Skip to content
GiveCare

September 11, 2026

· safety· research

Who owns the handoff?

Care crosses a hospital, a county office, an insurer, and a pharmacy, but we assess one system at a time. Before an agent acts on someone's behalf, three things belong in writing.

AM

Ali Madad

Contributor

Here is a scene that has not happened.

Dana's father comes home on a Thursday after eleven days in the hospital. She is his daughter. She does not hold power of attorney. The discharge team sends a referral to a county service that helps with in-home support, and the county opens a file. The file waits on a signature and a proof of income from her father.

Dana answers the questions she can answer. The ones about his finances are his to answer, and so far nobody has asked him.

Three weeks on, no aide has come. The hospital has not heard. The county has not heard either, because from where they sit the file is open and waiting.

Nothing in that story requires anyone to behave badly.

The unit of assessment

The Cooperative AI Foundation and Brookings warn that testing agents separately can miss risks created by their interactions. Their workshop memo calls for governance that also examines what happens when systems from different providers operate together.

That matches how we test software and how we assign blame. It does not match Dana's week, which crosses a hospital, a county office, an insurer, a pharmacy, and a benefits screener. The referral has to survive every crossing.

If agents begin handling these handoffs, the fragmentation they would inherit is here already.

On whose behalf?

Before asking whether an agent behaved safely, ask who it was acting for.

Three parties have a stake in Dana's week, and they are distinct. Her father's benefits, health, and money are the subject. Dana does the work. The institutions carry their own duties.

Being affected by a decision does not make someone authorized to make it. Dana is holding the phone. That does not make her the principal on her father's benefits application. GiveCare's agent is not established as authorized to act for both of them, and we do not design as though it were.

Take the discharge summary. Who decides whether it goes to the county, and under what rule? That depends on the authority Dana's father has given, and on the sharing rules that govern this particular disclosure. An agent that asks Dana and moves ahead has skipped the question it should ask out loud. Whose permission governs this action, and do we have it?

Agent identity work points the same way. Useful agent identity carries the relationships around an agent, including the human principal behind it. The exchange of identity with a counterparty is a key moment in an agent's operation. In care, that moment is a handoff between organizations.

What survives a handoff

Consent is the clearest case. Permission is given once, to one organization, for one purpose. Does it reach the contractor the county uses? The vendor behind the contractor? Those questions have answers, and a family has nowhere obvious to go and look them up.

Context can thin the same way. The reason behind a request, the urgency, the fact that a daughter is not a power of attorney, any of it can drop at a hop until what arrives is a form with fields.

Then there is the failure in Dana's story, which is quiet. It helps to treat an incident as anything unexpected, rather than only as something visibly going wrong. Carried into care, that counts support which was arranged and never arrived. An absence announces itself less readily than an error does, so someone has to be responsible for noticing that nothing happened. In Dana's case the job falls to her.

Accountability follows control. When many parties touch an action and many benefit from it, responsibility thins out. It concentrates again when responsibility for a piece of an agent's behavior sits with whoever controls that piece. So the useful questions are the boring ones. If Dana sees something wrong, who does she contact? What does that person need in order to decide? Can anyone revoke a permission or stop an action once it is moving, and how long does that take?

Monitoring across organizations means seeing across them, and that has a cost. There are ordinary reasons to limit what identity and interaction data gets exchanged, privacy among them. Caregiving data makes that tension sharp. It holds diagnoses, money, family conflict, and the private judgment that someone can no longer be left alone. Anyone proposing visibility across care organizations owes an answer on what is recorded and who may read it. How long it is kept is the question after that. We do not have a clean answer, and we would rather say so.

By infrastructure we mean two things. Shared requirements would say what travels with a referral, and what gets logged when responsibility moves between organizations. Usable mechanisms would give a caregiver a receipt for a handoff and a name for whoever holds the request now. Building that takes agreement more than it takes a new company.

One failure mode worth naming here involves no handoff at all. A study of three open-weight models found that simulated therapy-like conversations could move a model away from its usual assistant persona, and the authors show concerning examples involving dependency and vulnerable users. That work did not measure real caregiving outcomes, and it did not examine interactions between agents. It raises a separate evaluation question that sits beside the handoff ones. Does an assistant hold its role as the conversation changes?

Where we stand

We build InvisibleBench to test how caregiver-facing AI behaves across many turns, because a caregiving relationship runs long and a single exchange shows little of it. That is a foundation. It is not evidence of multi-agent safety. InvisibleBench evaluates one system's behavior in defined situations, and it does not observe what happens once that system hands off to an organization we do not control. Evaluation built for a single agent does not cover a chain of them, and no company closes that gap by evaluating itself.

Harmful output from a model is a real risk and worth testing for. Dana's three weeks are a second kind of risk, where each organization has completed its own step and the person waiting at home is the one who notices.

Safe behavior inside one system does not add up to a safe caregiving journey. So before an agent is allowed to act on someone's behalf, we think three things belong in writing:

  • what the action covers,
  • who is responsible for it,
  • how it gets corrected or stopped.

Define those first, then enable the action.


Source note

Cooperative AI Foundation and the Brookings Institution, "Establishing Foundational Principles and Thresholds for Multi-Agent AI Governance," IASEAI '26 workshop memo, 2 September 2026. Presented at the CAIF and IASEAI seminar "When AI Agents Meet: A Blueprint for Addressing Multi-Agent AI Governance," 10 September 2026.

The persona study is The Assistant Axis: Situating and Stabilizing the Default Persona of Language Models (arxiv.org/abs/2601.10387, January 2026). Its conversations were generated by models simulating users, and its subjects were three open-weight models that the authors state are not frontier models. The dependency and vulnerable-user material is presented there as qualitative case studies. Nothing in it establishes clinical or behavioral harm to a real person, and the authors find persona position is driven mainly by the most recent message, so it should not be described as drift that accumulates with conversation length.

Dana and her father are invented. The scenario illustrates one possible sequence. It is not a claim about how often any of it occurs, and nothing here is legal advice.