What happened
The Australian AI Safety Institute (within the Department of Industry, Science and Resources) released its inaugural public report, commissioned from the Gradient Institute, providing an analytical framework for the risks, controls, and governance arrangements that arise when AI agents interact across organisational boundaries. The report argues that existing AI agent governance frameworks — including NIST's AI RMF, OWASP's Agentic Top 10, and Singapore's Model AI Governance Framework — all assume a single organisation controls every agent in a system, an assumption that breaks down as supply-chain agents, customer-facing assistants, and procurement bots increasingly interact across company lines. Building on Gradient Institute's prior single-organisation multi-agent research (cited in the 2026 International AI Safety Report), the report extends the finding that 'a collection of safe agents does not guarantee a safe collection of agents' to argue that a collection of governed agent systems does not itself constitute a governed cross-organisational system. It is described as the first government publication anywhere to analytically address cross-organisational AI agent risk as a distinct governance problem.
Why it matters
Enterprises deploying agentic AI that interacts with partner, supplier, or customer agents face a governance gap that no existing framework (NIST, OWASP, Singapore) currently addresses — CISOs and risk leads need to treat cross-organisational agent interaction as a distinct control category before incidents occur.
Action needed
Risk and security teams should audit points where their AI agents interact with third-party or partner agents and assess exposure against the report's cross-organisational risk taxonomy.