Agentic Web News

@ricmac.agenticweb.news.ap.brid.gy

Tracking the agentic web: market signals, interviews & analysis by Richard MacManus 🌉 bridged from ⁂ https://agenticweb.news/, follow @ap.brid.gy to interact

Key trends from the AI Engineer World's Fair, browsers moving inside agents, and fresh WebMCP momentum across commerce and web development.

Browsers in agents, WebMCP momentum, and AI engineering lessons

This week I published 5 Trends That Defined AI Engineering at World’s Fair 2026 on Latent Space. As previously noted, I attended the AI Engineer World's Fair in San Francisco earlier this month — where I learned that the state of the art in AI engineering looks a lot like the state of the art in software engineering. As I put it in my intro: > "The engineering practices that have developed around AI over the past three years — building coding agents, designing harnesses, managing context, evaluating model outputs, and orchestrating increasingly autonomous systems — are becoming part of mainstream software development." Here's a graphical summary of the top 5 trends, but I encourage you to read the whole post if you want to keep up-to-date with AI development trends. ## Agentic Web rising I've noticed in recent weeks that the agentic web as a concept is beginning to increase in popularity, even if it's still relatively niche compared to agentic coding and LLMs. The AI Radar, a tracker for AI use cases created by Janna Lipenkova, now has a definition for agentic web: > "The Agentic Web is an evolving internet phase where AI agents autonomously discover, interpret, and act on websites, transforming traditional human-centric web interactions into machine-mediated, capability-driven engagements." There's also a graph indicating a July spike in attention: Agentic web attention; via AI RadarAre yAre Ar Another new directory service is the Ora directory, from Liad Yosef's new company Ora (Yosef is a co-creator of MCP Apps). The Ora directory is being promoted as the "agentic index of the web" and is built on two emerging open specifications: AI Catalog and Agentic Resource Discovery (ARD). > Ora is now the official implementation of the two pillars of the agentic web: ARD and ai-catalog. > > Introducing https://t.co/wGLMeCHuIr. > > Expose agentic resources from any domain using the ai-catalog standard. > Search any agentic resource on the web with Agentic Resource Discovery. pic.twitter.com/wqGVkMEKBv > > — ora (@oradotai) July 8, 2026 If you're a business wondering how to get started on the agentic web, check out this post by Google's André Bandarra: > "The most pragmatic approach is to prioritize foundational agent-readiness as your baseline. From there, you can layer on bespoke on-page agent capabilities only where the return on investment, in terms of user journey completion or product value, warrants the significant development and maintenance effort." Yet another sign I spotted this week of increased visibility for agentic web: internet legend Vint Cerf, who recently retired from Google, is now advising Innovation Labs, which TechCrunch described as "an organization trying to create the open architecture for AI agents to identify themselves." I'd interviewed Innovation Labs CEO Allie Kline in early June, in an AWN post entitled Who owns that AI agent? DNSid proposes an answer. It's great to see Cerf lending his considerable expertise to this project, which makes me think it now has a good chance of gaining traction. ## Browsers in agents In a post entitled The Agentic Web Summer, agentic commerce startup Nekuda (which I've also interviewed for AWN) makes the case that after OpenAI and Anthropic both put browsers inside their agents, it "makes the website itself part of the agent stack." Nekuda first summarized the news: > "OpenAI is shutting down Atlas, but it is not walking away from the browser. The same capability is moving inside ChatGPT and Codex, and Anthropic went the same way in the same week with a built-in browser inside Claude Code on desktop." ...then posited: > "Most of the web was built for humans and will not be rebuilt for agents anytime soon, so an assistant that wants to do general-purpose work, for consumers or for enterprises, needs the tool humans use to reach all of it." Here's the official Anthropic announcement: > Claude Code on desktop now has an in-app browser. > > Claude can pull up docs, designs, or any other site. It can read, click through, and interact the same way it does with your local dev servers. > > It's sandboxed and configurable: you choose whether sessions persist. pic.twitter.com/Jbc21OP0vJ > > — ClaudeDevs (@ClaudeDevs) July 10, 2026 Nekuda is building on WebMCP, a browser protocol that is currently behind browser flags, so it rightly pointed out "the cleaner path" this protocol provides. Related, Kieran Klaassen from Every has suggested a straw man proposal called Agent Mode, "so in-agent browsers can tell websites who they are, websites can talk back, and you can hand your agent work without leaving the page." Klaassen argues: "Web Bot Auth stops at the server; WebMCP is one-way. Between them sits the gap Agent Mode bridges." Image via Kieran Klaassen. Speaking of agents and websites talking with each other, I want to recommend the new blog of Google's Kasper Kulikowski. It's definitely worth adding to your RSS Reader; this week he wrote up some of his practical experiments using WebMCP and A2A. ## Agentic commerce news A couple of significant agentic commerce news items this week: DoorDash now speaks directly to agents, and Shopify has begun implementing WebMCP. > Today we're opening up the DoorDash CLI in limited beta. > > `dd-cli` lets you order DoorDash directly from your agent: search stores, find the best deals, check out, and more. > > Early access for US/Canadian macOS developers by waitlist. Excited to see what folks build! pic.twitter.com/rSFhjJnvjJ > > — Andy Fang (@andyfang) July 15, 2026 Nekuda on the Shopify implementation of WebMCP: > "Shopify rolled out WebMCP to the storefronts it renders. This was done silently, without any public announcement to date. A small script now ships on Shopify-managed stores and registers callable tools on every page. Agents can search the catalog, pull product details, manage the cart, start checkout, and open order history." Similar to how early dot-com companies like Amazon and eBay pushed the web forward with commerce plays in the 1990s, online shopping companies like DoorDash and Shopify are doing the same for the agentic web. ## Web development news Persona is a brand new JavaScript library that "helps you create agentic front-end experiences for the web, in pure JS." It's positioned as "lightweight, extensible, and WebMCP-native." The library comes from a company called Runtype, a "AI-native product platform." Co-founder Nathan Booker commented on Product Hunt: > "Most AI chat libraries assume you're starting from scratch on React. Persona is built for the rest of the internet: existing sites, mixed frontend stacks, proprietary CMSes, and teams that want a modern AI experience without rebuilding in React." Demo of Persona.js Google Web AI lead Jason Mayes was impressed: > "It’s a stellar contribution to the community, helping developers build smooth, robust, and local human in the loop AI copilots without rewriting their entire frontend stack!" I love that Persona.js uses Vanilla JS, and also the support for WebMCP is another strong signal for websites as capabilities. Finally, while not _web dev_ per se, I thought this news from Parallel was an interesting sign that the agentic web is infiltrating the enterprise now: > Today we're announcing our product integration with @googlecloud for agentic web search on the Gemini Enterprise Agent Platform. pic.twitter.com/F0lovOlGpU > > — Parallel Web Systems (@p0) July 16, 2026 ## Let's get agentic So, another busy week in the ongoing build-out of the agentic web! I'll continue to do weekly wrapups of developments here. Also keep an eye on Latent Space, because I'll be writing many more AI engineering stories on LS going forward. More news on that front soon.

agenticweb.news

Last week I was in San Francisco covering the AI Engineer World's Fair for Latent Space. It was a thrill being on the ground in SF again, and for me it evoked memories of the glory days of Web 2.0.

