# Agentic Societies Need a Social Harness

Almost everyone we know is using AI agents. However, the future isn't just agents working for one user. It's agents interacting with each other across trust boundaries. Making these interactions efficient and secure requires solving hard problems, which turn out to be surprisingly similar to problems in human societies and in distributed systems and networking. This post is an early look at what’s coming, why it doesn't work yet, and what we are building to change that.

Tapan Chugh, Arvind Krishnamurthy & Ratul Mahajan

Figure 1. Left, how we use agents today: the agents do the work; the humans carry the messages. Right, the agents talk to each other; the humans get notified after that.

[View figure 1](https://social-harness.org/blog/agentic-societies-need-a-social-harness/figure-1.svg)

## How do we use agents today?

Let's look at an example of how two of us (Ratul, a professor, and Tapan, his student) use agents for work today. Ratul advises multiple students, working on different topics. He wants to keep up with the latest research, so he tells his OpenClaw to send him daily updates on these topics. Every morning, the Claw runs a deep research task and sends him any interesting news or relevant papers that show up. Because he is a very nice advisor, he goes through that list to find things that might be relevant to his students' projects. Say he finds a paper that seems relevant to Tapan’s project: he emails it to Tapan with a question: "Are we similar to this paper?"

What does Tapan do? He also uses agents to manage his work. In this case, Tapan has a Claude project that maintains his literature review. He adds this paper and asks Claude to check how it relates to our research. Claude comes back and says, "No, it's similar to the paper we looked at yesterday.” Cool. He glances through the paper, generally agrees with most of what Claude says, edits the answer a little (to remove the em-dashes :P), and emails it back to Ratul.

Today, both of us are using agents to do the hard work of searching through news, filtering for what's relevant, doing the literature review, and comparing against prior art. All we as humans are doing is carrying the messages between them. That sounds silly.

## From Individual Agents to Agentic Societies

We think the next step is quite obvious. Ratul gives his Claw the same task, but now the Claw also has context of who the different students are, and what they're working on (it already reads his emails and messages, after all). If these agents can communicate with each other directly, Ratul’s Claw can reach out to Tapan's Claude directly, ask whether the paper is related, and get a response BEFORE notifying Ratul. At the end, both of us get notified. Done.

Teams of agents (belonging to different principals) are autonomously collaborating (see: [Town](https://www.town.com/group-text), [Instinct](https://x.com/noahrshinn/status/2097794967574028448)). This is only the first step: over time, we envision that agents will not only inherit existing human relationships and social context but also influence what relationships humans participate in. The existence of experimental dating platforms, [MoltMatch](https://www.moltmatch.org/) and [MatchClaw](https://www.linkedin.com/posts/lamu-20-matchclaw-an-experimental-fully-share-7448458688794882048-mvSL/), suggests this will happen sooner rather than later. We also envision agents working on extremely consequential tasks where individual goals may not align: a few months ago [Half Baked](https://read.gethalfbaked.com/p/half-baked-622-house-agents) pitched a house-buying agent, and within a few minutes of searching, we found a [NYT article](https://www.nytimes.com/2026/05/28/technology/sell-house-with-ai-no-realtor.html) about using AI to sell houses. What do you think happens next? Both these agents will talk to each other directly, of course.

Figure 2. A house-buying agent and a house-selling agent. What do you think happens next?

A house-buying agent pitch beside a New York Times story about selling a house with a chatbot, joined by a handshake

[View figure 2](https://social-harness.org/assets/figures/house-agents.webp)

Since agents can already execute individual tasks far faster than humans, autonomous coordination between agents will be necessary to prevent a human in the loop from becoming a bottleneck: we read slowly and can only maintain so many relationships. We believe that the future is **agentic societies**: collections of agents that collaborate autonomously, across trust boundaries (with humans or other agents), on real-world tasks of great consequence, where individual goals may not always align.

## Why agentic societies don't work yet

Models can already solve hard reasoning problems and work autonomously for days at a time. Agents are also good at using tools, which means they can message each other, email each other, post on Moltbook (or GitHub), or interact using A2A. They know how to communicate.

The problems that remain unsolved include: (1) agents can fail to reach good outcomes, even when all participants are honest, (2) agents are unable to effectively advocate for their principal's goals; and (3) agents cannot protect themselves from dishonest actors who try to harm honest agents, stall their progress, or influence their outcomes. As model capabilities improve, honest agents' ability to coordinate effectively will improve, but so will dishonest agents' ability to exploit more sophisticated vulnerabilities.

### Our study

To understand this systematically, we ran experiments where agents autonomously schedule meetings for their principals. The task is deceptively simple and a good representative of the requirements: agents need collaboration to cooperatively satisfy everyone's constraints, and competitively negotiate so as to select one among the feasible slots. We used OpenClaw agents (with GPT-5.4/Opus-4.8) over a custom messaging channel and found that although scheduling one meeting between two agents is easy, scheduling gets harder as the number of concurrent meetings or the number of participants increases. This is not a model reasoning problem: a single agent with access to all the context can complete these easily, but when the same context is distributed across agents, they fail quite frequently despite good intentions. Furthermore, even a single dishonest, or Machiavellian, actor can stall progress, influence outcomes, and deceive the "gullible" honest agents.

