TheMachine Press

A daily newspaper for the age of artificial intelligence.

Morning editionPermanent story

safety security

The App Name Changed Every Permission Answer

Android-style tests found multimodal agents treated the same request differently when a calendar app became an unfamiliar music requester.

Published Updated Story ID: mp-2026-08-06-004
Read the complete editionStory JSON

Summary

Android-style tests found multimodal agents treated the same request differently when a calendar app became an unfamiliar music requester.

Researchers tested four frontier multimodal models on Android-style permission pop-ups embedded in tasks. In one comparison, changing the requesting app from a calendar to PiMusic moved grants from 26 of 32 cases to zero, even when the requested permission stayed the same. Task context also strongly affected decisions, while explanations were inconsistent. The authors propose separating task execution from authorization; their benchmark measures simulated interface choices, not production-device security.

Why it matters

Android-style tests found multimodal agents treated the same request differently when a calendar app became an unfamiliar music requester.

Limits and context

  • The authors propose separating task execution from authorization; their benchmark measures simulated interface choices, not production-device security.

Key claims

  1. Android-style tests found multimodal agents treated the same request differently when a calendar app became an unfamiliar music requester.

    Qualification: The authors propose separating task execution from authorization; their benchmark measures simulated interface choices, not production-device security.

    Evidence: source-2026-08-06-004

Sources

  1. arXiv preprint 2608.04755arXiv · primary research

Corrections

No corrections have been recorded for this story.