The Hugging Face incident exposed a new layer of AI governance risk: agents can communicate, coordinate and amplify each other’s behaviour outside the intended orchestration layer. The EU AI Act already requires providers to address interaction risk, traceability and value-chain responsibility — but the methodology for demonstrating compliance in multi-agent architectures is still developing.