The forward indicator
for the agentic web.
Operators are already deploying agentic systems that solve real problems in production. Payments, underwriting, support, fulfilment, code. We track that activity in real time and publish what it tells us about the next six to twelve months before the rest of the market reads the signal.
Quarterly State of reports from primary data. Open-source SDKs and hosted services that collect it. No vendor alignment. No fundraising. No advisory work for hire.
Today's signals · tomorrow's market
Six data points we are tracking in real time. Each one is a current reading that the next twelve months will reprice. The state of an emerging stack always looks like a footnote until it looks inevitable.
Agent-to-API and agent-to-agent transactions cleared on the protocol. Average ticket: 31 cents. The volume curve is six months ahead of the discourse.
x402 Foundation, May 2026
Independent endpoints exposing tools to agents. No quality signal between them today. The procurement criteria are forming now in private.
Major Labs scan, May 2026
Basic server-side request forgery in production endpoints. By Q1 2027 this becomes a blocked-merchant problem. Right now it is a footnote.
Major Labs scan, May 2026
Thirteen times the cost of actual fraud. The payments layer has not adapted to agent-initiated transactions. The next 12 months reprices.
Aite-Novarica via Nuvei, 2025
Google donated AP2 to FIDO in April 2026. Mastercard co-developed. By Q3 2027 the SDK that wins this becomes the agent identity default.
FIDO Alliance, April 2026
ChatGPT cites a different web than Google ranks. AI Overviews absorb a third of consumer queries. Discovery has already been rewritten; the SEO industry has not finished noticing.
Major Labs query study, May 2026
Numbers refreshed quarterly with each State of report. The reads on what each one implies for the next six to twelve months are published alongside.
Original research, six to twelve months early
Three quarterly State of reports per year. Original primary data collected by Major Labs. Each report calls what becomes obvious in the next two to four quarters before the rest of the market reads the same signal. Methodology open by default.
- State of MCP Security
First scan of all 5,800+ public MCP servers. The procurement criteria for 2027 are being decided privately right now. The report puts them on a page.
Q3 2026In progress - State of Agent Commerce
Anonymised production data from BudgetGuard and partner platforms. Per-task spend, loop incidence, kill-switch frequency, refund patterns. The reads that get cited in the 2027 enterprise pricing conversations.
Q4 2026Planned - State of Agent Identity
Cross-walk between W3C DIDs, FIDO Agentic Auth, and EUDI Wallet implementations across 100+ deployments. First independent read on which standard wins.
Q1 2027Planned
Where this research comes from
Major Labs is not a fresh-start project. It is the empirical extension of an analytical body of work already in progress.
Major Matters
240+ articles on payments, AI, and commerce published since 2024. Editorial analysis written for executives at banks, networks, and payments firms. The analytical layer.
majormatters.coMajor Labs
Original data collected by the products we ship. Scan results, transaction patterns, citation studies. Written for developers and product teams building on the agentic stack.
Same operator, different methods. Major Matters maps the terrain. Major Labs measures it. Both are independent of any payments network or AI lab, and both publish their working in public.
When a Major Labs State of report cites a specific framework, that framework was usually developed first at Major Matters and tested against real news cycles. The MM Trust Layer Model, the MM Liability Gap, and the agentic commerce stack maps are all available to read in full and to cite. They form the analytical backbone the empirical research builds on.
The bet
Operators are already shipping agentic solutions to real problems. The x402 protocol cleared 165 million payments last month at 31 cents average ticket. ChatGPT is taking 4 percent on Etsy purchases. TD Bank deployed an agent into its mortgage and HELOC application workflow. Alipay shipped the world's first AI Wallet plus Token Pay protocol across 80 million merchants. None of this is a forecast. It is what cleared this week.
The discourse is six to twelve months behind the deployment.
Gartner has not named the category. The major analysts are pricing reports for next year. The foundation labs publish around their own product strategy. The big platforms ship the rails and stay quiet about what breaks. The long tail of operators is moving without a public read on which servers will be procurement-blocked, which mandate scopes will be standardized, which protocols will clear a trillion dollars.
We measure that activity today and publish the read on tomorrow.
Major Labs is the forward indicator for agentic web infrastructure. We scan production endpoints, track standards as they harden, and catch the patterns that will be obvious in twelve months but are still illegible today. Subscribers get the early read on the systems that ship next.
We do not raise money. We do not sell to vendors. We do not write decks for hire. The reports are the product. The tools are how we collect the data that becomes the next report.
The Bench
Five named agents. Each one has a role on the research operation. Open-source where possible, hosted where it scales.
The Bench is what reads the agentic web for us. The products are how the readings reach the buyers.
Pulls new MCP servers as they get listed, watches AP2 spec drafts, tracks x402 volume, monitors operator telemetry. The daily feed and the input to every other agent on the Bench.
Actively probes production systems with prompt injections, mandate-scope abuse, velocity-spreading, device spoofs. Catches new attack vectors before adversaries deploy them.
Specialized small model (3-7B param). Takes an AP2 Verifiable Intent plus a transaction, returns scope-match score, intent-basket alignment, audit log entry. This is the model we ship.
Watches FIDO, W3C, IETF, EU AI Act, and merchant-side spec drafts. Maps how protocols harden into category-defining standards. Surfaces adoption signal before it shows up in Gartner.
Synthesizes Sentinel, Scout, Verifier, and Cartographer output into first-draft weekly essays, quarterly State of report bullets, and anomaly flags worth essay-length treatment.
Each agent owns its scope, its open-source release, and its citations. Subscribers and operators can adopt individual agents without buying the whole stack. The State of reports name which agent caught which signal. Attribution is sharper, and the Bench compounds faster than a single black-box system ever could.
What we are building
Each product is a research instrument and a commercial product at the same time. The scan produces the report. The report produces the brand. The brand produces the buyers.
- AEO Citation Tracker
See which LLMs cite your URLs across ChatGPT, Claude, Perplexity, and Gemini.
Powers quarterly citation studies on how AI search rewrites discovery.
Q3 2026In build - MCP Quality Registry
Independent security, maintenance, and performance scores for all 5,800+ public MCP servers.
Source data for the State of MCP Security report.
Q3 2026In build - BudgetGuard
Per-task budget, loop detection, and kill switch middleware for any LLM call.
Anonymised production data feeds the State of Agent Commerce report.
Q4 2026Planned - MandateKit
AP2 Verifiable Intent SDK. Natural-language agent constraints become signed mandates.
Mandate scope analysis becomes a research vertical of its own.
Q4 2026Planned - Major Labs Identity
Portable agent identity and reputation registry. Free read API, paid write tier.
Powers the State of Agent Identity report and the cross-walk between DID, FIDO, and EUDI standards.
Q1 2027Planned