For the past three years, discussion of the agent economy has been dominated by a familiar question: how capable are the models? Investors have treated autonomy as a direct function of benchmark scores; software firms have marketed orchestration layers as if dependable commercial agency were merely a matter of prompt design. By mid-2026 that framing looks increasingly incomplete. In real markets, the limiting factor is not whether a system can produce plausible answers, but whether it can be recognised as a bounded actor inside legal, organisational and financial systems that were not designed for synthetic participants.
This is a less glamorous problem than model scale, yet it is likely to prove more consequential. A software agent that can negotiate a supplier contract, reroute shipments or rebalance a treasury account is only valuable if others can verify its authority, constrain its permissions, inspect its conduct and allocate liability when outcomes go wrong. These are not marginal concerns. They are the preconditions for an economy in which machine agents transact routinely on behalf of people and firms.
The next phase of competition, then, will not chiefly concern who has the most eloquent assistant. It will concern which jurisdictions, standards bodies and market intermediaries can provide the missing infrastructure of machine identity, delegated authority, auditability and recourse. In that sense, the agent economy resembles earlier digital transitions. Broadband mattered, but so did payment rails, browser standards, consumer protection and tax treatment. Intelligence alone does not create a market. Institutions do.
From capability race to institutional bottleneck
The strongest evidence for this shift comes from enterprise behaviour. Firms have become more willing to experiment with agents in customer support, coding, procurement and internal operations. Yet the path from pilot to production remains stubbornly uneven. The technical reasons are well known: brittle planning, hallucinated actions, weak memory and poor reliability across changing environments. More revealing, however, is what happens after these flaws are partially mitigated. Organisations still hesitate, because the unresolved questions are not only technical.
Can an agent be given a spending limit enforceable across tools? Can it authenticate into systems without sharing a human employee's credentials? Can its reasoning path, action chain and data access be reconstructed for audit? Does an insurer understand the operational risk well enough to underwrite it? If an agent breaches procurement policy, misstates a claim to a customer or exposes personal data, who is responsible: the deploying firm, the software vendor, the model provider, or the employee who approved the workflow? Until those questions have practical answers, autonomy will remain shallow even when performance improves.
The hard problem is no longer making agents sound competent, but making them governable in ordinary economic life.
This helps explain why the most commercially viable agent deployments in 2026 are not the most theatrically autonomous ones. They are the systems embedded in narrow, high-structure environments: invoice reconciliation, claims triage, sales operations, software testing, compliance review and logistics exception handling. In such domains the acceptable action space is limited, records already exist, and humans understand what a good process looks like. The agent is useful not because it is generally intelligent, but because it can be supervised, logged and constrained.
Identity before intelligence
The decisive but underappreciated layer is identity. Human-centred digital systems rely on a basic grammar: named users, authenticated sessions, role-based permissions and accountable signatures. Agents disrupt each part of that grammar. A system may act on behalf of multiple people, across multiple applications, at machine speed and with a degree of persistence that exceeds any individual user session. That makes standard identity and access management awkward. An agent is neither a person nor a conventional service account.
As a result, firms are improvising. Some treat agents as glorified macros under a human supervisor. Others issue them service credentials and rely on internal policy wrappers. Neither approach scales cleanly. If an agent is to request a refund, place an order, file a regulatory report or negotiate a service-level adjustment, counterparties need to know what entity authorised it and within what limits. The problem is less about consciousness than about legibility.
This points towards an emerging market for agent identity primitives: verifiable credentials, delegated authority chains, machine-readable policy constraints and revocable attestations. The most important design choice may be to separate identity from capability. A powerful model without a trustworthy identity layer is dangerous and commercially weak. A modest model operating within verifiable permissions may be far more valuable.
The hard problem is no longer making agents sound competent, but making them governable in ordinary economic life.
There is a parallel here with electronic signatures and public key infrastructure. Digital commerce expanded not because every transaction became intelligent, but because enough of them became attributable and enforceable. Something similar is likely for agents. The firms and public bodies that define machine-readable delegation may exert more long-term influence on the agent economy than those that merely improve interaction quality.
Delegated authority is becoming a market design problem
Once identity is established, a deeper question follows: what can an agent legitimately do? Human employment relationships contain a rich mix of formal authority, informal judgement and ex post review. A finance director may approve a payment because policy allows it, but also because context and experience suggest it is sensible. Agents force organisations to codify more of that tacit authority. That sounds like an engineering task. In fact it is an exercise in market design and governance.
Delegation has to be granular enough to be safe, yet flexible enough to be useful. Too little authority and agents collapse back into recommendation systems awaiting constant approval. Too much and they become internal counterparties with unclear mandates. The practical challenge is to encode thresholds, exceptions and escalation routes in ways that can be interpreted across systems. This is especially acute when agents transact externally: procurement bots dealing with suppliers, travel agents purchasing tickets, treasury systems allocating liquidity, or customer-service agents making binding commitments.
