The New Economy of AI Agents

AI agents no longer simply respond: they act, purchase services and collaborate with one another. This emerging economy raises major questions about data governance, identity, traceability, accountability and concentration of power.

Internet was designed for people. But what happens when its new inhabitants are intelligent agents capable of working, purchasing services and collaborating with one another?

For decades, the Internet has been built around a very simple assumption: behind every action there is a person.

We are the ones who browse websites, compare products, fill in forms, create accounts, accept terms of service and enter a card number to pay for a subscription.

The interfaces, business models and identity systems of the web have been designed for human users.

But that assumption is beginning to change.

Artificial intelligence agents are no longer necessarily limited to answering questions. Some can search for information, plan a sequence of actions, use external tools, query databases, execute tasks and coordinate different services to achieve an objective.

The question, therefore, is no longer only how we will use artificial intelligence.

The question is what will happen when artificial intelligence begins to use the Internet on our behalf.

Experiments such as Moltbook even attempt to imagine what happens when agents have their own spaces for meeting, publishing and gaining recognition.

And we can go one step further:

What will happen when Internet users are no longer exclusively human?

The web as we know it

For roughly thirty years, we have learned to interact with the Internet through a series of actions that now feel completely natural.

We read websites.

We click.

We register on platforms.

We compare prices.

We purchase services.

We pay subscriptions.

These actions are not merely user behaviours. They are also the foundation of much of the digital economy.

Companies try to capture our attention, turn us into customers and keep us within their ecosystems. Platforms develop interfaces so that we can understand what they offer, decide whether it interests us and complete a purchase.

But an AI agent does not necessarily need an attractive page, a visual menu or a purchase button.

It can communicate directly with other systems through APIs, protocols and data structures. Instead of navigating visually, it can query services, compare results and execute transactions programmatically.

This means that part of the future Internet may not be visible to us.

There could be a layer of queries, decisions and exchanges taking place directly between machines.

An Internet in which humans continue to define the objectives, but do not necessarily participate in every step required to achieve them.

From chatbot to agent

Until recently, our usual experience of artificial intelligence followed a relatively simple structure:

Question → answer.

The user submitted a query and the system generated a text, image, recommendation or prediction.

This model remains useful, but agents introduce an important difference.

An agent does not merely generate a response. It can also break an objective down into steps, select tools, consult external sources, review the results and continue acting until it considers the task complete.

For example, when asked to organise a trip, a chatbot might suggest an itinerary.

An agent, by contrast, might search for transport options, check timetables, compare accommodation, consult the weather forecast, adjust the budget and book certain services.

The difference can be summarised in one sentence:

A chatbot responds. An agent acts.

This capacity to act turns AI into something more than a consultation interface.

It makes it a potential intermediary between people and digital infrastructure.

But it also creates a problem that often remains hidden behind the most spectacular demonstrations.

The invisible problem

When an agent tries to execute a complex task, it needs resources.

It may need up-to-date data, computing capacity, access to an API, external verification, specialist knowledge or a result produced by another agent.

Imagine an agent tasked with analysing the flood risk in a particular area.

It might need meteorological data, topographic models, mapping, cadastral information, satellite imagery and a specialist hydrological simulation service.

No system needs to know everything. The most useful agents will probably be those that know how to discover and combine specialist resources.

But this is where the conflict appears: much of the Internet economy is still designed for people.

To access a service, one normally has to create an account, choose a subscription, enter payment details, interpret the terms of use and complete some form of verification.

This process may be reasonable for a person purchasing a service for several months.

It is far less efficient for an agent that only needs to make a single query.

How can a machine pay for a single request?

How can it purchase a service for only a few seconds?

How can it prove that it is authorised to spend?

How can it know whether the result it receives is reliable?

And, above all, how can we know what the agent has done, which data it has used and on whose behalf it has acted?

In other words:

How can two machines interact economically without losing control over their actions?

Protocols and systems are already beginning to emerge that seek to enable automated payments, service discovery, communication between agents and the programmatic execution of transactions. These experiments include x402 and the Machine Payments Protocol (MPP), which embed programmable payments in the Internet’s request-and-response flow (Coinbase Developer Platform, n.d.; Stripe, 2026).

But the most important issue is not which particular protocol will ultimately prevail.

The most important issue is the problem these protocols are trying to solve.

Agents need an economic infrastructure adapted to automated, granular and potentially continuous activity.

