An internal agent is supposed to order hardware for an employee from an external supplier.
In a post, Raghvender Arni (Google) describes an agentic enterprise scenario in which this interaction does not rely on a single standard. Different functions are addressed separately: Open Knowledge Format (OKF) structures internal purchasing rules, Agentic Resource Discovery (ARD) is used to discover resources and endpoints, Agent2Agent (A2A) structures the interaction between agents, and SPIFFE provides cryptographically verifiable runtime identity.
What is notable is what this architecture does not require.
A2A explicitly treats the internal execution of the remote agent as opaque. The client does not need to know its internal state, memory, or the tools it uses for the two agents to interact.
The response to this opacity in the Google corpus examined here is not full transparency. Instead, specific conditions of the interaction are made explicit.
Policy context can be represented in structured form. Resources can be described and discovered. Interactions and task states can be formalized. Runtime identities can be made cryptographically verifiable.
The agent as a whole does not become transparent. Specific conditions of its interaction become explicit.
This changes the object of control.
Control does not have to depend entirely on being able to inspect the internal decision logic of another agent. Specific control conditions can be explicitly represented or made addressable or verifiable outside that logic.
This is not, however, a complete governance solution.
A verifiable identity does not prove correct execution. Structured policy context does not prove that a policy has been applied correctly. Discovery does not prove that a discovered resource is permitted for use. And a formally described task does not make the executing agent’s internal decision logic transparent.
This brings a more precise governance question into view.
Not only:
How transparent is the agent?
But:
Which conditions of a specific interaction must be explicit, verifiable, and reconstructable for control to remain possible under opaque execution?
This connects to our analysis „The Carrier Stability Problem“: governance does not operate directly on risks, but through carriers on which its functions can be exercised. The Google corpus examined here shows more concretely how, under agentic conditions, different parts of an interaction can become explicitly addressable.
References:
Raghvender Arni (Google), Enterprise AI Agent Interoperability Workflow
AI Governance & Markets, The Carrier Stability Problem

