When Your AI Agent Deals With Theirs, Who's on the Hook?
Australia's AI Safety Institute has released its first report: the risk when your AI agent deals with a supplier's or customer's — and what SMEs should do now.
Australia just named a risk that has no single owner
On 9 August 2026, Australia's AI Safety Institute published its first report — and the risk it names is one your business can't fully control on its own. As soon as your AI agent starts dealing with a supplier's, a customer's, or a platform's, a failure can happen in the gap between them: a place none of your controls reach, and none of theirs do either.
The report, Risks and controls for multi-agent systems, was prepared by the not-for-profit Gradient Institute and released through the Department of Industry, Science and Resources. It is the first publication from the AI Safety Institute the government stood up under the National AI Plan, and the Gradient Institute describes its framework as a world-first: a structured map of what goes wrong when AI agents from different organisations interact, and who is actually in a position to fix it.
Why a plumber or an accountant should care
This sounds abstract until you trace a single job. A customer's AI assistant messages your AI receptionist to book a repair. Your receptionist hands the job to your scheduling tool. That tool pulls parts pricing from a wholesaler's system, which increasingly answers with an agent of its own. Four agents, three businesses, one invoice — and no human looked at any of the handoffs. In an accounting firm the chain is quieter but the same: your AI agent reads figures straight from a client's AI bookkeeping agent, and one hallucinated number flows through unchallenged.
The report's technical companion sets out six failure modes. Three are worth a small operator's attention. Cascading reliability failures: one agent's small error is propagated and reinforced down the chain until it's a big one. Inter-agent communication failures: misinterpretation, lost information, or agents stuck in a loop that never finishes the task. And mixed motive dynamics: each agent doing what's rational for its own owner, adding up to an outcome that's bad for everyone — the wholesaler's agent optimises its margin, yours optimises speed, and the quote that reaches your customer is wrong.
If you've switched on tools that talk to other companies' systems and aren't sure where the human checkpoints are, book a short review before the next one goes live.
The output is still yours
Here's the part the boundary problem doesn't change: to your customer, there is no chain. There's your business. Under the Australian Consumer Law, if your AI misleads a customer you're the one liable — it makes no difference that the bad answer started in a supplier's agent you don't control. And directors are now expected to govern AI use personally, not wave it through. The agent-to-agent gap adds risk without moving the responsibility anywhere. That's the uncomfortable combination the report is pointing at.
Want to know what this means for your business? We'll map it in one call.
Book a call →What to do about it this quarter
The report groups its controls into two: constrain what an agent is allowed to do, and design the plumbing between agents deliberately. For a small business that turns into three moves. First, map every point where your AI hands off to a system you don't own — the booking widget, the pricing feed, the payment agent, the client's software. Second, put a human back at the boundary: the moment an agent is about to act on another party's agent output on anything that costs money or touches a customer, that's where a person signs off. It lines up with the government's own advice to never give an agent broad or unrestricted access, and to start small. Third, get one line in writing from each vendor and partner — what happens when their agent gives yours a wrong answer? If they can't say, you've found your weakest link.
The quiet part is that you're early
Agent-to-agent commerce is still forming. That's the advantage. The businesses that come out of this well won't be the ones that wired everything together fastest; they'll be the ones that knew where their agents ended and someone else's began — and kept a hand on that seam. The government has now told you where to look. The work is small if you do it before the connections multiply.
Key takeaways
Common questions
What is a multi-agent AI system?
It's what you get when more than one AI agent operates in the same environment — including agents run by different businesses. Australia's AI Safety Institute report describes how, as organisations deploy agents, those agents increasingly interact with agents used by suppliers, customers and other parties, creating risks no single organisation can fully see or control.
Who is liable when one business's AI agent relies on another's?
You stay responsible for what your business's agent does. Under the Australian Consumer Law you're liable if your AI misleads a customer, regardless of whether the faulty input came from a supplier's or platform's agent you don't control. The cross-organisational gap adds risk without shifting responsibility.
What did Australia's AI Safety Institute recommend?
Constrain what agents can do — never grant broad or unrestricted access, especially to sensitive data or critical systems — design the connections between agents deliberately, and keep a human able to review and approve agent actions. For a small business that means mapping every handoff to a system you don't own and putting a person at each boundary that costs money or touches a customer.
Sources
▶Assumptions & methodology
- Australia's AI Safety Institute published 'Risks and controls for multi-agent systems' on 9 August 2026 (date per contemporaneous coverage by TechTimes and OpenGov Asia); it was prepared by the Gradient Institute and released through the Department of Industry, Science and Resources. The Institute was established under the National AI Plan.
- The six failure modes (cascading reliability failures, inter-agent communication failures, monoculture collapse, conformity bias, deficient theory of mind, and mixed motive dynamics) are drawn from the Gradient Institute's technical analysis of governed LLM-based multi-agent systems, the framework underpinning the report. This note discusses three of the six as most relevant to small operators.
- The customer-facing hand-off scenarios (AI receptionist, scheduling tool, wholesaler pricing agent, client bookkeeping agent) are illustrative examples constructed to show how cross-organisational agent interactions arise in trades and professional-services workflows; they are not taken from the report.
- 'World-first' reflects the Gradient Institute's own characterisation of its framework for cross-organisational multi-agent risk.
Field Notes are general commentary on AI trends for Australian businesses. They don’t constitute professional advice. Talk to your accountant, lawyer, or IT adviser before acting on anything specific to your situation — or talk to us if you want help working out where AI fits.
Subscribe
Don't miss the next one
Get each new Field Note in your inbox as it publishes — short, practical AI intelligence for business owners.
Not sure where your AI agents end and someone else's begin?
We map every point where your tools hand off to a system you don't control, mark where a human still needs to sign off, and flag which vendor can't answer for their own agent — one straight conversation about where the risk actually sits.
Book a call →