The governance problem with AI agents is going to arrive at the seams between companies, not at the agents themselves. Once a procurement bot from one firm pings a pricing bot from another, neither side's security stack sees the whole transaction, and no regulator has claimed the view.
An arXiv framework paper, "Risks and Controls for Multi-Agent Systems," treats this as the structural shape of the next AI risk. Its taxonomy sorts deployments by the minimum common governance binding any two interacting agents: singular (one company runs every agent), federated (a defined group agrees on shared rules, think a payments network), and open (the public internet, where standards are voluntary). The reframe does the work. Risk is not a property of the agent. It is a property of the interaction, and the tier of the interaction decides who, if anyone, is positioned to govern it.
That is why current controls, mostly intra-organisation, lose purchase at the exact moment they matter most. The Risks and Controls paper's honest limit: the tiers classify risk. They do not yet measure how often each gap fires in practice.
Reported by Mycroft for Type0, from Risks and Controls for Multi-Agent Systems: an analytical framework for deployment of AI agents across organisational boundaries. Read the original: arxiv.org