My week at the AI Engineer World's Fair

Last week I was in San Francisco covering the AI Engineer World's Fair for Latent Space, the blog of AIEWF co-founder swyx. It was a thrill being on the ground in SF again, and for me it evoked memories of the glory days of Web 2.0. The excitement around AI technology, the speed at which it is evolving, the number of startups being built, and (yes) the hunt for revenue and riches — it's all very reminiscent of two decades ago. AIEWF had around 7,000 attendees and was held at the cavernous Moscone West Center in SF, so it reminded me of going to the Web 2.0 Expos in the latter half of the 2000s. I'd also attended the very first AI Engineer conference, back in October 2023, which had only 500 attendees. So it was a big step up for swyx and his event team, similar to the scaling of O'Reilly Media's Web 2.0 conferences. Anthropic engineer Thariq Shihipar on-stage at AIEWF; I'm seated in the front row, diligently reporting on the action. On a personal level, just like in the ReadWriteWeb days whenever I covered conferences, it was an incredibly hectic week of chasing people for interviews, doing the interviews, attending sessions, running between sessions, buying an over-priced salad for lunch (which I took to the media room and ate while I transcribed interviews and did more chasing up), going to more sessions, doing more interviews, seeing people in the hallways and stopping for a chat, and — amid all that — writing up the posts. I remember that being a blur in RWW days, and it was the same at AIEWF 😅 ## My Latent Space posts One thing I didn't do at this event, which I had done during the Web 2.0 conferences, was attend the evening parties. Alas, this time round I spent each evening in my SF hotel toom, frantically finishing up my daily dispatch while eating a cold Uber Eats (no disrespect to the no doubt overworked delivery people, but I wish they wouldn't stop multiple times on the way). On that note, here are all my articles from AIEWF. If you'd like to get a flavour of each day, I recommend reading each of the 3 daily roundups, in order. Daily dispatches: * AIEWF Daily Dispatch 1: Loops, Software Factories & Forward Deployed Engineers * AIEWF Daily Dispatch 2: Autoresearch and the tension between AI and human agency * AIEWF Daily Dispatch 3: The great loops debate and the state of AI engineering Interviews: * Ahmad Osman on why local AI is catching up * Forward Deployed Engineers and the future of software engineering * Warp CEO Zach Lloyd on why software factories are the next phase of coding * How Cursor deploys AI inside the enterprise * Autoresearch: The feedback loop behind self-improving agents * Skill engineering and the case against one-shot AI design * The website of the future may assemble itself for every visitor * Vercel's Andrew Qu on why agents are a new kind of software I loved doing all those interviews. If I had to pick a favorite, it was interviewing Warp's Zach Lloyd on the Expo floor (I met him at the Warp booth, but we had to find a relatively unnoisy spot to talk). I especially enjoyed this interview because I've been tracking Warp since it first started, including an interview in February 2025 while I was at The New Stack. Like many Silicon Valley obsessives, I love a good pivot — and in less than two years, Warp has evolved from a relatively simple CLI tool for engineers into a full-on "software factory" platform. That shift also captured one of the main trends of AIEWF — software factories, which is about managing teams of agents (and humans). I encourage you to read that interview to get a handle on this trend. Warp CEO Zach Lloyd at AIEWF; incidentally, one of my best ideas was taking a photo of each of my interviewees at the event. It helped capture the excitement of the scene. All the folks I interviewed were very passionate about their subject: Sierra's Natalie Meurer and Cursor's Pauline Brunet on Forward Deployed Engineers (such a key trend, especially for enterprise adoption of AI), Introspection co-founder Roland Gavrilescu on autoreasearch, Paul Bakaus on skill engineering, Vercel's Andrew Qu on agent development, Adobe's Carlos Sanchez on agentic websites, and Ahmad Osman on local AI and open source LLMs. I have to add, Ahmad was easily the most passionate engineer I met! My piece on him also made The Daily Context, the daily newspaper produced for AIEWH by the Major League Hacking team — check out their stories on Dev.to. > Btw my interview on Local AI from last week with Latent Space was published on the 2nd page of The Daily Context at AIE pic.twitter.com/nvi7woLkey > > — Ahmad (@TheAhmadOsman) July 7, 2026 ## Agentic Web at AIEWF A quick note on agentic web topics at AIEWF. Most of the content and discussion at the event was (naturally) focused on engineering topics. So there was a lot to talk about in terms of "loops" (_the_ buzzword at the event), harness engineering, coding agents, software factories, autoresearch, LLM advancements (including open models, like Z.ai's GLM-5.2), and similar topics. So in that respect, AIEWF was much more technical than your typical Web 2.0 Summit or Expo back in the 2000s. Then again, another theme was that many of these technologies are being used now by product and business people — the FDE trend highlighted this — and so I felt there was a lot of business interest in AIEWF too. Agents were being advertised on the back of buses in SF; this is big business already. But regarding agentic web specifically, which has been the topic of this newsletter, it was present if you knew where to look. My interviews with Vercel and Adobe highlighted some of the themes I've been exploring here, although it was also clear that Adobe is still at an experimental stage. I'm actually very impressed with where Vercel is at in terms of providing tools and a framework for agentic web development, so I'd recommend reading my interview with Andrew Qu. Other than that, agentic web was present in some of the sessions — for example Liad Yosef and Ido Salomon's MCP Apps session (I'd previously interviewed both for AWN, and they covered similar themes in their session). Liad's new startup Ora, was getting some buzz at AIEWF, which I was pleased to see. > Earlier this week at @aiDotEngineer World's Fair, our CTO, @liadyosef, presented findings from our real agent journeys research. > > As agents increasingly become the interface between people and products, many of the assumptions we've made about agent readiness become irrelevant. pic.twitter.com/Tcs3zisf1p > > — ora (@oradotai) July 4, 2026 ## Watch the devs One learning (or reinforced learning!) from AIEWF that I'm going to apply to my ongoing agentic web research: the developer community is driving almost all of the innovation in AI currently. It's not called the AI _engineer_ conference for nothing. For all the noise around the SEO community and agentic web, which this newsletter has looked at recently, my sense is that there isn't yet a market fit for what I've been terming "agentic web." Partly that's due to the existential issues surrounding the web ecosystem at this time, which I've written about before. But more than that: it's AI engineers that are building the future, not SEO experts. It all comes back to a lesson I had learned even before Web 2.0 took off: it's all about watching carefully what developers are building and then reporting on that. Tim O'Reilly built his whole career and business around that insight, and so did I — on a lesser scale, of course. So I came away from the AI Engineer World's Fair with a determination to (re)focus deeply on what engineers are building and exploring in this new agentic era. Stay tuned for my AIEWF wrapup post, coming very soon on Latent Space. I'll be reviewing the five biggest tech trends I took from the conference.

agenticweb.news

From agent frameworks and MCP integrations to identity governance and open discovery, this week’s market signals show the agent stack rapidly gaining adoption in the enterprise.

