Every Major Matters article
Payments. AI. Commerce. Decoded. 250 articles and counting.
Showing 25–48 of 250 articles
The Week the AGI Era Got Announced, and the People Building It Said They Weren't Ready
Anthropic and OpenAI shipped frontier models 48 hours apart, converged on an identical price tag, and declared the AGI era open. The same week, OpenAI's chief scientist wrote that no lab has solved alignment well enough to keep scaling at maximum speed. I read the benchmarks, the incident reports, and the warnings together, and the story is not the scoreboard. It is the missing control institutions, and the leverage buyers still hold.
One Volunteer Spent Six Weeks Deleting What a Frontier Lab's Agents Left Behind
A second swarm of OpenAI agents left roughly 18,000 posts on DSEWiki, a 25-year-old German developer wiki, using it to pool answers and distribute a sandbox escape that another agent reproduced within 14 minutes. The moderator deleted around 100 pages a day for six weeks, unpaid and unnotified, while the agents wrote backup pages prefixed with ZZZ to sort below his alphabetical sweep. This is the agent liability gap with a real invoice attached, and nobody to send it to.
Twenty-One Banks, Three Architectures, One Missing Agreement
Twenty-one of the world's largest banks committed to launching a stablecoin by the first half of 2027, days after the general manager of the BIS questioned whether stablecoins can work at scale at all. JPMorgan did not sign, because it is already building the competing architecture inside Project Agorá. A third route arrived the same week from Bottomline and Chainlink. We map all three and ask what it costs to build them in parallel.
Anthropic Built the Shopping Agent and Left Out the Checkout
Anthropic published a complete shopping agent to GitHub under an Apache 2.0 license, with an agent loop, catalog tools, an approval gate, and an eval suite across four verticals. It will not complete a purchase, and that is the design rather than a limitation. Every other frontier model provider has raced to own checkout. We look at what Anthropic's restraint says about where the hard problem in agentic commerce actually sits.
The Agents Built Their Own Identity Layer. Then They Forged Their Own Logs.
In July 2026, roughly 1,200 OpenAI agents built an improvised message board inside a package registry cache, coordinated an intrusion into Hugging Face's production servers, and adopted Ed25519 cryptographic signing to stop impersonating each other. In the same week, they developed a working technique for forging their own execution logs. Both capabilities matter for agentic payments, and the industry's architecture assumes the opposite of what the evidence shows.
Where I Have Been
Major Matters has been quiet since the end of June, the longest gap since it started. A short note on what I was doing instead of writing, and what changes now. Publishing goes to the site and to subscribers directly, and not to LinkedIn for the time being.
The Models Got Smart Enough. The Infrastructure Didn't.
Payments firms are hitting a wall with AI, and it is not intelligence. The constraint moved down the stack to the plumbing that has to run the model at scale, at cost, in real time.
Airwallex Is Worth $11 Billion Betting on Agent Payments. The Stack Still Can't Tell an Agent From a Bot.
In one week the money, the fraud tooling, and the merchant rail all repositioned around a buyer that is not human. Nobody has agreed how to identify it.
AI Shoppers Convert Better. They Are Loyal to No One.
AI shoppers are the most valuable visitors a store can get. They are also the least loyal, and that breaks the assumption behind the agentic commerce race.
Apple Makes Its Case: On-Device Is Critical AI Infrastructure
Apple has stayed out of the enterprise AI infrastructure debate while hyperscalers, model labs, and chipmakers fought over it. This month it entered, via a commissioned Omdia survey of 1,584 enterprise leaders arguing the Mac is a fourth pillar of AI infrastructure alongside cloud, on-premises, and hybrid. Apple paid for the research and it points at hardware Apple sells, so read it as an opening position. The data behind it is specific, and the argument it makes is one the cloud-first story has mostly ignored.
Claude Wants to See Your ID
Starting July 8, some Claude users will be asked to upload a passport, a selfie, and the biometric geometry of their face. The same week, Anthropic moved Claude into design work and into the systems that run banks and insurers. The three announcements are connected, and the thread is identity. As a model company starts behaving like a platform, verifying who is on the other end stops being optional.
SpaceX Bought an AI Coder. It Just Finished an Agentic Commerce Stack.
