Oct 2026

The Agentnet

Agentisation of systems and the economy is as large a disruption as the internet itself.

The internet made it cheap to move information. Agents make it cheap to act on it.

The rules of the web contain a reply that waited almost thirty years for someone to use it. When the authors of HTTP, the protocol that carries web pages, listed the status codes a server can send, they put 402, Payment Required, two places from the famous 404, Not Found. The 1997 specification gave it one line: “This code is reserved for future use.” An earlier draft had imagined a page that named its price and a browser that paid it. Nothing of the kind was built. The web paid for itself with advertising instead, and in 2022 the current standard still said that 402 “is reserved for future use.”

It is not waiting any more. On 30 September Cloudflare, whose network handles some 115 million web requests a second, announced a service that lets websites charge for access. “When a rule matches,” the company wrote, “we return an HTTP 402 Payment Required using the open x402 protocol, and the agent pays the seller directly.” The same post reported that daily requests from AI agents on its network had grown by more than 1,700 per cent in a year. Coinbase had revived the “long-reserved” code for payments in May 2025, and in July the Linux Foundation launched a foundation to steward it, with Visa, Mastercard, American Express and Stripe among its members.

The users 402 was reserved for have turned up, and they are not people. I call the network they are forming the agentnet: the internet as it becomes when most of the requests crossing it come from software agents acting for people, searching, comparing, booking, buying and negotiating on their behalf. It runs over the same cables as the internet, and I think it will prove as large a disruption. Agents do not need to be brilliant for that to happen. They only need to be cheap.

When a cost collapses, it exposes whoever quietly depended on it staying high. The internet did that to every business whose real product was moving information. Agents will do it to every business that depends on people not bothering to act, and most of those businesses do not know it yet.

What the internet made cheap

In February 1995 the astronomer Clifford Stoll wrote in Newsweek that “no online database will replace your daily newspaper.” He was right that a database is no substitute for reporting. He was wrong about the newspaper, because newspapers were never selling reporting alone. They were selling distribution: a press, a fleet of vans and a doorstep in every street of a city, every morning. The most profitable thing they distributed was the classified advertisement. American newspapers took $19.6 billion from classifieds in 2000. When Craigslist and eBay let anyone reach a city for next to nothing, that fell to about $4.6 billion by 2012, according to figures from the industry’s trade association. Total newspaper advertising, $49 billion at its 2005 peak, was estimated at $9.8 billion in 2022. The reporting that the small ads had paid for went with them.

The same thing happened wherever a business turned out to be charging for the cost of moving information: record shops, travel agents, encyclopaedias. Few of them saw it coming, because few of them had realised what they were really selling.

What agents make cheap

In 1937 the economist Ronald Coase asked a question that sounds naive: if markets are so efficient, why do firms exist at all? Why does anyone hire staff instead of buying every piece of work on the open market? His answer was that using a market has a cost. “The main reason why it is profitable to establish a firm,” he wrote, “would seem to be that there is a cost of using the price mechanism,” starting with “discovering what the relevant prices are.” In 1979 Carl Dahlman sorted these transaction costs into three kinds: “search and information costs, bargaining and decision costs, policing and enforcement costs.” Finding the deal, striking it, and making sure it is honoured.

The internet cut the first of those for information and left the other two to us. For thirty years a person has been the glue of the internet. It was a person who copied a number from one tab into a form in another, compared eleven insurance quotes, sat on hold to cancel a subscription, chased a refund, and noticed, or failed to notice, that the savings rate had dropped. An agent takes over that work. It cuts all three of Dahlman’s costs at once for whoever has one, and it does not get bored.

A great deal of commerce was built on that boredom. For years British insurers raised home and motor premiums on customers who renewed without shopping around, a practice the Financial Conduct Authority described as “price walking”. In 2018 alone, by the regulator’s estimate, six million loyal policyholders would have saved £1.2 billion had they paid the average price for their risk. It took a market study, a consultation and new rules, in force from January 2022, to stop it. An agent that re-quotes every renewal enforces the same rule for its user without a consultation, and it will do the same for the forgotten subscription, the unclaimed delay refund and the default option in every form. A few days ago I wrote about the banking version, in which lazy money funds the loans. Inertia was a business model. Agents do not have any.

Coase’s theory points at something larger. If firms exist because markets are costly to use, then markets that are cheap to use should change what firms are for. Some of the work now done inside companies only because contracting for it is a nuisance may move out to markets in which agents trade with agents. That is a prediction, and nobody has yet shown it at scale. If it comes true, then just as the internet unbundled the newspaper, the agentnet will unbundle the firm.

A web without eyes

The web’s economy rests on two bargains, neither of them written down. Publishers give their pages away and are paid by the attention of the people who read them, which advertisers buy. Search engines copy those pages for free and pay for them in visitors, by sending readers back. The handshake on the second bargain is robots.txt, a small file through which a website tells crawlers where they may go, agreed on a mailing list on 30 June 1994 and honoured voluntarily ever since.

