Skip to main content
Live
Main content

Google DeepMind backs $10M fund to study multi-agent AI safety risks

Rohin Shah says agents deployed at scale create a new risk class, and academia needs to study it before deployment hits the economy.

Jaeden Schafer
Editor in Chief · · 5 min read
Google logo

Google DeepMind is putting money behind a problem it says nobody is studying: what happens when millions of AI agents start interacting with each other across the open internet. The lab, alongside Schmidt Sciences, the UK government's ARIA, the Cooperative AI foundation and Google.org, announced a $10 million fund on June 11 to seed academic research into multi-agent safety. Rohin Shah, who directs AGI safety and alignment research at Google DeepMind, says the field of research effectively does not exist yet, and agents are about to be deployed across the economy in numbers that make that gap dangerous.

The $10 million pot is modest compared with Google DeepMind's internal research budgets, and that is the point. Shah wants universities working on scenarios that industry labs will not prioritize until they are already a problem. Google made agent-based tools a centerpiece of Google I/O last month, and the broader industry is moving the same direction, so the window to study failure modes before deployment is short.

Shah frames the concern as a tipping point. Single agents are studied; small clusters are studied; what happens when there are millions of them reasoning, negotiating and acting on instructions from other agents is not. He compares it to human institutions, which can accomplish things no individual human can — for better and for worse.

Key facts

  • 01Google DeepMind, Schmidt Sciences, ARIA, the Cooperative AI foundation and Google.org are putting up $10 million for academic research into multi-agent safety.
  • 02Rohin Shah, who runs Google DeepMind's AGI safety and alignment research, says agents will be deployed across the economy in a matter of months.
  • 03Anthropic published zero-trust guidelines for agent deployment a couple of weeks ago, assuming any agent is a potential attacker.
  • 04Risks named include prompt injection, scams and cyberattacks at scale — the agent versions of existing internet abuse.
  • 05The fund was announced one month after Google made agent-based tools a centerpiece of Google I/O.

James Fox, who leads the Science of Trustworthy AI program at Schmidt Sciences, puts the stakes in concrete terms. The internet, he argues, is a digital commons that society depends on, and a flood of autonomous agents could break it. The risks Shah and Fox name are not exotic: scams at scale, prompt injection attacks that hijack an agent through malicious text buried in a document, and other cyberattacks adapted to a world where the target is a reasoning system rather than fixed software.

Shah does push back on the doomer end of the spectrum. Asked whether the fund is preparing for scenarios like widespread economic collapse, he said "certainly not if we're talking by the end of the year" — six months out — before allowing that longer horizons are fair game. The near-term work is empirical: drop agents into sandboxes, run realistic simulations, watch what happens when large language model–backed agents act irrationally or coordinate in unexpected ways.

Some Google DeepMind researchers have argued that artificial general intelligence, if it arrives, may emerge from a hive of interacting agents rather than a single dominant model. That makes multi-agent dynamics not just a safety question but a capabilities question — the same interactions that could spiral into anarchy could also be where the next jump in capability comes from.

Google DeepMind is not alone in flagging the risk. Anthropic published guidelines a couple of weeks ago for deploying agents on a zero-trust basis, the cybersecurity model that assumes the system is already compromised, the agent is an attacker, and a breach is inevitable. The two labs are converging on the same instinct: agents break the assumptions that prior security thinking was built on.

An agent breaks all of those assumptions. It reasons, it improvises, and it can be hijacked by a single sentence buried in a document it was asked to read.
Refael Angel, Cofounder and CTO of Akeyless

Refael Angel, cofounder and CTO of Akeyless, a Tel Aviv cybersecurity firm, says every previous approach to security assumed the machine was software written by a human, doing fixed things on fixed paths. Angel welcomes the new funding but warns that safety researchers can chase exotic hypotheticals while missing concrete problems that are already shipping. He also argues no single lab should be writing the safety standards everyone else has to trust — an argument for funding academic and independent work rather than letting frontier labs grade their own homework.

Related · from this week
OpenAI, Anthropic CEOs sign letter pushing DNA screening law to block AI bioweapons
Jaeden Schafer · 5 min read →

Fox's counter is that the line between hypothetical and real has been moving fast. Risks that read as speculative a few years ago are now operational concerns inside production systems. The future, he says, came more quickly than expected.

The harder question is whether $10 million spread across academic groups can build a field fast enough to matter. Multi-agent safety as a discipline does not exist in the way single-model alignment does — there are no shared benchmarks, no agreed-on simulation environments, no canonical failure cases. The fund is buying the early scaffolding: sandboxes, evaluation methods, and a generation of researchers trained to think about emergent behavior across populations of agents rather than single-model alignment.

For the AI market, the timing matters. Agent products are the commercial story of 2026, from Google's I/O announcements to OpenAI's Codex deployments to a wave of vertical agent startups. If multi-agent failure modes hit production before the research field exists to diagnose them, the regulatory response will be written by whoever shows up first with a story — and that is rarely the labs. DeepMind funding academia to do work it will not do itself is a bet that distributed expertise, not in-house red teams, is what keeps the agent economy from turning into the anarchy Fox is worried about.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

OpenAI logo
Security

OpenAI, Anthropic CEOs sign letter pushing DNA screening law to block AI bioweapons

Altman, Amodei, Hassabis and Suleyman want Congress to require gene synthesis providers to vet every order and customer.

Jaeden Schafer5 min read
OpenAI logo
Security

Illinois passes frontier AI safety bill requiring third-party audits

SB 315 mandates independent verification of safety practices at OpenAI, Anthropic, and Google DeepMind.

Jaeden Schafer5 min read
CAISI signs Google, Microsoft and xAI to AI safety tests after Mythos scare
Security

CAISI signs Google, Microsoft and xAI to AI safety tests after Mythos scare

Trump's renamed AI safety body locks in pre-deployment evaluations with three frontier labs as a mandatory testing executive order looms.

Jaeden Schafer5 min read