Research · Generative & Agentic AI

AI Agents & Multi-Agent Systems

AI agents plan and carry out multi-step tasks by calling tools and applications. Multi-agent systems divide work among several specialized agents. Both can automate work that used to need a person, and both need strong controls.

What they are

An agent combines a model with instructions, memory and access to tools such as search, databases, APIs or other applications. Given a goal, it decides which steps to take, acts and adjusts based on results. In a multi-agent system, several agents with different roles coordinate, for example one that plans, others that research or execute, and one that reviews.

Open protocols are emerging to connect agents to tools and to each other. The Model Context Protocol (MCP) is a widely adopted example for connecting models to tools and data sources.

Where they deliver value

  • Research and analysis that spans several systems.
  • IT and security operations tasks such as triage and routine fixes.
  • Back-office processes that read documents, update records and notify people.
  • Software engineering tasks from planning through testing.

Controls agents need

  • A distinct identity and least-privilege permissions for every agent.
  • Human approval for high-impact or irreversible actions.
  • Limits on spending, volume and scope.
  • Complete logs of tool calls and decisions.
  • Defenses against prompt injection from content the agent reads.

Risks and pitfalls

  • Agents given broad access for convenience.
  • Errors that compound across many steps before anyone notices.
  • Multi-agent designs that are hard to debug or audit.
  • Unclear accountability when an agent acts on a person’s behalf.

How to get started

  • Start with read-only or easily reversible tasks.
  • Define clear boundaries and escalation rules for each agent.
  • Evaluate agents on realistic scenarios, including failures and attacks.
  • Add autonomy gradually as performance is proven.

Questions leaders should ask

  • What can each of our agents do without human approval?
  • Does each agent have its own identity and minimum permissions?
  • Can we reconstruct exactly what an agent did and why?
  • Who is accountable when an agent makes a mistake?

Research Reports

In-depth guides, ebooks and certification prep.

Browse all reports →