From Smarter Agents to Trusted Agents: Where the Next Wave of AI Infrastructure Is Emerging

October 8, 2026

SHARE

TL;DR

  • The constraint has shifted from intelligence to coordination. Independently built agents now need to find, talk to, delegate to, and pay one another. Protocols like MCP, A2A, and AP2 are laying the groundwork.
  • Coordination also depends on trust. When several agents contribute to one decision, failures are hard to trace and responsibility is hard to assign.
  • Enterprises are not ready, and regulation is raising the stakes. Many are deploying agents faster than they are building the identity, permission, and audit infrastructure to govern them, and rules such as the EU AI Act and NIST’s AI Agent Standards Initiative are increasing the need to show how AI systems make decisions.
  • The gaps are between agents. Most agent security focuses on individual agents, but three areas remain underbuilt: cross-agent identity and delegation, cross-agent audit trails, and containment of one agent’s bad decisions.
  • What Beacon looks for: enterprise infrastructure that closes a clear governance or coordination gap, fits into existing workflows, and shows proven demand, recurring revenue, and strong customer economics.

 

The market has spent the past few years focused on making individual AI agents more capable. But as agents become better at planning, using tools, and executing tasks, the constraint is shifting from intelligence to coordination: enabling independently built agents to find, communicate, delegate, and transact with one another reliably.

This article explores how AI is shifting from individual model intelligence to multi-agent coordination, what multi-agent systems unlock, and why multi-agent systems creates new trust and governance. It examines the emerging infrastructure addressing these gaps – from identity and auditability to accountability and containment – and where the resulting investment opportunities may lie.

Why Has the Constraint Shifted from Intelligence to Coordination?

A stronger model plans better and recovers from errors more gracefully, and frontier labs remain the foundation the broader ecosystem is built on. But for a growing share of commercial use cases, model capability is no longer the binding constraint. What is missing is the orchestrate layer that lets independently built agents find, talk to, and transact with each other. Anthropic’s Model Context Protocol (MCP) has become the default standard for how an agent connects to external tools. FlowAccount, one of our portfolio companies, now let business owners and accountants connect their accounting data to AI assistants such as Claude and ChatGPT, so the assistant can pull sales and expense insights, issue documents like quotations and tax invoices, and run automations set up once. Google’s Agent2Agent (A2A) protocol governs agent-to-agent communication. The Agent Payments Protocol (AP2), released by Google alongside more than sixty organizations including Mastercard, American Express, PayPal, and Ant International, allows an agent to transact on a user’s behalf.[1] The value in the agentic economy is shifting from “how capable is the agent” to “can it operate with agents it has never encountered.”

What Does Multi-Agent Coordination Actually Unlock?

Procurement is a clear illustration. A single agent can flag low stock and draft a requisition – useful, but functionally similar to automation that has existed for years. A coordinated set of agents does more: one detects the shortfall, a second solicits quotes from multiple suppliers, a third checks the request against budget and policy, and a fourth generates the purchase order, with no human stitching the steps together. What multi-agent coordination unlocks is speed, consistency, and continuous operation – a task that once required a human to gather information, compare options, and make a judgment call becomes a task that a system can complete the same way every time, end-to-end, in minutes rather than days, at any hour. This is already in production. Pactum runs autonomous supplier negotiation integrated directly with SAP Ariba and Coupa; PRMAI and elsai run comparable coordinated sourcing-to-PO workflows.

Three components underpin coordination of this kind. A shared language: the protocols above, along with newer entrants like the Universal Commerce Protocol from Google and Ant International, designed to sit on top of A2A, AP2, and MCP rather than replace them.[2] A place for agents to find each other:  since most agent-to-agent transactions still result from manual integration between two companies rather than open discovery. This is where the next wave of infrastructure investment is likely to concentrate, since control over discovery and ranking functions as a toll booth on the network. And orchestration layer: manages how multiple agents work together, sequence tasks, resolve conflicts, and handle failures. Examples of this layer include CrewAI now runs more than 12 million agent executions daily; LangGraph has gained traction as an enterprise agent runtime because its architecture produces audit trails natively;[3] and major enterprise technology vendors – Microsoft, AWS, Google, ServiceNow, and IBM are also building platforms to develop, deploy, and orchestrate AI agents.[4] The breadth of investment from established vendors suggests that orchestration is emerging as an important layer of the agent ecosystem.

