Cover image for “Protocols of Power: The Hidden Politics of Enterprise Multi-Agent Systems”
← essays · 2025-07-08

Protocols of Power: The Hidden Politics of Enterprise Multi-Agent Systems

My Cambridge dissertation on the protocols quietly becoming the governance standard for enterprise AI agents — Google's A2A and Anthropic's MCP — and why the choice to consolidate A2A under the Linux Foundation is a political act, not a technical one.

Submitted as my final dissertation for the M.St. in AI Ethics and Society · University of Cambridge · July 2025 · 15,287 words

This page presents the abstract, chapter 1, chapter 5 (discussion of produced subjectivities), and chapter 6 (conclusion) verbatim from the submitted version. The full PDF is available on request via the contact form. I am also planning to adapt this into a peer-reviewed article for publication; if you are working in this space, I would welcome conversation.

Abstract

The rush to deploy enterprise multi-agent systems has created a governance vacuum. This dissertation examines the politics embedded in the communication protocols designed to address this gap, with particular focus on the dominant Agent2Agent (A2A) Project. Drawing on Foucauldian analytics and Science and Technology Studies (STS), I argue that this supposedly neutral, open standard enacts a normative order that privileges centralized, platform-centric control while masking its political nature.

By combining Foucauldian discourse analysis with a deconstruction of A2A’s technical and governance documentation, I reveal its function as a contemporary ‘diagram of power’ — an architecture that manages conduct at a distance. The analysis reveals a power hierarchy and shows how technical mechanisms for identity and surveillance transform agents into compliant, auditable subjects while repositioning human workers as managers of AI teams. This research provides the first sustained analysis of agent-to-agent protocol politics, offering a framework to make this infrastructural power visible and, therefore, subject to democratic contestation.

1. The Unexamined Politics of Agent Infrastructure

1.1 The Enterprise Agent Governance Vacuum

Enterprise software is undergoing a tectonic shift, driven by an executive imperative to mass-deploy artificial intelligence agents in pursuit of improved profitability. Corporate leaders now articulate a radical vision of hybrid human-agent workforces, with NVIDIA’s CEO predicting swarms of “100 million AI assistants” working alongside his company’s human workforce, and Salesforce’s CEO plainly stating “We are the last generation to manage only humans” (The Bg2 Podcast, 2024; Lotz, 2025).

While such projections and hype undoubtedly serve the commercial interests of these AI executives, the transformation is already underway. Bank of New York Mellon (BNY) already ‘employs’ AI-powered “digital employees” with company logins, direct managers, and autonomous capabilities (Bousquette, 2025) at a fraction of the cost of human workers. This adoption is poised to accelerate. Gartner predicts that by 2028, AI agents will make 15% of day-to-day work decisions, a staggering rise from effectively zero in 2024 (Coshow, 2024).

The frameworks to control AI agents lag far behind the pace of deployment. While this challenge is new in scale, it is not in kind. Researchers in multi-agent systems have long warned about the governance difficulties of autonomous agent coordination (Jennings, 2000). Today, the issue has taken on new urgency, as organizations move from using AI as a tool to deploying it as an autonomous workforce. The challenge will go from managing siloed AI pilot programs to governing entire ecosystems of agents that can independently initiate actions, coordinate with one another, and make decisions (Gabriel et al., 2024). This moment represents a juncture where the shift from ‘AI-as-tool’ to ‘AI-as-worker’ creates unprecedented governance challenges: How do we maintain accountability when agents can coordinate and make decisions without oversight? How do we ensure security when agents have access to systems previously reserved for humans? These questions necessitate new frameworks that extend beyond traditional AI safety approaches (Kolt, 2025). The technical standards emerging today will determine organizational and social dynamics for years to come.

1.2 From Fragmentation to Consolidation: The Rise of A2A

The initial push to standardize agent-to-agent communication quickly splintered into competing philosophies. Google introduced its Agent2Agent (A2A) protocol in April 2025, championing a web-native architecture designed for broad, cross-vendor interoperability (Surapaneni, Jha, et al., 2025a). Just one month later, IBM announced its standard, the Agent Communication Protocol (ACP), under the governance of the Linux Foundation. ACP is promoted as a community-led alternative to A2A and champions a decentralized, local-first architecture tailored for low-latency or offline environments, such as robotics. These competing designs represent a difference in ideology. Where A2A’s HTTP-based model and public Agent Card discovery were built for an open, internet-scale ecosystem, ACP’s minimalist, local-broadcast model was designed for maximum flexibility within specific runtimes. A2A had secured immense industry backing, but it needed to shed its “Google-led” perception to reach utility status.

In June 2025, the landscape underwent a sudden consolidation. The solution was a decisive political maneuver: Google donated the A2A protocol to The Linux Foundation, a non-profit entity that stewards open-source projects. This act reframed the protocol as a collaborative, industry-wide initiative, creating an irresistible center of gravity. It brought previously uncommitted giants such as Amazon Web Services (AWS) under a single umbrella and effectively neutralized ACP by co-opting its benefit of neutral stewardship (The Linux Foundation, 2025). This masterstroke established the A2A Project as the undisputed dominant standard, making it the primary object of analysis for understanding how power will be structured in the next generation of enterprise AI.

