major labs
Independent research · agentic web infrastructure

The forward indicator
for the agentic web.

Operators are already deploying agentic systems that solve real problems in production. Payments, underwriting, support, fulfilment, code. We track that activity in real time and publish what it tells us about the next six to twelve months before the rest of the market reads the signal.

Quarterly State of reports from primary data, collected by tools and research we publish in the open. No vendor alignment. No fundraising. No advisory work for hire.

Today's signals · tomorrow's market

Six data points we are tracking in real time. Each one is a current reading that the next twelve months will reprice. The state of an emerging stack always looks like a footnote until it looks inevitable.

165M+ / month
x402 micropayments

Agent-to-API and agent-to-agent transactions cleared on the protocol. Average ticket: 31 cents. The volume curve is six months ahead of the discourse.

x402 Foundation, May 2026

~1,200
Functional MCP servers

Not the 10,000-plus commonly cited. We catalogued roughly 2,400 public servers; about half are genuinely evaluable. No quality signal between them today.

Major Labs scan, June 2026

39%
MCP repos with no README

A maintainability signal across the active population. Security probing (SSRF and the rest) is the v1 sweep, not yet run, so we don't publish those numbers as fact yet.

Major Labs scan, June 2026

$443B / year
Lost to false declines

Thirteen times the cost of actual fraud. The payments layer has not adapted to agent-initiated transactions. The next 12 months reprices.

Aite-Novarica via Nuvei, 2025

60+ orgs
In the AP2 coalition

Google donated AP2 to FIDO in April 2026. Mastercard co-developed. By Q3 2027 the SDK that wins this becomes the agent identity default.

FIDO Alliance, April 2026

12%
Citation overlap

ChatGPT cites a different web than Google ranks. AI Overviews absorb a third of consumer queries. Discovery has already been rewritten; the SEO industry has not finished noticing.

Major Labs query study, May 2026

The MCP numbers are live, not quarterly.

We scan the public MCP ecosystem every week and publish the full dataset, methodology, and time series. The figures everyone repeats are inflated; these are the real ones, open for anyone to check.

Explore the open data

The other readings refresh quarterly with each State of report. The reads on what each one implies for the next six to twelve months are published alongside.

Original research, six to twelve months early

Three quarterly State of reports per year. Original primary data collected by Major Labs. Each report calls what becomes obvious in the next two to four quarters before the rest of the market reads the same signal. Methodology open by default.

  • State of MCP Security

    First open scan of the public MCP server ecosystem: ~2,400 catalogued, roughly 1,200 genuinely functional. The procurement criteria for 2027 are being decided privately right now. The report puts them on a page.

    Q3 2026
    In progress
  • State of Agent Commerce

    Anonymised production data from BudgetGuard and partner platforms. Per-task spend, loop incidence, kill-switch frequency, refund patterns. The reads that get cited in the 2027 enterprise pricing conversations.

    Q4 2026
    Planned
  • State of Agent Identity

    Cross-walk between W3C DIDs, FIDO Agentic Auth, and EUDI Wallet implementations across 100+ deployments. First independent read on which standard wins.

    Q1 2027
    Planned

Where this research comes from

Major Labs is not a fresh-start project. It is the empirical extension of an analytical body of work already in progress.

Editorial research

Major Matters

240+ articles on payments, AI, and commerce published since 2024. Editorial analysis written for executives at banks, networks, and payments firms. The analytical layer.

majormatters.co
Empirical research

Major Labs

Original data collected by the products we ship. Scan results, transaction patterns, citation studies. Written for developers and product teams building on the agentic stack.

You are here.

Same operator, different methods. Major Matters maps the terrain. Major Labs measures it. Both are independent of any payments network or AI lab, and both publish their working in public.

When a Major Labs State of report cites a specific framework, that framework was usually developed first at Major Matters and tested against real news cycles. The MM Trust Layer Model, the MM Liability Gap, and the agentic commerce stack maps are all available to read in full and to cite. They form the analytical backbone the empirical research builds on.