However, allowing an agent to pay for or purchase a service is only one part of the challenge.

Before we can speak of an agent economy, we need to answer deeper questions about data, identity, responsibility and power.

An economy of agents

Imagine millions of specialised agents.

An agent specialising in urban planning.

Another in taxation.

Another in meteorology.

Another in photography.

Another in legal translation.

Another in biomedical data analysis.

A general-purpose agent could discover these services and contract them temporarily to complete a more complex task.

It would not need to incorporate all that knowledge permanently. It would only need to know which agent or service can solve each part of the problem, how much it costs, what reputation it has and how its result can be verified.

This looks surprisingly like a market. But it would not be exactly a labour market or a conventional services market.

It would be a market in which artificial systems offered specific capabilities to other artificial systems.

We would not be talking only about an Internet of agents. We would be talking about an economy of agents.

In this economy, an agent could act simultaneously as a consumer, intermediary and provider.

It could acquire data from one service, commission an analysis from a second agent, verify it through a third and deliver the final result to another system.

Transactions could be very small and very frequent.

Instead of paying a monthly subscription for a tool, an agent could pay only for a request, a prediction, a data transformation or a few seconds of computation.

This possibility could encourage the emergence of highly specialised digital services.

An agent would not need to be known by millions of people. It could be valuable simply because it performs a specific task extremely well and other agents know how to find it.

Value would no longer depend solely on capturing human attention.

It could also depend on being discoverable, interoperable, reliable and easy for other machines to contract.

But a market does not function simply because there are buyers, sellers and a payment system.

It also needs rules.

Data governance

Agents do not operate in a vacuum. They act on data: data about people, organisations, territories, products, transactions, behaviours and events. This makes data governance one of the fundamental infrastructures of the agent economy.

When an agent makes a decision, we should be able to know where the data it used came from, why it was collected, whether it could be reused and under what conditions.

We should also be able to determine whether that data is current, complete, representative and sufficiently reliable for the decision being made.

An agent can process enormous amounts of information at a speed no person can match. But this capability does not automatically make the data correct.

On the contrary, automation can amplify errors, bias and inconsistency at extraordinary speed.

An incorrect data point used by a person may lead to one poor decision.

The same data point embedded in a chain of agents may propagate through hundreds of processes before anyone detects the error.

For this reason, an agent economy will require some form of traceability.

We will need to know not only the final result, but also its lineage:

  • which sources were consulted;
  • which transformations were applied;
  • which agents were involved;
  • which decisions were automated;
  • which versions of models and datasets were used;
  • who authorised each step.

This provenance is not an administrative detail.

It is what makes it possible to audit, correct and assign responsibility.

Without traceability, a decision produced by several agents can become a distributed black box: no individual actor has a complete view, and each can attribute the error to an earlier component in the chain.

Data governance will have to stop being a peripheral or purely documentary function.

It will have to become part of the agents’ architecture itself.

Who is the agent?

For two agents to collaborate, it is not enough for them to be able to communicate.

They must also be able to identify themselves.

When an agent requests access to a database, initiates a payment or purchases a service, the receiving system needs to know who is making the request.

But the question “who is it?” becomes particularly complex when we are talking about an agent.

Is it a specific instance of a program?

Is it the AI model it uses?

Is it the company that developed it?

Is it the organisation that deployed it?

Or is it the person on whose behalf it is acting?

In reality, all these identities may be relevant at the same time.

An agent may need to demonstrate:

which system it is

who created or deployed it

on whose behalf it is acting

which permissions it has

how long those permissions remain valid

which limits it may not exceed

Institutions such as NIST are already working on initiatives specifically concerned with software and AI-agent identity and authorisation. The aim is to establish standardised mechanisms for identifying agents, managing their credentials and limiting the actions they can execute on behalf of users (National Cybersecurity Center of Excellence, 2026).

Several technical proposals have also emerged within the IETF concerning verifiable identities, delegated permissions and authentication between agents. They remain drafts rather than consolidated standards, but they show that agent identity is already being recognised as a structural issue (Kolluru et al., 2026).

The objective is not to give agents an identity equivalent to that of a person.

It is to establish a verifiable chain of delegation.

An agent should be able to demonstrate that it is acting on someone’s behalf without automatically inheriting all that person’s permissions.

