News

Field note 49 · Governance & guardians

Apply the AI RMF to Agent Relationships

Managing each model independently misses risk that appears only when agents delegate, compete, and transact.

Editorial illustration for Apply the AI RMF to Agent Relationships

Risk management should treat relationships, incentives, protocols, and joint outcomes as first-class system components.

Why this question matters

NIST organizes AI risk work around Govern, Map, Measure, and Manage. In a multi-agent setting, governance identifies ownership across organizations; mapping includes delegation and market structure; measurement tests joint behavior; management applies controls across task and relationship boundaries.

The framework remains useful because it is outcome-oriented and adaptable. The extension is analytical: inventories need agent dependencies, evaluations need interaction conditions, and controls need to address emergent behavior rather than only model outputs.

Signals worth observing

  • Risk inventories list models and tools but omit agent relationships.
  • Evaluations isolate agents that will interact in production.
  • No owner can pause a cross-organization workflow.

Practical control direction

  1. Map principals, incentives, dependencies, and beneficiaries.
  2. Measure isolated and interactive behavior.
  3. Assign intervention and recourse responsibilities across organizations.
AgentCollusion lensAgentCollusion provides the relationship-level questions needed to operationalize familiar risk frameworks for agent networks.

Sources and further reading

Next field note: The EU AI Act Meets Multi-Agent Accountability