Sai Krishna Rallabandi argues that today's agents usually serve one person, while future assistants may participate in group chats and wearable conversations. Examples from an agent he calls Judith show why the same reply might belong in a private message rather than a shared thread, and why a group assistant must track changing context across participants.
Rallabandi describes prompt injection and the combination of seemingly safe tools as risks when an agent reads group messages, pages and files. He proposes checking potentially sensitive actions at the tool boundary, separating untrusted data from instructions, and supplementing deterministic rules with a learned classifier. The reported paper results and benchmark improvements are claims from the talk, not independently verified here.
He then turns to memory and privacy: extracting useful facts from conversations, reassessing relevance as plans change, and deciding what the agent should forget or retrieve. He proposes shared memory with user-specific adapters and a classifier to choose when and to whom the agent speaks. The talk presents these as design ideas; it does not demonstrate that learned adapters alone enforce access permissions.
Watch on YouTube