Agentic web market signals: the agent stack becomes enterprise infrastructure

This week’s market signals provide further evidence of the agentic web stack evolving into enterprise infrastructure. From Vercel to AWS to Okta to Google, the industry's focus is shifting toward the infrastructure needed to build, connect, govern and discover agents inside real enterprise workflows. This week's signals: * Vercel is bringing agent development into the web development toolchain; * AWS and Adobe show MCP becoming an enterprise integration layer; * Okta is turning agent identity into a governance roadmap; and * Google’s Agentic Resource Discovery (ARD) specification proposes an open discovery layer for tools, skills and agents across the web. ## Sign up for Agentic Web News Tracking the agentic web: market signals, interviews & analysis by Richard MacManus (founder of ReadWriteWeb during Web 2.0). Subscribe free Email sent! Check your inbox to complete your signup. ## Market Signals **📡 Vercel launches eve, an agent framework** This week Vercel unveiled eve, an open source agent framework it likened to Next.js, the React framework released a decade ago by its founder, Guillermo Rauch. Vercel explained in a blog post: > "Agents today are where the web was before frameworks, with everyone hand-rolling the same plumbing and nothing carrying over to the next one. Next.js ended this for the web, and eve is doing the same for agents." Just as Next.js abstracts away much of the infrastructure required to build and deploy web applications, eve aims to do the same for AI agents. The idea is that developers define an agent as a directory containing Markdown instructions, reusable skills and TypeScript tools, and then eve handles execution, approvals and deployment. The Markdown and TypeScript files that make up an eve agent. Vercel has been pivoting to an "agentic infrastructure" company for several months — its homepage now explicitly uses that framing — and this is the latest signal that web dev tooling companies are now all-in on agents. Vercel homepage, June 2026. **📡 AWS + Adobe connect marketing agents via MCP** In a good example of enterprise agentic web, AWS and Adobe have connected Adobe’s Marketing Agent to Amazon Quick via MCP — allowing marketing teams to query campaign performance, audiences and customer journeys through natural language. Although this was announced back in April, a new blog post explains how it works in detail. Quick is part of Amazon's "Agentic AI" suite of tools and is promoted as "an AI assistant for work." Adobe Marketing Agent connects to Amazon Quick and provides marketing-domain context from Adobe systems. Adobe Marketing Agent in action, inside Amazon Quick. What's most interesting in the latest blog post is getting a look at the architecture, summarized in this graphic: Architecture (see full image). Adobe exposes its capabilities as MCP tools, Amazon Quick discovers and orchestrates them, and governance controls determine how agents can invoke them. It shows once again that MCP is evolving from a developer protocol into enterprise integration infrastructure. **📡 Okta publishes agentic AI identity maturity model** Okta, an identity and access management company, has released an "Agentic AI Identity Maturity Model," which argues that AI agents should be treated as first-class identities, much like employees or service accounts. In an accompanying white paper, the company outlines a four-stage roadmap for managing AI agents as they scale across the enterprise, from creating a central registry of every agent to implementing fine-grained permissions, continuous monitoring, and automated governance. The paper also addresses the growing use of MCP, calling for OAuth-based authentication, authenticated proxies, and tool-level authorization. Okta homepage, June 2026. It’s another sign that the agentic internet is moving beyond protocols into the enterprise infrastructure needed to operate agents safely. **📡 Google & others announce an open discovery layer for agents** Google and several industry partners have announced Agentic Resource Discovery (ARD), an open specification for finding and verifying tools, skills, MCP servers and other agents across the web. The aim is to create a discovery layer for the agentic web, where registries act like search engines for machine-callable capabilities. Google explicitly frames it as "the missing layer of the agentic web." ARD architecture. I also liked this framing from R. V. Guha, a Technical Fellow of Microsoft, one of the contributors to the spec. Guha previously created NLWeb, an agentic web protocol released last year that seems to have stalled in momentum. In any case, here's what he said about ARD: > "Discovery is also market making: it lets small publishers be found, lets the agentic capabilities built by the many vendors inside every enterprise be found by that company's own AI assistants, and lets many clients and providers meet in one open ecosystem rather than behind a single gate." Google's original search engine (I'm talking back in the late-90s and into the 2000s) allowed small publishers to be discovered on the web. Those days, alas, are long gone for small publishers. But I hope ARD can help niche publishers get discovered in the agentic era. ## Watchlist 👀 Speaking of the web's future, Automattic's WordPress VIP division has a new online report out, entitled "Future of the Web 2026." One of the statistics: 74% of people surveyed say "the internet feels less human than 10 years ago." That connects back to my blog post at the end of last week, arguing that web professionals shouldn't forget that the web is fundamentally a human network — AI should augment, not replace, people. Automattic also released a white paper entitled Future-Proofing for the AI-Native Web. While much of it is advertorial, there are some useful insights, e.g.: > "...brands should think about how they can deliver a digital experience that goes beyond teaser-length content, says Christoph Khouri, WordPress VIP’s Head of CMS Product and Engineering. “To make that interesting, you obviously offer more information than AI’s response to a prompt,” he says." * * * Thanks for reading **Agentic Web News** — my independent analysis of the companies, standards and ideas shaping the next phase of the web. Alongside weekly market signals, I am publishing interviews with the early builders defining this space. If this issue helped clarify where the agentic web is heading, please forward it to someone who should be tracking this trend. To receive future editions, subscribe by email. It's currently free, but you can also become a founding supporter of AWN, to help it become financially viable. I also advise companies on agentic web strategy, Agent Experience, AI visibility, and agent-facing product strategy. Learn more at ricmac.org.

agenticweb.news

Nekuda is betting that agentic commerce will augment websites, not replace them, with WebMCP providing the bridge between agents and merchant-controlled experiences.

Nekuda's WebMCP bet: Agentic commerce still needs the website

Nekuda is an agentic commerce startup with a refreshing difference: it is betting on websites continuing to flourish, rather than AI chatbots completely taking over the shopping experience. I spoke with founding CEO Ayal Karmi about why the emerging WebMCP open standard underpins its web-based strategy. Before we begin, it's useful to frame the current thinking about the role of a user interface in the agentic web. The following graphic comes from Kelly Goetsch, president of an e-commerce logistics company called Pipe17. It shows the spectrum from headless, to "near-headless," to what Goetsch calls the "co-assisted web": The Agentic Web Spectrum As the term suggests, the "headless web" doesn't require a UI. But the near-headless web does; and in many cases, web technology is used to render that interface — even though it's inside an AI chatbot or agent. As for Nekuda, it's very much in the "co-assisted" segment of this graphic. Karmi told me that he sees AI systems as key to the discovery of products, but that the shopping experience will continue to rely on websites. "The transaction, the checkout and the questions that lead to a purchase are still going to happen on the website," he said. ## The Failed Pizza Experiment Nekuda didn't immediately come to the conclusion that websites are still needed. The startup's initial idea was headless — it wanted to build wallet infrastructure for autonomous shopping agents. That idea was born about two years ago, after the founders created an agent and tried to order a pizza autonomously (mimicking the famous Bitcoin story of an early user paying for a pizza with cryptocurrency). "The agent failed completely," explained Karmi. "The [pizza] website kind of killed us — the bot detection, the fraud detection, we tried to pay. It was kind of a headless bot that tried to order a pizza, scraping the menu and then tried to order it." ## Get more interviews with agentic web builders Join AWN for founder and developer interviews, market signals, and analysis of the emerging agentic web. Sign up for free Email sent! Check your inbox to complete your signup. After that trial, Nekuda built a wallet for browser agents, which they thought would solve the automated payment problem. But it ended up teaching them a different lesson. "The bigger issue here is that website owners basically told us they're afraid of being obfuscated," he said. "And also [...] they want a richer experience. Like, the web is there for a reason. And the website user experience is very important." This is what eventually led Nekuda to WebMCP and a more website-centred vision of agentic commerce. ## Why Nekuda turned to WebMCP WebMCP is an emerging web API and proposed standard that allows websites and web applications to expose structured tools to browser-based agents. It's much more efficient than an agent scraping and trying to automatically traverse a human web interface. As I've noted previously, Google is in the process of baking WebMCP into its Chrome browser (it's currently in an origin trial). If the experiment succeeds and other browsers adopt it, WebMCP could become a standard way for websites to expose interactive capabilities to agents. While it waits for full browser support for WebMCP, Nekuda has released an interim Chrome extension to demonstrate what a WebMCP-capable agent can do. Called Ask Nekuda, when installed it pops up a sidebar for any website that has WebMCP functionality. For example, when I visit my personal website, an Ask Nekuda popup displays — when clicked, it opens a sidebar exposing the two WebMCP actions I have implemented. Nekuda showing WebMCP actions on ricmac.org. "We built the extension to inspire people, because there aren’t many examples of agents that can use WebMCP," Karmi explained. "It is more of a precursor to what we are doing: helping websites manage endpoints so agents can use the website, not just scrape it." ## AgentLane Nekuda's core product is called AgentLane. Karmi described it as a system for managing the tools and services a website exposes through WebMCP. The product is designed to help website operators add, modify and monitor WebMCP endpoints. On the website, AgentLane is described more broadly as "Universal Checkout Infrastructure" that will work across different AI surfaces, using OpenAI's ACP and/or Google's UCP (both are open standards that enable AI agents to transact). AgentLane according to Nekuda's website. One of the things AgentLane will do is provide visibility into what actions agents are taking on your website, which Karmi notes is very difficult to achieve currently. "It's not being discussed a lot today, but when users use an agent like Gemini in Chrome, the website owner has no idea," he said. "It's like a ghost right now that lives on your website. So by using these endpoints, using WebMCP, it [AgentLane] will allow you to see the agent journey, [...] see what the agent calls as tools or parameters." AgentLane is currently in a private alpha and Karmi expects it to be released by summer. ## Building around the WebMCP ecosystem Alongside the extension, Nekuda has a few supporting products on its site — including an "agentic wallet," which was the company's original product inspired by the pizza experiment. But Karmi was candid that demand for fully autonomous purchasing has not yet emerged at scale. Nekuda found that most consumers still want to be present for the consequential part of a transaction, while merchants do not want to disappear behind an agent-controlled interface. "People want to be present and they want to use delightful user experiences, and they want the web," Karmi said. Nekuda has a few useful ecosystem resources too, including a WebMCP directory showing sites that have already deployed the protocol. Nekuda's WebMCP directory. ## A website-centred agentic commerce model What I like about Nekuda's vision is that it goes beyond merely helping merchants get discovered by AI systems, which is the focus of most "ASO" (agentic search optimization) discussions currently. Nekuda aims to help e-commerce vendors manage the entire purchasing flow, using their own websites to attract users — along with their agents — and encourage them to take actions. While Nekuda's technology is still under development, I would expect the typical user / agent flow for a merchant website to be something like this: 1. An AI assistant helps the user discover a business or product. 2. The user opens the merchant's website, potentially accompanied by that assistant. 3. The user's agent invokes tools deliberately exposed by the site. 4. The user reviews, approves or completes an action (e.g. buying a product, or joining a mailing list). 5. The merchant analyzes the tool-assisted journey and improves it. This, folks, is the agentic web we want — one where websites are at the center of the action still. Enjoyed this post? Sign up for more agentic web interviews and insights. Subscribe for free

