Australia maps risks across interacting AI agents
Australia’s Department of Industry, Science and Resources commissioned research to map AI-agent risks and controls without creating binding duties.

Australia's Department of Industry, Science and Resources published a multi-agent risk framework on 10 August 2026 for AI systems that interact across organisational boundaries. The government commissioned Gradient Institute to conduct the study and released it as the first publication of the Australian AI Safety Institute.
The official report page defines an AI agent as software that uses a large language model to plan and execute self-directed actions toward a human-specified goal. Its premise is that a collection of individually safe agents does not necessarily form a safe system. Failures can emerge through interaction, and the organisation deploying one agent may be unable to inspect or control the other agents involved.
The framework uses governance reach as its organising variable.
Tier 1 is singular governance: one organisation deploys every agent and can specify, inspect, monitor and intervene across the system. The main concerns are coordination failures between cooperating agents and propagation, where an error, wrong belief, sensitive data or malicious instruction moves through the network. The report notes that adaptive agents can revise plans in response to each other, allowing one erroneous output to influence later actions elsewhere in the system.
Tier 2 is federated governance. Several organisations deploy agents into a shared environment under agreed rules, but no participant controls the whole system. The framework says this tier requires common infrastructure plus agreed standards and conditions of participation. It also introduces incentive risk: each agent may rationally pursue the task given by its owner while their combined behaviour produces conflict, collusion or another harmful outcome.
Tier 3 covers open environments in which agents interact through public infrastructure without a central governing authority. The report gives organisations two broad routes: lock an agent down on the assumption that counterparties cannot be trusted, or use voluntary standards so it interacts only with agents meeting the same conditions. The report calls the second route polycentric governance and treats it as a control arrangement with risks of its own, not a complete solution.
Across the tiers, the study groups failures into four families: miscoordination, propagation and contagion, strategic and incentive failures, and infrastructure or environmental failures. The last category concerns collective effects on shared software, marketplaces or resources. The common question is who is positioned to act, how far that actor's controls reach and where no participant can currently intervene.
Each tier is defined by the minimum governance shared by all interacting agents, and later tiers carry forward the risk factors present in earlier ones. Moving from an internal deployment to a federated or open environment therefore does not replace coordination and propagation risk; it adds counterparties, divergent incentives and gaps in authority over the same technical behaviours.
The framework is research, not a binding Australian rule.
For organisations deploying agents, its practical value is a system map. A review should identify every agent and owner, the data and tools each agent can reach, the counterparties it may contact, the protocol or shared infrastructure used for interaction, and the party able to monitor, pause or terminate the exchange. Authentication and authorisation controls need to address the counterparty agent as well as the employee or customer on whose behalf it acts.
Evidence should then be assigned to each boundary: logs that reconstruct inter-agent messages and tool calls, controls that constrain delegation, tests for error propagation, rules for handling divergent objectives, incident escalation across firms and a shutdown path that does not depend on cooperation from an unknown external actor. In a federated setting, the evidence also includes participation standards, allocation of responsibility and a process for removing an agent that breaches the shared rules.
A useful approval paper should state the tier in which the proposed use actually operates and identify the event that would move it into another tier. Allowing a previously internal agent to contact supplier or customer agents changes the reach of the organisation's controls even if the underlying model and prompt remain unchanged.
The department's announcement describes the publication as a map for policymakers, organisations and researchers. The next supervisory question is whether the AI Safety Institute or another Australian authority converts parts of that map into testing guidance, voluntary standards or binding requirements. Until such an instrument appears, 10 August 2026 is the publication date and the framework should be used as technical governance guidance rather than represented as law.
Permanent link to this Atlas analysis
Related Atlas analysis
Continue with coverage connected by market, topic and operating context.
- AustraliaASIC seeks court restraints against Royce entities over alleged misconductASIC’s Federal Court application seeks restraints on Royce entities and individuals, affecting Australian fundraising and communications about offshore investment funds.
- United KingdomUK AML amendments phase controls through October 2027The instrument already changed pooled-account and customer-diligence rules, with crypto correspondent controls and part of the change-in-control regime still ahead.
- United StatesCFTC alleges $397 million crypto fraud by GoliathThe CFTC’s civil complaint seeks restitution, penalties and trading bans against Goliath Ventures and Christopher Delgado over alleged crypto-asset fraud.
Continue with Atlas
Move from this development into the relevant research, comparison and workflow.