Researchers built a system that stops AI agents from teaming up to do something none of them could do alone, without shutting down collaboration entirely.
The paper, posted to arXiv on October 2, 2026, describes a method called authorization-paired evaluation, paired with a framework named FlowReview. Instead of judging each agent's action in isolation, FlowReview checks the combined output that multiple agents produce together, tracking object identity and permission alongside the data itself. In the researchers' controlled composition experiments, a baseline setup let 86.0% of improper multi-agent actions through unblocked. With FlowReview reviewing the combined artifacts, that denied-commit rate dropped to zero, and the system still delivered every authorized task it was supposed to complete.
Multi-agent AI systems work by passing partial information between agents, and each piece can look harmless on its own. The actual risk shows up only when those pieces are combined, a classic access-control problem that gets harder as more autonomous agents share evidence and delegate tasks to each other. The paper's core claim is that preserving a record of where data came from isn't enough: permission has to travel with the data through execution, and the outputs need to be independently verifiable.
It's a narrow, controlled experiment rather than a deployed product, so the real test is whether this holds up once agents are coordinating across real tools and real data, not lab-built composition tasks.