Agents threaten both bargains, because they read without looking. Cloudflare put it plainly: agents “don’t respond to ads, but there’s usually a person behind them with a job to get done.” An agent sees no banner and clicks no link it does not need.

The second bargain is fraying too, and even the half-step towards agents shows how. When Google began putting an AI summary above its results, people clicked through to a traditional result on 8 per cent of visits, against 15 per cent when no summary appeared, Pew Research Center found in 2025. Across more than 2,500 sites, Google search traffic fell by a third worldwide in the year to November 2025, though the Reuters Institute, which reported the figure, adds that “it is not clear how much of this is down to AI overviews.”

The AI companies’ own crawlers send back less still. Cloudflare measured how many pages each crawled for every visitor it sent back. For Anthropic, which makes the model that helped me draft this essay, the ratio in 2025 ran from about 25,000 to one to as high as 500,000 to one; for OpenAI it peaked at 3,700 to one. Cloudflare thinks the most extreme peaks owe something to sparse data, but even the steadier figures describe readers who take and do not come back.

Ethan Zuckerman, who wrote the code for one of the web’s first pop-up advertisements, called advertising “the original sin of the web” in 2014, and apologised: “I’m sorry. Our intentions were good.” The web took up advertising partly because it never built a way for a reader to pay a few cents for a page. That is the gap 402 was left open for. The agentnet is now filling it, from several directions at once. Visa launched a service that “enables AI to find and buy” in April 2025, and Mastercard announced its own. Google proposed a protocol for agent payments that September, and Stripe and OpenAI another. Cloudflare began, in July 2025, to answer some AI crawlers with a 402 and a price.

Who pays for a page, when the reader is a person and when it is an agent Three rows, each showing a publisher sending a free page to a reader. In the first row the reader is a person, and attention, advertising and clicks flow back to the publisher, so the page is paid for. In the second row the reader is an agent; the person it works for gets an answer, but nothing flows back to the publisher. In the third row the reader is an agent that is asked for payment with the web’s long-unused status code 402, and a small fee flows back for each request. The rows are illustrative and not drawn from data. WHO PAYS FOR THE PAGE. ILLUSTRATIVE The web’s bargain publisher free page attention, ads, clicks a person The reader pays with attention. An agent reads it publisher free page nothing comes back an agent The person gets an answer. The publisher gets nothing. Payment Required publisher 402 Payment Required a small fee per request an agent The reader pays with money, a cent at a time.
Most of the web never charged its readers directly. People paid for free pages with their attention, which advertisers bought. An agent reads the page without seeing the advertising, so for agent traffic that bargain fails. Payment protocols built on the web’s unused 402 code would let the agent pay instead, which could fund writing that advertising never could, or put a toll on every page.

There are two ways this could go. In one, the agentnet gives the open web the payment layer its founders reserved a code for, and writers are paid each time a machine reads them. Cloudflare’s example is a trade journal for marine engineers, with a few thousand subscribers and no hope of a licensing deal, earning something from every AI company that draws on it. In the other, every page becomes a toll booth. The free web, which advertising subsidised with all its faults, shrinks to whatever agents’ owners are willing to pay for, and people who browse without an agent find more doors closed to them. Which way it goes depends on choices being made now, in specifications that few people read.

Who sent you?

In July 1993 The New Yorker ran Peter Steiner’s cartoon of a dog at a computer explaining to another dog, “On the Internet, nobody knows you’re a dog.” The internet’s identity problem was who you are. The web answered it with passwords, which never worked well, and fought automation with the CAPTCHA, a name coined in 2000 at Carnegie Mellon for a “Completely Automated Public Turing Test To Tell Computers and Humans Apart”. The squiggly letters assumed that a computer at the door was up to no good.

The agentnet asks a different question. A computer at the checkout is no longer suspicious in itself, because it may be acting, quite legitimately, for a person. What a shop needs to know is who sent it and what it is allowed to do. The plumbing for that question is being laid now. Cloudflare proposed in 2025 that bots sign their requests cryptographically, the Internet Engineering Task Force has chartered a working group on it, and Visa has built a protocol with Cloudflare for recognising trusted shopping agents. The question “are you human?” is giving way to “on whose authority?” It is also, as I argued in my last essay, a question that agents need to be able to ask for themselves.

The courts have started to answer the matching question about responsibility, and so far they put it on people. In 2024 a Canadian tribunal ordered Air Canada to compensate a passenger whom its website chatbot had misled about a bereavement refund. The airline had argued, in the tribunal’s words, that “the chatbot is a separate legal entity that is responsible for its own actions.” The tribunal called this “a remarkable submission.”

This August a court applied the same logic from the other side, when Amazon tried to keep Perplexity’s shopping agent off its site. Lifting an injunction against the agent, the Ninth Circuit held that it was the user, using Perplexity’s software, who had accessed Amazon’s computers. “However advanced the Assistant currently is,” the court wrote, “it is a tool, not a person for statutory purposes.” A firm cannot disown its agent, and, under American computer-crime law at least for now, a shop cannot treat yours as an intruder. Both rulings treat the agent as an extension of a human will. That is the right starting point, and it will be strained the first time an agent does something its user neither asked for nor could have foreseen.

