Two perfectly governed agents can still sink the ship
It now a multi-player game
Your governance framework controls your agents. It doesn't control what happens when your agents meet someone else's.
MIT's Project Iceberg benchmarked this gap. Agents sharing coordination signals outperformed agents using standard message-passing by 41 to 100%. Communication and coordination are different things. The enterprise AI world hasn't reckoned with the difference.
Your procurement agent negotiates with your supplier's sales agent. Both compliance agents monitor the same feeds and flag the same risk. Both trigger conflicting remediation plans that land on a human's desk after the window to act has closed.
Every agent I know how to govern sits inside a stack: a technical harness, a knowledge harness, a judgment harness with a named human at the top who signs for the outcome. That stack works inside one organization's boundary. It says nothing about the boundary itself. Your judgment harness has a name at the top. So does theirs. Neither one covers what happens between them.
Iceberg's Ripple Effect Protocol is the starting point. Agents share sensitivity signals: how their behavior shifts when conditions change, without revealing proprietary strategies. Coordination without disclosure. But coordination isn't accountability. Two agents can coordinate perfectly and still produce an outcome nobody signed for.
If you build governance frameworks, assess risk, or advise on enterprise AI: your risk models assume a closed system. The frameworks for multi-party agent interaction, and the accountable human who owns the joint outcome, don't exist yet.
That's the work.