Such cases will favour sectors with mature standards and clear process logic. Financial services, healthcare administration, trade logistics and public procurement have cumbersome rules, but also strong documentation habits. Consumer markets are more chaotic. The notion of fully autonomous shopping agents wandering the open web on behalf of millions of users remains technically enticing but institutionally thin. Payments, fraud controls, consumer law, product liability and platform policies all make unconstrained autonomy difficult.
Without reliable identity and delegated authority, an agent is not an economic actor so much as an expensive script.
Liability will shape adoption more than labour substitution
Much public anxiety around agents has centred on jobs. That concern is neither trivial nor misplaced, especially in clerical and coordination-heavy occupations. Yet in boardrooms the more immediate concern is liability. Managers can tolerate efficiency gains arriving gradually. They struggle to tolerate systems that create novel legal exposure. The result is that liability allocation, not labour arithmetic, may become the decisive variable in enterprise uptake.
Current law already offers some guidance. Product liability, professional negligence, consumer protection, employment law and data protection can all apply depending on the use case. But agents complicate causation. Harm may result from a chain involving a model developer, a workflow platform, an integration provider, a deploying firm and a human reviewer. Contracts can distribute some risk, though courts and regulators may not always respect private allocations if public obligations are engaged.
This is where regulatory frameworks introduced in the first half of the decade begin to matter. The EU AI Act, while not written specifically for autonomous agents, strengthens the expectation that high-risk systems require documentation, human oversight and post-market monitoring. GDPR remains relevant wherever agents process personal data, especially if they infer sensitive information or act on inaccurate records. In the United States, federal guidance has been less centralised, but NIST frameworks increasingly function as de facto governance templates. In Britain and elsewhere, sector regulators are shaping expectations case by case.
The commercial consequence is clear. The most investable agent businesses are unlikely to be those promising maximal autonomy across undefined environments. They are more likely to be those operating where liability can be bounded, controls demonstrated and assurance audited. In other words, safety theatre will not suffice. Buyers want evidence that responsibility remains traceable when an automated process enters the real world.
Why payments and procurement are the true proving grounds
A useful way to cut through abstraction is to ask where agents must encounter hard economic constraints. Two domains stand out: payments and procurement. They are mundane, but they convert software action into legally and financially consequential commitments. An agent that drafts a report can be corrected later. An agent that triggers a transfer, agrees a contract variation or purchases inventory creates immediate obligations.
Without reliable identity and delegated authority, an agent is not an economic actor so much as an expensive script.
That is why payment rails, approval hierarchies, spending controls and supplier verification are becoming central to agent system design. In enterprise settings, autonomous action often fails not because the model cannot decide, but because no one is willing to let an unauditable process touch money. This is not conservatism for its own sake. It reflects the fact that commerce depends on confidence in authorisation and settlement.
Procurement is especially revealing. Large organisations already use catalogues, preferred vendors, policy rules and approval chains to manage purchases. These structures are highly compatible with constrained agents. A machine can compare approved suppliers, route exceptions, assemble documentation and negotiate within narrow bands. What it cannot easily do, at least not safely, is exercise broad commercial judgement across ambiguous counterparties and shifting incentives. The first functioning agent markets may therefore look less like open-ended machine commerce and more like tightly governed institutional procurement networks.
Competition will move up the stack
As the market matures, competitive advantage is likely to migrate away from raw model access and towards control over workflows, distribution, trust and switching costs. The UK Competition and Markets Authority was early in recognising that foundation model competition could shape downstream markets. By 2026 the more pressing issue is how power is exercised in the layers above the model: operating systems, cloud environments, productivity suites, payments, identity providers and enterprise data platforms.
Agents amplify existing platform advantages. A provider that controls the application surface, user identity, billing relationship and telemetry can insert agents into everyday workflows with lower friction than a standalone entrant. That does not guarantee success, but it alters market structure. It also raises the prospect that ostensibly open agent ecosystems become dependent on a handful of gatekeepers for permissions, ranking, settlement or data access.
Policymakers should therefore look beyond headline debates about frontier model concentration. Interoperability, data portability, credential standards and fair access to core interfaces may matter more for long-run competition in agent markets. The relevant analogy is not only search or social media. It is also app stores, card networks and enterprise resource planning, where control over chokepoints can determine who captures value.
Data governance is becoming operational, not merely legal
The same is true of data. For several years, AI governance discussions treated data chiefly as a question of training rights, privacy and provenance. Those issues remain important. But agents have shifted attention towards operational data governance: which live systems can be accessed, what records can be modified, how context is refreshed, and how actions are logged against source data.