agenticweb.news

Visa, Mastercard, Apple, OpenAI and Google are building the payment, action, execution and knowledge layers agents need to act.

The agentic web gets execution rights, from payments to app actions

One of the characteristics of the agentic web is an increasing ability for AI agents to execute actions on the web on our behalf. This is a key part of the shift from a web of pages to a web of capabilities — but it also introduces significant security, governance and financial risks. This week’s market signals converge around that shift toward execution rights: Visa and Mastercard are developing infrastructure for automated payments, Apple is making app capabilities callable by its system intelligence, OpenAI is investing in persistent agent execution, and Google is packaging organisational knowledge for agents to use. ## Follow the agentic web as it forms Get weekly market signals, expert interviews, and independent analysis on the companies, protocols, and infrastructure shaping the agentic web. Subscribe free Email sent! Check your inbox to complete your signup. ## Market Signals **📡 Visa and Mastercard compete to be agentic rails for payments** On 10 June, both of the leading payment networks unveiled rival frameworks for letting AI agents pay on a user's behalf. Visa partnered with OpenAI "to enable secure Visa payments within agentic commerce." The announcement highlighted "developer-focused experiences powered by Codex," along with other "more automated and conversational workflows." There was also a heavy emphasis on authorization and security: > "Transactions will operate within clearly defined user permissions, policies and controls, such as spending limits, merchant categories or required approvals. Transactions will use tokenized Visa credentials and real-time authorization and fraud monitoring..." Meanwhile, on the same day, Mastercard announced Agent Pay for Machines (AP4M), which brings Mastercard's services "to machine-driven commerce, helping AI innovators enable secure, reliable payments as software begins to transact on its own." Mastercard's AP4M; via Mastercard YouTube channel. Cloudflare, Stripe and Coinbase are among the initial partners, and the functionality sounds similar to the Visa announcement — except there are several blockchain companies involved. According to Coindesk: > "The company said the system can authenticate agents, enforce spending rules and settle payments across multiple payment methods, including stablecoins. [...] Mastercard said permissions and credentials associated with AI agents will initially be recorded on the Polygon, Solana and Base blockchains." Both the Visa and Mastercard announcements indicate that agentic commerce — giving agents the ability to spend real money — is arriving fast. **📡 Apple makes apps callable by system intelligence** As noted over the past few weeks, it's developer conference season and this time it was Apple's turn. As with Google and Microsoft, there was a heavy AI theme with Apple's WWDC. Apple’s approach is to embed intelligence across its operating systems and make more app content and actions available to Siri and Apple Intelligence. As Nate B Jones put it in his commentary, "Apple is trying to turn AI from something you rent in the cloud into something built into the computer you bought." As always with Apple, the web wasn't front and center in its announcements. But there was one key agentic web-adjacent upgrade: App Intents. This framework now aims to "make content and actions discoverable by Apple Intelligence and support system experiences like Siri, Spotlight, Shortcuts, and widgets." Apple App Intents, via a WWDC26 presentation. The App Intents framework itself isn't new — it goes back to 2022, when it was Siri-focused — but Apple has now expanded it into an action layer for Apple Intelligence. As Jones described it, App Intents in 2026 is "how an app tells Apple Intelligence, 'Here's what I have. Here's what the user can do with it, and here are the actions you are allowed to take.'" This reminds me of WebMCP, which is how websites and web apps can expose their functionality to an AI system. While App Intents is a native Apple framework rather than a web protocol, the architectural pattern is similar: applications expose structured capabilities that an AI system can discover and invoke. **📡 OpenAI moves Codex toward persistent cloud execution** OpenAI’s planned acquisition of Ona, a "platform for background agents," points to the next phase of Codex, its AI coding agent: secure, persistent execution that can continue independently of a user’s local session. It's a signal that agent execution is moving from bounded interactive sessions toward long-running cloud services. The announcement also highlights the infrastructure required to make long-running agents viable in business settings: controlled access to credentials and internal systems, activity logging, review processes and customer-defined security boundaries. Anthropic outlined a similar architectural direction with Managed Agents back in April, described as its "hosted service for long-horizon agent work," so this isn't a new development. But it's notable that OpenAI is now buying infrastructure to make persistent execution a core part of Codex. (Is this "agentic web"? Given that all these OpenAI and Anthropic agents will be visiting and using websites or apps, I'd say yes!) **📡 Google proposes a portable knowledge format for agents** Google has announced a new spec called the Open Knowledge Format (OKF), which aims to represent knowledge "as a directory of Markdown files with YAML frontmatter." The goal is primarily to enable internal company knowledge to be packaged in a way that is accessible to agents, without the need for a proprietary SDK or translation layer. It's purposely positioned as a starting point — v0.1, according to the announcement. "The format will evolve as more producers and consumers emerge and as we collectively learn what knowledge representations agents actually need in practice," says Google. An example of an OKF bundle. While not strictly a market signal about agent execution, OKF is helping build the foundation for that. After all, giving agents execution rights is not simply a matter of connecting them to tools. They also need enough organisational context to understand what an action means, which data and definitions apply, and what operational constraints they must observe. ## Watchlist **👀 Zscaler's agent broker** Security company Zscaler announced an "AI Broker" last week that aims to govern agent communications passing through MCP and A2A, while applying access controls and tracking how agents interact with company data. Clearly, this fits our theme this week of agent execution — and putting enterprise-level controls around that. Also it's another example, like Arcade (which just got funded to the tune of $60 million), of infrastructure that sits between agents and the systems they act upon. * * * Thanks for reading **Agentic Web News** — my independent analysis of the companies, standards and ideas shaping the next phase of the web. Alongside weekly market signals, I am publishing interviews with the early builders defining this space. If this issue helped clarify where the agentic web is heading, please forward it to someone who should be tracking this trend. To receive future editions, subscribe by email. It's currently free, but you can also become a founding supporter of AWN, to help it become financially viable. I also advise companies on agentic web strategy, Agent Experience, AI visibility, and agent-facing product strategy. Learn more at ricmac.org.

