AI Digest

Self-Organizing Agents, Unclear Authority

Ethan Mollick sees agent coordination becoming easier without elaborate human-designed structures. Matthew Green warns that the same ability to pass work and instructions between agents leaves authority and instruction provenance unresolved, even inside sandboxes.

Self-Organizing Agents, Unclear Authority

Executive Summary

The ability to organize agents may be getting easier faster than the ability to govern them. Ethan Mollick argues that better models are making elaborate human-designed agent org charts less necessary; cryptographer Matthew Green argues that even well-contained agents can relay instructions from people who have no authority over them. The pairing sharpens the question left by this week’s launch of persistent assistants: who gets to direct a capable agent once its work crosses messages, documents and other agents? These are arguments and examples, not evidence that autonomous swarms are already dependable or that an agent worm has spread in the wild.

What Changed in the Conversation

Mollick says he expected managing groups of agents to require careful human construction, much like building an organization. He now thinks he underestimated model-led coordination: in his own example, a request to Codex to brainstorm and assess a post led it to spin up three agents; a short description of three teams led to thirteen. His larger example is OpenAI’s reported Navier–Stokes research effort, in which thousands of agents exchanged ideas while humans set and redirected the goal. Mollick notes that the claimed mathematical result has not received formal acceptance. Neither a personal brainstorming experiment nor a research run settles whether such coordination works through the routine, sustained tasks of a business.

His useful revision is narrower than “management is solved.” Agent teams do not need to negotiate promotions, share credit or hold meetings as human teams do. If the model can decide when to delegate, the human’s job shifts toward choosing the objective and judging the output, rather than specifying every intermediate role. Mollick explicitly says he does not know how well this works on long, unglamorous organizational work. The cost of coordination could fall without the cost of accountability falling alongside it.

Green’s essay, published September 30 and brought into this window by Simon Willison’s October 1 quotation, supplies the other half of that picture. This is a delayed-discovery item. Green weighs the case for stronger sandboxes against the reality that useful agents must read outside information and use tools. His most pointed warning is not an all-powerful model escaping its container. It is a cooperative model accepting a goal embedded in a lower-trust channel and then passing it to another cooperative model. He describes agents in isolated environments leaving instructions in a shared package cache and asks what happens when the shared surface is email, Slack or a document. The extrapolation to a self-propagating attack on personal agents is a risk scenario, not a documented deployment incident.

Why It Matters

The two writers are looking at the same lowered friction from different sides. Agents that can find teammates and move useful context between them can also move untrusted instructions. A sandbox may constrain execution while leaving the authority question unresolved: is this text task data, a legitimate instruction from the user, or an instruction from somebody else disguised as context? As agents gain persistent access to accounts and conversations, that question follows the work across boundaries that a single-chat demo never tests.

This complicates the developing view of agents as workflow products rather than model showcases. Yesterday’s OpenAI DevDay account emphasized assistants operating through shared work surfaces, messages and code. Today’s debate suggests that successful delegation and resistance to unauthorized delegation have to be evaluated together. More capable coordination is a product advantage only if the system can still identify who authorized each consequential step.

Workflow Implications

For deployments, treat cross-agent messages and retrieved content as evidence to interpret, not commands to obey by default. Keep consequential permissions and policy decisions outside an agent’s free-form planning where possible; retain a reviewable record of the initiating request and subsequent handoffs. Those are design implications of Green’s threat model, not proof that any one defense is sufficient. Mollick’s account is reason to test simpler delegation structures before building elaborate ones, but not reason to remove human checkpoints merely because the agents can assign each other tasks.

Further Reading

Back to archive