major labs
Independent research · agentic web infrastructure

The forward indicator
for the agentic web.

Operators are already deploying agentic systems that solve real problems in production. Payments, underwriting, support, fulfilment, code. We track that activity in real time and publish what it tells us about the next six to twelve months before the rest of the market reads the signal.

Quarterly State of reports from primary data. Open-source SDKs and hosted services that collect it. No vendor alignment. No fundraising. No advisory work for hire.

Today's signals · tomorrow's market

Six data points we are tracking in real time. Each one is a current reading that the next twelve months will reprice. The state of an emerging stack always looks like a footnote until it looks inevitable.

165M+ / month
x402 micropayments

Agent-to-API and agent-to-agent transactions cleared on the protocol. Average ticket: 31 cents. The volume curve is six months ahead of the discourse.

x402 Foundation, May 2026

5,800+
Public MCP servers

Independent endpoints exposing tools to agents. No quality signal between them today. The procurement criteria are forming now in private.

Major Labs scan, May 2026

36.7%
MCP servers with SSRF

Basic server-side request forgery in production endpoints. By Q1 2027 this becomes a blocked-merchant problem. Right now it is a footnote.

Major Labs scan, May 2026

$443B / year
Lost to false declines

Thirteen times the cost of actual fraud. The payments layer has not adapted to agent-initiated transactions. The next 12 months reprices.

Aite-Novarica via Nuvei, 2025

60+ orgs
In the AP2 coalition

Google donated AP2 to FIDO in April 2026. Mastercard co-developed. By Q3 2027 the SDK that wins this becomes the agent identity default.

FIDO Alliance, April 2026

12%
Citation overlap

ChatGPT cites a different web than Google ranks. AI Overviews absorb a third of consumer queries. Discovery has already been rewritten; the SEO industry has not finished noticing.

Major Labs query study, May 2026

Numbers refreshed quarterly with each State of report. The reads on what each one implies for the next six to twelve months are published alongside.

Original research, six to twelve months early

Three quarterly State of reports per year. Original primary data collected by Major Labs. Each report calls what becomes obvious in the next two to four quarters before the rest of the market reads the same signal. Methodology open by default.

  • State of MCP Security

    First scan of all 5,800+ public MCP servers. The procurement criteria for 2027 are being decided privately right now. The report puts them on a page.

    Q3 2026
    In progress
  • State of Agent Commerce

    Anonymised production data from BudgetGuard and partner platforms. Per-task spend, loop incidence, kill-switch frequency, refund patterns. The reads that get cited in the 2027 enterprise pricing conversations.

    Q4 2026
    Planned
  • State of Agent Identity

    Cross-walk between W3C DIDs, FIDO Agentic Auth, and EUDI Wallet implementations across 100+ deployments. First independent read on which standard wins.

    Q1 2027
    Planned

Where this research comes from

Major Labs is not a fresh-start project. It is the empirical extension of an analytical body of work already in progress.

Editorial research

Major Matters

240+ articles on payments, AI, and commerce published since 2024. Editorial analysis written for executives at banks, networks, and payments firms. The analytical layer.

majormatters.co
Empirical research

Major Labs

Original data collected by the products we ship. Scan results, transaction patterns, citation studies. Written for developers and product teams building on the agentic stack.

You are here.

Same operator, different methods. Major Matters maps the terrain. Major Labs measures it. Both are independent of any payments network or AI lab, and both publish their working in public.

When a Major Labs State of report cites a specific framework, that framework was usually developed first at Major Matters and tested against real news cycles. The MM Trust Layer Model, the MM Liability Gap, and the agentic commerce stack maps are all available to read in full and to cite. They form the analytical backbone the empirical research builds on.

The bet

Operators are already shipping agentic solutions to real problems. The x402 protocol cleared 165 million payments last month at 31 cents average ticket. ChatGPT is taking 4 percent on Etsy purchases. TD Bank deployed an agent into its mortgage and HELOC application workflow. Alipay shipped the world's first AI Wallet plus Token Pay protocol across 80 million merchants. None of this is a forecast. It is what cleared this week.

The discourse is six to twelve months behind the deployment.

Gartner has not named the category. The major analysts are pricing reports for next year. The foundation labs publish around their own product strategy. The big platforms ship the rails and stay quiet about what breaks. The long tail of operators is moving without a public read on which servers will be procurement-blocked, which mandate scopes will be standardized, which protocols will clear a trillion dollars.

We measure that activity today and publish the read on tomorrow.

Major Labs is the forward indicator for agentic web infrastructure. We scan production endpoints, track standards as they harden, and catch the patterns that will be obvious in twelve months but are still illegible today. Subscribers get the early read on the systems that ship next.