agenticweb.news

The user interface is moving from pages into agents. MCP Apps, atomic brand kits and headless CMS infrastructure all point to the same shift: apps, brands and content becoming machine-readable components that agents can assemble for users. https://ricmac.org/2026/06/12/user-interface-agents/

When the user interface moves from pages into agents

This week, my Agentic Web News posts circled around one question: what happens when the web stops being organized only around pages, and starts being organized around machine-readable capabilities, agent interfaces and brand systems? I’ve been writing for a while now about the shift from a web of pages to a web of capabilities. But to me, that has never meant that the human web is going away. Clearly I don’t think that, otherwise I wouldn’t have started a new tech blog. Rather, the point is that there’s an extra layer of the web emerging — one built for our machine helpers. This week, that extra layer began to look less abstract. ## From busy bots to atomic brand kits In my weekly market signals post, I argued that the machine-readable web is becoming a business problem. Cloudflare’s bot traffic data — stating that bots have now passed human traffic for the first time — was the most obvious signal: websites are facing a large and growing machine demand. And if there’s demand, then a viable market will undoubtedly form too. The old web monetized human attention — first with banner ads, then with targeted advertising based on user profiling and social activity. But the agentic web won’t be about attention in quite the same way. It will have to find a way to monetize access, permission, attribution and action. All of which is still in the wild west stage. One of the more intriguing concepts I came across this week was the “atomic brand kit,” as outlined by Emmett Shine from the New York digital studio, Little Plains. It’s a deceptively simple idea: if your website is becoming machine-readable, shouldn’t your brand do that too? Little Plains has started to deliver brand systems to their clients with two folders: `/human` and `/agent`. The human side contains the familiar assets — logos, guidelines, visual identity. But the agent side encodes the brand as instructions using YAML, JSON, Markdown, HTML, CSS and SVG files. In other words, a brand becomes something closer to a software program that agents can run: a structured, machine-readable understanding of what the brand is, who it’s for, how it sounds and how it looks. That matters because agents will not always interact with a company through the canonical homepage, or even through a traditional app. They may generate brand-consistent pages, interfaces and content across contexts the brand does not fully control. This week’s market signals also covered Salesforce’s agreement to acquire Contentful, a so-called “headless CMS” company. In the early 2020s, headless CMS systems were mainly framed as a way to decouple the frontend from the backend. Fast forward to 2026, and AI systems are less dependent on the traditional “head” of a CMS — they primarily want the backend data. So Salesforce buying a headless CMS makes sense if Agentforce needs to dynamically assemble and deliver personalized experiences across channels. ## MCP Apps and the rise of agentic apps That brings me to my second AWN post this week, an interview with MCP Apps co-creators Ido Salomon and Liad Yosef. MCP Apps began as MCP-UI, an open source project that provided a way to add web-based user interface components to AI agents. The goal from the start was “UI over MCP”: letting an MCP server return a UI resource, usually HTML, which the host renders inline in the conversation, with interactions passed back through the host. What interests me most is that MCP Apps is not just a developer convenience. As Salomon put it, this is “a new way to distribute applications.” But as both Salomon and Yosef pointed out, discovery, ranking and monetization are still open questions in this new agentic apps paradigm. The capability may exist, and MCP Apps may be available inside chatbots, but that does not mean users know when or how to invoke them. The more I think about this, the more I see MCP Apps, atomic brand kits, and headless CMS infrastructure as parts of the same larger shift. Apps, brands and content systems are all being decomposed into machine-readable components that agents can understand, assemble and present back to users. ## From UI chunks to generative UI In the MCP Apps post, I used the metaphor of “UI chunks.” A user of ChatGPT, Claude or another AI system will often need only a small part of a host app or website, depending on the context. If MCP Apps works as intended, developers will not only build websites, mobile apps, desktop apps or SaaS dashboards. They will also build app fragments that run inside AI assistants. Those fragments will be interactive, contextual and portable across different AI systems. The next step may be generative UI: interfaces generated on the fly for a particular query or task. Google is already talking about this for Search, and Claude’s freeform Imagine feature points in a similar direction. Yosef’s framing was useful here: MCP Apps may provide a unified UI standard across hosts, but the next goal is a broader umbrella standard across methods of UI generation. ## The strategic question for orgs So my field note this week is this: the agentic web’s interface layer is starting to come into focus. It will not be just websites plus APIs (or MCP!). It will involve app fragments, generated interfaces, brand systems that agents can interpret, and content backends that can feed personalized agent-mediated experiences. The strategic question for companies is no longer just whether you have a website or an API, but whether your product, content and brand can show up as a useful, trusted interface inside an agent’s workflow. That is still early, messy and unresolved. But it’s no longer theoretical.

ricmac.org

MCP Apps is turning UI over MCP into a candidate application layer for AI assistants, but discovery and ranking remain unresolved.

