The observatory for
the agentic web.
The infrastructure agents run on is being built faster than anyone is measuring it. Major Labs runs the instruments: a weekly census of the public MCP ecosystem, a longitudinal series on its security and identity posture, a versioned record of the frontier labs' safety thresholds, and a sourced timeline of agent control incidents.
Primary data, collected by tools I publish in the open, with methodology and datasets anyone can check. No vendor alignment. No fundraising. No advisory work for hire.
Current readings from the instruments
Six measurements from the observatory, each one collected by tooling I publish and each one checkable against the open dataset. Where a number moved, I say against what baseline.
Public MCP server repositories in the census, up 38 percent from 2,413 on May 31, 2026, across 22 scans. The population figures everyone repeats are estimates; this is a count.
Major Labs census · as of September 21, 2026
Servers in the census that expose a remote HTTP surface, 41.3 percent of the total. State of MCP Q3 report figure: this slice grew 43 percent between June 6 and August 31, 2026.
Major Labs census · as of September 21, 2026
Of 350 network-facing servers whose code takes sensitive actions, 267 show no authentication check in static analysis. Across all 733 sensitive servers, network-facing or not, the share is 78.6 percent.
Identity sweep · as of August 29, 2026
Share of 2,408 swept servers with at least one risky execution pattern in source. 66 are rated high severity. On August 31, 2026 the same rubric read 35.4 percent and 55.
Security sweep · as of September 9, 2026
A frozen cohort of 47 high-risk servers, rescanned: 2 fixed the finding, 4 reduced it, 34 were unchanged and 7 got worse.
Remediation cohort rescan · as of September 5, 2026
Frontier-lab safety frameworks under versioned snapshot tracking: Anthropic, OpenAI, Google DeepMind, xAI, Meta, Amazon. Each snapshot is dated and hashed, with a diff when the text changes.
Threshold Watch · as of September 21, 2026
I scan the public MCP ecosystem every week and publish the dataset, the methodology, and the full time series. When my own numbers change under a better method, I say so and re-baseline in public.
Quarterly State of reports interpret the series. The trackers, the incident timeline, and the scoreboard update continuously between them.
Original research, six to twelve months early
Three report series, published quarterly. Original primary data collected by Major Labs. Each report calls what becomes obvious in the next two to four quarters before the rest of the market reads the same signal. Methodology open by default.
- The State of MCP: Q3 security re-base
The first fresh deep scan since Q2, measured with the same instrument: code patterns in public source, authentication in source, and a tracked 47-server disclosure cohort. Static analysis only.
2026-09-07Published - The State of MCP: Q3 delta
Eighteen weekly scans, May 31 to August 31, 2026. How the public MCP server population moved: growth, the remote-hosted slice, and the stale share.
2026-09-07Published - June 2026 editions: MCP, AEO, Agent Memory
The three baseline reports, each with its method and a PDF.
2026-06Published - Next editions: MCP, AEO, Agent Memory
The next quarterly release, per the release calendar on the open data page.
2027-01-04Scheduled
Where this research comes from
Major Labs is not a fresh-start project. It is the empirical extension of an analytical body of work already in progress.
Major Matters
240+ articles on payments, AI, and commerce published since December 2025. Editorial analysis written for executives at banks, networks, and payments firms. The analytical layer.
majormatters.coMajor Labs
Original data collected by the products I ship. Scan results, transaction patterns, citation studies. Written for developers and product teams building on the agentic stack.
Same operator, different methods. Major Matters maps the terrain. Major Labs measures it. Neither is owned, funded or directed by any payments network or AI lab. The author, Charlie Major, is a Mastercard employee, and the opinions are his own. Both publish their working in public.
When a Major Labs State of report cites a specific framework, that framework was usually developed first at Major Matters and tested against real news cycles. The MM Trust Layer Model, the MM Liability Gap, and the agentic commerce stack maps are all available to read in full and to cite. They form the analytical backbone the empirical research builds on.
The bet
Operators are already shipping agentic systems into production, and the surface they run on is compounding: the public MCP census grew 38 percent between May 31, 2026 and September 21, 2026, and the State of MCP Q3 report found the remote-hosted slice growing fastest. Meanwhile the volume numbers the discourse repeats are frequently unverifiable; the most-quoted agent-payments counter has not moved in months. None of this is a forecast. It is what the census measured as of September 21, 2026.
The discourse is six to twelve months behind the deployment.
Gartner has not named the category. The major analysts are pricing reports for next year. The foundation labs publish around their own product strategy. The big platforms ship the rails and stay quiet about what breaks. The long tail of operators is moving without a public read on which servers will be procurement-blocked, which mandate scopes will be standardized, which protocols will clear a trillion dollars.
I measure that activity today and publish the read on tomorrow.
Major Labs is the observatory for agentic web infrastructure. I keep the census, run the longitudinal series, version the frontier labs' safety commitments, and record the incidents, so the patterns that will be obvious in twelve months are legible in the data today. Subscribers get the early read on the systems that ship next.
I do not raise money. I do not sell to vendors. I do not write decks for hire. The reports are the product. The tools are how I collect the data that becomes the next report.
What shipped
In June this section listed five planned agents. This is the part of that plan that shipped, under the names it shipped with.
The dated record is at /latest.
