When Every AI Agent Is Authorized—and the System Is Still Unsafe

By Cheryl Benoit, COO & CDO, Iron Gate Program Advisory LLC


Organizations are getting better at governing individual AI systems.

They identify owners, define intended use, establish permissions, limit access to data and tools, determine where human oversight is required, and document accountability.

Those controls remain essential.

But as AI moves from individual assistants toward autonomous and multi-agent systems, another governance problem is emerging:

An organization can govern every AI agent correctly and still create an unsafe system.

The reason is that risk does not necessarily remain within the boundary of an individual agent. It can emerge through the way authorized agents interact, exchange information, delegate activity, invoke tools and combine their permissions across a shared environment.

Recent research makes that distinction increasingly important. Anthropic’s August 2026 examination of emerging multi-agent systems warns that benign individual behaviors can compound into unwanted global outcomes and anticipates significant growth in real-world agent-to-agent interaction.

The governance boundary must evolve with the technology.

Diagram showing how risk can emerge through interactions among individually authorized AI agents and the four governance dimensions needed to manage it.

Authorization Is Necessary. It Is Not Sufficient.

Traditional governance appropriately asks:

Is this system authorized to perform this action?

Agentic systems require another question:

Is the resulting interaction authorized—and is it still operating within the conditions under which the individual agents were approved?

Consider three agents operating within one workflow.

One retrieves information. A second analyzes it and generates a recommendation. A third is authorized to take an operational action.

Each may have a legitimate purpose, defined permissions and an accountable owner.

But their interaction creates something that may not have existed when those individual approvals were granted: a pathway through which information, influence and authority can move across the system.

If the first agent retrieves manipulated information, the second may treat it as legitimate input. If that agent’s recommendation becomes an instruction, the third may be permitted to act on it.

No individual agent necessarily exceeds its permissions.

Yet the system may produce an outcome that no one explicitly evaluated or intended.

That is the governance problem.

The Risk Can Exist Between the Agents

Security guidance is beginning to reflect this shift.

OWASP identifies excessive agency as a vulnerability that can arise from excessive functionality, permissions or autonomy. Its guidance specifically recognizes manipulated input from a compromised peer agent as a potential trigger in multi-agent environments.

Microsoft similarly identifies agent-to-agent propagation as a security concern: when agents interact, compromise in one part of an environment can spread through other agents. Its broader agentic-risk guidance also warns that agent-to-tool, agent-to-service and agent-to-agent interactions expand the attack surface.

Google now describes AI agents as systems that may be permitted to read email, query databases and trigger APIs. They do not merely retrieve information; they act.

And ISACA recently highlighted an especially important governance distinction: an AI agent can use legitimate credentials and fully authorized interfaces while taking actions that do not align with the purpose for which the access was approved.

Recent analysis of AI-enabled cyber operations has reached a related conclusion: as autonomous systems operate with greater speed and less human intervention, effective governance increasingly depends on real-time monitoring, reconstructable logs, defined intervention authority and the ability to constrain or stop activity when predefined boundaries are exceeded.

Taken together, these developments point to a clear conclusion:

Valid credentials do not guarantee valid outcomes. Individual authorization does not guarantee safe interaction.

Governance Must Follow Authority Through the System

The critical question is no longer simply whether an agent possesses authority.

Organizations increasingly need to understand how authority moves, combines and changes through interaction.

Can one agent delegate work to another?

Can one agent’s output automatically trigger another agent’s action?

Can information generated by one system materially alter the decisions available to another?

Can several individually limited permissions combine into a capability that would never have been approved for a single agent?

Can a new tool, data source or external system alter an otherwise approved workflow?

Answering those questions requires governance to extend beyond an inventory of individual agents to the environment in which they interact.

Four areas become particularly important.

1. Authority Boundaries

Organizations should define not only what each agent may do, but where that authority begins, where it ends and how it can be delegated or amplified.

One agent may have read access. Another may have analytical authority. A third may have execution authority.

Individually, those permissions may be reasonable. Combined, they can create an end-to-end capability with significantly greater consequence.

Governance therefore needs visibility into cumulative authority, not merely individual permissions.

2. Interaction Pathways

An inventory that identifies every agent but not the relationships among them provides only part of the risk picture.

Organizations need to understand which agents communicate, what information moves between them, which tools they can invoke, where automated handoffs occur and which outputs become inputs to downstream decisions.

The interaction map may become as important as the agent inventory itself.

3. Observability

When consequential outcomes emerge from multiple interacting systems, accountability depends on reconstructing what occurred.

Organizations should be able to determine what initiated an action, which agents participated, what information was exchanged, which tools were invoked, where authority changed hands and what ultimately produced the outcome.

Without that evidence, an organization may know something went wrong without understanding which governing assumption failed.

That is both a security issue and a governance issue.

4. Reassessment

Authorization should not be treated as permanent.

An agent can remain unchanged while the risk surrounding it changes substantially.

Another agent may enter the workflow. Permissions may expand. A new integration or data source may be introduced. A new vulnerability or adversarial technique may emerge. Or experience may reveal interaction effects that were not apparent during initial testing.

NIST’s AI Risk Management Framework provides an important foundation for this principle. It describes AI risk management as continuous across the lifecycle and calls for ongoing monitoring, periodic review, post-deployment monitoring and change management.

NIST’s current work on trustworthy AI in critical infrastructure extends that lifecycle perspective into high-stakes environments and specifically contemplates the deployment of AI agents and tools.

The relevant governance question therefore cannot stop at:

Was this agent acceptable when it was approved?

It must also ask:

Does the current interaction environment still satisfy the conditions under which that approval was granted?

From Agent Governance to Environment Governance

This does not require organizations to discard existing AI governance.

It requires them to extend it.

Govern the model.

Govern the data.

Govern the permissions.

Govern the individual agent.

But also govern the system of interactions through which those components produce outcomes together.

Leaders should be able to answer:

Who currently holds authority?

How can that authority propagate?

Which systems can interact?

What happens when one system’s output becomes another system’s instruction?

What evidence allows the interaction to be reconstructed?

What changes trigger reassessment?

And who has the authority to restrict, isolate or stop activity when the environment no longer matches the assumptions under which it was approved?

These are not exclusively technical questions.

They are questions of accountability, operational risk and organizational authority.

The Next Governance Question

As organizations move deeper into agentic AI, governance must evolve from asking only:

Is the agent authorized?

to also asking:

Is the interaction authorized, observable and still within the conditions we approved?

That distinction matters.

An individually reasonable permission can contribute to unreasonable cumulative authority.

An individually acceptable action can become part of an unacceptable chain of actions.

And an individually governed agent can still participate in a poorly governed system.

Govern the agent. Govern the authority. Govern the interaction. Reassess the environment.

Because in an agentic system, the most consequential risk may not belong to any single agent.

It may exist in the space between them.

References

1. Anthropic. Patterns and Problems in Emerging Multiagent Systems. August 13, 2026.

2. Microsoft. Microsoft Entra Security for AI Overview. 2026.

3. Microsoft. Reduce Autonomous Agentic AI Risk. 2026.

4. OWASP GenAI Security Project. LLM06:2025 Excessive Agency.

5. Google Cloud. Empowering Autonomous Agents with Advanced Security Governance. August 24, 2026.

6. ISACA. Four Governance Questions to Ask Before an AI Agent Goes Live. August 24, 2026.

7. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0).

8. National Institute of Standards and Technology. Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure. 2026.

9. Bearman, Theo. AI-Cyber Operations: A New Frontier for Public-Private Partnerships. Just Security, August 27, 2026.