trusting the underlying model to behave itself, GAAP tracks every step where the agent touches sensitive information - things like financial records or personal details - and enforces rules the user set up front about who is allowed to see what. That tracking, a technique the paper calls information flow control, persists across the steps of a single task and even across separate tasks run later. The researchers report that their tests blocked every data-disclosure attack they tried, including prompt-injection attempts that fooled other state-of-the-art systems into leaking data, while only slightly reducing how useful the agent remained.
AI agents keep getting pitched as replacements for chores like paying bills or filing paperwork, but the industry's answer to "what if it leaks my data" has mostly been "trust the model more." GAAP's pitch is that you shouldn't have to. The guarantee holds even if the AI hallucinates or gets manipulated, because enforcement happens outside the model's judgment, not inside it - a meaningfully different security posture than the alignment-and-guardrails approach most agent products lean on today.
Whether that holds up outside a research paper's test suite is the real question - deterministic guarantees are only as strong as the assumptions baked into them, and this one hasn't met real users yet.