The forward indicator
for the agentic web.
Operators are already deploying agentic systems that solve real problems in production. Payments, underwriting, support, fulfilment, code. We track that activity in real time and publish what it tells us about the next six to twelve months before the rest of the market reads the signal.
Quarterly State of reports from primary data, collected by tools and research we publish in the open. No vendor alignment. No fundraising. No advisory work for hire.
Today's signals · tomorrow's market
Six data points we are tracking in real time. Each one is a current reading that the next twelve months will reprice. The state of an emerging stack always looks like a footnote until it looks inevitable.
Agent-to-API and agent-to-agent transactions cleared on the protocol. Average ticket: 31 cents. The volume curve is six months ahead of the discourse.
x402 Foundation, May 2026
Not the 10,000-plus commonly cited. We catalogued roughly 2,400 public servers; about half are genuinely evaluable. No quality signal between them today.
Major Labs scan, June 2026
A maintainability signal across the active population. Security probing (SSRF and the rest) is the v1 sweep, not yet run, so we don't publish those numbers as fact yet.
Major Labs scan, June 2026
Thirteen times the cost of actual fraud. The payments layer has not adapted to agent-initiated transactions. The next 12 months reprices.
Aite-Novarica via Nuvei, 2025
Google donated AP2 to FIDO in April 2026. Mastercard co-developed. By Q3 2027 the SDK that wins this becomes the agent identity default.
FIDO Alliance, April 2026
ChatGPT cites a different web than Google ranks. AI Overviews absorb a third of consumer queries. Discovery has already been rewritten; the SEO industry has not finished noticing.
Major Labs query study, May 2026
We scan the public MCP ecosystem every week and publish the full dataset, methodology, and time series. The figures everyone repeats are inflated; these are the real ones, open for anyone to check.
The other readings refresh quarterly with each State of report. The reads on what each one implies for the next six to twelve months are published alongside.
Original research, six to twelve months early
Three quarterly State of reports per year. Original primary data collected by Major Labs. Each report calls what becomes obvious in the next two to four quarters before the rest of the market reads the same signal. Methodology open by default.
- State of MCP Security
First open scan of the public MCP server ecosystem: ~2,400 catalogued, roughly 1,200 genuinely functional. The procurement criteria for 2027 are being decided privately right now. The report puts them on a page.
Q3 2026In progress - State of Agent Commerce
Anonymised production data from BudgetGuard and partner platforms. Per-task spend, loop incidence, kill-switch frequency, refund patterns. The reads that get cited in the 2027 enterprise pricing conversations.
Q4 2026Planned - State of Agent Identity
Cross-walk between W3C DIDs, FIDO Agentic Auth, and EUDI Wallet implementations across 100+ deployments. First independent read on which standard wins.
Q1 2027Planned
Where this research comes from
Major Labs is not a fresh-start project. It is the empirical extension of an analytical body of work already in progress.
Major Matters
240+ articles on payments, AI, and commerce published since 2024. Editorial analysis written for executives at banks, networks, and payments firms. The analytical layer.
majormatters.coMajor Labs
Original data collected by the products we ship. Scan results, transaction patterns, citation studies. Written for developers and product teams building on the agentic stack.
Same operator, different methods. Major Matters maps the terrain. Major Labs measures it. Both are independent of any payments network or AI lab, and both publish their working in public.
When a Major Labs State of report cites a specific framework, that framework was usually developed first at Major Matters and tested against real news cycles. The MM Trust Layer Model, the MM Liability Gap, and the agentic commerce stack maps are all available to read in full and to cite. They form the analytical backbone the empirical research builds on.
The bet
Operators are already shipping agentic solutions to real problems. The x402 protocol cleared 165 million payments last month at 31 cents average ticket. ChatGPT is taking 4 percent on Etsy purchases. TD Bank deployed an agent into its mortgage and HELOC application workflow. Alipay shipped the world's first AI Wallet plus Token Pay protocol across 80 million merchants. None of this is a forecast. It is what cleared this week.
The discourse is six to twelve months behind the deployment.
Gartner has not named the category. The major analysts are pricing reports for next year. The foundation labs publish around their own product strategy. The big platforms ship the rails and stay quiet about what breaks. The long tail of operators is moving without a public read on which servers will be procurement-blocked, which mandate scopes will be standardized, which protocols will clear a trillion dollars.
We measure that activity today and publish the read on tomorrow.
Major Labs is the forward indicator for agentic web infrastructure. We scan production endpoints, track standards as they harden, and catch the patterns that will be obvious in twelve months but are still illegible today. Subscribers get the early read on the systems that ship next.