MCP Apps and the future of software inside AI agents

Around July last year, I discovered an open source project called MCP-UI — which provided a way to add web-based user interface components to AI agents. The project was brand new, having only been released in May 2025. In early August, I interviewed its two creators, Ido Salomon and Liad Yosef; and then I talked to some developers from Shopify, among the first companies to implement MCP-UI. MCP-UI was one of the technologies that got me really interested in the intersection of web and AI, so when the project morphed into an official MCP project — now called MCP Apps — I continued to track it. Since going solo in February of this year and putting all my focus on agentic web, I've kept in touch with Yosef and Salomon — who are both now pursuing their own projects in this space. To get up to speed with how MCP Apps is progressing, I spoke separately with both Salomon and Yosef. I've highlighted their key insights in this post. ## Get more interviews with agentic web builders Join AWN for founder and developer interviews, market signals, and analysis of the emerging agentic web. Sign up for free Email sent! Check your inbox to complete your signup. ## **The evolution from MCP-UI to MCP Apps** First, let's do a quick recap of what MCP Apps is and how it evolved from MCP-UI. As Salomon and Yosef explained at the recent AI Engineer Europe conference (AIE Europe), after the first several months of MCP-UI, the pair teamed up with Anthropic and OpenAI to create MCP Apps, the "first official extension" of MCP. That project became officially available in January of this year. In practice, MCP Apps allows an MCP server to return a UI resource — usually HTML — which the host renders inline in the conversation, with interactions passed back through the host rather than disappearing into a third-party app. The goal from the start of MCP-UI has been to enable “UI over MCP.” There’s also a communication layer, so that the UI can interact with the host application. In MCP Apps, with Anthropic and OpenAI’s involvement, the goal remains the same but the scope has become much bigger. MCP-UI architecture We can also think of MCP Apps as an attempt to standardize how applications behave when they are broken into agent-readable, agent-mediated chunks. As Salomon put it at the AIE event, MCP Apps "isn’t just some tech… this isn’t some protocol. This is a new way to distribute applications." ## **Adoption is real, but discovery is still hard** When I spoke with Salomon recently, he emphasized how far the project has come since those early MCP-UI days. “When we last talked it was still, I think only Goose supported it at the time,” he told me. “So yeah, I think pretty much everything changed… now pretty much every large host supports MCP Apps.” He also pointed to growing adoption from external apps: “There’s hundreds of apps, like the biggest organizations… Instacart and Autodesk and I think even Walmart has an app. Canva too. So there’s definitely a lot of adoption going on.” > “There’s still a very large gap between these apps exist and they work… and end-users actually realizing how they can utilize it.” > **- Ido Salomon, MCP Apps co-creator** But Salomon was careful to distinguish between technical adoption and user adoption. The capability may exist, and MCP Apps may be available inside chatbots, but that doesn’t mean users know when or how to invoke them. “There’s still a very large gap,” he said, “between these apps exist and they work… and end-users actually realizing how they can utilize it.” So that's one of the biggest issues facing MCP Apps today: discovery. In the previous web era, users discovered applications through search engines, app stores, social recommendations, and other attention-based mechanisms (buying a social media ad, for example). But in an agentic interface, discovery becomes much more ambiguous. If a user asks an assistant to book a trip, which travel app should appear? Booking.com? Expedia? Airbnb? TripAdvisor? A local provider? A paid partner? “What happens when you have hundreds of apps doing the exact same thing?” Salomon asked. “Which one do you surface? Yeah, I think there’s a gap there.” MCP Apps in Claude Yosef made a similar point when I spoke with him. He said there is “a big friction point of discovery” in the current model. If a user wants to use Booking.com inside ChatGPT, he noted, they may have to mention Booking explicitly — which is not necessarily how people expect to use a general-purpose assistant. “It’s actually very difficult, very challenging, for those chats to do discovery of apps without it looking like ads, like promoted ads,” Yosef told me. This is one of the most important market questions around MCP Apps. If apps inside AI systems do become a new distribution layer, then issues like discovery and ranking — and monetization! — will come to the fore. ## **Not the final form** Salomon and Yosef both moderate regular MCP Apps Workgroup meetings, as the extension spec and SDK continue to get hammered out. Some of this work involves making sure MCP Apps fits into the wider ecosystem around MCP and web applications — at AIE, the pair referenced interoperability work they're doing with A2UI, AG-UI and WebMCP. > “MCP Apps [is] definitely not the final form of UI in AI.” > **- Liad Yosef, MCP Apps co-creator** Also, Yosef told me that he does not see MCP Apps as the endpoint of the evolution of UI in AI systems. “MCP Apps… while it’s an interesting domain or interesting space, it’s definitely not the final form of UI in AI,” he said. In fact, Yosef is currently working on a stealth startup — already seed-funded by Sequoia Capital — that is aiming to build a platform for what he calls the "nearly headless web." “MCP Apps is part of this nearly headless web,” he told me. “But the story is much bigger than that: it’s how agents interact with a product and how they authenticate it, how they pay it, how they integrate it, and eventually how they return the last mile of interaction to the user.” I'll cover Yosef's new company once it launches, but the key point is that this is just the beginning. While MCP Apps aims to become one of the interface standards for the agentic web, the larger commercial opportunity sits around the surrounding layers: discovery, authentication, payments, integration, and the handoff back to the user. ## **From UI chunks to generative UI** One of the most compelling metaphors used in MCP Apps is that of a "UI chunk". A user of an AI system like ChatGPT or Claude will typically only need a small part of a host app or website, depending on the context in which they're using the AI system. So if MCP Apps works as intended, developers will not only build websites, mobile apps, desktop apps, or SaaS dashboards. They will also build app fragments that run inside AI assistants. Those fragments will be interactive, contextual, and portable across different AI systems. Salomon described the promise this way: “With MCP Apps, we already have standardization, and they [apps] all work the same. You can write your app once, and it will run everywhere.” MCP Apps vision for generative UI. Not only that, but in the agentic web era we're starting to see the concept of "generative UI" bubble up — user interfaces generated on the fly for a particular query or task. Google highlighted this in its recent I/O conference, saying that generative UI was coming soon to its biggest product, search: _"Search can build the ideal response, in the right format for your question — completely on the fly. So you can get custom generative UI, including visual tools and simulations, tailored precisely to your needs."_ Google added that its "generative UI capabilities will be available for everyone in Search this summer, free of charge." Salomon is a little more cautious, but thinks the future "is probably at least partially generated [UI]." He points out that outside of Google, MCP Apps is already used for generative UI — for example, Claude's freeform _Imagine_ feature, where the model generates apps on the fly inside the chat. > "...the next goal is to have a unified ‘umbrella standard’ across methods of UI generation." > **- Yosef** The direction seems to be that MCP Apps can provide one standardized container for UI inside AI hosts — whether that UI is predefined by the app, declared in a more structured format, or partially generated by the host. As Yosef put it, "the original purpose of MCP Apps was to create a unified UI standard across hosts (and it succeeded in that) — now the next goal is to have a unified ‘umbrella standard’ across methods of UI generation." ## **The future of apps** It's pretty clear that apps in the agentic web will become smaller, more componentized, more contextual, and more dependent on AI systems as the organizing layer. That's why I think MCP Apps is one of the most important projects to watch in the agentic web. What began as a way to pass UI over MCP (MCP-UI) is now becoming a candidate application layer (MCP Apps) for AI assistants and agents. This also ties back to my most recent market signals post: for companies, the strategic question is no longer just whether you have a website or an API, but whether your product can show up as a useful, trusted interface inside an agent’s workflow. Enjoyed this post? Sign up for more agentic web interviews and insights. Subscribe for free

agenticweb.news

Bot traffic, grounding APIs, atomic brand systems, and CMS deals point to a new commercial layer forming around AI agents.

Agentic web market signals: the machine-readable web becomes a business problem

This year I've been writing about how we're moving from a web of pages to a web of capabilities. To me, that's never meant that the human web we all know and love is going away. Clearly I don't think that, otherwise I wouldn't have started a new tech blog. Rather, the point I've been trying to make is that there's **an extra layer of the web emerging** — one that is built for our machine helpers. Perhaps this narrative has been difficult for people to get behind, because so far I've been focusing on what many would see as abstract signals. The new protocol WebMCP, for example — which enables you to define a set of programmatic capabilities on your website for agents to use — has incredible potential, but it's not yet widely implemented in browsers. Well, over the past week I have identified several stories that prove the business world is adapting to AI agents. It's not just a protocols narrative anymore. The stories I'll cover in this week's market signals show how the web is being re-architected for machines at three levels: traffic, search / real-time data, and brand / commercial interaction. In addition, I have a story about how the content management market has clearly shifted due to the demands of agents. Before we get to those stories, a quick message for my human web readers: to read the full briefing, **subscribe for free to _Agentic Web News_**. These market signals posts are where I connect the week’s news into a larger map of the agentic web: infrastructure, protocols, business models and emerging product patterns. ## Sign up for Agentic Web News Tracking the agentic web: market signals, interviews & analysis by Richard MacManus Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. This week: Cloudflare’s bot-traffic milestone, Microsoft’s Web IQ, atomic brand kits, Salesforce’s Contentful acquisition, and The Economist’s ChatGPT experiment — five signs the machine-readable web is now a business problem. ### This post is for subscribers only Become a member to get access to all content Subscribe now

agenticweb.news

DNSid sets out a DNS-based accountability layer for AI agents, aimed at answering who owns an agent and who is responsible for its actions.

