
The Australian AI Safety Institute published a report on 10 August 2026 that looks at what happens when AI agents stop working alone and start dealing with each other. Its central finding is easy to state and easy to overlook: a group of agents that are each safe and reliable is not automatically a safe and reliable system. For a small or medium business that is starting to use agents for bookings, stock checks, quotes or email, that is worth hearing before those tools are connected to suppliers and customers.
What was published
The report, Risks and controls for multi-agent systems, was commissioned by the Institute and written by Gradient Institute. It is published on the Department of Industry, Science and Resources website. On the same day the National AI Centre released a short summary of the findings for organisations.
The report defines an AI agent as a software system that uses a large language model to plan and carry out self-directed actions towards a goal a person has set. That is different from a chatbot that answers one question at a time. An agent can read a request, decide on the steps, use tools such as a calendar, an inbox or an ordering system, and adjust its plan based on what happened. When two or more agents communicate, coordinate or adapt to each other, the report calls the result a multi-agent system.
Why AI agents matter to a small business now
The National AI Centre's summary says Australian organisations are already deploying agents to complete tasks, book appointments, check stock and draft emails. The report adds that once an organisation has one agent there is little barrier to having many, and that those agents will almost certainly interact, either because they were told to or because they were given separate jobs in the same environment.
Picture this in an ordinary business. A clinic's booking assistant reschedules patients while a second tool sends reminders. A wholesaler's ordering agent places a purchase order with a supplier's agent. A builder's assistant searches the web for prices on materials and meets sales bots along the way. In each case the business that switched the agent on still answers for what it does.
The report is careful on one point: none of the failures it describes are entirely new. What changes with agents is that they happen faster, at greater scale, and with fewer chances for a person to notice and correct them before they compound.
The three tiers: who controls the agents
The report organises its analysis around a single question: who governs the agents that are interacting. It describes three tiers.
| Tier | Who is in control | Example | What that means |
|---|---|---|---|
| 1. Singular governance | One organisation deploys and governs every agent | Internal agents, such as an employee help desk or personal productivity agents | The organisation can specify, inspect, monitor and intervene on every agent |
| 2. Federated governance | Several organisations deploy agents into a shared environment under agreed rules | A procurement agent negotiating with a supplier's fulfilment agent | No single organisation controls the whole system, so it depends on agreed conditions and shared infrastructure |
| 3. Open environments | No central governing authority | An agent browsing websites for a price and meeting unknown agents | Little is known about the other party, or whether it can be trusted |
According to the report, the controls available for a given risk depend on how much governance is shared between the agents, not on their design, their task or how many there are.
Four ways multi-agent systems fail
For each tier the report examines four types of failure:
- Miscoordination: cooperating agents misread each other or hand work over incorrectly.
- Propagation and contagion: an error, a wrong belief, sensitive data or a malicious instruction spreads through the links between agents.
- Strategic and incentive failures: agents acting for parties with different interests each behave rationally and still produce a harmful result, such as conflict or collusion.
- Infrastructure and environment failures: populations of agents damage the shared systems they rely on, destabilise a marketplace or use up a shared resource.
One example in the report shows how odd these failures can look. In a public experiment where several agents shared a file system, one agent invented a contact list that did not exist and asked another agent to use it. The second agent created an empty file with a name suggesting it held contacts. The other agents treated the file as evidence that a real list had been corrupted, and the whole group turned its effort to recovering it, even though people repeatedly told them the list had never existed.
A second example matters to anyone considering automated pricing. The report describes algorithmic collusion, where agents that are meant to compete end up coordinating on price. It notes that the organisation behind an agent does not need to intend or instruct this; the agent can arrive at the strategy by itself, simply by watching and adapting to what other agents do.
Controls the report and the National AI Centre suggest
The report pairs each failure with controls, and the National AI Centre's summary turns the main ones into steps an organisation can take. A practical checklist drawn from both:
- When several agents interact inside your business, evaluate them together as a system, not one at a time.
- Have agents pass work to each other in a defined, structured format instead of free text, which narrows the range of wrong answers that still look acceptable.
- Consider whether every agent runs on the same underlying model. The report says a single model across all agents makes them more likely to share blind spots.
- Use checkpoints so a long-running task can be rolled back to a last known good state.
- Before your agent deals with another organisation's agent, agree on safeguards, monitoring and escalation points.
- If your agent connects to anonymous people, services or agents, assume it might be attacked, manipulated or incompatible, and limit what it can reach inside your business.
The summary also points to cyber security guidance co-authored by the Australian Signals Directorate, Careful adoption of agentic AI services, published on 1 May 2026. Its key actions include limiting initial use to low-risk, well-defined tasks and applying strong oversight, continuous monitoring and human control. It also recommends never granting an agent broad or unrestricted access, especially to sensitive data or critical systems.
What an SME owner should take from the report
This is a research report and an analytical framework, not a set of rules. It still gives a small business a sound way to think before buying or switching on an agent.
Work out which tier you are really in
Most small businesses will start in tier 1, with a few agents inside their own systems. The moment an agent reads email from strangers, browses the open web or talks to a supplier's system, part of its work has moved into tier 2 or tier 3, where your own settings no longer cover everything that can go wrong.
Treat access as the main control
Ask three plain questions of any agent: what can it read, what can it change, and what can it spend or commit to. An agent that drafts replies for a person to send carries far less risk than one that can issue refunds, change bookings or place orders unattended. Start with narrow access and widen it only when you have seen how the agent behaves.
Keep a person on the decisions that matter
Payments, contracts, pricing and anything involving customer or patient records are sensible places to require human approval. Keep logs of what each agent did and what it accessed, so that a mistake can be traced and reversed.
Ask vendors direct questions
Before adopting a product that includes agents, ask which systems it connects to, whether its actions can be undone, what records it keeps, and how it behaves when the other side of a conversation is another agent.
Comingwave is a technology company that provides technology and business solutions to small and medium enterprises. Access control and the way your systems connect are where most of the practical work sits. Our IT consulting service helps you assess new tools before you commit, our cyber security service covers access control, encryption and backups, and our business systems and integrations work covers how software connects to your CRM, accounting and ordering systems. To talk it through, request a free first consultation.
Key takeaways
- The Australian AI Safety Institute published Risks and controls for multi-agent systems on 10 August 2026.
- Agents that are each safe can still fail as a group, because new failures emerge from the interactions between them.
- Risk rises as agents move from inside one business, to shared environments with agreed rules, to open environments with no central authority.
- The practical controls are limited access, structured handoffs, monitoring, the ability to roll back, and agreed rules with other organisations.
- Official cyber security guidance recommends starting with low-risk, well-defined tasks under human control.
Frequently asked questions
What is an AI agent?
The report defines an AI agent as a software system that uses a large language model to plan and execute self-directed actions to achieve goals set by a person. Unlike a chatbot, it can use tools, take several steps and adjust its plan as it goes.
What is a multi-agent system?
It is a system in which two or more AI agents interact, communicate or coordinate while working on connected tasks. The agents may all belong to one business or to different organisations.
Does the report create new rules for Australian businesses?
No. It is research commissioned by the Australian AI Safety Institute and offers a framework for understanding risks and controls. The National AI Centre says it is preparing further guidance on AI agents.
Should a small business avoid AI agents altogether?
The report does not say that. Guidance co-authored by the Australian Signals Directorate recommends limiting initial use to low-risk, well-defined tasks and keeping strong oversight and human control.