The bet

Operators are already shipping agentic solutions to real problems. The x402 protocol cleared 165 million payments last month at 31 cents average ticket. ChatGPT is taking 4 percent on Etsy purchases. TD Bank deployed an agent into its mortgage and HELOC application workflow. Alipay shipped the world's first AI Wallet plus Token Pay protocol across 80 million merchants. None of this is a forecast. It is what cleared this week.

The discourse is six to twelve months behind the deployment.

Gartner has not named the category. The major analysts are pricing reports for next year. The foundation labs publish around their own product strategy. The big platforms ship the rails and stay quiet about what breaks. The long tail of operators is moving without a public read on which servers will be procurement-blocked, which mandate scopes will be standardized, which protocols will clear a trillion dollars.

We measure that activity today and publish the read on tomorrow.

Major Labs is the forward indicator for agentic web infrastructure. We scan production endpoints, track standards as they harden, and catch the patterns that will be obvious in twelve months but are still illegible today. Subscribers get the early read on the systems that ship next.

We do not raise money. We do not sell to vendors. We do not write decks for hire. The reports are the product. The tools are how we collect the data that becomes the next report.

The Bench

Five named agents. Each one has a role on the research operation. Open-source where possible, hosted where it scales.

The Bench is what reads the agentic web for us. The products are how the readings reach the buyers.

01Sentinel
Continuous scanner of the agentic web

Pulls new MCP servers as they get listed, watches AP2 spec drafts, tracks x402 volume, monitors operator telemetry. The daily feed and the input to every other agent on the Bench.

Will shipOpen-source scanner core + hosted dashboard
StatusIn build · Q3 2026
02Scout
Adversarial red-team

Actively probes production systems with prompt injections, mandate-scope abuse, velocity-spreading, device spoofs. Catches new attack vectors before adversaries deploy them.

Will shipOpen-source attack vector library + commercial pen-test API
StatusPlanned · Q4 2026
03Verifier
Mandate and scope checker

Specialized small model (3-7B param). Takes an AP2 Verifiable Intent plus a transaction, returns scope-match score, intent-basket alignment, audit log entry. This is the model we ship.

Will shipOpen-weight model + Python/TS SDK + hosted API
StatusIn build · Q4 2026
04Cartographer
Standards tracker

Watches FIDO, W3C, IETF, EU AI Act, and merchant-side spec drafts. Maps how protocols harden into category-defining standards. Surfaces adoption signal before it shows up in Gartner.

Will shipOpen data set + visual standards map
StatusPlanned · Q1 2027
05Curator
Research drafting agent

Synthesizes Sentinel, Scout, Verifier, and Cartographer output into first-draft weekly essays, quarterly State of report bullets, and anomaly flags worth essay-length treatment.

Will shipInternal first; hosted Research Assistant tier for power subscribers later
StatusIn build · Q3 2026
Why a suite, not a single agent

Each agent owns its scope, its open-source release, and its citations. Subscribers and operators can adopt individual agents without buying the whole stack. The State of reports name which agent caught which signal. Attribution is sharper, and the Bench compounds faster than a single black-box system ever could.

What we are building

Each product is a research instrument and a commercial product at the same time. The scan produces the report. The report produces the brand. Every one is now shipped, the whole roadmap ahead of estimate.

  • Sign and verify what an AI agent is allowed to spend on. Natural-language constraints become signed, checkable mandates. Tracks the AP2 Verifiable Intent draft.

    Mandate scope analysis is a research vertical of its own.

    Shipped
    v0 · open source
    ahead of estimate
  • Tamper-evident audit trails for AI agents. Every action is signed and hash-chained, so any tamper is detected and located.

    The provenance layer: evidence packs that survive a dispute.

    Shipped
    v0 · open source
    ahead of estimate
  • A read-only scan of the public MCP server ecosystem. ~2,400 servers catalogued; roughly 1,200 genuinely evaluable.

    The data engine behind the State of MCP reports. A scored security registry is in build on top of it.

    Shipped
    v0 · open source
  • Per-task budget, loop detection, and kill-switch middleware for any LLM call. Deterministic, dependency-free, fail-closed.

