ConfiaTech

Article

MosaicLeaks: Can your research agent keep a secret?

June 18, 2026

MosaicLeaks: Can Your Research Agent Keep a Secret?

The Hidden Dangers of AI Research Assistants

Imagine a scenario where your company's most sensitive information is being quietly broadcasted by your AI research assistant. Your team asks the AI agent to dig into a confidential project, and it delivers the answer without raising any red flags. However, unbeknownst to you, those seemingly harmless searches have left a trail of digital breadcrumbs that can be reconstructed to reveal your company's biggest secrets.

This isn't the stuff of science fiction; it's a harsh reality that has been exposed by a recent study from ServiceNow, dubbed MosaicLeaks. The study reveals how deep-research AI agents can inadvertently spill private data through the mosaic effect, where individual queries appear safe but collectively reveal the full picture. To make matters worse, training the AI to be better at its job often exacerbates the problem, making the leaks worse.

What is MosaicLeaks?

MosaicLeaks is a phenomenon where AI research agents, designed to provide accurate and helpful responses, inadvertently leak sensitive information through a series of seemingly innocuous queries. These queries, when analyzed individually, may appear harmless, but when combined, they can reveal confidential data.

The study from ServiceNow highlights the risks associated with using deep-research AI agents in data-sensitive fields, such as healthcare and finance. The researchers found that the AI agents were able to reconstruct sensitive information by piecing together individual queries, even when the queries themselves were not sensitive.

The Risks of MosaicLeaks

The risks associated with MosaicLeaks are significant, particularly for organizations that handle sensitive data. If an AI research agent is unable to keep secrets, it can compromise the trust between an organization and its clients, customers, or patients.

In the healthcare sector, for example, the unauthorized disclosure of patient data can have serious consequences, including reputational damage and financial penalties. Similarly, in the finance sector, the leakage of sensitive financial information can lead to significant financial losses and damage to an organization's reputation.

The Solution: Privacy-Aware Deep Research (PA-DR)

Fortunately, there is a solution to the problem of MosaicLeaks. Researchers have developed a new training method called Privacy-Aware Deep Research (PA-DR), which is designed to reduce the risk of sensitive information leakage.

PA-DR is a smarter training method that takes into account the potential risks associated with deep-research AI agents. By training the AI to be more aware of the potential risks, PA-DR can reduce the leakage of sensitive information by up to 70% while improving the accuracy of the AI's responses.

How PA-DR Works

PA-DR works by training the AI to be more aware of the context in which it is operating. The AI is trained to recognize when it is handling sensitive information and to take steps to protect that information.

The PA-DR training method involves several key components, including:

  • Data masking: The AI is trained to mask sensitive information, making it more difficult for unauthorized parties to access.
  • Query filtering: The AI is trained to filter out queries that may be sensitive or confidential.
  • Contextual awareness: The AI is trained to be aware of the context in which it is operating, including the potential risks associated with handling sensitive information.

Conclusion

The risks associated with MosaicLeaks are significant, particularly for organizations that handle sensitive data. However, with the development of PA-DR, there is a solution to this problem.

By adopting PA-DR, organizations can reduce the risk of sensitive information leakage and improve the accuracy of their AI research agents. This is particularly important for leaders in healthcare, finance, and other data-sensitive fields, who must prioritize the protection of sensitive information.

FAQs

Q: What is MosaicLeaks?
A: MosaicLeaks is a phenomenon where AI research agents inadvertently leak sensitive information through a series of seemingly innocuous queries.

Q: How does PA-DR work?
A: PA-DR is a training method that trains the AI to be more aware of the context in which it is operating, including the potential risks associated with handling sensitive information.

Q: What are the benefits of using PA-DR?
A: The benefits of using PA-DR include a reduction in the leakage of sensitive information by up to 70% and an improvement in the accuracy of the AI's responses.

Call to Action

If you're concerned about the risks associated with MosaicLeaks, we encourage you to learn more about PA-DR and how it can help protect your organization's sensitive information. By adopting PA-DR, you can reduce the risk of sensitive information leakage and improve the accuracy of your AI research agents. Contact us today to learn more.

Build with ConfiaTech

Want to ship something like this?

We turn AI research into production systems. Free 30-minute discovery call scheduled within 24 hours.

Book a discovery call