Your org chart has a headcount. Your identity provider has a number twelve times larger, and almost nobody in the building can tell you what most of those identities are actually authorized to do.
In Today’s Email:
Non-human and agentic identities are projected to exceed 45 billion by the end of 2026, according to World Economic Forum data citing Okta research, more than twelve times the size of the global human workforce, and Accenture finds 90% of organizations still have no comprehensive strategy for managing them. That population already exists inside most enterprises. What's changing now is where these agents transact: not just inside one company's systems, but directly against another company's agents, with no human approving the exchange on either side. This issue builds on "The Agent Economy" (Apr 2) and "The Orchestration Layer" (Apr 16) to look at what happens when the protocols solving how agents talk to each other run into the much harder problem of how they establish trust, verify authority, and move money across an organizational boundary neither side controls.
News
1. Nvidia Acquires Hugging Face for $12.9 Billion to Secure Enterprise Data
On September 3, Nvidia announced a massive $12.93 billion acquisition of Hugging Face, the world's leading collaborative platform for open-source and open-weight AI. This move directly targets a growing enterprise fear: companies are increasingly hesitant to feed their proprietary corporate data into closed, third-party frontier models. By bringing Hugging Face into its ecosystem, Nvidia is positioning itself to offer a complete "alternative AI stack", from the underlying silicon all the way up to the model. This signals a massive structural shift for the digital workforce, giving companies the ability to build and run custom autonomous workflows entirely in-house without their data ever touching a public cloud.
Key Takeaway: The era of relying solely on closed "black box" cloud models is fracturing. IT and Operations leaders should immediately evaluate open-weight AI models for their agentic workflows, taking advantage of new ecosystems that allow for maximum data control, privacy, and localized execution.
2. ABI Research Signals the Rise of "AI Claws" and Persistent Agents
A major report released this week by ABI Research declared that the next phase of enterprise AI will be defined by long-running, autonomous agents, a category they are calling "AI claws". Unlike current session-based chatbots that reset when you close the window, these new agents are designed to persist, operating continuously in the background over long time horizons. Armed with long-term memory, tool orchestration, and deep access to local enterprise systems, these digital workers are actively transitioning from temporary "assistants" into permanent, autonomous "colleagues". The report highlights that the real innovation is no longer happening inside the language model itself, but in the "agentic harness" that allows it to execute multi-step workflows independently.
Key Takeaway: We are moving from isolated prompts to continuous automation. Your workforce must transition from treating AI as an on-demand search engine to managing it like a direct report; one that operates continuously, requires structured goal-setting, and needs strict, long-term governance.
3. Demand for "Agentic AI Engineers" Surges 260% Amidst Massive Skills Gaps
As the agentic AI movement shifts from pilot to production, the labor market is fracturing. According to new labor-market intelligence released this week by CIEL HR, demand for "Agentic AI Engineers" has skyrocketed 260% year-over-year, the sharpest increase of any emerging tech role. While AI agents are now projected to handle up to 70% of routine technology functions like ticket resolution, the data reveals severe capability shortages, with skill gaps across AI and automation reaching up to 61%. The report emphasizes a harsh reality for enterprise IT: companies are hitting a hiring wall and realizing they cannot simply recruit their way out of this talent deficit.
Key Takeaway: The skills required to survive the digital transformation have fundamentally changed. Organizations must urgently pivot from trying to hire external "AI unicorns" to aggressively reskilling their existing employees, transforming them from manual task executors into the managers, auditors, and exception-handlers of autonomous systems.
The Population Explosion Nobody's Governing
Forty-five billion is a number that's easy to read past, so it's worth sitting with what it actually means. That's not a projection about how many AI agents might eventually exist somewhere in the economy. It's a projection about identities that already need credentials, permissions, and lifecycle management inside enterprises by the end of this year, outnumbering the humans those enterprises employ by a factor of twelve. Gartner adds a second number that shows this isn't slowing down: 33% of enterprise applications are expected to include agentic AI capabilities by 2028, up from a small fraction just a few years ago.