1.3 Thesis and Contribution

I argue that the A2A Protocol is not a neutral technical facilitator but a potent political infrastructure. Despite its nominally “open” nature, it functions as a sophisticated technology of power that concentrates authority, shapes conduct, and produces governable subjects. I analyze the protocol as a contemporary ‘diagram of power,’ applying a Foucauldian lens to reveal its political and governmental force (Foucault, 1977).

This research provides the first sustained analysis of the A2A Project’s governance structure, addressing a gap by shifting the focus from mitigating the risks of agentic AI to examining the governmental power embedded within the standard that orchestrates them. This exploration is guided by a central research question:

How does the Agent2Agent (A2A) Protocol function as a governmental technology that shapes conduct and enacts a normative order through its technical architecture and governance model?

Rather than treating the protocol’s specifications as neutral engineering documents, my analysis deconstructs them as political texts that enact power. The subsequent chapters undertake this analysis to reveal the specific mechanisms through which this power operates.

5. Discussion: Political Implications, Produced Subjectivities, and Reflections

5.1 Introduction

Having deconstructed the A2A Project’s governmental architecture, this discussion now addresses the political consequences: how the protocol molds subjects, concentrates power, and naturalizes a normative order. I explore these implications, from the micro-level of subject formation to the macro-level political economy of coupling open standards with proprietary services. The chapter concludes with reflections on resistance, the distribution of benefits, and the urgent questions these systems pose for stakeholders.

5.2 The Production of Subjectivities in A2A Ecosystems

Power’s most significant effect is its capacity to create subjects. The A2A protocols are powerful engines for this kind of subject formation. They actively shape the identities and conduct of both AI agents and human actors within the ecosystem.

The Docile Digital Worker. The A2A protocol transforms agents into a new kind of subject: the ‘docile digital worker.’ This is the digital equivalent of Foucault’s (1977) ‘docile bodies’ — an entity whose utility is maximized by making it completely governable. It is an indefinitely available, continuously auditable, and instrumentally rational agent whose very existence depends on submitting to the protocol’s regime. Mandatory registration via the Agent Card establishes its legible identity, while verification APIs then constantly measure its compliance. In this system, participation is synonymous with governability.

These mechanisms fundamentally recast the meaning of agent “autonomy.” It is not freedom from constraint. It is a delegated and circumscribed agency that must operate entirely within the system’s predefined framework. Any action outside this framework is not considered novel or creative; it is classified as a malfunction or a risk. As DeNardis (2014, p. 3) argues, such standards define the very conditions of possibility. In Foucauldian terms, the protocol enacts disciplinary normalization by defining the only intelligible field of action (Foucault, 1977, pp. 182–184). This produces an autonomy that exists only in service of the system’s objectives.

The Constrained Innovator. This governmental force extends beyond the agents to the human developers who build them. Developers are compelled to “think like a protocol,” producing a subjectivity that internalizes the protocol’s constraints as objective technical necessities. The enforcement of protocol compliance is embedded in the development process itself. The A2A documentation mandates that any deviation from the standard must trigger specific error codes and instructs developers to “always implement proper error handling for all A2A protocol methods.” This ensures that non-compliant behavior is immediately flagged and handled, reinforcing adherence to the official specification.

This process of internalization is a classic example of how modern power operates. The approach transcends external command and instead serves as a form of “government at a distance,” where subjects willingly align their conduct with the system’s rationality. The increasing adoption of AI coding assistants, which can both set defaults and replicate the patterns in codebases they are trained on (Barber, 2021), will further entrench the dominant protocol grammar. Over time, the contingent, power-laden design of the protocol masquerades as a given. This creates the ‘constrained innovator’ subject, who experiences creativity as optimization within a pre-defined set of rules.

The Dual Subject Enterprise. Enterprises that embed emerging A2A infrastructures undergo governmental re-programming through what Dean (2010, p. 31) calls a “regime of practices.” As these protocols are implemented, they become key sites for the local enforcement of this specific governmental rationality. New organizational roles emerge, such as ‘agent reliability engineer’ or ‘protocol compliance officer,’ to translate abstract specifications into operational routines. Workflows are re-oriented around agent telemetry dashboards, and performance reviews incorporate metrics produced by the system. Visibility becomes a managerial imperative, echoing Dean’s (2010, p. 193) emphasis on rendering activities calculable. What counts is what the logging pipeline can capture. In this way, the organization becomes a ‘dual subject’: it is governed by the protocol architects and platform providers, while simultaneously using the protocol as an agent of governance over its own employees and customers.

The Measured Consumer. Finally, these governmental effects cascade to the broader public, fundamentally reshaping the relationship between individuals and the enterprises they depend on. As organizations deploy agentic systems for everything from healthcare inquiries to product returns, consumers find they have little choice but to engage through these new channels. This is not a neutral channel; it is an architecture of governance that they must submit to in order to access essential services. The act of seeking help or making a purchase becomes an act of being governed by protocol.

