Position: Protocol-Aware Guardrails Are Necessary for Multi-Agent Systems
Abstract
Multi-agent systems (MAS) are quickly becoming the default medium for tool-using AI in products: agents delegate, negotiate, call tools, exchange artifacts, and operate diverse system environments. Yet most deployed guardrails remain single-agent in design, operating on local text or turn-level constraints. This mismatch creates a structural safety gap: in MAS, harm is often \emph{protocol-shaped}, emerging from how messages, roles, capabilities, and state transitions compose across agents over time. We argue for \emph{protocol-aware guardrails}: defenses that treat the MAS as a distributed system with explicit interaction semantics. We propose concrete building blocks, typed interaction protocols, capability/consent tokens bound to provenance, and runtime monitors enforcing global invariants over execution traces, and outline evaluation criteria that reflect deployment constraints such as latency, utility, and composability.