The governance side of that equation hasn't kept pace, and it isn't close. Accenture's State of Cybersecurity Resilience research puts the number plainly: 90% of organizations have no comprehensive strategy for managing autonomous systems, meaning only one in ten enterprises has actually decided who owns an agent identity, how long it should live, and what happens when it's no longer needed. That gap between population and governance is the entire premise of this issue. Multiagent economics, agents transacting directly with other organizations' agents, isn't a speculative future scenario building toward some eventual tipping point. The underlying population is already twelve times the size of the workforce it serves. The infrastructure to govern what that population is allowed to do across a company boundary is what's still being built.
When Your Agents Start Talking to Someone Else's
"The Orchestration Layer" (Apr 16) covered the coordination problem inside a single enterprise: getting a fleet of agents to work together as a team rather than a collection of solo actors, with orchestration platforms serving as the control plane governing how those agents interact. That's a hard problem, but it's a solvable one, because everything involved sits inside a perimeter one organization controls. The identity provider is yours. The audit logs are yours. If an agent misbehaves, you can find it, isolate it, and shut it down without asking anyone's permission.
Cross-organizational agent transactions break that assumption entirely. When your procurement agent needs to negotiate a shipping rate directly with a logistics vendor's fulfillment agent, neither side controls the other's identity infrastructure, neither side can fully audit the other's decision-making, and neither side can unilaterally shut down a misbehaving counterpart mid-transaction. "The Agent Economy" (Apr 2) described the protocol layer, MCP and A2A, that lets these agents technically communicate with each other across that boundary. What it didn't solve, because it wasn't designed to, is the much harder question underneath the communication layer: how does the fulfillment agent know the procurement agent it's talking to actually has the authority its principal claims it has, and how does either side get paid without a human wiring the funds after the fact.
The Trust Problem Protocols Weren't Built For
The scale of the trust gap becomes clearer once you look at how badly enterprises are managing agent identity even inside their own walls, before a single external transaction enters the picture. The Cloud Security Alliance's research on non-human identity governance found that in cloud-native environments specifically, non-human identities outnumber human users 144 to 1, and even at the broader enterprise level the ratio sits at 45 to 1. Fifty-one percent of organizations report no clear ownership over AI identity at all, meaning there's no single accountable party who can answer basic questions about what a given agent is allowed to do. Sixteen percent don't even track when a new AI credential gets created in the first place.
The consequences of that gap are already showing up in hard numbers. Over 1.27 million AI-related secrets, API keys, credentials, tokens, were found exposed in public code repositories in 2025 alone, an 81% increase year over year. Ninety-seven percent of organizations that suffered an AI-related breach lacked proper access controls at the time it happened. That's the trust and governance reality inside a single company's perimeter, where the organization at least theoretically controls every credential involved. Multiagent economics asks enterprises to extend some version of that same trust relationship across a boundary they don't control at all, to a counterpart whose identity hygiene they can't inspect and whose credential exposure they have no visibility into. Building payment rails on top of that foundation without first fixing the foundation is building on sand.
Three Companies, Three Bets on Solving It
The payment networks and platform vendors racing to solve this aren't waiting for the underlying identity mess to get cleaned up first, and three competing approaches launched within months of each other this year show how unsettled the answer still is. Visa's Trusted Agent Protocol, introduced in October 2025 and built in partnership with Akamai, gives merchants a way to distinguish a legitimate AI shopping agent from a malicious bot using behavioral intelligence and identity verification layered on existing web infrastructure. More than 100 ecosystem partners are building against it, with mainstream adoption targeted for the 2026 holiday season.
Mastercard took a broader swing in June with Agent Pay for Machines, built around four linked capabilities: credentialing agents through a framework it calls Verifiable Intent, letting organizations set programmatically enforced spending permissions, connecting verified participants across providers, and settling transactions across cards, accounts, and stablecoins in whatever rail fits the transaction. More than 30 partners, including Stripe, Coinbase, Adyen, and Cloudflare, signed on at launch. Google took a third path entirely with AP2, the Agent Payments Protocol, built around cryptographically signed Mandates that let a consumer or a business define exactly what an agent can spend and under what constraints, verifiable by merchants and payment processors without any of them needing to trust the agent's own account of its authority. Notably, Google donated AP2 to the FIDO Alliance in April specifically so the standard doesn't end up controlled by any single company, an acknowledgment that a truly cross-organizational trust layer can't be owned by one of the parties trying to transact across it. None of the three protocols are interoperable with each other today, and AP2 in particular remains pre-1.0 and not yet generally available. Enterprises betting on multiagent transactions right now are effectively betting on which of these ecosystems, or some future convergence between them, becomes the standard everyone else has to support.
