Market Analysis
Every well-funded team in the agent-commerce category is building the same thing: a faster, cheaper way to move money. Almost nobody is building the layer that decides whether an agent should be allowed to move it at all.
In the last eighteen months, "AI agents that pay for things" went from a demo trick to a funded category. Every hackathon has an agentic-payments track. Every major infrastructure player has shipped a standard for it. The pattern is now clear enough to describe precisely, and once you see it, the gap in the category becomes obvious.
x402 (the "402 Payment Required" pattern for machine-to-machine payment) moved from a spec to production faster than almost anything else in this space. Coinbase and Cloudflare are behind the foundation stewarding it. Visa, Mastercard and Ripple are engaging with it. By mid-2026 it had processed on the order of tens of millions of transactions across roughly 75 million cumulative calls. That is not an early-stage primitive anymore. It's a rail, and it's already owned.
Look at who's winning the funded competitions in this category: teams building agentic clearing, agent-to-agent settlement, routing layers on top of x402 and ERC-8004. They're good teams solving a hard problem. But they're all solving the same problem: how does money move faster and cheaper between two agents. That problem is closing, not opening. A themed hackathon bounty is alpha only while the category is still novel; once the pattern is understood, it attracts clones faster than differentiation.
The wallet-infrastructure incumbents, the well-known custody and embedded-wallet platforms serving this space, all offer some version of spend limits, allowlists and session-scoped keys. But in every case it's a feature attached to a wallet product, configured through a dashboard, enforced by a policy engine that sits next to the signing key rather than in front of it.
That's a meaningfully different thing from a standalone, neutral, auditable authority primitive: infrastructure whose entire job is deciding what an agent may do, independent of which wallet, which chain, or which application is asking. Nobody in the category is shipping that as the product, on-chain, enforced before settlement rather than configured alongside it.
"Agentic AI is blockchain's killer use case" isn't a claim about payment volume. It's a claim about who gets to authorize what a machine is allowed to do with money it doesn't own.
Pull the numbers from any large hackathon dataset in this category and two things jump out. First, sponsor money manufactures apparent trends: at events with thousands of submissions, a single major sponsor has funded roughly half of all agent-track prizes. That tells you where the marketing dollars go, not where the unowned ground is. Second, agents only meaningfully outperform other categories inside events specifically themed around agentic use cases. Outside of that framing, the category is noisy.
Meanwhile the crowded, cloned categories are easy to spot from the outside: cross-chain swap tooling has been the worst-performing category in aggregate submission data, because it attracted hundreds of near-identical entries chasing a small prize pool. That's what a solved, commoditizing problem looks like from the data. Payments-for-agents is heading the same direction. Authority isn't there yet.
Bounded authority is not a bigger spend-limit checkbox. It's a different question entirely: given that a human has delegated some scope of financial action to a piece of software, what enforces the boundary of that delegation when the software is wrong, compromised, or simply doing something the human didn't intend? Does that enforcement happen before money moves, or after?
Every credible answer to that question that we've seen shares three properties:
That's a primitive, not a feature. Primitives get built once and get depended on by everyone downstream of them, which is exactly why almost nobody has built one yet. It's a harder, less glamorous problem than shipping a payment rail, and the market hasn't rewarded it yet the way it's rewarded x402 adoption.
We think the category is going to bifurcate the same way every infrastructure category eventually does: a commoditized settlement layer that everyone uses and nobody differentiates on, sitting on top of a much smaller number of authority primitives that the entire ecosystem ends up depending on. We're building for the second layer. We think that's where the actual moat is, and where it will still matter after the payments-rail conversation is over.
This piece reflects our own reading of public market data and is not financial or investment advice. Where we describe our own infrastructure, we describe it at the level we would describe any engineering system generally. Some implementation specifics are intentionally withheld while related patent applications are in progress.
We talk to teams working on agent infrastructure most weeks. If you're thinking about the authority layer specifically, we'd like to compare notes.
Get in touch