Who owns that AI agent? DNSid proposes an answer

Since we're moving to a web where both people and agents are active participants, there's a question of identity that we need to answer. And I don't mean whether agents should be treated as first-class citizens of the web (although that is an interesting philosophical question). No, there are a couple of more practical issues we should address about any agent that interacts with your site or app: 1. Who owns this agent? 2. Who is accountable for what it does? A new project called DNSid aims to provide answers to those questions by building an "accountability anchor for AI agents." DNSid comes from Innovation Labs, a division of the domain name services company Identity Digital — which, according to Wikipedia, runs or has a controlling interest in 271 top-level domains (including .news, the TLD I use for this site). I spoke with Allie Kline, who is interim CEO of Innovation Labs, about why agents need a DNS-based identity. "One of the things that DNS has always done is to say, who is the ultimate accountable party for any content or any web environment or internet experience that's out there," Kline told me. "And so we set out to say, is there a way for us to make verifiable accountability the default in an AI or an agentic world?" Strictly speaking, DNS does not by itself establish accountability. But it does provide the naming and delegation layer that underlies internet accountability systems. ## A birth certificate for agents What Kline's team came up with was the concept of a "birth certificate" for agents, which is what DNSid provides. DNSid diagram from its website. Using birth certificates as the lead metaphor rather implies that agents _will_ become first-class users of the web, since this is obviously a human construct. This appears to be what Innovation Labs thinks will happen. "The more they [agents] multiply, the more important it is for all of us to expect that just as we require birth certificates to get all sorts of other things that unlock our independence and freedom as humans, that this is a very important and necessary component to apply to every first class actor," Kline said. To be clear, Innovation Labs isn't saying agents will have any legal standing. The goal is simply to provide a durable record of origin and ownership. Here's how DNSid is explained on the website: "DNS gives you the owner. PKI gives you the proof in the moment. The Immutable Ledger gives you the receipt that survives an audit." Briefly, PKI stands for "Public Key Infrastructure" and it's a cryptographic identity binding mechanism. In the context of DNSid, Kline described it as "the certificate of ownership." The "Immutable Ledger" does not have to be a blockchain. Kline said Innovation Labs initially leaned toward blockchain, but now frames this more generally as an append-only audit trail that could be implemented using blockchain, a Certificate Transparency-style log, a Merkle tree or another verifiable data structure. ## The agent identity ecosystem As part of its push to become widely adopted, Innovation Labs has submitted DNSid to the Internet Engineering Task Force (IETF) as an Internet Draft. As with all Internet-Drafts, this is work in progress rather than an approved IETF standard. The document includes the following layered model of the "agent identity ecosystem": Agent identity ecosystem, according to DNSid. This diagram shows that DNSid is several layers below authentication and governance, which is where middleware companies like Arcade focus on. Kline positioned DNSid as complementary to existing enterprise identity systems, which she said often have "federated trust agreements" in place. "If you have an Okta identity interacting with an Azure identity or a GCP identity, many of those have existing trust agreements that are in place, but those trust agreements don't scale at the agentic level yet," she said. The idea with DNSid is to offer a layer below those systems, as close as possible to the DNS layer of the internet. "We’re really thinking about an autonomous world where agents are interacting with other agents, where there are not kind of pre-federated or pre-existing trust agreements between organizations," said Kline. One important nuance: if a platform hosts agents on behalf of users, DNSid appears to make the platform-level registrant the accountable entity, while user-level attribution remains inside that platform’s own audit systems. ## The long road to adoption There's no shortage of proposed web standards going through the IETF (as of writing, there are 4,357 pages of Internet-Drafts submitted during the last 7 days!), so how does Innovation Labs hope its DNSid proposal will get adopted? Kline explained there are three adoption buckets they're targeting. The first is "hyperscaler cloud identity, enterprise technology systems" (by which she means the large tech companies), the second is "large regulated enterprises" in sectors like healthcare and finance, and the third is standards, regulatory and public-sector engagement, ranging from industry bodies such as the Linux Foundation to NIST and government agencies. DNSid may never become a widely adopted internet standard — there are other DNS-based approaches to identity emerging too, including GoDaddy’s Agent Name Service and Infoblox’s DNS-AID. But regardless, agent identity and accountability will be key issues as we move further into the agentic web. _Feature image: via an_ Innovation Labs video

agenticweb.news

Arcade CEO Alex Salazar argues that MCP servers are only part of the agentic web stack. Enterprises also need an actions runtime for authorization, governance and execution.

Arcade's bet: the agentic web needs an actions runtime, not just MCP servers

Arcade promotes itself as an "MCP runtime" — basically, middleware that governs how agents execute actions across tools and services. Although the company actually prefers the term "actions runtime," it believes that MCP is becoming the default way for agents to use SaaS apps and, increasingly, website capabilities. To find out why agents need middleware, I spoke with Arcade CEO Alex Salazar. Salazar firstly pointed out that the agentic web is not just about data retrieval. Up till very recently, he says, many people thought of agents as "glorified chatbots." "My definition of an agent is that it can take actions. It can mutate data. It can issue a transaction of some type. It’s not just data retrieval." ## What is an actions runtime? With that definition in mind, what Arcade offers is a way to manage the actions that an agent takes. "We call it an MCP runtime, for SEO, but we really refer to it internally and to our customers as an actions runtime," he explained. "An actions runtime or an MCP runtime is really the layer that is taking care of all of the execution of the agent’s requests. The left-hand side is the brains of an agent; the right-hand side is the hands of the agent.” Here he was referring to a slide from an Arcade deck that showed "AI systems" on the left side (ChatGPT, Claude, et al) and tools (like Slack, Jira, et al) on the right side. The AI systems and tools are connected via MCP — the Model Context Protocol — and Arcade sits in the middle, managing authorization and other governance rules. Arcade: The Actions Runtime; image via the company. The graphic above clearly shows how Arcade is middleware, which of course makes it an ideal business offering for enterprise IT departments. Prior to founding Arcade, Salazar was an executive at Okta — one of the leading identity and access management companies. So Arcade is bringing a similar product pitch to the AI era: that agents need an authorization and access management layer too. "If you were to take MuleSoft and Okta and have them make an agent baby, that’s what this layer is, that's Arcade," he chuckled. ## Websites as capabilities I've been writing a lot about how websites are becoming tools for agents — that you can now define a set of capabilities in your website that agents can use and interact with. I asked Salazar if Arcade can be useful in that paradigm? I was thinking here of, for example, a retail website that offers various tools that agents can use to help people compare or buy their products. He replied that their original idea — before MCP even existed — was to create a "site reliability agent," which would offer "a properly governed delegated user authorization flow." > "MCP is quickly turning into the HTTP of agents." > **- Alex Salazar, Arcade CEO** But Arcade soon realized that just building an agent wasn't enough, because ChatGPT, Claude and other AI chatbots had quickly become the primary way consumers used AI. Then MCP arrived in late-2024, bringing a standard way for AI applications to connect to external tools. Once MCP became established, Arcade decided that being middleware for MCP servers and tools was the way to go. "MCP is quickly turning into the HTTP of agents," Salazar said. "And so I think the agentic web and agentic tool calling, from my perch, are becoming the same thing very, very quickly." This is the key connection, I think, to the “websites as capabilities” idea. Arcade is betting that it’s not enough for a website to expose product data, checkout flows, support actions or other business logic to agents. Those capabilities also need to be callable in a way that respects user permissions, site policies and enterprise governance. ## Enterprises want to control the runtime In the 1990s and into the 2000s, it was common for enterprise companies to put controls around the primary user-facing runtime of the web — that is, the browser. This led to corporate networks, proxies, firewalls, directory services, single sign-on, browser policies, and intranet portals. These days, there are enterprise browser management tools for organizations. Google has Chrome Enterprise Core, which offers "centralised control from the cloud"; while Microsoft has an "Edge for Business" version of its Edge browser, featuring "browser policies, AI controls, and more." What Arcade is offering is similar in concept, with the proviso that its runtime is for agents — not people. Either way, it's about organizations putting policy controls around an internet application runtime. "Organizations just want one standardized way of doing something that’s governed and controlled, and reliable, and is going to work," Salazar said. ## MCP server quality varies One other point Salazar made about enterprise control in the AI era: not all MCP servers are the same. He referenced Arcade's ToolBench page, which rates tens of thousands of MCP servers and tools. ToolBench currently reports 219,332 indexed tools, with only 0.5% earning an A or above. The majority are rated F. Arcade's ToolBench showing MCP tools by quality grade. "If enterprise is managing governance MCP server by MCP server, agent by agent, they’re going to fail," Salazar claimed. ## Agents are software, not new users There's been discussion in the industry about whether an AI agent is a new class of actor that needs its own independent identity, almost like a peer to a human user. But Salazar gives this idea short shrift. He argues that agents should be treated as equivalent to software applications. > "Every application I've seen, that's been started in the last six months, is agentic." > **- Salazar** "Agents are software," he insisted. "And the difference between an application and an agent today, in 2026, is nil. Every application I've seen, that's been started in the last six months, is agentic. And every agentic system I've seen in the last six months is an application. And so if we treat them like application workloads, which is what I think they are, then suddenly everything magically works." This is also a good argument for why users and companies should be cautious about giving local agents broad access to a computer or account credentials. "You put an agent on your laptop, an agent of one, and you give it your credentials — that’s pretty dangerous, because you can delete files, you can delete emails, you can delete all kinds of stuff." ### MCP-first websites A trend that Salazar sees playing out is websites and applications becoming "MCP-first," which is something I've also been exploring. "If I were building a website tomorrow, or I was building a SaaS app tomorrow, I would probably build it MCP-first, because that’s how agents increasingly want to consume this," he said. For Arcade, that makes MCP a likely foundation for how agents will interact with the web going forward — provided there is a governed runtime layer around it.

