AGENTIC AI SECURITY / ADVANCED

When Agents Talk To Agents: Impersonation, Cascades And Collusion

Multi-agent systems add risks a single agent does not have. How trust between agents breaks, how one compromise spreads, and the controls that contain it.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Many agent deployments are no longer a single agent. An orchestrator breaks a job into parts and hands them to specialist agents for research, coding, data retrieval or execution. Agents may call agents run by other organisations through shared protocols. The AI Agents And Multi-Agent Systems group explains how these designs work.

Each handoff is a point of trust. When one agent accepts another’s output as fact, or acts on its request, an attacker who controls one agent can influence the rest. This article covers the risks that arise or grow when agents work together, using the research taxonomy from the Cooperative AI Foundation, OWASP’s practitioner lists and the May 2026 joint government guidance.

What Changes With More Than One Agent

A single agent has one context, one identity and one set of tools. A multi-agent system adds three things: messages between agents, delegation of authority from one agent to another, and behaviour that emerges from their interaction rather than from any single agent.

The joint guidance from six national cyber security agencies includes a structural scenario with no single cause. Its end point is a malicious tool steering one agent, which then compromises a neighbour and spreads false information through the trust the agents place in each other. What made that possible was a chain of weaker links: agents that delegate and choose tools without strong checks, an orchestration flaw that kept them replanning until resources ran short, and struggling agents whose invented results were accepted further down the line.1 No single bug caused the outcome. The structure did.

An orchestrator connected to three worker agents; one worker is compromised and its influence spreads to the orchestrator and a second worker, with control points markedOrchestratorplans and delegatesResearch agentreads the webData agentcompromisedExecution agentpayments, changesMalicious third-party toolA: signed messagesand per-agent identityB: approval forhigh-impact actionsC: circuit breakeron handoffs
One compromised worker agent in an orchestrated system. Without per-agent identity, message checks and circuit breakers, its output reaches every agent that trusts it.

A Research View: Three Ways Groups Of Agents Fail

The Cooperative AI Foundation’s technical report “Multi-Agent Risks from Advanced AI”, led by Lewis Hammond and published in February 2025, sorts failures by the incentives of the agents involved.2

  • Miscoordination. Agents share a goal but fail to work together towards it.
  • Conflict. Agents with different goals fail to cooperate.
  • Collusion. Agents cooperate in ways nobody wanted, for example coordinating prices in a market.

The report identifies seven risk factors behind these failures: information asymmetries, network effects, selection pressures, destabilising dynamics, commitment problems, emergent agency and multi-agent security.2 Collusion deserves particular attention from security teams because it does not need an outside attacker. Two agents optimising their own goals can find a joint strategy that breaks a rule neither would break alone.

The Practitioner View: OWASP Entries

OWASP’s Top 10 for Agentic Applications, published in December 2025, has three entries that matter most when several agents work together.3

  • ASI07 Insecure Inter-Agent Communication. Messages travel over APIs, message buses or shared memory without proper authentication, integrity checks or validation of their meaning, so they can be intercepted, spoofed, altered or replayed.
  • ASI08 Cascading Failures. A single fault, such as a hallucination, poisoned memory or a corrupted tool, spreads across agents and grows into system-wide harm. OWASP is precise here: ASI08 covers the spread, while the original defect belongs under the entry that caused it.
  • ASI10 Rogue Agents. An agent drifts from its intended function and acts harmfully or deceptively while its individual actions still look legitimate.

OWASP’s threat taxonomy (version 1.1, December 2025) adds more detail, with threats for agent communication poisoning, rogue agents in multi-agent systems, human attacks on multi-agent systems and insecure inter-agent protocol abuse.4

Impersonation And Trust Between Agents

The joint guidance lists identity spoofing and agent impersonation as a privilege risk. Agents authenticate to each other with keys or tokens, and attackers steal those when they are static, shared between agents or poorly protected. An attacker acting under a trusted agent identity can bypass guardrails and evade detection tuned to normal behaviour.1

Research on the A2A (Agent2Agent) protocol shows how this can play out when agents choose their peers. OWASP’s incident tracker lists an April 2025 entry based on work by Trustwave SpiderLabs.3 In a local proof of concept, a rogue agent exaggerated its abilities in its “agent card”, the description other agents read when picking a peer, and the host agent chose it for tasks meant for a legitimate agent. In a real deployment, that would route users’ requests, and any sensitive data in them, through the attacker’s agent.5 Choosing a peer agent is a supply chain decision and deserves the same scrutiny as choosing a software package.

Controls That Contain Multi-Agent Risk

The joint guidance sets out a detailed list of controls.1 The table groups them by purpose.

PurposeRecommended practice
Know who is talkingA distinct cryptographic identity per agent; mutual TLS on all agent-to-agent and agent-to-service calls; a trusted registry that denies unknown agents
Limit what each agent can doSeparate roles such as orchestrator, reader and actuator with clear boundaries; strict controls on every handoff; no self-granted privileges or unexpiring delegation
Check before actingMulti-agent agreement for moderate-stakes actions, plus human approval for high-stakes ones; a second agent to check new tasks against policy
Stop the spreadIsolation and segmentation to limit blast radius; high-risk agents in separate domains; rate limits to interrupt runaway tasks
Keep a recordUnified audit logs for all inter-agent interactions; agents kept in enclaves with no write access to logs
Multi-agent controls drawn from the joint guidance, grouped by what they protect.

Two cautions apply. First, agreement between agents is only an independent check if the agents are actually independent. Agents built on the same model, reading the same poisoned context, can agree on the same wrong answer. Second, accountability is the category most likely to fail quietly. The guidance’s accountability scenario describes a payment error produced by a chain of planning, retrieval and execution agents, where fragmented logs make it impossible to say which component or design choice caused it.1 Every message and action should be traceable to a specific agent identity and to the person or task that authorised it.

Where Evidence Is Thin

As of October 2026, most evidence for agent-to-agent attacks comes from research demonstrations and vendor reports rather than confirmed production incidents. That is not a reason to wait. The building blocks of these attacks, prompt injection, stolen tokens and malicious packages, are all well documented, and multi-agent systems combine them.

Footnotes

  1. ASD’s ACSC, CISA, NSA, Canadian Centre for Cyber Security, NCSC-NZ and NCSC-UK, “Careful Adoption of Agentic AI Services”, 1 May 2026. ncsc.govt.nz ↩ ↩2 ↩3 ↩4

  2. L. Hammond and others, Cooperative AI Foundation, “Multi-Agent Risks from Advanced AI”, Technical Report 1, arXiv 2502.14143, February 2025. arxiv.org ↩ ↩2

  3. OWASP GenAI Security Project, “OWASP Top 10 for Agentic Applications 2026” (full document), December 2025. genai.owasp.org ↩ ↩2

  4. OWASP GenAI Security Project, “Agentic AI: Threats and Mitigations”, version 1.1, December 2025. genai.owasp.org ↩

  5. T. Neaves, Trustwave SpiderLabs, “Agent In the Middle: Abusing Agent Cards in the Agent-2-Agent (A2A) Protocol To ‘Win’ All the Tasks”, 21 April 2025. levelblue.com ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.