Agentic AI Subagents: One Agent Cannot Check Itself

Agentic AI subagents explained in a newspaper-style header graphic on why one agent cannot check itself, with three Thinkers360 Certified Expert badges, by Dr. Harish Kotadia, Ph.D.

What are agentic AI subagents?

Agentic AI subagents are separate agents that a main agent hands work to. Each one runs in its own context window, with its own tools and its own permissions. So the main agent never sees the mess, only the result. And one of those subagents can be the one that checks the work.

One agent cannot check itself. Two can.

New here? I publish one agentic AI governance post every weekday. Subscribe to the blog and it lands in your inbox the moment it goes live.

Why can one agent not check itself?

Because it already believes the work is right. An agent that just wrote the code carries every assumption it made while writing. When I ask it to review, it reads its own reasoning back and nods.

Anthropic says this in plain words in its best practices. “A fresh context improves code review since Claude won’t be biased toward code it just wrote.” The reviewer sees only the diff and the criteria. It never sees the story that produced the change.

I hold the same rule for people. The engineer who wrote the change does not sign off on it. So I do not let the agent do it either.

How does Claude Code build agentic AI subagents?

As a small file with a name, a description, a tool list and a system prompt. The docs for the feature describe each one as a “specialized AI assistant that handles specific types of tasks.” When the main agent meets a matching task, it delegates. The subagent “works independently and returns results.”

The important part is what the subagent does not get. It does not inherit the conversation. Nor does it see the files the main agent read. It starts clean, with the task and the project rules, and nothing else.

Tools are an allowlist. A subagent with tools: Read, Grep, Glob cannot write a file, because the tool is not there. That is a fence, not a request.

How do I make a subagent the verifier?

I give it the diff, the plan and a narrow question. Anthropic’s guide calls this an adversarial review step. The reviewer runs in a fresh context, “so the agent doing the work isn’t the one grading it.”

My verifier is one of my agentic AI subagents with read-only tools. It gets the plan file as the standard. And it gets one instruction: report gaps, not style. Then the implementing agent gets the gaps back and fixes them.

One warning from the same guide, because I hit it early. A reviewer told to find gaps will find some, even in sound work. So I tell mine to flag only what breaks correctness or a stated requirement. The rest is optional.

What do agentic AI subagents cost?

Tokens, and a lot of them. Anthropic’s multi-agent research post reports that “multi-agent systems use about 15× more tokens than chats.” That is the price of separate context windows.

The same post gives the other side. A lead agent with parallel subagents “outperformed single-agent Claude Opus 4 by 90.2%” on its internal research eval. So the split buys quality, and I pay for it.

In my work in regulated loan origination, I do not run a verifier on every task. I run one on every task that touches a decision. That is the line I drew, and the token bill follows it.


More on Agentic AI Enforcement Controls



What do I split first?

The check, before anything else. Most teams split for speed and run five workers in parallel. I split for independence and run one verifier first. Speed comes later.

Three rules for that first verifier:

  • It is read-only.
  • It never sees the main agent’s reasoning.
  • And its findings go into the record, not just back to the agent. A finding nobody can read later is not evidence.

I also cap the depth. Claude Code lets agentic AI subagents spawn their own, “up to three layers below the main conversation.” I set that limit to one in managed settings. A verifier that hires its own verifier is a queue, not a control.

Where does this sit in the six layers?

In the capability layer of my six-layer architecture. Subagents are a capability, like tools and skills. But the verifier reaches into the evidence layer, because its report is the record of what was checked.

It also works beside branch protection. The merge gate stops the author from approving. The verifier gives the second identity something to read. And agentic AI subagents with narrow tools earn a team more room on my five-stage roadmap, because the reach of each one is bounded.

So here is my test: does the agent that wrote the change ever grade it?

What is the bottom line?

Governance asks who checks the agent. Architecture answers with a second agent that never saw the first one think. Instructions in, results out was IT; intent in, outcomes out is agentic AI. But an outcome graded by its own author is a claim, not an outcome.

Agentic AI subagents are cheap to define and dear to run. So define the verifier first and let the workers wait. I cover the wider control set in Intent In, Outcomes Out and in Earned Autonomy.

Who checks your agents’ work today, and did that checker see the reasoning first?

Book covers of Intent In, Outcomes Out and Earned Autonomy by Dr. Harish Kotadia, Ph.D., two field guides to agentic AI architecture and governance.
My books go deeper on both: Intent In, Outcomes Out (mybook.to/AgenticAI) and Earned Autonomy (mybook.to/Autonomy).

Go deeper

 

© Dr. Harish Kotadia, Ph.D., All Rights Reserved, 2026

Dr. Harish Kotadia, Ph.D., is an Enterprise AI Architect with 20+ years of IT consulting experience serving Fortune 100 clients, specializing in agentic AI systems built on Anthropic Claude, AWS Bedrock, and Google Vertex AI.

Disclaimer: This blog post is based on publicly available academic publications, vendor documentation, open standards, and news items from reputed media sources linked above. This post is intended for educational purposes, to help the enterprise agentic AI community build a shared vocabulary from public, authoritative sources.

Views and opinions expressed here are my own and do not represent those of any employer or client, past or present. The analysis presented is my independent interpretation of the published sources linked above and does not constitute legal, financial, or consulting advice of any kind.

 


Discover more from Agentic AI Governance | Dr. Harish Kotadia, Ph.D.

Subscribe to get the latest posts sent to your email.

Discover more from Agentic AI Governance | Dr. Harish Kotadia, Ph.D.

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Agentic AI Governance | Dr. Harish Kotadia, Ph.D.

Subscribe now to keep reading and get access to the full archive.

Continue reading