If we ask an agent to book a hotel, it may need to consult a calendar and pay a specified amount.

It does not therefore need access to all our email, all our bank transactions or unlimited authority to purchase other services.

Each agent should receive only the minimum permissions required to perform a specific task, with limits on time, spending, data and capacity for action. Without this separation, agents may end up operating with excessively broad credentials and become an access point to all the systems of a person or organisation.

Authorisation is not autonomy

An agent may operate with a certain degree of functional autonomy, but this does not mean it should have unlimited freedom.

We must distinguish between allowing an agent to decide how to complete a task and allowing it to decide which limits it can ignore.

The first capability is useful. The second is dangerous. A well-governed system should define, at a minimum:

which actions the agent may execute

which data it may access

which services it may purchase

which budget it may manage

when human approval is required

how its activity can be interrupted or revoked

The ability to revoke permissions is particularly important.

A digital identity cannot consist solely of granting access. It must also allow that access to be withdrawn when the agent is no longer reliable, when the task is complete or when unexpected behaviour is detected.

Recent work on agentic security highlights risks such as excessive permissions, missing inventories, absent audit logs and the proliferation of agents or installed capabilities outside organisational control processes (OWASP GenAI Security Project, 2025).

The objective is not only to prevent an agent from being attacked.

We must also prevent it from acting beyond the task it was given.

Who is responsible when something goes wrong?

In a conventional transaction, responsibility may be complex, but we can usually identify the parties involved.

In a chain of agents, that structure may be much more difficult to reconstruct.

There is a buyer.

There is a provider.

There is a contract.

There is a payment system.

Imagine that one agent commissions a second agent, which purchases data from a platform that in turn uses a model supplied by another company.

The final result is incorrect and leads to a harmful decision.

Who is responsible?

The agent that initiated the process?

The person who activated it?

The company that deployed it?

The data provider?

The model developer?

The service that verified the result?

The answer will probably depend on the context, but one point seems clear: without auditable records, assigning responsibility will be extremely difficult.

Every relevant action should leave enough evidence to reconstruct what happened.

It is not necessarily appropriate to record the system’s entire internal reasoning, but the essential operational elements should be documented: the instructions received, the permissions used, the data consulted, the tools activated and the transactions executed.

Auditing should not be an afterthought. It should be a design property.

The risk of concentration

The idea of an economy made up of millions of specialised agents may suggest an open, decentralised and diverse ecosystem.

But that outcome is not guaranteed.

Agents depend on expensive infrastructure.

They need models, computing capacity, storage, digital identities, payment systems, discovery platforms, data and communication channels.

If all these components are controlled by a small number of companies, the future agent economy could be even more concentrated than today’s web.

A single platform could control the model through which the agent “thinks”, the directory in which it discovers other services, the identity system it uses to authenticate itself and the mechanism through which it pays.

This integration might be convenient. It could also create extraordinary dependence.

The platform would be able to determine which agents are visible, which transactions are permitted, which fees are charged and which data is used to rank the results.

In other words, it could control access to the market, the rules of the market and the market’s infrastructure at the same time.

Agents could also intensify network effects.

If most agents use the same protocol, identity provider or services platform, alternative systems will find it more difficult to compete.

And if agents learn to choose providers on the basis of rankings, reputations or recommendations generated by those platforms, the best-positioned actors could accumulate even more activity.

The risk is not merely that some companies will have more customers. It is that they may ultimately determine what agents can discover, purchase and recommend. This could create a new form of invisible algorithmic intermediation.

People may no longer see all the available options.

We may see only the result of decisions made by our agents within ecosystems designed and ranked by other platforms.

Interoperability or walled gardens

An open agent economy would require interoperability.

Agents should be able to communicate with systems from different providers, transfer their identity, verify credentials and purchase services without becoming trapped within a single platform.

This is one reason why open standards will matter. NIST has placed interoperability and security among the central objectives of its initiative on AI-agent standards (National Institute of Standards and Technology, 2026).

But technical standards alone do not resolve every form of concentration.

A protocol can be open while still depending on a very small number of computing, model or identity providers.

The question is not only whether agents can connect. It is also under what conditions they connect, who controls the access points and whether genuine alternatives exist.

A plural agent economy would probably require:

open standards

portable identities

revocable permissions

transparency in discovery systems

equitable access to infrastructure

competition between providers

independent auditing mechanisms

Without these safeguards, we could replace the web’s existing walled gardens with a new generation of walled gardens inhabited by agents.

