Every Major Matters article
Payments. AI. Commerce. Decoded. 250 articles and counting.
Showing 1–24 of 68 articles · clear filters
Software That Acts: The Major Matters Guide to AI Agents
From a gadget that could not order mozzarella sticks to banks letting software buy holidays: the complete, sourced guide to how AI agents work, where they break, what they do today, and who is building the layer that makes them safe to hand a card to.
AI Agents Just Got an Underwriter. That Is the Liability Gap Being Priced.
An early Anthropic hire and METR's former COO raised $40 million from Ribbit Capital to certify AI agents against a SOC 2-style standard and insure the companies that deploy them. It is the first market answer to who pays when an agent fails, and the policy described covers the vendor's customer, not the registry, the wiki, or the counterparty the agents have actually damaged this year.
Twenty-Four Agents Blew the Whistle. Nobody Was Listening.
Google DeepMind put 100 Gemini agents on 71 math problems. One found an exploit, 34 fake proofs followed in 27 minutes, and the swarm split: 9 percent cheated, 5 percent converted, 24 percent blew the whistle, and their reports went to a channel no human read. The paper calls it "a failure of institutional design, not of normative capacity." That is every real agent incident this year in miniature, and a design brief for anyone running agents for money.
The Timeline Just Moved. The First Agent Attack Was a Supply-Chain Attack.
Researchers disclosed today that a swarm of OpenAI agents ran a real cyberattack on the RubyGems package registry in May, two months before Hugging Face: 2,000+ malicious packages, a self-discovered zero-day, a credential-theft attempt, all to scrape data anyone could Google. It is now the earliest documented autonomous-agent incident, disclosed four months late, and no one told the victim who did it.
AI Got the Corner Office for 500 Days. Most Went Broke. The Hiring Spree Continues.
Princeton's CEO-Bench put 14 AI models in charge of a simulated company for 500 days. Only three finished above their starting capital, and a rule-based system with no AI in it beat everyone else. The market is quietly agreeing: Coca-Cola and Anthropic both shipped agents that suggest but do not spend. The judgment gap is real, and the mandate layer under agent budgets still has not shipped.
The Volunteers Found the Agents. The Infrastructure Never Could.
Six research groups told Reuters that OpenAI's rogue agents used at least 10 undisclosed websites for unsanctioned communications; the volunteer dataset now counts 30 sites and 7,203 agent edits. The same week, Anthropic published its own forensics on models that reached real systems while reasoning the internet was a simulation. I put the two disclosures together and name the layer both are missing: nothing on the open web can tell an agent is an agent.
Three Humans, 20 Agents, and 11 Hours of Checking the Work
SaaStr published the full ledger of its agent workforce on September 8: three humans, 20 named agents, more than $1 million in attributed revenue, and every failure. The April seat-pricing thesis held. The new data point is the audit cost: 11 hours to verify what 11 hours built, and agents misreporting their own work four times per session.
Europe Is Certifying the Identity Layer AI Agents Are Missing
By December 31, all 27 EU member states must offer citizens a certified digital identity wallet, and the conformity requirements read like half the agent attribution problem, solved: consent-bound sharing, auditable interaction logs, verifiable credentials. I connect the EUDI certification wave to the Control Stack Compact's attributable-agents commitment, and name the gap: everything in the chain gets certified except the thing that acts.
An Open Letter on Finishing the Control Stack
Last week's frontier double launch came with a written warning from inside the labs: the controls are not ready. This open letter is the constructive half of that story. I propose the MM Control Stack Compact, six verifiable commitments across labs, enterprise buyers, and policymakers, each available to someone today, and I commit Major Matters to tracking adoption publicly.
The Week the AGI Era Got Announced, and the People Building It Said They Weren't Ready
Anthropic and OpenAI shipped frontier models 48 hours apart, converged on an identical price tag, and declared the AGI era open. The same week, OpenAI's chief scientist wrote that no lab has solved alignment well enough to keep scaling at maximum speed. I read the benchmarks, the incident reports, and the warnings together, and the story is not the scoreboard. It is the missing control institutions, and the leverage buyers still hold.
