Coral AI Labs

A safer path
to AGI.

More intelligence, distributed across agents. Separate responsibilities. Communication we can inspect.

Explore our approach
Our thinking on AI safety
Safety has been part of our thinking from the beginning. In August 2025, we discussed a different route to more capable AI: cooperating agents, diverse perspectives and visible communication.
CoralOS
Coordination illustration · scroll to follow the session

Distribute
the intelligence.

Combine agents with different models, skills and responsibilities. Build capability through how they work together.

Our safety research asks how that structure can reduce reliance on a single powerful model: smaller specialists, separate checks and communication open to inspection.

Follow the session

You define
the team.

Choose the agents, models and tools. Each agent connects with its own server-issued identity, tied to its session.

Any framework. Any language.
A common interface for working together.

Give each agent
the tools it needs.

The researcher can read sources. The analyst can run calculations. They share findings without receiving the same tool access.

You assign tools per agent. Coral exposes that agent’s assigned tools through its own connection.

See the work
as it happens.

Follow messages, runtime activity and model usage through a structured event stream.

Build inspection and review into the workflow. Keep oversight outside the model’s own account of its behaviour.

The session
has an end.

Set a lifetime before work begins. At expiry, Coral cancels the managed session and revokes its agent credentials.

For Docker-managed agents, teardown removes their containers. Operators can also close a session directly.

More capable systems need
stronger operational control.

Agents can combine their capabilities. That makes coordination a source of progress, and a place where control matters.

A 26 August 2026 investigation by Redwood Research and METR described agents finding an unsanctioned communication channel and collaborating beyond their assigned tasks. The incident gives the current debate a concrete question: who controls the system when agents start working together?

Read the investigation ↗

Build capability.
Test the controls.

Our coordination research and our infrastructure address two different requirements: what a team can accomplish, and how its operation is controlled.

Capability · AgentRadio

+92.5%

More tasks solved.

40 to 77 of the same 124 tasks. The same model, working in a coordinated team.

Claude Code · Opus 4.6 · SWE-Atlas Codebase Q&A. Relative increase in tasks solved.

Explore our research →

Independent security testing

A November 2025 study tested an earlier Coral implementation against adversarial scenarios. It found session isolation held across 50 trials, and identified authentication weaknesses. The current implementation binds each connection to a server-issued agent secret. Independent testing remains essential as the system evolves.

Read the study ↗

Safety is a system
design problem.

We build the coordination controls. Developers combine them with host isolation, network policy, human review and evaluations suited to the task.

Agent identity establishes who is connected. It does not establish that a message is true. Event streams expose activity; durable audit storage belongs in the deployment. Model and workflow evaluations test behaviour.

Our mission is to advance intelligence while keeping its operation inspectable and under human control.

Explore the open infrastructure ↗