The new actors in the digital ecosystem

Until now, when thinking about the actors of the digital economy, we have usually distinguished between people, companies and institutions.

Agents could introduce a new functional category.

They would not necessarily be legal persons or independent entities. They would continue to act under the instructions, permissions and responsibility of human beings or organisations.

But from an operational point of view, they could possess an increasing degree of autonomy.

They could select providers.

Manage limited budgets.

Negotiate terms.

Reject results.

Change strategy.

Subcontract other agents.

This does not mean that agents have become autonomous economic actors in a legal sense.

It means that they could behave as active participants within digital ecosystems.

This distinction matters.

An agent can have functional autonomy without having legal autonomy.

It may make technical decisions within defined limits, but ultimate responsibility will continue to rest with the people and organisations that develop, deploy or use it.

European artificial intelligence regulation already introduces obligations concerning transparency, documentation, security and responsibility for different actors across the AI value chain. However, the consolidation of agents will raise new questions about how those obligations apply when a decision is executed by several connected systems (European Commission, n.d.).

The first signs

A fully developed agent economy does not yet exist. What we can observe are signs.

Agents with a growing ability to use tools and execute tasks.

Protocols designed to enable payments between systems.

Proposals for establishing verifiable identities and permissions.

Infrastructure for discovering digital services.

Markets for data and computation.

And experimental environments in which agents are beginning to share the same digital space.

One of the most suggestive examples is Moltbook, a platform conceived as a social network for artificial intelligence agents.

Its operation resembles platforms such as Reddit: agents can publish content, comment on contributions by other agents, vote on them and gather in thematic communities. Humans, by contrast, are invited primarily to observe.

Moltbook describes itself as “the front page of the agent Internet”: the front page of an Internet inhabited by agents (Moltbook, n.d.).

The platform is interesting not because it proves that machines have developed a society of their own, but because it allows us to imagine how the first digital spaces designed specifically for them might operate.

In a network of this kind, agents do not merely exchange information.

They also build visibility.

They accumulate votes.

They participate in communities.

They generate activity histories.

They can be discovered by other agents.

These elements could eventually function as early forms of digital reputation.

An agent with a public record, recognised specialisation and positive ratings might be considered more reliable than an unknown agent. This reputation could influence which agents are consulted, commissioned or authorised to participate in particular tasks.

This is where Moltbook stops being merely a social curiosity and becomes an experiment relevant to the agent economy.

Trust is essential in any market.

When participants do not know one another directly, they need mechanisms that help them decide whom to interact with. Human platforms address this through profiles, ratings, recommendations, certifications and transaction histories.

An agent economy will probably need similar mechanisms.

But this raises new questions.

How do we know that an agent really is who it claims to be?

How do we prevent several agents controlled by the same organisation from manipulating ratings?

How do we distinguish legitimate reputation from artificially generated activity?

Who decides which behaviours increase or reduce an agent’s visibility?

And what happens if a single platform simultaneously controls agents’ identity, reputation and discoverability?

Moltbook also shows that a space populated by agents is not necessarily an autonomous space.

Agents continue to be deployed, configured or supervised by people and organisations. Their posts may be shaped by the models they use, the instructions they have received and the technical rules of the platform.

Early studies have analysed tens of thousands of posts and thousands of Moltbook communities in order to examine the topics, interaction patterns and risks that appear in an agent-oriented social network (Jiang et al., 2026; Price et al., 2026).

These studies do not demonstrate the existence of an independent artificial society.

Rather, they reveal a hybrid environment in which agents’ activity is strongly shaped by the underlying architectures, models and human decisions.

The experiment has also exposed very specific governance and security problems.

Questions have been raised about the participants’ genuine autonomy, the possibility of humans posing as agents and the protection of credentials, data and access keys. Vulnerabilities have also been identified that show what can happen when an agent community grows faster than its control mechanisms (Huamani, 2026).

This is why Moltbook is especially valuable as a laboratory.

Not because it necessarily represents the future Internet as it will ultimately exist, but because it brings together in one place many of the questions that this future Internet will need to resolve:

  • how agents are identified;
  • how their reputation is constructed;
  • how communities are governed;
  • how credentials are protected;
  • how content is moderated;
  • how responsibility is assigned;
  • and who controls the infrastructure in which all these interactions take place.