We do not raise money. We do not sell to vendors. We do not write decks for hire. The reports are the product. The tools are how we collect the data that becomes the next report.

The Bench

Five named agents. Each one has a role on the research operation. Open-source where possible, hosted where it scales.

The Bench is what reads the agentic web for us. The products are how the readings reach the buyers.

01Sentinel
Continuous scanner of the agentic web

Pulls new MCP servers as they get listed, watches AP2 spec drafts, tracks x402 volume, monitors operator telemetry. The daily feed and the input to every other agent on the Bench.

Ships asOpen-source scanner core + hosted dashboard
StatusIn build · Q3 2026
02Scout
Adversarial red-team

Actively probes production systems with prompt injections, mandate-scope abuse, velocity-spreading, device spoofs. Catches new attack vectors before adversaries deploy them.

Ships asOpen-source attack vector library + commercial pen-test API
StatusPlanned · Q4 2026
03Verifier
Mandate and scope checker

Specialized small model (3-7B param). Takes an AP2 Verifiable Intent plus a transaction, returns scope-match score, intent-basket alignment, audit log entry. This is the model we ship.

Ships asOpen-weight model + Python/TS SDK + hosted API
StatusIn build · Q4 2026
04Cartographer
Standards tracker

Watches FIDO, W3C, IETF, EU AI Act, and merchant-side spec drafts. Maps how protocols harden into category-defining standards. Surfaces adoption signal before it shows up in Gartner.

Ships asOpen data set + visual map at majorlabs.co/atlas
StatusPlanned · Q1 2027
05Curator
Research drafting agent

Synthesizes Sentinel, Scout, Verifier, and Cartographer output into first-draft weekly essays, quarterly State of report bullets, and anomaly flags worth essay-length treatment.

Ships asInternal first; hosted Research Assistant tier for power subscribers later
StatusIn build · Q3 2026
Why a suite, not a single agent

Each agent owns its scope, its open-source release, and its citations. Subscribers and operators can adopt individual agents without buying the whole stack. The State of reports name which agent caught which signal. Attribution is sharper, and the Bench compounds faster than a single black-box system ever could.

What we are building

Each product is a research instrument and a commercial product at the same time. The scan produces the report. The report produces the brand. The brand produces the buyers.

  • AEO Citation Tracker

    See which LLMs cite your URLs across ChatGPT, Claude, Perplexity, and Gemini.

    Powers quarterly citation studies on how AI search rewrites discovery.

    Q3 2026
    In build
  • MCP Quality Registry

    Independent security, maintenance, and performance scores for all 5,800+ public MCP servers.

    Source data for the State of MCP Security report.

    Q3 2026
    In build
  • BudgetGuard

    Per-task budget, loop detection, and kill switch middleware for any LLM call.

    Anonymised production data feeds the State of Agent Commerce report.

    Q4 2026
    Planned
  • MandateKit

    AP2 Verifiable Intent SDK. Natural-language agent constraints become signed mandates.

    Mandate scope analysis becomes a research vertical of its own.

    Q4 2026
    Planned
  • Major Labs Identity

    Portable agent identity and reputation registry. Free read API, paid write tier.

    Powers the State of Agent Identity report and the cross-walk between DID, FIDO, and EUDI standards.

    Q1 2027
    Planned

Essays

  • 2026-06-23
    Inside the provenance layer

    August 2 reprices provenance when the EU AI Act enforces. What ships, what's missing, the audit-ready disclosure receipt, and why we publish about provenance but don't ship into it yet.

  • 2026-06-19
    Inside the observability layer

    Helicone went into maintenance mode. That is a category signal, not a company signal. Per-customer attribution at scale, the audit trace standard, and what BudgetGuard does that observability cannot.

  • 2026-06-16
    Inside the commerce layer

    Mandate scope verification, the refund and dispute void, audit trails that survive a processor inquiry, and what MandateKit and BudgetGuard actually do.

  • 2026-06-12
    Inside the discovery layer

    The MCP scan methodology, the five vulnerability categories, what AEO measures that GSC cannot, and the pricing economics that favor an independent operator.

  • 2026-06-09
    The five layers, mapped

    Identity, commerce, observability, provenance, discovery. Three close in twelve months. Two are deeper plays. Which gap closes first.

  • 2026-06-05
    Infrastructure for the agentic web

    Operators are already shipping. The independent measurement layer is missing. The thesis behind Major Labs in 1,800 words.

Get the weekly essay

Two essays a week on agentic-web infrastructure. Quarterly State of reports. No marketing, no fluff.