{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/deepmind-ai-control-roadmap-2026/",
 "asOf": "2026-09-26",
 "id": "deepmind-ai-control-roadmap-2026",
 "date": "2026-06-18",
 "datePrecision": "day",
 "title": "Google DeepMind publishes an AI Control Roadmap treating internal agents as potential insider threats",
 "lane": "defense",
 "kind": "framework",
 "summary": "Google DeepMind introduces an AI Control Roadmap for internally deployed agents. It treats potentially misaligned AI as an insider threat, builds a threat model on MITRE ATT&CK tactics and techniques, and scales detection and response requirements with levels of agent evasion (D1-D4) and attack capability (R1-R3). It reports analyzing about a million coding agent tasks with a prototype asynchronous monitor, which informed a live monitor for its Gemini Spark agent. It says the majority of flagged events were not adversarial and often stemmed from misinterpretation or overeagerness.",
 "whyItMatters": "A frontier lab is applying security-operations concepts directly to monitoring its own agents.",
 "actors": [
  "google-deepmind"
 ],
 "topics": [
  "monitoring-and-control"
 ],
 "atlas": [
  "monitor",
  "model",
  "credentials"
 ],
 "artifacts": [
  "gemini"
 ],
 "sources": [
  {
   "url": "https://deepmind.google/blog/securing-the-future-of-ai-agents",
   "publisher": "Google DeepMind",
   "title": "Securing the future of AI agents",
   "date": "2026-06-18",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Capability levels: detection evasion D1-D4 and attack execution R1-R3; metrics tracked include coverage, recall and time-to-response.",
   "locator": "Understanding AI Control; Scaling security as AI gets smarter"
  },
  {
   "fact": "About a million coding agent tasks analyzed by an internal asynchronous monitoring prototype; Google DeepMind says the majority of flagged events did not stem from adversarial intent and often reflected misinterpretation or overeagerness.",
   "locator": "Analyzing a million agent trajectories to inform live monitoring"
  }
 ],
 "significance": 3,
 "fideQuestions": [
  "FID-074"
 ],
 "methods": [
  "ai-monitoring",
  "monitor-evasion"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}