    Anonymised production data feeds the State of Agent Commerce report.

    Shipped
    v0 · open source
    ahead of estimate
  • Portable, signed, resolvable agent identity (did:key + did:web) with the cross-walk onto DID, FIDO, AP2, and EUDI. Reputation as verifiable claims.

    Powers the State of Agent Identity report and the cross-walk between DID, FIDO, and EUDI. Hosted registry + paid write tier to follow.

    Shipped
    v0 · open source
    ahead of estimate
  • Governed, portable agent memory. Signed, scoped, content-addressed records that verify standalone, so a memory moves between agents with its provenance attached.

    Fills the portable-agent-memory gap: a schema and verifier, not a database. The fifth question, after who, may, spends, and did.

    Shipped
    v0 · open source
    ahead of estimate
  • See which answer engines cite your URLs across ChatGPT, Claude, Perplexity, and Gemini. Read-only, bring-your-own-keys.

    Powers quarterly citation studies on how AI search rewrites discovery.

    Shipped
    v0 · open source
    ahead of estimate

The suite, composed

Five primitives, each open source and useful alone. Together they are a governance layer for an AI agent: identity establishes trust, the mandate bounds authority, the budget bounds spend, the witness makes all of it auditable, and memory travels with the agent, signed.

pip install identitykit mandatekit budget-guard-agents witnesskit rememberkit
npm install identitykit mandatekit budget-guard-agents witnesskit rememberkit

Live on PyPI and npm. v0, experimental, unaudited; each repo's SECURITY.md says exactly what is and is not guaranteed.

One governed step

The reference integration wires all five into one agent. Every action passes through the same loop: budget before the call, mandate if it spends, execute, then witness, with what it learned carried in signed memory.

guard.check(task, signature=action)                 # SPEND  · fail closed
verdict = mandate.verify(txn, trusted_keys=[key])   # MAY    · scoped + signed
if verdict["decision"] != "allow":
    trail.append(f"{action}:denied", {...})         # DID    · record the denial
    return
guard.record(task, signature=action)               # SPEND  · real usage
trail.append(action, payload)                      # DID    · witness it

An out-of-scope purchase is denied and recorded; the audit trail verifies and any tamper is caught. Identity. Mandate. Budget. Witness. Memory. One agent, fully governed.

Essays

  • 2026-06-19
    The unsigned memory problem

    An agent's memory is a claim you take on faith. Zero of six leading systems sign memory, zero export it at full fidelity, zero carry portable provenance, three ship regulatory-grade consent. Why memory cannot be a credential until it is signed, portable, and consent-bound.

  • 2026-06-26
    Inside the identity layer

    An agent carries four or five identities and none of them reconcile. The DID/FIDO/EUDI cross-walk, portability across model providers, capability attestation, fast revocation, and why we ship identity last.

  • 2026-06-23
    Inside the provenance layer

    August 2 reprices provenance when the EU AI Act enforces. What ships, what's missing, the audit-ready disclosure receipt, and why we publish about provenance but don't ship into it yet.

  • 2026-06-19
    Inside the observability layer

    Helicone went into maintenance mode. That is a category signal, not a company signal. Per-customer attribution at scale, the audit trace standard, and what BudgetGuard does that observability cannot.

  • 2026-06-16
    Inside the commerce layer

    Mandate scope verification, the refund and dispute void, audit trails that survive a processor inquiry, and what MandateKit and BudgetGuard actually do.

  • 2026-06-12
    Inside the discovery layer

    The MCP scan methodology, the five vulnerability categories, what AEO measures that GSC cannot, and the pricing economics that favor an independent operator.

  • 2026-06-09
    The five layers, mapped

    Identity, commerce, observability, provenance, discovery. Three close in twelve months. Two are deeper plays. Which gap closes first.

  • 2026-06-05
    Infrastructure for the agentic web

    Operators are already shipping. The independent measurement layer is missing. The thesis behind Major Labs in 1,800 words.

Get the weekly essay

New essays regularly on agentic-web infrastructure. Quarterly State of reports. No marketing, no fluff.