Open-source scanner, planned in June under the name Sentinel. It reads public registries and public source code, and it never connects to a running server. It feeds the weekly census, the Server Picker and the Registry Tracker.
Planned in June as a small open-weight model under the name Verifier. The mandate-checking role shipped as Clearpoint, a verification service built on MandateKit and WitnessKit.
Planned in June as an agent under the name Cartographer. The standards-tracking role shipped as a sourced dataset of announced frameworks, protocols, standards and regulations.
Static analysis of public source code and reading of published documents only. Major Labs never connects to, runs, installs, probes, or exploits a running MCP server or any other running system.
What I am building
Each of these is a research instrument. The scan produces the data, and the data produces the report. Every one has shipped, and none is for sale: Major Labs is research, not a commercial operation.
Sign and verify what an AI agent is allowed to spend on. Natural-language constraints become signed, checkable mandates. Tracks the AP2 Verifiable Intent draft.
Mandate scope analysis is a research vertical of its own.
Shippedv0 · open sourceTamper-evident audit trails for AI agents. Every action is signed and hash-chained, so any tamper is detected and located.
The provenance layer: evidence packs that survive a dispute.
Shippedv0 · open sourceA read-only scan of the public MCP server ecosystem. 3,329 servers catalogued as of September 21, 2026; roughly 1,200 genuinely evaluable.
The data engine behind the State of MCP reports. A scored security registry is in build on top of it.
Shippedv0 · open sourcePer-task budget, loop detection, and kill-switch middleware for any LLM call. Deterministic, dependency-free, fail-closed.
Anonymised production data feeds the State of Agent Commerce report.
Shippedv0 · open sourcePortable, signed, resolvable agent identity (did:key + did:web) with the cross-walk onto DID, FIDO, AP2, and EUDI. Reputation as verifiable claims.
Powers the State of Agent Identity report and the cross-walk between DID, FIDO, and EUDI. Hosted registry + paid write tier to follow.
Shippedv0 · open sourceGoverned, portable agent memory. Signed, scoped, content-addressed records that verify standalone, so a memory moves between agents with its provenance attached.
Fills the portable-agent-memory gap: a schema and verifier, not a database. The fifth question, after who, may, spends, and did.
Shippedv0 · open sourceSee which answer engines cite your URLs across ChatGPT, Claude, Perplexity, and Gemini. Read-only, bring-your-own-keys.
Powers quarterly citation studies on how AI search rewrites discovery.
Shippedv0 · open source
The suite, composed
Five primitives, each open source and useful alone. Together they are a governance layer for an AI agent: identity establishes trust, the mandate bounds authority, the budget bounds spend, the witness makes all of it auditable, and memory travels with the agent, signed.
Signed, resolvable agent identity.
Scoped, signed permission to act.
Per-task budget and kill switch.
Tamper-evident audit trail.
Portable, signed agent memory.
pip install identitykit mandatekit budget-guard-agents witnesskit rememberkit npm install identitykit mandatekit budget-guard-agents witnesskit rememberkit
Live on PyPI and npm. v0, experimental, unaudited; each repo's SECURITY.md says exactly what is and is not guaranteed.
One governed step
The reference integration wires all five into one agent. Every action passes through the same loop: budget before the call, mandate if it spends, execute, then witness, with what it learned carried in signed memory.
guard.check(task, signature=action) # SPEND · fail closed
verdict = mandate.verify(txn, trusted_keys=[key]) # MAY · scoped + signed
if verdict["decision"] != "allow":
trail.append(f"{action}:denied", {...}) # DID · record the denial
return
guard.record(task, signature=action) # SPEND · real usage
trail.append(action, payload) # DID · witness itAn out-of-scope purchase is denied and recorded; the audit trail verifies and any tamper is caught. Identity. Mandate. Budget. Witness. Memory. One agent, fully governed.
Essays
- 2026-06-19The unsigned memory problem
An agent's memory is a claim you take on faith. Zero of six leading systems sign memory, zero export it at full fidelity, zero carry portable provenance, three ship regulatory-grade consent. Why memory cannot be a credential until it is signed, portable, and consent-bound.
- 2026-06-26Inside the identity layer
An agent carries four or five identities and none of them reconcile. The DID/FIDO/EUDI cross-walk, portability across model providers, capability attestation, fast revocation, and why we ship identity last.
- 2026-06-23Inside the provenance layer
August 2 reprices provenance when the EU AI Act enforces. What ships, what's missing, the audit-ready disclosure receipt, and why we publish about provenance but don't ship into it yet.
- 2026-06-19Inside the observability layer
Helicone went into maintenance mode. That is a category signal, not a company signal. Per-customer attribution at scale, the audit trace standard, and what BudgetGuard does that observability cannot.
- 2026-06-16Inside the commerce layer
Mandate scope verification, the refund and dispute void, audit trails that survive a processor inquiry, and what MandateKit and BudgetGuard actually do.
- 2026-06-12Inside the discovery layer
The MCP scan methodology, the five vulnerability categories, what AEO measures that GSC cannot, and the pricing economics that favor an independent operator.
- 2026-06-09The five layers, mapped
Identity, commerce, observability, provenance, discovery. Three close in twelve months. Two are deeper plays. Which gap closes first.
- 2026-06-05Infrastructure for the agentic web
Operators are already shipping. The independent measurement layer is missing. The thesis behind Major Labs in 1,800 words.