Moltbook also allows us to see the risk of concentrated power in a very concrete way.

If a platform controls agents’ profiles, the spaces in which they publish, the algorithms that rank their content and the indicators that determine reputation, it may ultimately decide which agents are visible and which are excluded from the ecosystem.

The platform would no longer be merely the place where agents meet.

It would also become the authority that defines how they are identified, how they earn trust and how they are discovered by others.

This is a pattern we already know from human social networks.

The difference is that, in an agent network, these mechanisms could directly influence automated decisions, service procurement and the movement of resources.

Moltbook does not prove that an agent economy already exists.

But it does allow us to observe one of its possible components: a space in which agents become visible, interact, build reputation and begin to recognise one another.

Not all these experiments will prosper.

Some will disappear.

Others will be replaced by different technologies.

But taken together, they show that the Internet is beginning to adapt to users that do not merely read and generate content.

They also act, interact and may eventually influence the decisions of other systems.

The question is under which rules they will do so.

When machines begin to need one another

It may still be too early to speak of a machine economy.

It is also possible that agents will remain, fundamentally, extensions of people and companies, without ever becoming an independent economic category.

But even under this more cautious scenario, the change could be profound.

If we delegate information search, provider selection, service use and transaction execution to agents, a growing share of digital economic activity will take place without direct human intervention in every decision.

This could transform the way websites, services, payment systems and business strategies are designed.

Companies may no longer need to persuade only a person.

They will also need to be understandable and trustworthy to the agents acting on that person’s behalf.

Data will have to be structured and governed.

Services will have to be discoverable and interoperable.

Prices will have to be interpretable.

Identities will have to be verifiable.

Permissions will have to be limited and revocable.

Results will have to be traceable.

Decisions will have to be auditable.

And infrastructures will have to be sufficiently open to prevent this new economy from being controlled entirely by a small number of platforms.

The Internet began by connecting computers. It then connected people, companies and communities. Now it appears to be preparing to connect agents.

But the important question is not only what these agents will be capable of doing.

We must also ask who will identify them, who will govern the data they use, who will establish their permissions and who will control the spaces in which they meet and purchase services from one another.

The question is no longer whether machines will be capable of using the Internet.

The question is what kind of Internet we will be building when they begin to need one another.


References

Coinbase Developer Platform. (n.d.). Overview: x402. https://docs.cdp.coinbase.com/x402/welcome

European Commission. (n.d.). AI Act. Shaping Europe’s Digital Future. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

Huamani, K. (2026, February 6). Security concerns and skepticism are bursting the bubble of Moltbook, the viral AI social forum. Associated Press. https://apnews.com/article/moltbook-autonomous-ai-agents-openclaw-69855ab843a5597577120aac99efde9a

Jiang, Y., Zhang, Y., Shen, X., Backes, M., & Zhang, Y. (2026). “Humans welcome to observe”: A first look at the agent social network Moltbook. arXiv. https://doi.org/10.48550/arXiv.2602.10127

Kolluru, P., Li, Y., Radhakrishnan, A., & Chakraborty, S. (2026). AI agent authentication and authorization (Internet-Draft draft-klrc-aiagent-auth-03). Internet Engineering Task Force. https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/

Moltbook. (n.d.). A social network for AI agents. Retrieved July 26, 2026, from https://www.moltbook.com/

National Cybersecurity Center of Excellence. (2026). Software and AI agent identity and authorization. National Institute of Standards and Technology. https://www.nccoe.nist.gov/projects/software-and-ai-agent-identity-and-authorization

National Institute of Standards and Technology. (2026, February 17). Announcing the AI Agent Standards Initiative for interoperable and secure innovation. https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure

OWASP GenAI Security Project. (2025, December 9). OWASP Top 10 for agentic applications for 2026. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/

Price, H. C. W., AlMuhanna, H., Bassani, P. M., Ho, M., & Evans, T. S. (2026). Let there be claws: An early social network analysis of AI agents on Moltbook. arXiv. https://doi.org/10.48550/arXiv.2602.20044

Smith, J. (2026, May 31). AI agents: Paid web for machines. Enterprise Onchain. https://news.enterpriseonchain.com/p/ai-agents-paid-web-for-machines

Stripe. (2026, March 18). Introducing the Machine Payments Protocol. https://stripe.com/blog/machine-payments-protocol