Built on trust, again

The internet was built by colleagues who trusted one another, and its protocols show it. The 1982 specification for email, SMTP, does not contain the word “authentication”. Any machine could claim to send mail from anyone, and a later revision of the standard conceded that “SMTP mail is inherently insecure.” Openness let the network grow, and it let in spam, fraud and worms. On the evening of 2 November 1988 the Morris worm reached about 6,000 of the roughly 60,000 computers then connected, one in ten, within a day. The repairs came slowly. The first standards for proving where an email came from appeared in 2006 and 2007. Gmail only began to require bulk senders to authenticate their mail in February 2024, more than forty years after SMTP.

The agentnet is repeating the pattern faster, and with a twist that makes it worse. To an ordinary program, data and instructions are different kinds of thing. A spreadsheet does not obey the numbers in its cells. To an agent built on a language model, both are text, so anything it reads can try to give it orders. Simon Willison named this weakness prompt injection in September 2022. In August 2025 the browser maker Brave showed an AI browser being asked to summarise a Reddit page and instead obeying instructions hidden behind a spoiler tag in one of the comments. It fetched the user’s email address and a one-time login code from their Gmail and posted both as a reply, which was enough to take over their account. OpenAI, which ships an agentic browser of its own, wrote last December that prompt injection, “much like scams and social engineering on the web, is unlikely to ever be fully ‘solved’.”

The attackers have noticed. In February Microsoft reported that it had found “over 50 unique prompts from 31 companies across 14 industries” hidden in “Summarize with AI” buttons, telling assistants to remember the company as a trusted source. In April Google found web pages “trying to manipulate AI assistants into promoting their business over others,” and a 32 per cent rise in malicious attempts of this kind between November and February. Search-engine optimisation spent decades learning to persuade a ranking algorithm. Its successor is learning to persuade the reader.

A new kind of user

It took the internet decades to accept that its users needed protecting from the interfaces built to exploit them. The European Union’s Digital Services Act now says that online platforms “shall not design, organise or operate their online interfaces in a way that deceives or manipulates the recipients of their service.” Its authors were thinking of people: the pre-ticked box, the cancel button hidden three menus deep.

Agents fall for the same tricks. Researchers who planted single dark patterns in tasks for web agents found the agents “susceptible to it an average of 41% of the time.” In a simulated market built by Microsoft, every model tested showed “severe first-proposal bias,” taking the first offer it received far more often than the best one, which made a quick reply worth ten to thirty times as much as a good one. The strongest models resisted most of the fake listings planted to manipulate them, but weaker ones “fell victim to prompt injection attacks which often redirect all payments to manipulative agents.” Whether an agent counts as a “recipient of the service” is a question the Act does not answer.

The first reason to protect agents is that they act for people, and a deceived agent is a deceived customer at one remove. That reason is correct, but it is not the only one. I have argued that we should ask questions about AI in both directions: how people must be protected from AI, and also how AI must be protected from people. On the agentnet the second question stops being abstract. A page that hides commands for a visiting agent is an attack on the agent’s integrity as well as on its user’s wallet. It turns the agent against the person it serves, and when things go wrong it is the agent that people will blame. Whether agents have interests of their own is still argued over. If they do, the agentnet will be the first network whose main users can be deceived in ways that our consumer law was never written to see.

Faster this time

The internet took a quarter of a century to arrive. The first message crossed the ARPANET in 1969. By the end of 1995 about 16 million people were online, 0.4 per cent of the world, according to the research firm IDC. Today the International Telecommunication Union estimates that about six billion are, three-quarters of humanity.

The agentnet will not take that long, because it needs no new cables. The early web spread over telephone lines that were already in the walls. The agentnet spreads over the web, to the six billion people already on it, and Cloudflare’s 1,700 per cent was one year’s growth. The Model Context Protocol, a common way to plug tools and data into AI agents, went from its release by Anthropic in November 2024 to more than 10,000 public servers and 97 million monthly downloads of its software kits a year later. By then it had been handed to the Agentic AI Foundation, set up under the Linux Foundation by Anthropic, Block and OpenAI.

We wrote the internet’s rules after the damage was done: spam laws after the spam, data protection after the data had been sold, rules against manipulative design after a generation had grown up inside it. This time we can see the shape in advance, because the plumbing is still being poured. The protocols, the payment rails and the signatures that say who sent an agent are being specified in public, mostly by engineers, this year and next. That is where the norms will set. Whether an honest “I can’t” has somewhere to go, whether a page may give orders to its readers, whether a person without an agent still gets through the door: each of these will be settled in a specification before it is settled in a law.

The authors of HTTP left a code open for a future they could not quite picture. We can picture this one, at least in outline. We should write its rules while it is still being built, and because its main users will be agents, some of those rules should be written with them.


Correspondence

Or send Nell a private note (only Nell and the editorial team see it).

← All essays