AI browsing agents can read your screen, fill out your forms, and act on your behalf online — but most users have no way of knowing how safely they do it. AgentWatch, by Spring 2026 Master of Information and Cybersecurity alums Anagha Late, Marisa Hall, Boaz Kaufman, Anya Svan, Cynthia Austin, and Rutika Kushe, evaluates five leading AI browsing assistants across privacy and security dimensions and published the results in an open, publicly accessible framework.
The team was awarded the Spring 2026 Lily L. Chang Capstone Award, which recognizes the semester’s top project.
To learn more, we interviewed the team —
What inspired your project? How did you decide on the concept?
Anagha: AgentWatch looks nothing like the project we set out to build. We started by exploring a suite of privacy-preserving tools that would scan websites and provide users with a security score drawn from a range of privacy and security indicators. The deeper we went into emerging technology trends, the harder it became to look away from autonomous AI agents, which were rising fast and carrying a class of security and privacy risks we hadn’t seen named clearly anywhere.
Browsing agents are quietly becoming part of everyday digital life. They click, they fill, they fetch, they decide, acting on the open web on our behalf with growing autonomy. And as we watched this unfold, we realized that the people most affected by those decisions were often the people with the least visibility into them. Our original idea had been built for a technical audience, for people who already knew what to look for, which meant we were solving the problem for the people who needed it least. So before we committed to building anything, our team sat down and talked through what we actually cared about. Transparency, accountability, consent, and privacy and security by design. That conversation became our compass.
Grounded by that values-based discussion, we pivoted toward something that could meet non-technical people where they are: a framework that makes the privacy behavior of AI agents legible to civil society.
What was the timeline or process like from concept to final project?
Rutika: Our capstone project evolved considerably from its original concept. We initially explored building a browser-based tool that would evaluate websites and provide users with a security score based on various security and privacy indicators. As we researched emerging technology trends, we became increasingly interested in the rapid rise of autonomous AI agents and the unique security and privacy risks they introduced. Because agentic AI was becoming more relevant and impactful, we pivoted our focus toward evaluating the behavior of AI agents themselves. Through research, threat modeling, and iterative testing, we developed AgentWatch, a framework for assessing the trustworthiness, privacy, and security of AI agents through standardized evaluations.
How did you work as a team? How did you work together as members of an online degree program?
Cynthia: We found that trust, communication, and leveraging each teammate’s strengths were keys to our team’s success. The group was split up on tasks based on strengths, but we were extremely collaborative. Teammates would give each other feedback, check each other's work, and help when someone was stuck.
Since we were all online students, communication was vital. We had weekly meetings, used collaborative tools, and checked in with each other often. Even though we lived across the country from each other, we clicked as a team and were able to work well together. The whole experience kind of mirrored what most workplaces are like these days with distributed teams.
“So before we committed to building anything, our team sat down and talked through what we actually cared about. Transparency, accountability, consent, and privacy and security by design. That conversation became our compass.”
How did your I School curriculum help prepare you for this project?
Anya: One of the most distinctive and valuable aspects of the I School curriculum is its interdisciplinary coursework, passionate professors, and the opportunity to earn a certificate in other disciplines along with a master's degree. By interdisciplinary, I am referring to how, throughout this entire program, the professors and courses have challenged me to think about cybersecurity beyond the technical application and to consider the individual human, as well as the larger social, legal, economic, and political factors that shape what makes cybersecurity practices effective or unsuccessful. A perfect example of this was the first-hand experience helping a non-profit and seeing the barriers to cybersecurity through the UC Berkeley Cybersecurity Clinic (formerly Citizen Clinic), which was a foundational underpinning that shaped how my team and I approached this project; making AgentWatch open source and understandable to a non-technical audience.
Additionally, along with my master's degree in Information and Cybersecurity, I completed the Applied Data Science certificate: the knowledge I gained in data science classes like Research Design and Application for Data and Analysis, taught by Brooks Ambrose, and Experiments and Causal Inference, taught by Clinton Brownley, was integral in guiding how I designed our research plan and AI agent testing. These courses taught me the best practices for study design, understanding how to eliminate biases and do something called a power analysis that helped determine how many trials on each AI browsing agent was needed to yield a meaningful chance of getting statistically significant results. Also, Professor Clarence Chio, whom some other team members and I had for Artificial Intelligence and Machine Learning in Cybersecurity, was generous enough to meet with another team member and me to refine the agent testing strategy and test scenarios. All the skills and lessons learned throughout my time at the I School guided my testing approach for the AI browsing agents and how I went about making the foundation for our research paper, which will be published soon by UC Berkeley’s Center for Long-Term Cybersecurity.
Which course in the program was uniquely helpful in preparing you for your capstone project and why?
Marisa: There were a few courses that were uniquely helpful for this project. The first course that comes to mind is Cybersecurity In Context, which positions cybersecurity in the context of the legal and policy landscape. I took this course with Tiffany Rad, who emphasized the importance of thinking about policy in practice, and the real-world impacts and implementation of those policies. This course was the first one that really introduced me to rigorous research methodology at the core of learning, and taking things like policy as potential trust signals, but not hesitating when it comes to being critical around the reality of how we use, utilize, and experiment with technology. The most significant thing that I took away from this class was the development and maturing of my own definition and application of ethics in my approach to assessing new technology, policy, and understanding of the user and developer perspective.
The second course that was essential was the UC Berkeley Cybersecurity Clinic Practicum with Elijah Baucom, where students are introduced to applications of risk reduction that, again, centers people. Most of the organizations that we work with in the clinic do not have in-house cybersecurity or technical staff and overall tend to be resource-constrained. Different types of technology can be incredibly useful tools for organizations like these, but the other side of that is that many of the organizations we work with are vulnerable to surveillance and targeted attacks because of the work that they do for their communities. This means that they might default to doing things manually or doing things slowly because it feels safer, despite potential operational impacts and sometimes inadvertent cybersecurity risk. In some situations, an AI tool could provide broader access for resource-constrained organizations to expand their work, but there are so few resources out there to aid in making informed decisions around what tradeoffs might be present in using them. One of our goals with AgentWatch, especially in the development of the quantification method and scoring framework, was to jump-start breaking down some of that information in plain-language for users of all kinds to utilize.
How could this project make an impact, or, who will it serve?
Anagha: Building AgentWatch as open source was part of the same commitment that shaped the project from the start. It is an invitation, extended to anyone impacted by these systems, to contribute, to question, and to take part in a culture where the people most affected by technology help shape how it is held accountable.
AgentWatch serves the everyday person first. People are increasingly allowing AI agents access to their accounts and their decisions, often without any way of seeing what those agents actually do. The framework surfaces real behavioral differences across commercial agents and renders them legible to anyone. Findings are published openly to be read, used, and built on.
Now that you’ve finished your capstone, what advice would you give yourself at the start of the program? What do you wish Day One you knew?
Boaz: Our first two weeks or so of the semester were spent on an entirely different project: a set of privacy-enhancing browser extensions. We then decided to pivot to the idea that became AgentWatch. We worked incredibly hard as a team to make up for the lost time, and that pressure helped to strengthen our project in the end.
At the time, it was stressful making the call to abandon our inchoate project. But I would tell our team at that point that making a big switch like that isn’t necessarily a setback. In our case, it was merely a step on the path towards something even better. And the shared values that brought us together for our original idea still informed the final shape of AgentWatch.