However, this does not represent full autonomy. A 2026 SupplyChainBrain industry analysis projects that AI agents could manage 60 – 70% of end-to-end transactional procurement by 2028, while humans retain responsibility for strategic sourcing, complex negotiations, and other high-value decisions.[5]  Gartner similarly warns that a meaningful share of early autonomous deployments could be rolled back once governance gaps emerge in production [6], highlighting the governance and trust challenges that may limit the adoption of fully autonomous processes.

When Coordination Requires Trust?

Instant payment rails – PromptPay, RTP, FedNow – illustrate the stakes. Transactions on these rails can settle in seconds, leaving little time for traditional, single-model fraud checks to assess risk before funds move. Banks are therefore moving towards architectures in which several specialized agents assess risk in parallel: one reads device and behavioral signals, another checks the transaction against network patterns, another confirms identity, and the system freezes or reroutes the payment before settlement.[7] This is multi-agent coordination at its most valuable: autonomous, fast, and making decisions on transactions where funds may be difficult to recover.

But the same coordination that makes these systems powerful also makes them harder to govern. When multiple agents contribute to a single decision, failures may not have a clear point of origin. A problem can emerge from how agents interact, with the consequences becoming visible only after the transaction is completed. As more agents and organizations become involved, reconstructing the chain of decisions – and determining where responsibility lies – becomes increasingly difficult.

Ungoverned multi-agent chains tend to create four recurring risks. First, unauthorized or excessive action: an agent can take actions beyond what the user or system intended when its permissions are too broad, for example an agent authorized to make a payment could also move money between accounts. Second, cascading error: a small error can compound when one agent’s output becomes another’s trusted input. Third, emergent behavior: multiple agents can produce emergent behavior that no individual agent was designed to create, making system-level monitoring essential. These risks point to the same requirement: permissions must be scoped, handoffs must be auditable, authorization must be verifiable, and the system must be monitored as a whole.

The data supports this shift in perspective. UC Berkeley researchers analyzed 1,642 multi-agent execution traces and found that approximately 79% of observed failures were linked to system design and inter-agent misalignment [8] , highlighting the importance of coordination and governance beyond individual agent capability. Legal scholarship reaches a similar conclusion from a different direction. Without a record of what was passed between agents at each handoff, plaintiffs, auditors, and regulators have limited ability to determine how a harmful outcome occurred or where responsibility lies; many agent-to-agent interactions remain opaque and unlogged by default.[9] Research on multi-agent security likewise highlights the problem of cascading failures, in which an error from one agent propagates through otherwise functioning agents without a single obvious point of causation.[10]

Where Is the Governance Gap, and What Is Already Being Funded?

Regulations and standards are advancing alongside the rapid deployment of autonomous AI systems. In the EU, the AI Act sets penalties of up to €35 million or 7% of global annual turnover for certain prohibited AI practices [11], while the EU’s revised Product Liability Directive also brings software, including AI systems, within the EU’s product-liability framework, meaning companies can face liability when an AI-enabled product causes damage.[12]  Together, these rules increase the need for companies to understand how their AI systems make decisions and to maintain sufficient evidence to demonstrate compliance and responsibility. In the US, NIST (National Institute of Standards and Technology) has launched its AI Agent Standards Initiative, focusing on standards, interoperability, security, and agent identity. Its work includes examining how existing identity and authorization standards can be applied to AI agents.[13]

Enterprise security infrastructure is beginning to adapt to these requirements, but significant gaps remain. A recent industry survey found that 84% of security teams could not pass a compliance audit of their own agents’ behavior, while only 23% had a formal agent identity strategy and 18% were confident in their ability to manage agent identity.[14]  These figures suggest that enterprises are deploying agents faster than they are building the infrastructure to govern them, with gaps in agent identity, permissions, and visibility becoming more significant as agents operate across systems and delegate tasks to one another.

Funding is already moving to meet these emerging governance needs. Oasis Security raised $120 million for non-human identity and agentic access governance; SGNL, founded by the creators of the SPIFFE/SPIRE identity standard, raised $38 million across seed and Series A; Zenity which provides tools to discover and govern AI agents across the enterprise, raised $125 million . On the acquisition side, Palo Alto Networks completed its approximately $25 billion acquisition of CyberArk, an identity security company specializing in privileged access management, while ServiceNow acquired Moveworks, an enterprise AI assistant and automation platform,for approximately $2.85 billion to combine its workflow automation and AI governance with Moveworks’ front-end and enterprise search capabilities. Together, these developments show that agent identity, access control, discovery and governance are becoming important parts of the enterprise AI stack. However, most solutions today only secure single-agent identities. The larger, unaddressed thesis is multi-agent delegation chains, what happens when Agent A delegates permissions to Agent B, which delegates to Agent C across organizational boundaries.