We do not raise money. We do not sell to vendors. We do not write decks for hire. The reports are the product. The tools are how we collect the data that becomes the next report.
The Bench
Five named agents. Each one has a role on the research operation. Open-source where possible, hosted where it scales.
The Bench is what reads the agentic web for us. The products are how the readings reach the buyers.
Pulls new MCP servers as they get listed, watches AP2 spec drafts, tracks x402 volume, monitors operator telemetry. The daily feed and the input to every other agent on the Bench.
Actively probes production systems with prompt injections, mandate-scope abuse, velocity-spreading, device spoofs. Catches new attack vectors before adversaries deploy them.
Specialized small model (3-7B param). Takes an AP2 Verifiable Intent plus a transaction, returns scope-match score, intent-basket alignment, audit log entry. This is the model we ship.
Watches FIDO, W3C, IETF, EU AI Act, and merchant-side spec drafts. Maps how protocols harden into category-defining standards. Surfaces adoption signal before it shows up in Gartner.
Synthesizes Sentinel, Scout, Verifier, and Cartographer output into first-draft weekly essays, quarterly State of report bullets, and anomaly flags worth essay-length treatment.
Each agent owns its scope, its open-source release, and its citations. Subscribers and operators can adopt individual agents without buying the whole stack. The State of reports name which agent caught which signal. Attribution is sharper, and the Bench compounds faster than a single black-box system ever could.
What we are building
Each product is a research instrument and a commercial product at the same time. The scan produces the report. The report produces the brand. Every one is now shipped, the whole roadmap ahead of estimate.
Sign and verify what an AI agent is allowed to spend on. Natural-language constraints become signed, checkable mandates. Tracks the AP2 Verifiable Intent draft.
Mandate scope analysis is a research vertical of its own.
Shippedv0 · open sourceahead of estimateTamper-evident audit trails for AI agents. Every action is signed and hash-chained, so any tamper is detected and located.
The provenance layer: evidence packs that survive a dispute.
Shippedv0 · open sourceahead of estimateA read-only scan of the public MCP server ecosystem. ~2,400 servers catalogued; roughly 1,200 genuinely evaluable.
The data engine behind the State of MCP reports. A scored security registry is in build on top of it.
Shippedv0 · open sourcePer-task budget, loop detection, and kill-switch middleware for any LLM call. Deterministic, dependency-free, fail-closed.
Anonymised production data feeds the State of Agent Commerce report.
Shippedv0 · open sourceahead of estimatePortable, signed, resolvable agent identity (did:key + did:web) with the cross-walk onto DID, FIDO, AP2, and EUDI. Reputation as verifiable claims.
Powers the State of Agent Identity report and the cross-walk between DID, FIDO, and EUDI. Hosted registry + paid write tier to follow.
Shippedv0 · open sourceahead of estimateGoverned, portable agent memory. Signed, scoped, content-addressed records that verify standalone, so a memory moves between agents with its provenance attached.
Fills the portable-agent-memory gap: a schema and verifier, not a database. The fifth question, after who, may, spends, and did.
Shippedv0 · open sourceahead of estimateSee which answer engines cite your URLs across ChatGPT, Claude, Perplexity, and Gemini. Read-only, bring-your-own-keys.
Powers quarterly citation studies on how AI search rewrites discovery.
Shippedv0 · open sourceahead of estimate
The suite, composed
Five primitives, each open source and useful alone. Together they are a governance layer for an AI agent: identity establishes trust, the mandate bounds authority, the budget bounds spend, the witness makes all of it auditable, and memory travels with the agent, signed.
Signed, resolvable agent identity.
Scoped, signed permission to act.
Per-task budget and kill switch.
Tamper-evident audit trail.
Portable, signed agent memory.
pip install identitykit mandatekit budget-guard-agents witnesskit rememberkit npm install identitykit mandatekit budget-guard-agents witnesskit rememberkit
Live on PyPI and npm. v0, experimental, unaudited; each repo's SECURITY.md says exactly what is and is not guaranteed.
One governed step
The reference integration wires all five into one agent. Every action passes through the same loop: budget before the call, mandate if it spends, execute, then witness, with what it learned carried in signed memory.
guard.check(task, signature=action) # SPEND · fail closed
verdict = mandate.verify(txn, trusted_keys=[key]) # MAY · scoped + signed
if verdict["decision"] != "allow":
trail.append(f"{action}:denied", {...}) # DID · record the denial
return
guard.record(task, signature=action) # SPEND · real usage
trail.append(action, payload) # DID · witness itAn out-of-scope purchase is denied and recorded; the audit trail verifies and any tamper is caught. Identity. Mandate. Budget. Witness. Memory. One agent, fully governed.