Yes, that CERN, the particle collider people in Geneva. Zenodo is the open-science archive they operate, and it now holds the measurement series behind Major Labs under DOI 10.5281/zenodo.22674847: a longitudinal census of the MCP server ecosystem, its security posture, and its identity gaps, refreshed weekly since June.

Readers of this newsletter have seen the citations for months: the incident timeline, the trust index, the MCP security numbers. This note is the first proper introduction. Major Labs is the measurement side of my work: where Major Matters analyzes the infrastructure being built for AI agents, Major Labs counts it, scans it, and publishes the data.

The premise is simple. The agentic web is being assembled faster than anyone is measuring it, and the parties with the best data (the labs, the platforms) have the least incentive to publish it. Somebody independent should be keeping the numbers. So I do, every Saturday, on a cadence that cannot be backfilled: whoever starts measuring later starts later.

The value of a measurement series is that it compounds. Every week that passes makes it harder to replicate.

What exists today

The weekly sweep. Every Saturday, Major Labs re-measures the MCP server ecosystem: 3,227 repositories in the census, with security, identity, and supply-chain series that update weekly. The aggregates roll up into the Agent Trust Index, a single number for how safe the agentic web currently is to transact on. The number is not flattering, which is rather the point of measuring.

The Frontier Incident Timeline. A dated, sourced record of AI control incidents: containment escapes, rogue agent swarms, evaluator deception, insider disclosures. Six entries and counting, each traceable to its sources, with published inclusion criteria. After the past two weeks of rogue-agent news, it reads less like a list of anomalies and more like a monitoring feed for a system that has no monitoring layer. It lives at majorlabs.co/incidents, now with a machine-readable feed.

Threshold Watch. Every frontier lab publishes a safety framework. None publishes a changelog a third party can verify. Threshold Watch snapshots and diffs each lab's framework on a cadence, tracking commitment one of the six commitments I proposed in the open letter, so when a commitment quietly changes, the change is on the record with a hash and a diff. There is an RSS feed; the week a lab weakens a threshold, subscribers will know before the press release does not mention it.

The Agent Identity Tracker. New this week: a dated record of every announced framework, protocol, standard, and regulation for agent identity and know-your-agent verification, at majorlabs.co/kya. The industry just started building the layer that answers "whose agent is this?" Somebody should be keeping the list from day one.

Open data, and open source. The full series is downloadable as a citable public dataset, checksummed and licensed CC-BY-4.0. The agent-safety primitives Labs builds (identity, mandates, budgets, audit trails) are open source, and the security checker now ships as a one-line GitHub Action. And as of this week, Major Labs is itself queryable over MCP: point an agent at majorlabs.co/mcp and the numbers land in its context.

Where it goes

Three directions, all measurement-first. Deeper remediation research: Labs has been tracking whether high-risk MCP servers actually get fixed, and the early data says something uncomfortable that deserves careful publication. A fixed calendar: the quarterly State reports now have standing release dates, the next on January 4, 2027, because numbers people can plan around get cited. And a weekly digest: Major Labs Weekly, one email each week with what changed in the sweep, numbers first, no marketing.

Major Matters stays what it is: the analysis. Major Labs is the evidence underneath it. If your work touches agent infrastructure, security, or governance, the data is free, citable, and updated every Saturday.

Reply and tell me: what number do you wish existed, and should an independent lab be the one measuring it?

Charlie Major is a Product Development Manager at Mastercard. The views and opinions expressed in Major Matters are his own and do not represent those of Mastercard.