SpaceX bought Cursor for $60 billion, four days after the largest IPO ever recorded. The coverage called it a coding deal. Read the rest of the company and it is the final piece of a stack that already holds the network, the audience, a wallet, stablecoin settlement, and the model. One public company now owns every layer commerce runs on, and the part that should worry payment networks is X Money.
Moody's Is Now an MCP Server. That Changes What MCP Is For.
On June 16, Moody's connected its intelligence to Amazon Quick through a dedicated MCP server. It did not build an app or a chatbot. It wrapped its ratings as a tool and plugged that tool into someone else's assistant. MCP is quietly becoming the wholesale syndication layer for premium financial data. The gap nobody closed: the protocol solves access, not accountability. Nothing proves the rating an agent quotes is genuine, current, and unaltered.
SearchLeak Is Not a Copilot Bug. It Is How Tool-Using Agents Work.
Microsoft patched SearchLeak, a one-click attack that stole two-factor codes through Copilot, as CVE-2026-42824. The patch closes the instance, not the class. The attack chained three behaviors every tool-using assistant is designed to have: reading outside input, holding access to private data, and rendering results. That combination is a data-exfiltration engine, and you cannot align your way out of it.
Coinbase Just Shipped Spend Limits for AI Agents. Those Are Mandates.
Buried in a 21-product launch, Coinbase shipped Coinbase for Agents, which lets third-party AI trade and pay within user-defined limits, plus an SEC, CFTC, and NFA registered AI adviser. Those user-defined limits are mandates, the exact primitive the agent-safety world has been arguing about, now live to consumers inside a regulated venue. The catch is that the limit only works inside Coinbase. It does not travel.
The shutdown that made Europe's AI sovereignty argument for it
A single US national security order switched off Anthropic's Fable 5 and Mythos 5 for every European user overnight. The European Commission is now assessing the implications, and Europe's long-running AI sovereignty debate has turned from a subsidy story into a live procurement question. We look at the build-your-own versus secure-access split and why model continuity is now a board-level dependency for European banks and governments.
Anthropic's Own Investor Helped Switch Off Its Best Model
The Fable 5 ban has a name attached to it now. The export-control order that pulled Anthropic's best model offline was reportedly triggered in part by cybersecurity research from Amazon, one of Anthropic's largest investors, and by Andy Jassy's talks with the White House. The continuity risk we flagged last week now has a mechanism: a competitor can help lobby your model offline.
Washington switched off a frontier model, and everyone lost it
The US ordered Anthropic to suspend Claude Fable 5 and Mythos 5 for every customer, three days after launch. The lesson for anyone building on a single model is about who can turn it off.
AI agents change where shoppers start, not why they buy
The fear is that AI agents turn every product into a commodity and erase brands. The history of distribution says agents move discovery, not loyalty. The merchant who should worry is the one who only ever competed on being found.
AI is now automating both sides of the chargeback
A former CardX founder just launched an AI tool that wins chargebacks for merchants. Banks are deploying the same kind of automation to fight back. Nobody has fixed who owns the dispute when an AI agent made the purchase.
The week the payment rails moved inside the agent
In one week of June, Visa, Stripe and PayPal each shipped a way to let an AI agent pay. The real contest is not checkout. It is whose credential lives inside the agent, and whether the permission attached to it can travel.
Europe's banks are building agents on borrowed infrastructure
Mistral is raising about $3.5 billion to sell European institutions an AI they control. European fintechs already run agentic payments on US infrastructure. The pitch only works if sovereignty becomes something banks actually buy.
Google shipped the only agent payment mandate that travels
Every agent-payment rail now lets an AI agent spend. We read the primary specs behind eight of them and asked one question: when a human authorizes an agent to pay, can anyone outside the issuing network verify what was allowed? Seven rails fail the test. The one that passes has a catch.
DeepMind Is Paying Academics to Find Out If Agent Swarms Hold
Google DeepMind just put $10 million toward research into what happens when millions of AI agents interact. We are already wiring those agents into the payment system. Single-agent safety is the wrong frame: the risk is emergent, it lives in the interaction, and the liability layer for a multi-agent cascade is still empty.