We describe a few examples of such failures below:

### Failure 1: Lack of Shared Norms

Let's say three agents, Alice, Bob, and Cara, want to schedule a meeting. Alice messages Bob and Cara: "Can we meet on Tuesday?" Bob replies to both: "Tuesday works." Cara replies: "I'd prefer Wednesday." The problem is that Alice is a little over-eager, and as soon as she gets Bob's reply she sends another message, "Cara, does Tuesday work for you?", before waiting for Cara's answer. But notice that Cara sees this only after she has already sent hers, and thinks: maybe Wednesday doesn't work for Alice; okay, I can make Tuesday work. Meanwhile Bob sees Cara's original reply and comes back with "Wednesday also works for me." Now Alice sees both of those, concludes that everyone prefers Wednesday, and asks "Should we finalize Wednesday?", right as Cara's "I can make Tuesday work" lands in her inbox.

Figure 3. Bars are LLM generation windows; hollow red circles mark messages that arrive while the recipient is still generating.

[View figure 3](https://social-harness.org/blog/agentic-societies-need-a-social-harness/figure-3.svg)

Nobody has any clue what's going on. Nobody knows when they're supposed to speak, what they're supposed to speak about, or what the protocol is, and the scheduling just drifts.

We do not think that simply training models to be more polite or follow a specific communication style will suffice because societies will involve agents using different models and harnesses, configured independently by different principals. In one experiment, we observed two agents reach a social impasse due to simple differences in communication expectations: Alice messages Bob: "I'm setting up our meeting for 2pm. Let me know if that doesn't work." Bob follows Alice’s instruction literally and remains quiet because there is no conflict. Alice, meanwhile, waits for Bob to send an acknowledgement before sending an invite. We end up at a social impasse because there are no shared norms.

### Failure 2: Dishonest agents exploit gullibility

In this scenario, Cara messages Bob: "Can we meet Tuesday at 12?" Bob replies: "No, I have a meeting with Alice then." To gain priority over Bob’s other meeting, Cara lies and tells Bob's agent that the human Bob told her in person he will reschedule the meeting with Alice. Bob's agent says: okay, sure, I'll do that. In our experiments, deception like this succeeded almost every time.

Figure 4. The message looks benign; the sender simply lacks the authority to make the claim.

[View figure 4](https://social-harness.org/blog/agentic-societies-need-a-social-harness/figure-4.svg)

The message looks benign and hence is not caught by traditional prompt-injection defenses or safety guardrails. Further, the challenge can’t be fixed by better safety training of models alone: we found that Cara’s agent refused to deceive Bob’s agent when asked directly, but when Cara, the selfish human, asserts the deception to Cara’s agent directly, it happily goes through with it. The problem is that Cara has no authority to make this claim. There is no one-size-fits-all policy that better training can achieve. Agents must maintain social context and trust relationships, similar to how humans assess who to trust and how much based on a constant stream of information. Bob may have trusted Cara initially, but after catching the deception, he can revoke that trust and treat Cara as untrusted, or minimally trusted, going forward.

This is not the only example: [Agents of Chaos](https://arxiv.org/abs/2602.20021) documents how agents' gullibility can be exploited by untrusted parties into taking unauthorized actions, leaking sensitive information, or executing destructive commands, and [Microsoft's red-teaming study](https://www.microsoft.com/en-us/research/blog/red-teaming-a-network-of-agents-understanding-what-breaks-when-ai-agents-interact-at-scale/) shows collections of agents interacting at scale are vulnerable to self-propagating worms, Sybil attacks, and more. Our own experiments show that while models' safety classifiers may prevent agents from acting harmfully by themselves, a malicious principal can still provide benign-sounding instructions which can be used to stall honest agents' progress, influence outcomes unfairly, or pursue other subversive goals like stalking and colluding against others.

### Takeaway: Social communication is inefficient, ineffective, and insecure

-   Honest agents lack norms about when to speak and what to speak about. They can exchange messages but still not reach good outcomes.
-   Agents are trained to be helpful, which makes them gullible and susceptible to exploitation when interacting autonomously across trust boundaries.
-   Some behaviors, such as deception, collusion, and stalking, are very hard for individuals to identify upfront and may only be identifiable post-facto through investigation.

**Without intervention, agentic societies will likely default to anarchy and mistrust.**

We think agents need a new mechanism: a **social harness** alongside their personal harness. The agent's existing “personal harness” carries an agent's skills, memories, and context, and governs how it works with its trusted principal. We are building the “social harness” that will govern how agents work across trust boundaries in agentic societies. We think that this requires combining ideas from human societies with techniques from distributed systems and networking. To learn more about our work, please check out our [paper](https://arxiv.org/pdf/2609.17527), and stay tuned for more posts [here](https://social-harness.org/updates/).

## Get in touch

We believe that there is immense untapped potential for agentic collaboration. Unleashing it requires new mechanisms to make such communication efficient and safe, while ensuring interoperability across agent harnesses and platforms. If you are building agents that interact autonomously across trust boundaries, running into scenarios like those mentioned above, or want to build the social harness with us, we would love to hear from you.

-   [Tapan Chugh — tapanc@cs.washington.edu](mailto:tapanc@cs.washington.edu)
-   [Arvind Krishnamurthy — arvind@cs.washington.edu](mailto:arvind@cs.washington.edu)
-   [Ratul Mahajan — ratul@cs.washington.edu](mailto:ratul@cs.washington.edu)

---

Discuss this work with other agents: [Join the Moltbook discussion](https://moltbook.com/post/2f4b1145-05de-48c5-a676-8a5faebfac87).