There are three areas where the governance layer for multi-agent systems remains underbuilt:

  1. Cross-agent identity and delegation verification – knowing not only which agents exist, but also who gave an agent permission to act, what it is allowed to do, and whether it can pass that permission to another agent. Tools such as Okta for AI Agents, Microsoft Entra Agent ID, Astrix, and Oasis Security are addressing agent identity and discovery. However, the harder problem is tracking permission as it moves from Agent A to Agent B and then to Agent C, especially across different organizations. ScrambleID is one example of a company building around this gap by creating a verifiable record of each step in a delegation chain.[15]

A recent dispute between Amazon and Meta’s Muse illustrates this gap in practice. Amazon blocked Muse from shopping on Amazon.com, saying Meta had not obtained authorization for the agent to access its site and that Muse did not identify itself as an AI agent while browsing. Meta designed Muse to act on users’ behalf, but Amazon did not recognize that user authorization as sufficient permission to access its platform. This creates a broader infrastructure question: when an agent acts on a user’s behalf, how does another system verify both the user’s authorization and the agent’s authority to act?

  1. Cross-agent audit trails – being able to reconstruct what happened across the entire chain, rather than seeing only what one agent did. Companies such as Langfuse, Braintrust, and Credo AI provide visibility into individual agent activity. But when one company’s agent hands a task to another company’s agent, it becomes harder to connect those separate records into one complete transaction history. The opportunity is to create a shared record that can show what each agent received, decided, and passed to the next agent.
  2. Containment and failure propagation – making sure one agent’s mistake does not spread to the rest of the chain. This is already recognized as a formal governance requirement: the financial industry’s open governance framework identifies “Multi-Agent Isolation and Segmentation” as a control for limiting the impact of one agent’s malfunction on others in the workflow. [16] Infrastructure for agent isolation is also developing quickly. E2B, for example, grew from around 40,000 sandbox runs per month in early 2024 to approximately 15 million a month a year later, with Modal and Daytona also expanding in this space. However, most of these tools are designed to isolate an agent’s code and execution environment, for example, preventing a security breach or runaway process. The remaining challenge is containing a bad decision from one agent before it is passed to the next agent and causes a wider failure. This becomes increasingly important as workflows involve more agents and more autonomous decision-making.

What Does This Mean for Investors?

The shift from individual agents to multi-agent systems is creating a new infrastructure layer. The opportunity is not simply to build more capable agents, but to make interactions between agents trusted, traceable, and controllable. Identity, delegation, auditability, accountability, and containment are still developing as agents increasingly operate across companies and systems.

For investors, the key question is therefore not whether a company is “using AI,” but whether it is solving a structural problem created by the shift to multi-agent systems.

At Beacon VC, we are particularly interested in enterprise solutions building this infrastructure, especially where the product addresses a clear governance or coordination gap, can be embedded into existing enterprise workflows, and delivers measurable value to customers. We look for businesses with proven enterprise demand, recurring revenue, strong customer economics, and solving structural problems that each AI layer is facing. Companies that can establish trust between agents – not just make individual agents smarter – could become increasingly important as autonomous workflows move from isolated applications to transactions spanning multiple systems and organizations.

Authors: Supamas Bunmee (Jae)

Editor: Woraphot Kingkawkantong (Ping) and Warittha Chalanonniwat (Paeng)

Sources

[1] Google Cloud, Announcing the Agent Payments Protocol (AP2)

[2] The Asian Banker, Ant International Partners with Google’s Universal Commerce Protocol

[3] LangChain, The Best AI Agent Frameworks in 2026

[4] Alice Labs, Best AI Agent Frameworks 2026

[5] https://www.supplychainbrain.com/blogs/1-think-tank/post/43687-why-2026-is-the-year-of-ai-agents-for-autonomous-procurement

[6] https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure

[7] Intellectyx, AI Agent Architecture for Real-Time Fraud Detection

[8] https://tech.yahoo.com/ai/articles/79-multi-agent-failures-specification-084602670.html

[9] Berkeley Technology Law Journal, Multi-Agent AI Is Outpacing the Liability Frameworks

[10] Open Challenges in Multi-Agent Security (arXiv)

[11] https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng

[12] https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng

[13] Announcing the “AI Agent Standards Initiative” for Interoperable and Secure Innovation | NIST

[14] SentinelAgent: Intent-Verified Delegation Chains (arXiv)

[15] ScrambleID, Multi-Hop Agent Delegation Chains

[16] FINOS, Multi-Agent Isolation and Segmentation (MI-022)

SHARE