Skip to main content
Live
Main content

Cisco's Outshift pitches an 'Internet of Cognition' to fix multi-agent AI failures

Open-source multi-agent systems fail between 41% and 87% of the time; Outshift says a coordination layer raises success to 93%.

Jaeden Schafer
Editor in Chief · · 5 min read
Cisco's Outshift pitches an 'Internet of Cognition' to fix multi-agent AI failures

Cisco's Outshift group is pushing an architectural bet on how multi-agent AI actually gets useful: an open-source coordination stack it calls the Internet of Cognition, built on a connectivity layer named AGNTCY that has been contributed to the Linux Foundation. The pitch responds to a hard number the industry has been quietly living with — one recent study of seven open-source multi-agent systems found failure rates between 41% and 87%. Outshift's own testing found unstructured groups of agents reached a decision just a third of the time across 14 scenarios. A structured coordination protocol pushed that figure to 93%.

The framing comes from Vijoy Pandey, senior vice president and general manager of Outshift by Cisco, in a sponsored piece published in MIT Technology Review. His argument is that vertical scaling — bigger models, more compute, more data — has produced capable single agents, but the next axis has to be horizontal. Agents from different domains, vendors, and companies need a shared way to discover each other, prove identity, exchange messages, and align on goals. Without that layer, naive multi-agent setups can perform worse than a single agent working alone.

The example Pandey uses is a healthcare workflow with four agents: symptom assessment, scheduling, insurance, and pharmacy. Each is competent on its own. None of them can currently coordinate patient care without a human in the loop authorizing every handoff. The intelligence exists; the connective tissue does not.

Key facts

  • 01One study of seven open-source multi-agent systems found failure rates between 41% and 87%.
  • 02Outshift's internal testing showed unstructured agent groups reached a decision only a third of the time across 14 scenarios; a coordination protocol raised that to 93%.
  • 03Roughly 90% of the time, an agent cannot confirm it is authorized for the task it was handed, according to Outshift SVP Vijoy Pandey.
  • 04Outshift's connectivity layer AGNTCY is now an open-source project under the Linux Foundation.
  • 05Outshift also released Mycelium, an open-source coordination layer, and CASA, a reference implementation for continuous agent authorization.

Outshift breaks the problem into three layers. AGNTCY, the connectivity substrate, handles discovery, identity, and messaging across systems — the plumbing. On top of that sits a semantic layer, the Internet of Cognition, where agents share intent, share context, and share reasoning. This is the layer Pandey argues will separate coordinated teams of agents from loose collections of chatbots calling APIs at each other.

The intent piece runs through what Outshift calls cognition state protocols, delivered via an open-source coordination layer called Mycelium that organizations can clone and run against their own agents. The idea is a semantic handshake: agents declare a shared goal, surface what they don't know, and resolve conflicts before taking action, rather than plunging ahead and hoping the orchestration holds.

The 93% success figure comes from that protocol. Across 14 internal test scenarios, groups of agents left to coordinate freely landed on a decision roughly one time in three. Forcing them to negotiate intent up front nearly tripled the hit rate.

Context is handled by what Outshift calls a cognition fabric — a policy-governed shared memory so that agent insights compound across sessions rather than evaporating each time a task ends. Pandey frames the status quo as organizational amnesia: every workflow starts from zero, and no institutional knowledge accrues on the agent side. Reasoning gets a third pillar, combining cognitive amplifiers that speed up modeling with guardrail technologies that enforce security, cost, and compliance.

The security story is where Outshift's Continuous Agent Semantic Authorization, or CASA, comes in — an open-source reference implementation designed to keep an agent's actions bound to the specific task a user actually authorized. CASA reads what the agent is trying to accomplish, then checks each tool call against that task. An agent told to summarize a single patient record that suddenly starts querying a whole database gets denied, because the request no longer matches the authorized job.

Today's controls are scoped to a role or a session not to the task so an agent granted a tool can use it for anything.
Vijoy Pandey, SVP and GM, Outshift by Cisco
Related · from this week
Open Secure AI Alliance drafts SAFE guidelines for agentic AI incident sharing
Jaeden Schafer · 5 min read →

Pandey argues the existing enterprise security stack was not built for entities that behave like humans but operate at machine speed. Access control, identity, and compliance were designed for either a person or a service — not for an autonomous system with the attributes of both. His striking claim: roughly 90% of the time, an agent has no way to confirm it is even cleared for the job it was handed. That is a compliance problem waiting to become a breach.

The counterweight is that this is a sponsored analysis from a vendor selling the coordination layer it is describing, and the industry has heard grand unified protocol pitches before. Google DeepMind researchers have separately called for more study of what happens when millions of agents interact, and the risks — unintended delegations, prompt injection, memory poisoning, over-privileged agents — are still being mapped, not solved. AGNTCY being under the Linux Foundation helps the open-standards claim, but adoption across OpenAI, Anthropic, and the hyperscaler agent stacks is the test that matters.

The strategic read is that Cisco is trying to own the layer between agents the same way it once owned the layer between networks. If multi-agent systems become the default enterprise deployment pattern — and the failure-rate data suggests they will not without something like this — the company selling the coordination fabric, the identity layer, and the authorization engine sits in an unusually valuable spot. Whether that company ends up being Cisco or one of the labs building agents from the model side down is the real fight, and it is only just starting.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Analysis

Nvidia logo
Security

Open Secure AI Alliance drafts SAFE guidelines for agentic AI incident sharing

The 120-member Linux Foundation group opened a Request for Comments on shared incident reporting as Black Hat kicks off in Las Vegas.

Jaeden Schafer5 min read
Nvidia logo
Security

Nvidia's Open Secure AI Alliance ships SAFE proposals one week in

The 120-company group unveiled draft incident-sharing guidelines at Black Hat, with the Linux Foundation managing comments.

Jaeden Schafer5 min read
Anthropic logo
Business

Tokenomics arrives: how 8x8 and Baseball Lifestyle 101 are managing Claude bills

Royal Bank of Canada's token usage jumped 500% in six months as CFOs grapple with a new line item that didn't exist two years ago.

Jaeden Schafer5 min read