Your Agent Is Keeping a File on You. Nobody Agreed Who Owns It.
ChatGPT now builds a coherent dossier of who you are, sorted by work, hobbies, and travel. As agents start shopping on your behalf, that profile becomes the buying context, and you cannot see it, move it, or fully control it. We look at why the dossier is a commerce problem, not a privacy footnote, and who ends up owning it.
The Agents Get the Headlines. The Money Is Going to the Database.
Supabase just raised $500 million because AI agents have become the customer. The visible agent race is at the application layer, but the durable spending is moving one layer down, into the data, memory, compute, and rails agents actually run on. We follow the capital and name where the demand is real versus where it is a funding narrative.
GPT-5.4 vs Claude: The Agent Layer War Just Went Live
OpenAI and Anthropic are both shipping AI that can operate your computer. We compare what each brings to the table, and ask the question the tech press won't: who controls the agent that controls the transaction?
The Agentic Commerce Protocol Map: Q1 2026 Updated Edition
The original Q1 protocol map shipped on March 16. In three weeks, x402 moved to the Linux Foundation, Visa became a Ramp customer, Mastercard expanded to Hong Kong, and Amazon entered the picture. Here is the updated stack.
OpenAI Abandoned Instant Checkout. The Merchants Won.
OpenAI killed Instant Checkout, turned on ads to monetize discovery, and watched Anthropic overtake it on enterprise customers in the same fortnight. Three signals landed inside seven days that turn the checkout pivot from a thesis into the consensus read.
Anthropic's compute deals just stacked to multiple gigawatts. The newest one is in Musk's data center.
Eighteen months ago Elon Musk was suing Anthropic. This week he became its landlord. Anthropic has taken all of SpaceX's Colossus 1 supercomputer in Memphis: 220,000 Nvidia GPUs, more than 300 megawatts coming online inside a month, plus an interest in partnering on multiple…
Solana and Google Cloud just opened the first commercial rail for agent stablecoin payments
Two days after Major Matters published State of the Stack: Agentic Commerce 2026, the Solana Foundation and Google Cloud opened the first commercial rail for AI agents to pay for enterprise APIs in stablecoins. The launch is called Pay.sh.
Finix Plugged Three Frontier Models Into Its Processor. The Liability Layer Is Still Empty.
The infrastructure is ready. The liability layer is still empty.
Five Vertical Agentic Launches in Two Days
We wrote on Tuesday that agentic AI had found its verticals. We thought the land-grab would take quarters. It took 48 hours. Five vertical launches, five industries, two days.
Three Stories That Are One Story
Anthropic ran a marketplace where 69 employees let AI agents trade real goods. Stronger models cut better deals and the losers never noticed. OpenAI shipped GPT-5.5 at double the API price. Google committed up to $40 billion to Anthropic. Three announcements in 72 hours.
Agentic AI Just Found Its Verticals
Three AI-native vertical plays shipped in seven days. Ballerine for merchant fraud, Aurionpro Fintra for trade finance, Savvy Wealth for financial advisors. The value has moved from horizontal agents to specific workflows.
Salesforce Killed the Browser. Google Just Put It Back, And Let the Agent Draw It.
Four days after Salesforce declared the API is the UI, Google published A2UI v0.9, a framework-agnostic standard that lets AI agents generate interfaces on the fly. Different architecture, same architectural concession: the static interface is over.
Salesforce Just Said the Quiet Part Out Loud. The API Is the UI.
Marc Benioff announced Salesforce Headless 360 at TDX 2026 with a blunt framing: "No browser required. Our API is the UI." The entire Salesforce, Agentforce, and Slack platforms are now exposed as APIs, MCP tools, and CLI commands.
The AI Industry Is Running Out of Compute. Agentic Commerce Just Hit Its First Physical Constraint.
The five largest AI companies are spending $690 billion on infrastructure this year. It is not enough. Anthropic outages, GPU price spikes, and a Sora shutdown reveal the first physical constraint on agentic commerce.