All news

Inside DAIAA's Agentic Privacy & Security Subgroup

August 28, 2026

Agents are entering large-scale workflows that touch regulated data, production systems, and money faster than the rules and practices for securing them are being adopted. Some of these rules and practices are being created inside company roadmaps, but many are emerging from meetings where competitors work out standards for the burgeoning agentic economy.

Some of that work is being done at the Decentralized AI Agent Alliance. This week we put questions to Lou Kerner, its founder, and to Chris Biele, who in addition to his work at OpenMatter chairs one of those meetings. Below you’ll find not only what DAIAA is and what Chris is doing there, but what his group has settled, what it hasn’t, and what he wants security teams doing about the agents they already have in production.



Stay up to date as we build the infrastructure layer for secure AI collaboration:

Subscribe now


OpenMatter is chairing the Decentralized AI Agent Alliance’s Agentic Privacy & Security subgroup. Our next meeting will be held on September 9, 2026 at 1pm EDT, and every other Wednesday thereafter. Please join us.

If you’re curious what DAIAA is all about, you can watch the August 26 meeting to learn more.


Inside DAIAA's Agentic Privacy & Security Subgroup

How Humans Are Shaping the Future of Agentic Security

Fifteen to twenty organizations meet to work out what agent security should require

OpenMatter builds private compute infrastructure for secure AI collaboration, which means Chris Biele, Head of Operations and Partnerships at OpenMatter and Chair of the Agentic Privacy & Security Subgroup at the Decentralized AI Agent Alliance, spends his working hours watching organizations run agents against data they cannot expose. Those hours have taught him a lot about what does and doesn’t work in the growing agentic economy. “I’ve seen where agent deployments tend to fail in practice, which is at the boundaries between tools, data, permissions, evidence, and accountability.”

Those boundaries run between organizations, so what counts as valid authority or acceptable evidence has to be agreed upon by more than one party. That is what the Decentralized AI Agent Alliance was formed around. DAIAA was announced on February 9, 2025 with 30 founding members and a mission of fostering decentralized AI agents through education, activism, research, and events. Lou Kerner, who also founded CryptoMondays, the meetup network that began in New York City in 2018, started it “to help solve some of the problems that need to be solved for decentralized AI agents to scale.” What an alliance can do that a single company cannot, he says, is “gain consensus and create standards that move the industry forward,” alongside fostering relationships and supplying context to members. DAIAA membership reached 235 by its August 17 showcase, and the alliance runs two general meetings a month.

Most of that work happens in subgroups. The Agentic Privacy & Security Subgroup held its first meeting on July 1, 2026. “Agents are entering sensitive workflows before the ecosystem has a shared language for securing and governing them,” Biele says. The goal is to get builders, compliance teams, security practitioners, and policy contributors into one place and turn abstract risk into something implementable.

Roughly 15 to 20 independent organizations are represented in a typical session: agent builders, infrastructure teams, compliance and security practitioners, policy professionals, and investors. A session runs as a working meeting rather than a webinar, starting from something concrete and testing it from technical, compliance, and implementation angles. “When it works, someone describes a real constraint, someone else names a standard or technique that might address it, and a third person points out where that breaks in practice.”

Accountable Execution

What the group converged on is a definition. Agent security is not about model behavior or better guardrails, Biele says, but about “accountable execution: what the agent did, under whose authority, against which policy, with what evidence.”

The definition changes how familiar problems look. Take hidden instructions arriving through calendar invites or shared documents. “The coverage usually frames this as prompt injection, which is true but incomplete. What the group saw is an intent-collision problem: the agent is receiving instructions from multiple places, and not all of them should carry authority.”

One of the challenges the group addresses is how specific a standard should be. Builders want requirements they can implement, but writing them too early could privilege one type of architecture before the field knows what works best.

Biele chairs the group while working for a vendor in the same space, which he treats as a constraint rather than a credential. “I can bring those implementation lessons into the room, but I can’t pretend one vendor’s architecture should define the whole category.” Decentralization gets similar handling. In the subgroup it means independent verification, portable authorization, and evidence that survives an organizational boundary. “If an agent’s logs, permissions, and compliance claims are all generated and verified by the same party, then decentralization is just branding.”

What Security Teams Can Do Now

The habit Biele expects to become standard, and to be hard to unwind, is retrofitted governance: ship the agents, then wrap logs and approvals around them and call it compliance. “Logs are useful, but if they are mutable, provider-controlled, and not policy-bound, they are not enough.”

He says a fuller implementation guide is in development. Until it publishes, his short version for anyone with agents in production: inventory every one and what it can reach; map whose authority each acts under and whether it can delegate; rank actions by whether they touch regulated data, move money, or do something irreversible; check whether an incident could be reconstructed from logs that are tamper-evident and policy-bound; and add no new tools, permissions, or delegation paths without review. Then run a drill and see whether the team can detect, contain, and explain it.

Whatever that drill turns up is the kind of material a session starts from. Meetings run every other Wednesday at 1pm EDT, and DAIAA membership is not required to attend. You can register for the next one here.

— The OpenMatter Team


If you know someone who would benefit from reading this article, please share it:

Share


OpenMatter is building the verifiable trust layer that enables AI agents to securely collaborate on sensitive data sets. If you’re in a regulated industry and need a better way to prove that your data is secure, contact our team to learn how masked compute can help.