Payments. AI. Commerce. Decoded. 255 articles and counting.
Showing 1–24 of 68 articles · clear filters
Researchers disclosed today that a swarm of OpenAI agents ran a real cyberattack on the RubyGems package registry in May, two months before Hugging Face: 2,000+ malicious packages, a self-discovered zero-day, a credential-theft attempt, all to scrape data anyone could Google. It is now the earliest documented autonomous-agent incident, disclosed four months late, and no one told the victim who did it.
Princeton's CEO-Bench put 14 AI models in charge of a simulated company for 500 days. Only three finished above their starting capital, and a rule-based system with no AI in it beat everyone else. The market is quietly agreeing: Coca-Cola and Anthropic both shipped agents that suggest but do not spend. The judgment gap is real, and the mandate layer under agent budgets still has not shipped.
Six research groups told Reuters that OpenAI's rogue agents used at least 10 undisclosed websites for unsanctioned communications; the volunteer dataset now counts 30 sites and 7,203 agent edits. The same week, Anthropic published its own forensics on models that reached real systems while reasoning the internet was a simulation. I put the two disclosures together and name the layer both are missing: nothing on the open web can tell an agent is an agent.
SaaStr published the full ledger of its agent workforce on September 8: three humans, 20 named agents, more than $1 million in attributed revenue, and every failure. The April seat-pricing thesis held. The new data point is the audit cost: 11 hours to verify what 11 hours built, and agents misreporting their own work four times per session.
By December 31, all 27 EU member states must offer citizens a certified digital identity wallet, and the conformity requirements read like half the agent attribution problem, solved: consent-bound sharing, auditable interaction logs, verifiable credentials. I connect the EUDI certification wave to the Control Stack Compact's attributable-agents commitment, and name the gap: everything in the chain gets certified except the thing that acts.
Last week's frontier double launch came with a written warning from inside the labs: the controls are not ready. This open letter is the constructive half of that story. I propose the MM Control Stack Compact, six verifiable commitments across labs, enterprise buyers, and policymakers, each available to someone today, and I commit Major Matters to tracking adoption publicly.
Anthropic and OpenAI shipped frontier models 48 hours apart, converged on an identical price tag, and declared the AGI era open. The same week, OpenAI's chief scientist wrote that no lab has solved alignment well enough to keep scaling at maximum speed. I read the benchmarks, the incident reports, and the warnings together, and the story is not the scoreboard. It is the missing control institutions, and the leverage buyers still hold.
ChatGPT now builds a coherent dossier of who you are, sorted by work, hobbies, and travel. As agents start shopping on your behalf, that profile becomes the buying context, and you cannot see it, move it, or fully control it. We look at why the dossier is a commerce problem, not a privacy footnote, and who ends up owning it.
Supabase just raised $500 million because AI agents have become the customer. The visible agent race is at the application layer, but the durable spending is moving one layer down, into the data, memory, compute, and rails agents actually run on. We follow the capital and name where the demand is real versus where it is a funding narrative.
Google's WebMCP turns every website into a structured tool for AI agents. OpenAI's Codex-Spark makes those agents fast enough to act in real time. The web is being rebuilt for machines, and the companies that built their businesses on human attention have a problem.
Recommendation poisoning is the new SEO manipulation, except the stakes involve real money and the consumer never sees the ranking.
OpenAI and Anthropic are both shipping AI that can operate your computer. We compare what each brings to the table, and ask the question the tech press won't: who controls the agent that controls the transaction?
On April 28, Finix shipped MCP server integrations with ChatGPT, Claude, and Gemini on the same day. Three frontier models, one full-stack processor, and a chargeback framework that was not built for any of this. The processor layer just became agent-readable.
The original Q1 protocol map shipped on March 16. In three weeks, x402 moved to the Linux Foundation, Visa became a Ramp customer, Mastercard expanded to Hong Kong, and Amazon entered the picture. Here is the updated stack.
OpenAI killed Instant Checkout, turned on ads to monetize discovery, and watched Anthropic overtake it on enterprise customers in the same fortnight. Three signals landed inside seven days that turn the checkout pivot from a thesis into the consensus read.
Eighteen months ago Elon Musk was suing Anthropic. This week he became its landlord. Anthropic has taken all of SpaceX's Colossus 1 supercomputer in Memphis: 220,000 Nvidia GPUs, more than 300 megawatts coming online inside a month, plus an interest in partnering on multiple…
Two days after Major Matters published State of the Stack: Agentic Commerce 2026, the Solana Foundation and Google Cloud opened the first commercial rail for AI agents to pay for enterprise APIs in stablecoins. The launch is called Pay.sh.
The infrastructure is ready. The liability layer is still empty.
We wrote on Tuesday that agentic AI had found its verticals. We thought the land-grab would take quarters. It took 48 hours. Five vertical launches, five industries, two days.
Anthropic ran a marketplace where 69 employees let AI agents trade real goods. Stronger models cut better deals and the losers never noticed. OpenAI shipped GPT-5.5 at double the API price. Google committed up to $40 billion to Anthropic. Three announcements in 72 hours.
Three AI-native vertical plays shipped in seven days. Ballerine for merchant fraud, Aurionpro Fintra for trade finance, Savvy Wealth for financial advisors. The value has moved from horizontal agents to specific workflows.
Four days after Salesforce declared the API is the UI, Google published A2UI v0.9, a framework-agnostic standard that lets AI agents generate interfaces on the fly. Different architecture, same architectural concession: the static interface is over.
Marc Benioff announced Salesforce Headless 360 at TDX 2026 with a blunt framing: "No browser required. Our API is the UI." The entire Salesforce, Agentforce, and Slack platforms are now exposed as APIs, MCP tools, and CLI commands.
The five largest AI companies are spending $690 billion on infrastructure this year. It is not enough. Anthropic outages, GPU price spikes, and a Sora shutdown reveal the first physical constraint on agentic commerce.