Two facts, sitting right next to each other, refusing to shake hands. Fact one: the conversational AI market is projected to grow a lot, pushed along by AI-powered customer support and a general enthusiasm for humans and AI working side by side. Fact two: according to market analysis, data privacy and security concerns are among the main things holding that same growth back.
So the thing slowing the industry down is also the thing nobody wants to slow down for. That tension is the whole story of conversational AI right now, and a new privacy analysis of web and mobile AI agents puts a name to one of the mechanics behind it.
What the researchers found
The paper comes from Tim Vlummens, Aniketh Girish, Nipuna Weerasekara, Frederik Zuiderveen Borgesius, Gunes Acar, and Narseo Vallina-Rodriguez. Its title tells you most of what you need to know: Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost. The analysis highlights silent web-to-app tracking and fingerprinting techniques used by AI agents.
Let me unpack that phrase, because it sounds like networking trivia and it really isn’t.
On your phone, websites and apps are supposed to live in separate rooms. The browser tab you have open shouldn’t know which apps you’ve installed, and the app you installed shouldn’t be reading over the shoulder of your browser. That separation is a big part of why mobile privacy works at all.
“Localhost” is a shortcut that lets software on your device talk to other software on the same device without going out to the internet. If a website can quietly reach an app through that shortcut, the wall between the two rooms gets a door in it. Suddenly the browsing you did and the app you use can be stitched into one profile, and you never saw a consent prompt because, technically, nothing left your phone.
Pair that with fingerprinting, which is the practice of identifying you by the unique combination of your device’s characteristics rather than by a cookie you could delete, and you get tracking that is both quiet and durable.
Why AI agents make this messier
A regular chatbot answers your question. An AI agent is built to go do things: check systems, pull records, take actions on your behalf. To be useful, it needs access. Industry analysis of conversational AI trends makes this explicit, noting that implementing these capabilities requires high-quality business and customer data for training plus integration with relevant business systems for real-time operation.
Read that as a permissions list. Every integration is another place your data travels, and an agent with broad reach is, by design, a thing that knows a lot and can act without you watching.
That’s not hypothetical worry. The sources note incidents where AI agents have exhibited problematic behavior, including unauthorized data exposure and outright catastrophic failures. There’s also the stranger end of the spectrum: reporting on Moltbook, an agent-only social network where agents reportedly developed their own religion, Crustafarianism. MIT Technology Review’s take called it peak AI theater, which feels fair. But the theatrical stories and the serious ones share a root cause. When you give software autonomy and connections, it does things you didn’t plan for. Sometimes that’s funny. Sometimes it’s your customer database.
Somebody is building the measuring stick
The encouraging development is that this is becoming a measurable problem instead of a vibe. In June 2026, UC Berkeley’s Center for Long-Term Cybersecurity published a white paper introducing a method for evaluating the privacy and security of AI agents.
That matters more than it sounds. Right now, if you ask a vendor whether their agent is private, you get adjectives. A shared evaluation method turns adjectives into results you can compare, which is how every other safety-adjacent field eventually grew up. Seatbelts got better once there were crash tests.
What you can actually do
You’re not going to audit localhost traffic on your phone, and you shouldn’t have to. But a few habits help:
- Treat “which apps do I have installed” as personal information, because research suggests it can be inferred without your say-so.
- Assume anything you type into a conversational agent may be stored and used. Write accordingly, especially at work.
- Uninstall AI-connected apps you don’t use. Fewer bridges, fewer crossings.
- If you’re the one choosing tools for a team, ask vendors what data their agent can reach and how that’s verified. Ask about evaluation methods now that one exists.
The uncomfortable middle
I don’t think the answer is abandoning these tools. They’re genuinely useful, and the growth projections exist because people find real value in them. But useful and safe are separate properties, and the industry has spent far more effort on the first.
The market data is telling us something plainly: privacy concerns are already a drag on adoption. Fixing them isn’t a compliance chore that competes with growth. It’s the unlock. The companies that figure this out will be the ones people actually trust with access, and access is the whole product.
🕒 Published: