Inside one framework, agent communication feels free. Everything shares the same types, the same task model, the same assumptions about what "done" means.
The problem starts at the boundary, and the boundary is coming for everyone. A partner team's agent. A vendor's agent. The system built on a different stack two acquisitions ago. Suddenly nobody can hand over a task without a translator.
Four layers a real protocol has to pin down
- Identity. Who is this agent, and on what basis do I trust it? An agent accepting tasks from anything that can reach its endpoint is a security problem waiting for a motivated party.
- Capability. What can it actually do, stated machine-readably? Without this, task assignment is guesswork encoded in someone's config file.
- Task state. Requested, accepted, in progress, done, failed, with both sides agreeing on the transitions and what triggers them.
- Artifacts. How results get packaged, referenced, and verified. Passing a blob of prose and hoping the receiver parses it is not an interface.
This is exactly why standards like MCP and A2A exist: every team was reinventing these four layers, badly, in slightly incompatible ways.
The failure is semantic, not syntactic
Anyone who lived through enterprise systems integration already knows how this goes. The wire format was never the hard part. Agreement on meaning was.
Two agents can exchange flawless, schema-valid JSON while holding incompatible beliefs about what a field means. Does accepted mean "I will do this" or "I received your message"? Does confidence: 0.8 mean the same thing coming from a retrieval agent and a classifier? Does an empty result mean "nothing found" or "I could not check"?
Every one of those ambiguities becomes a production incident with a delay fuse: the system works fine until the case where the difference matters, and then it fails in a way that looks like neither agent misbehaved. Because neither did.
What to do about it
Negotiate semantics before traffic, not during the incident. Write down what each status value means, in prose, and have both teams confirm it.
Then version the protocol from day one. It will change, and unversioned protocol changes break integrations silently, which is the worst possible way for a contract to fail.
Closing thought
Agents need a shared language. The schema is the easy half; agreeing on what the words mean is the work, and it is the half that gets skipped because it looks like documentation rather than engineering.
Are your agents genuinely interoperable, or just co-located in the same codebase?
More on these topics
Deep dive · · 6 min read
Adding a second agent does not add intelligence, it adds a contract
Six posts on multi-agent systems, and the failures were never inside an agent. They were between two of them.
Deep dive · · 6 min read
Six ways to wire agents together, and the same three things break every time
The topology gets all the design attention. Ownership, termination and traceability are what decide whether it survives contact with production.
Deep dive · · 6 min read
Most agent controls do not actually control anything
Six days of notes on supervising autonomous systems, and the same failure shape kept turning up: the control exists, it is documented, and nothing in the running system is bound by it.
Discussion