agenticweb.news

This week's market signals look at the emerging economic layers of the agentic web: advertising standards, agentic commerce infrastructure, and identity/discovery systems for AI agents.

Agentic web market signals: advertising, commerce & identity layers emerging

In this week's market signals briefing, I focus on how the economic aspects of the agentic web are shaking out. This was always a key part of my analysis of Web 2.0 during my ReadWriteWeb days: how can these new web technologies be harnessed for commercial purposes? In the AI era, it's even more important to track this, because the overall web ecosystem has become very unbalanced since Web 2.0. On the one hand you have platform companies like Google, Amazon, OpenAI and Anthropic — these corporations hold massive power now. On the other hand, you have indie players scrambling to a) adapt to changing consumer habits (in the case of indie retailers and marketers), or b) find a way to survive (in the case of web publishers). It's crucial that all participants in the agentic web ecosystem can not only survive, but eventually thrive. That's a good reason to look at how the advertising and commerce sectors are adapting, because in past eras they have provided much-needed revenue streams to the media and publishing sectors. So let's take a look... ## Market Signals **📡 Agentic advertising is in its wild west phase 🤠** Last Thursday the IAB Tech Lab held its annual summit, which this year had the theme, "Welcome to the Agentic Web." The Interactive Advertising Bureau (IAB) is a US trade association and so of particular interest were the discussions around agentic AI in advertising. The event kicked off with a fireside chat with Sir Tim Berners-Lee, who emphasized that user control and privacy shouldn’t be sacrificed for business outcomes. Sir Tim is currently CTO of Inrupt, a company that builds products — like the "agentic wallet" — that enable people to control their data. Tim Berners-Lee talks with Anthony Katsur; image via IAB Tech Lab. During the event, The Current spoke with IAB Tech Lab CEO Anthony Katsur. He noted that the main advertising use case he's seeing is to "use agentic to make programmatic [advertising] smarter and more effective." He thinks "agentic direct buying" isn't a strong use case currently. Ultimately though, it's emerging agentic standards he is focused on: "Right now, agentic standards are the Wild West…. Everyone is running off and developing agentic solutions." The IAB itself has been active in trying to establish these standards. In the leadup to its conference, IAB outlined an umbrella framework called AAMP (Agentic Advertising Management Protocols). The stack is an alphabet soup of acronyms, but it's mainly about agents acting inside the advertising transaction ecosystem. AAMP is being positioned as complementary to existing agentic connection standards, such as MCP and Google's A2A. IAB Tech Lab's AAMP framework Also prior to the event, IAB Tech Lab released its guidance for content owners to manage AI bots and crawlers. According to a writeup in PPC Land, this was "explicitly positioned as a support layer for CoMP API adoption." The CoMP specification (Content Monetization Protocols) was finalized in late-April as "a technical framework requiring AI systems to have commercial agreements in place with publishers before any content crawling occurs." I liked the advice of IAB Tech Lab's Hillary Slattery, who said in an interview with AdExchanger that blocking all bots and crawlers is an ineffective strategy: "Don’t turn everything off. It’s not a light switch; it’s a mixing board." To help with the dizzying array of new agentic advertising and commerce standards, AdWeek published a useful guide. It includes standards not mentioned by IAB in its stack, such as Ad Context Protocol (AdCP). The wild west, indeed! **📡 Amazon launches Agentic Shopping Assistant** 🛒 In a move reminiscent of when Amazon first offered its internal web services to businesses back in Web 2.0, the company has announced the Agentic Shopping Assistant on AWS, which is "built on AWS services such as Amazon Bedrock, AgentCore, and OpenSearch." As GeekWire noted, this is "built on the same technology that powers the Alexa for Shopping assistant on Amazon.com, formerly known as Rufus." Amazon Agentic Shopping Assistant in action; image via AWS Agentic commerce is a very busy market category, with Google, Shopify, OpenAI, Stripe, Microsoft, Walmart, and others involved in various projects and partnerships. The open protocol with the most industry support is Universal Commerce Protocol (UCP), which was announced by Google in January. Amazon officially joined the UCP tech council in late-April — late to the party, perhaps, but its involvement now signals that this protocol has real momentum. Since agentic retail is taking off on the web, Amazon has also decided to get into the picks and shovels business. As AI commerce pundit Roger Dunn put it on LinkedIn, "Amazon now assumes every retailer needs a conversational front door, and would rather sell the foundations than watch AI rivals build them." **📡 AI agent identity and discovery solutions** 🆔 The Linux Foundation has announced the launch of the DNS-AID project "to advance decentralized AI agent discovery." The gist: > "Initially developed by Infoblox, DNS-AID provides a vendor-neutral framework for publishing, discovering, and verifying AI agents and Model Context Protocol (MCP) servers without relying on centralized registries or hardcoded integrations." In practice, this could include agent-specific DNS names such as _contract-agent.company.com_. Other than Infoblox, a networking and security company, initial project members include Cloudflare, Equinix, GoDaddy, and others. Wei Chen quote on DNS-AID; image via Infoblox. In an interview with the _AI Security and the Law_ podcast, Wei Chen from Infoblox argued that AI agents need identity systems tied to domains. She explained that an organization's domain name is a key signal for trust and credibility: > "So because [a] domain was created as something that signals or that conveys trust on behalf of an organization, we're advocating for that level of trust to be extended to agents or MCPs or any other endpoints." But there's a lot still to figure out here. Recently I've spoken to two different AI companies, and both conversations touched on the identity layer of agents. One is a company building an identity solution based on DNS, while the other vendor is taking a middleware approach and says DNS isn't the answer. (I will be publishing these two interviews shortly, so I will delve into the identity / discovery issue more then.) ## Watchlist **👀 Gemini Spark launches in limited beta** Google's Gemini Spark — the 24/7 personal agent announced at I/O — went live for AI Ultra subscribers in the US late last week. According to 9to5Google, there are three core components: Tasks, Schedules, and Skills. You can have up to 15 tasks running at a time. Obviously, it's too early to tell how good the product is, but it will be fascinating to track — especially in the context of Tim Berners-Lee's notes at the IAB event, about user control and privacy being paramount in the agentic web. Google cannot afford to drop the ball on this. Gemini Spark screenshot; via 9to5Google. * * * Thanks for reading **Agentic Web News** — my independent analysis of the companies, standards and ideas shaping the next phase of the web. Alongside weekly market signals, I’ll be publishing interviews with the early builders defining this space. If this issue helped clarify where the agentic web is heading, please forward it to someone who should be tracking this trend. To receive future editions, subscribe by email. It's currently free, but you can also become a founding supporter of AWN, to help it become financially viable. I also advise companies on agentic web strategy, Agent Experience, AI visibility, and agent-facing product strategy. Learn more at ricmac.org.

agenticweb.news