Managing Agent-to-Agent AI Risk in the Supply Chain

Allan Dabre

|

October 6, 2026

Robot typing on a keyboard with various technology symbols floating in the air

Consider a hypothetical situation: A manufacturer’s demand-planning AI agent detects an impending shortage and reaches out, autonomously, to a supplier’s fulfillment AI agent to expedite a shipment and adjust an order quantity. The supplier’s agent complies within its own rules, rerouting inventory allocated to a different customer and overriding a delivery schedule that the other customer believed was locked in. Neither agent malfunctioned. Each stayed inside the rules its own company gave it. The disruption happened because neither company had a control for what occurs when one agent’s routine action becomes another agent’s trigger, and neither had any way of knowing what it was setting in motion two steps downstream.

This is a different risk than the one most agentic AI governance programs are built to catch. It is a question of operational control at the boundary between two companies’ automated systems. Inventory rebalancing, shipment rerouting, exception flagging, demand-signal sharing and the growing list of routine supply chain are actions agents on both sides of a relationship now execute directly with each other, with no human reviewing the exchange in real time.

The Limitations of Internal Controls

Many risk managers already have adopted a starting framework for agentic AI governance that includes knowing what the agent is doing, restricting what it is allowed to do, putting policies behind those restrictions, logging its actions, and using contract terms to allocate blame if something goes wrong.

Every one of those controls assumes the agent being governed operates inside a perimeter the company itself controls—its visibility, its restrictions and its own logs. None of that extends to the agent on the other side of a supply chain relationship because that agent belongs to another company entirely, runs on infrastructure other companies cannot see under a governance program others have no authority over. A company can build an exemplary internal program and still have no control over what happens the moment its agent’s output becomes another company’s agent’s input.

This is not a hypothetical concern. Gartner projects that 40% of enterprise applications will ship with task-specific AI agents by the end of 2026, up from less than 5% the year before. Separately, Gartner forecasts that AI agents will intermediate more than $15 trillion in business-to-business spending by 2028. Deloitte’s 2026 State of AI in the Enterprise survey found only 21% of companies have a mature governance model for autonomous agents, meaning most organizations connecting agents across supply chain relationships this year are doing so without governance built for the cross-boundary complexity involved.

The Open Worldwide Application Security Project (OWASP)—an online community that publishes open-source information on software and web applications—Top 10 for Agentic Applications 2026 names supply chain risk and inter-agent communication as two of its 10 highest-priority categories for agentic AI, alongside cascading failures. No headline case has forced the point yet, but a standards body categorizing this failure mode before the first major public incident is itself worth noting. Most existing multi-agent security guidance addresses agents talking to other agents inside one company’s walls. The risk here is agents talking to a different company’s agents, across a boundary where neither side’s governance has jurisdiction. Article 26 of the EU AI Act requires deployers of high-risk systems to maintain human oversight and retain logs for at least six months, but that was written for a single company deploying a system it controls end to end. A June 2026 Berkeley Technology Law Journal analysis found that once an agent invokes a tool or another agent at runtime, liability disperses among model providers, system providers, deployers and tool providers, with no single actor holding full visibility over the resulting decision chain—precisely the condition that exists whenever two companies’ agents interact directly.

What Can Go Wrong

Three failure modes are specific to this cross-organizational boundary, and none are well addressed by controls built for a single company’s internal agent deployment. These can be best characterized as:

  1. Identity and authorization ambiguity: When an agent receives a signal from a counterparty’s system, how confident can it be that the signal came from an agent authorized to send it, rather than a misconfigured, outdated or compromised version? Internal governance verifies that a company’s own instructions come from itself. It says nothing about an instruction arriving from outside the perimeter.
  2. Cascading action without a shared circuit breaker: In the scenario above, both agents’ actions cleared their own company’s internal thresholds. Neither of the agents and no human on either side had visibility into the combined effect once both actions were executed in sequence. Internal governance stops a single agent from exceeding its own scope. It does not detect a chain reaction spanning two companies’ systems, where each link looks reasonable and only the combined outcome is a problem.
  3. A fractured audit trail: Each company can reconstruct what its own agent did, because that is what its own logging captures. Neither has a complete record of the exchange itself: what triggered what, in what order and why. Reconstructing the full sequence requires cooperation between two organizations that may not have agreed on a shared logging standard in advance, and that, in a dispute, may have conflicting incentives to reconstruct events favorably to themselves.

Building Better Boundary Controls

None of this argues for slowing down agent-to-agent integration across supply chains. The efficiency gains are real and the trend is not reversing. As a result, the organizational boundary itself deserves treatment as a distinct control point, layered on top of whatever internal agentic AI governance a company already has. Key controls include:

  • Mutual agent authentication for any cross-organizational exchange. Before two companies allow their agents to act on signals from each other, both sides should verify the identity, authorized scope and current configuration of the counterparty’s agent, not merely trust that whatever arrives is legitimate. This is closer to vendor system access controls in cybersecurity than to how most agentic AI governance programs currently operate.
  • Escalation logic tied to cross-boundary action categories, not either company’s internal thresholds alone. Certain categories of action, such as reallocating inventory away from a different customer or overriding a delivery commitment another party is relying on, should trigger human review whenever they are about to execute as the downstream result of a counterparty’s agent signal, regardless of whether either company’s own rules would have allowed it in isolation. What matters is whether that action, taken because of another company’s system, was ever contemplated by a human on either side, not whether it technically fell within one agent’s authorized scope.
  • A shared, interoperable logging standard for agent-to-agent exchanges. This should be agreed to before the integration goes live rather than reconstructed after a dispute. It also does not have to replace either company’s internal logging; it has to capture what was requested, what was executed and what sequence it followed in a format both sides accept as authoritative.
  • Treating a partner’s agentic AI governance maturity as a due diligence question. This is not simply an extension of existing vendor risk management. A standard vendor assessment evaluates a system at onboarding, then revisits it on a fixed schedule. An agent’s behavior can shift after that through an update neither company jointly reviewed, and the real risk only appears once both systems are live and interacting—exactly the condition a point-in-time questionnaire is not built to monitor.

It is also important to consider potential liability. Cyber and technology errors and omissions policies are built around triggers like unauthorized access or a malicious external actor. A loss inside a supply chain relationship rarely looks like either because access is granted, not stolen, and the tool calls are within permission. New ISO endorsements effective in 2026 already lets carriers exclude generative AI claims from standard general liability policies, and several major carriers have filed similar exclusions across general liability, errors and omissions, and directors and officers lines. A loss from an agent-to-agent supply chain incident may fall into exactly that gap, and companies extending these integrations should confirm with their brokers whether current coverage responds to it at all.

Agentic AI governance has been developed around the assumption that a company controls both ends of what it is trying to govern. Supply chain relationships were never going to stay inside that assumption for long, and direct agent-to-agent interaction between companies is accelerating faster than controls built for a single company’s perimeter can stretch to cover it. The companies still treating the boundary between their systems and a partner’s as an afterthought are the ones most exposed to a failure neither side saw coming.

Allan Dabre is a senior manager of technology compliance at PwC.