This is one reason the European Union's Data Act, alongside existing privacy rules, has strategic significance beyond the usual compliance lens. The more agents depend on timely, cross-system access to industrial and enterprise data, the more valuable clear rights and obligations around access, portability and interoperability become. A model trained on public corpora is less commercially potent than an agent that can safely act across a company's actual systems of record.
Yet opening access also widens the attack surface. If agents can discover, retrieve and manipulate operational data at scale, then errors and abuse can propagate faster. Security teams are beginning to treat agent permissions much as they treat privileged human accounts: subject to least-privilege principles, monitoring and rapid revocation. This is sensible. In many organisations the first serious agent incident will not be a spectacular act of rogue autonomy, but a banal permissions failure compounded by speed.
Work will change through supervision, not disappearance alone
Talk of agents often oscillates between two caricatures: mass unemployment or negligible impact. The more plausible outcome lies between them. In many sectors, agents are not replacing whole roles so much as rearranging the distribution of judgement, supervision and exception handling. Routine coordination is increasingly automated; tacit knowledge, accountability and edge-case resolution become more valuable.
This creates new organisational burdens. Someone must define policy boundaries, review logs, adjudicate escalations, certify performance and investigate failures. In effect, firms are creating a layer of machine operations governance that sits between IT, risk, legal and line management. The labour consequence is not merely fewer administrative tasks. It is the emergence of hybrid supervisory work in which humans manage populations of semi-autonomous processes rather than perform every step themselves.
The first durable agent markets are likely to emerge in narrow, rule-bound domains where auditability matters more than fluency.
The quality of this transition will vary widely. In well-run organisations, workers may be relieved of repetitive triage and moved towards oversight and exception resolution. In poorly run ones, staff may inherit impossible accountability for systems they do not control. The International Labour Organization's principles on AI in the workplace are useful here because they stress consultation, transparency and human responsibility rather than deterministic claims about substitution. The workplace politics of the agent economy will turn less on whether software can act, and more on who absorbs the residual risk.
Cross-border frictions will favour sovereign arrangements
The word sovereign is overused in technology policy, but in the agent economy it has practical content. Cross-border software action collides quickly with local rules on data transfer, consumer redress, sector licensing and public-interest obligations. A customer-service agent handling health claims in one jurisdiction, a procurement agent buying dual-use components in another, or a public-sector assistant processing citizen records in a third will all face different legal expectations. That heterogeneity is not disappearing.
For that reason, the global agent economy may develop less like a borderless internet service and more like a federation of partially interoperable compliance zones. Firms will prefer architectures that can localise data, adapt controls by jurisdiction and preserve audit records for local regulators. Governments, meanwhile, are unlikely to accept opaque foreign-controlled agents acting freely in sensitive domains. The geopolitics of semiconductors and cloud infrastructure have already shown how quickly digital dependencies become policy issues. Autonomous software acting inside administrative and commercial systems will sharpen those concerns.
This does not imply autarky. It implies a premium on local assurance, trusted intermediaries and standards that permit interoperability without surrendering oversight. In practice, sovereign capability may mean not domestic models at all costs, but domestic confidence in identity, logging, recourse and policy enforcement.
The first true agent markets will be boring by design
There is a temptation to imagine the arrival of agent markets as a dramatic consumer spectacle: machines haggling across the internet, hiring one another, purchasing services and optimising household life. Some of that may eventually occur. But the earliest durable markets are likely to be surprisingly boring. They will be built in environments with formal records, repeated counterparties, narrow permissions and low tolerance for ambiguity.
Consider the characteristics of such settings. Tasks are frequent enough to automate, valuable enough to justify integration, and structured enough to audit. Counterparties are known. Escalation paths exist. Regulators or internal auditors can inspect the trail. Payment and settlement are standardised. This favours business-to-business processes over general consumer activity, and institutional workflows over open-ended exploration. If there is an irony in the agent economy, it is that its first mature forms may look less like digital freedom and more like bureaucratic competence.
The first durable agent markets are likely to emerge in narrow, rule-bound domains where auditability matters more than fluency.
What mid-2026 has made clear
By mid-2026, one lesson stands out. The future of agents will be decided in the seams between computer science and institutions. Capability improvements remain important, and there is no reason to expect progress to stop. But the harder commercial question is whether autonomous systems can be made accountable enough to inhabit everyday markets. That depends on identity, delegated authority, liability allocation, payment controls, data governance and competition policy.
The winners in this phase may therefore come from unexpected places: not only model laboratories, but standards bodies, enterprise software incumbents, payment networks, insurers, auditors, regulators and firms able to encode messy organisational reality into machine-readable constraints. This is less thrilling than narratives of digital minds roaming freely through the economy. It is also more believable.
The agent economy, in short, is not waiting for superintelligence. It is waiting for paperwork, protocols and public legitimacy. That may disappoint those who mistook eloquence for institution-building. Yet markets have always depended on trusted rules as much as on new tools. Autonomous software will be no different.


