When AI agents interact: new research from the Australian AI Safety Institute

A headshot of Lauren Solomon from the National AI Centre
Lauren Solomon
Manager, Guidance and Best Practice, National AI Centre
10 August 2026
First published
10 August 2026
The Australian AI Safety Institute has released new research exploring the risks, controls and governance of AI agents that engage with each other.

AI agents are being deployed by Australian organisations to help them complete tasks, book appointments, check stock or draft emails. AI agents are different to other types of AI systems because they don’t just answer questions, they interact with systems and tools and can manage a process with multiple steps.

This new research delivered by Gradient Institute highlights the emerging challenges for organisations when their AI agents interact with agents of their partners, suppliers and customers. This is what’s known as a multi-agent system: a system where two or more AI agents interact, communicate or coordinate as they work on connected tasks.

Key findings that organisations should consider when deploying agents

  • A collection of safe individual agents is not the same thing as a safe and reliable system of agents. While effective controls might be applied to one agent which operates as intended, once agents interact new system-level failures can emerge.
  • When multiple agents are owned and operated entirely within the boundaries of one organisation, risks are easier to manage, but can still be challenging. The organisation can set the rules, monitor the behaviour and apply appropriate controls.
  • When agents deployed by separate organisations interact, risks can increase. This is because no one organisation governs all the agents. An example of agents interacting in a shared environment might be a business’s agent interacting with a supplier’s agent as it works to place a purchase order. If the different organisations agree on a shared governance framework, including rules and protocols for how agents might interact, it can help manage those risks. 
  • When an organisation’s agent interacts with another agent in an open environment, such as the open web, this can present greater risks. This is because the organisation has little visibility or control over how the other agents will act, or who is responsible for them. An example might be an AI agent browsing websites to find the best price on materials, where it encounters other AI agents (such as a sales agent, a pricing bot or something malicious) with no common rules and no way to verify who's on the other side.

Reducing risk in multi-agent systems

Steps organisations can take when considering using multiple agents or deploying agents in shared or open environments: 

  • When multiple agents interact with each other within your organisation, take care to evaluate them together as a system.
  • Set clear rules between organisations before AI agents interact – organisations can reduce risk by agreeing on safeguards, monitoring and escalation points before agents operate across shared environments.
  • If your AI agent connects to anonymous people, their services or their agents, assume it might be attacked, manipulated or be incompatible. Limit what your agent can access inside your organisation, and configure it to use agreed standards for connecting as set out in the report.

Further guidance on AI agents

The Risks and controls for multi-agent systems report includes more detailed information and specific controls that can be applied based on each operating environment. 

Keep an eye out for upcoming new guidance from the National AI Centre on AI agents, the risks they pose and what actions organisations can take. 

 

Related resources

Careful adoption of agentic AI services
Australian Signals Directorate guidance on key cyber security safeguards for organisations using AI agents.

Australian AI Safety Institute
Explore the Australian AI Safety Institute's work on AI safety, security and risk assessment.