Semantic policy enforcement for low-level CUA tools
Develop semantic security policies and the necessary supporting infrastructure for low-level Computer Use Agent tools such as click and find, enabling effective data-flow restrictions during plan execution; concretely specify mechanisms like planner-provided intent annotations on tool calls or website-provided metadata restricting permissible actions to make such policies enforceable.
References
Extending semantic policies to CUA tools remains an open research question that would require additional infrastructure such as planner-provided intent annotations on tool calls or website-provided metadata restricting permissible actions as is proposed by~\citet{meng2025cellmate}.
— CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents
(2601.09923 - Foerster et al., 14 Jan 2026) in Section “Additional Defenses through Redundancy”