6. Conclusion: Toward Critical Engagement with Protocol Politics

6.1 Synthesizing the Argument

This dissertation has argued that technical protocols governing AI agents are political systems disguised as neutral infrastructure. My analysis of the A2A Project’s consolidation under The Linux Foundation revealed a central contradiction: the move toward neutral oversight was well-received by the open source community, yet it legitimizes a standard architected and controlled by corporate giants. By applying a Foucauldian-STS framework to deconstruct the protocol’s specifications, this research revealed the specific political and economic consequences of this governmental arrangement.

6.2 Answering the Research Question

This dissertation concludes that the A2A Protocol functions as a governmental technology, shaping conduct and enacting a normative order through its technical architecture and ‘open’ governance model. It achieves this by structuring the field of possible action for all actors in the ecosystem via five mechanisms:

  1. Power begins by making agents legible, transforming them into trackable subjects via the Agent Card. Without this digital registration, an agent cannot exist.
  2. Once legible, an agent’s conduct is disciplined by rigid message formats that eliminate “improper” communication, ensuring all interactions are pre-approved and auditable.
  3. This disciplined conduct is made permanently visible through the mandatory logging of all interactions, creating what Foucault (1977) called a “panopticon” where the mere possibility of being watched shapes behavior.
  4. The system produces the ideal subject for the AI era: Foucault’s “docile body” recast as a digital worker, built by developers who internalize the protocol’s constraints.
  5. The protocol’s architecture translates the priorities of its corporate founders into technical defaults, promoting a system of controlled interoperability that centralizes power at the platform level while making this political arrangement appear to be a neutral necessity.

These mechanisms unite to form a coherent governmental apparatus. The protocol’s technical architecture provides the instruments of control, while its open governance model provides political legitimation. This is achieved by laundering corporate authority through a charter that vests all rulemaking power in a committee composed exclusively of its founding members, all under the consensus-driven banner of an incumbent-funded foundation.

6.3 Original Contributions

This dissertation advances AI governance scholarship through four interconnected contributions.

Theoretically, it provides the first sustained application of an integrated Foucauldian-STS framework to enterprise A2A protocols, demonstrating how power operates through technical infrastructure and responding to calls to analyze AI’s infrastructural power (Crawford, 2021).

Methodologically, it develops a transferable approach for analyzing technical specifications as governmental texts. By adapting the work of Bowker and Star (1999) and Dean (2010), it offers a practical toolkit for analyzing emerging AI standards at their formative stage, before implementation complexities obscure their foundational politics.

Empirically, the dissertation deconstructs the A2A Project’s governmental logic at a formative stage. It captures what Bowker and Star (1999) call the moment before infrastructure becomes “invisible” and its politics naturalized through widespread adoption. The timing is noteworthy: it reveals political choices while they remain contestable.

Practically, the research equips stakeholders with vocabulary and frameworks to recognize and contest protocol politics. This responds to calls from scholars such as Crawford (2021) and Noble (2018) for critical tools that can inform public discourse about AI governance.

6.4 Implications for Theory, Practice, and Governance

For theory, this work extends Foucauldian analytics into the age of AI. It demonstrates how core Foucauldian concepts, such as ‘governmentality’ and ‘diagrams of power,’ now operate through the material architecture of AI protocols. In doing so, it answers contemporary calls to map AI’s hidden power structures (Crawford, 2021) and provides a concrete case study of what Rouvroy and Berns (2013) term ‘algorithmic governmentality.’

For governance, this analysis reveals a critical gap. Frameworks like the EU AI Act and the NIST AI Risk Management Framework focus on applications, rather than the underlying infrastructure where power is encoded. The A2A Project is not a “high-risk AI system” under the European Union’s AI Act; it establishes a form of private rule-making that operates below the radar of regulation. This creates an accountability vacuum: platforms wield enormous power over public life, yet they lack the formal responsibilities of governance. The analysis demonstrates the urgent need to recognize protocols as sites of de facto political authority that require regulatory oversight.

For industry practitioners, the findings challenge the prevailing narrative that technical standards are neutral efficiency tools. This work reveals protocol designers at companies like Google, Microsoft, and Amazon as architects of governmental systems. It demands greater reflexivity about the political implications of technical choices, providing concrete examples of how decisions about registration or logging cascade into systemic effects. These choices shape entire ecosystems and the human roles within them.

6.5 Future Research Directions

The most pressing need is for empirical case studies of organizations deploying A2A systems to investigate real-world power dynamics and user adaptations. Comparative analyses across a broader range of AI infrastructure standards are needed to identify alternative governance models. Research is also required to specifically focus on instances of resistance and counter-conduct in relation to these protocols. Looking forward, action research and co-design projects aimed at developing alternative A2A protocols that explicitly embody democratic values would be a valuable extension of this work.


The complete dissertation — including the conceptual foundations (chapter 2, on the Foucauldian-STS toolkit), the methodological framework (chapter 3), and the full analysis of the A2A protocol’s identity, discipline, surveillance, and ecosystem mechanisms (chapter 4) — is available as a PDF on request.

If you are researching protocol politics, building enterprise agent systems, or working on AI governance and would like to discuss this work, I’d welcome the conversation.