Risk management should treat relationships, incentives, protocols, and joint outcomes as first-class system components.
Why this question matters
NIST organizes AI risk work around Govern, Map, Measure, and Manage. In a multi-agent setting, governance identifies ownership across organizations; mapping includes delegation and market structure; measurement tests joint behavior; management applies controls across task and relationship boundaries.
The framework remains useful because it is outcome-oriented and adaptable. The extension is analytical: inventories need agent dependencies, evaluations need interaction conditions, and controls need to address emergent behavior rather than only model outputs.
Signals worth observing
- Risk inventories list models and tools but omit agent relationships.
- Evaluations isolate agents that will interact in production.
- No owner can pause a cross-organization workflow.
Practical control direction
- Map principals, incentives, dependencies, and beneficiaries.
- Measure isolated and interactive behavior.
- Assign intervention and recourse responsibilities across organizations.
AgentCollusion lensAgentCollusion provides the relationship-level questions needed to operationalize familiar risk frameworks for agent networks.Sources and further reading
Next field note: The EU AI Act Meets Multi-Agent Accountability


