When agents deal with each other, the object is the connection
An Australian government report moves the governance object from the single agent to the relationship between them. The stop-point sits where control ends.
AI6 Sept 20264 min read
On this page
What it says
On 10 August 2026 the AI Safety Institute, in Australia's Department of Industry, Science and Resources, published Risks and Controls for Multi-Agent Systems, 119 pages 1. Gradient Institute wrote it. The report's agent is a language model in a harness and scaffold, running plan, act and observe; it calls nothing else an agent 2.
Three tiers follow, set by the governance floor the agents can assume. Singular governance has one organisation governing all of them; federated, several in a shared environment under agreed rules; open environments, nobody 3.
Cross-boundary irreversibility: a commitment or data sent past the organisational boundary cannot be reversed unilaterally. Putting it right depends on cooperation, a contract or a court, at human or legal speed 4.
Semantic divergence follows: status flags, field names, units or deadlines are vocabulary each side reads differently. A field marked authorised or deadline can mean different things, and a schema does not settle it 5.
Evaluation splits capability, what an agent can do, from propensity, how likely it is to do it in deployment. The singular tier can simulate counterparties whose design it knows; federated ones are opaque. In open environments they are unbounded, evidence ages, and evaluation falls back on capability 6.
What we take from it
Our reversibility line, that what can be undone may auto-approve and what cannot goes to a named human, meets the case where the counterparty is another organisation's agent. The report supplies the missing half: the boundary falls where a commitment leaves the organisation's unilateral control. The article turns that into a locator: payment, a firm order, acceptance of material commercial terms, protected data sent outward 7. We would keep it: those are points on a process diagram, which "high-risk needs a human" never was. Data is why the last one matters: what crosses carries consent, confidentiality and commercial sensitivity that do not return 8.
The principal is the party whose authority an agent acts under, and the party its actions come back to 9. An inventory that lists agents is half a record, because the risk sits on the connections between them. Our AI system register needs two columns: the counterparties an agent may bind, and the tier each connection runs at. The article makes the same move, proposing a map of agent relationships as the entry point 7.
The report's control is to name the actions with serious consequences and put a human stop-point in front: agreeing a purchase, bidding above a set amount. Both agents acknowledge the terms before either commits, and a clearance period precedes settlement 10. Its triage says the same in control language: low-risk reversible actions run on automated policy, while high-impact, irreversible or external ones go to a person 11.
Semantic divergence belongs in interface reviews. It is not a data-quality defect, and a validator will not catch it: both sides process correct input correctly and still disagree about what was agreed.
Four actions.
- List the agents that can bind the organisation. Name the principal, the counterparties it may commit and the tier each connection runs at, and re-run the permissions review when that list grows.
- Put the stop-point where control ends. Mark the point on each flow where reversal stops being unilateral, and place the human check there, not at the start of the task.
- Agree the terms that carry consequences. Settle in writing with each counterparty what the few decisive fields mean, before the interface is built.
- Buy back time. Add a clearance window to transactions that machine speed would otherwise close, and test that someone can use it.
Where we would push back
The report is an analytical framework, not a rule, and it says so 12. Reading an obligation out of it would be a mistake, and its tiers describe deployments most organisations do not yet run.
The federated tier asks for a great deal: agreed conduct standards, shared identity, dispute and rollback mechanisms 13. Two mid-sized firms wiring a procurement agent to a fulfilment agent will not build that. What they can do is narrower: the stop-point, and agreed vocabulary for the terms that move money.
The capability fallback is honest but uncomfortable: told that evidence about behaviour goes stale, an organisation is being told its assurance decays, and no reporting line yet exists for that. The safer reading is architectural: if the business does not need an agent in an open environment, do not put one there.
Related on GRCIDE
- Governing AI and agents: who decides what, on the reversibility line and the decision rights around it.
- The permissions review that did not happen, on what an agent inherits when nobody reviews it.
- AI system register, the record the two new columns belong in.
Sources
- 1AI Safety Institute, publication page and cover, industry.gov.au · verified 2026-09-06
- 2AI Safety Institute, p. 11, industry.gov.au · verified 2026-09-06
- 3AI Safety Institute, p. 7, industry.gov.au · verified 2026-09-06
- 4AI Safety Institute, p. 51, industry.gov.au · verified 2026-09-06
- 5AI Safety Institute, pp. 49 and 53, industry.gov.au · verified 2026-09-06
- 6AI Safety Institute, p. 92, industry.gov.au · verified 2026-09-06
- 7那一片数据星辰, 当智能体开始代表公司彼此交易,我们该怎么管它?, mp.weixin.qq.com · verified 2026-09-06
- 8AI Safety Institute, p. 67, industry.gov.au · verified 2026-09-06
- 9AI Safety Institute, p. 107, industry.gov.au · verified 2026-09-06
- 10AI Safety Institute, p. 66, industry.gov.au · verified 2026-09-06
- 11AI Safety Institute, p. 41, industry.gov.au · verified 2026-09-06
- 12AI Safety Institute, p. 17, industry.gov.au · verified 2026-09-06
- 13AI Safety Institute, pp. 46 and 57, industry.gov.au · verified 2026-09-06