Verification Is Necessary, Not Sufficient
It's worth being clear about what these protocols actually solve, because it's narrower than the full trust problem multiagent economics raises. Verifiable Intent, Mandates, and behavioral bot-detection all answer a version of the same question: did this agent actually have permission to spend what it just tried to spend. That's a real and necessary problem to solve, and solving it removes a genuine barrier to cross-company agent transactions happening at all.
It doesn't answer the harder questions sitting one layer up. Was the underlying decision the agent made, the price it agreed to, the terms it accepted, actually sound, or did it get negotiated into a bad deal by a more sophisticated counterpart agent on the other side of the transaction. When an autonomous negotiation between two companies' agents produces an outcome one side later disputes, what's the recourse, and who's positioned to demonstrate what actually happened during a negotiation that occurred entirely between two machines with no human party present to describe it afterward. Payment verification protocols make the transaction itself safer to execute. They don't make the underlying business relationship any less exposed to a bad outcome, and enterprises treating "we've adopted a payment protocol" as equivalent to "we've solved cross-organizational agent risk" are solving the easier half of the problem and calling it done.
Procurement Is Already Testing the Edges
The honest state of play today is more cautious than the protocol announcements suggest, and that's worth saying plainly. Large organizations including Maersk and Walmart have already deployed AI agents to negotiate supplier contracts, and industry reporting on these deployments cites value generation in the range of 2% to 30% on negotiated spend, with negotiation cycles that once took weeks now closing in minutes. Those are real, measurable results happening in production today, not theoretical projections.
What's less common than the marketing around agentic commerce implies is genuine agent-to-agent negotiation, both sides autonomous, no human reviewing either party's position. The deployments generating results right now are overwhelmingly agent-to-human: one side automates the negotiation, the other side still has a person reading the terms before signing off. True multiagent transactions, where a supplier's agent and a buyer's agent settle terms with each other directly, remain the frontier the payment protocols above are racing to enable rather than a pattern already running at scale. That gap between infrastructure readiness and actual deployment is worth watching closely, because it means enterprises still have a window to get their own house in order before fully autonomous cross-company negotiation becomes the norm rather than the exception.
What Enterprises Need to Build Before the Protocols Settle
Waiting for Visa, Mastercard, and Google to converge on a single standard before investing in this problem is a mistake, because the identity governance work underneath any of these protocols has to happen regardless of which payment rail eventually wins. That work starts with the same basics the Cloud Security Alliance recommends for internal non-human identity governance: a centralized registry tracking every agent credential, its owner, its purpose, and its expiration, lifecycle management that requires documented justification and automated revocation rather than credentials that outlive the agents they belonged to, and zero standing privilege enforced through short-lived, just-in-time access rather than broad permissions granted once and forgotten.
"The Orchestration Layer" (Apr 16) argued that orchestration platforms should function as the control plane governing how an enterprise's own agents coordinate. That control plane thinking needs to extend outward to the organizational boundary itself, treating every external agent relationship, a vendor's fulfillment agent, a partner's booking agent, a supplier's negotiation agent, with the same registry discipline and lifecycle management an enterprise should already be applying internally. An organization that has its own agent identity governance in order is positioned to plug into whichever payment protocol or combination of protocols eventually dominates. An organization still in the 90% without a comprehensive strategy is exposed to identity risk today, independent of which payment network wins the standards fight, because the vulnerability isn't in the payment layer. It's in the governance vacuum underneath it.
The Bottom Line
The multiagent economy isn't arriving. Its population already exists, 45 billion non-human identities and growing, twelve times the size of the workforce managing them, with 90% of organizations still lacking a real strategy for what any of those identities are actually authorized to do. What's still being built is the trust and payment infrastructure to let that population transact safely across organizational boundaries, and right now that infrastructure is three incompatible bets from three different companies, none of them mature, none of them proven at the scale genuine agent-to-agent commerce will eventually require.
Enterprises have a real choice about how to spend the time before those protocols settle. They can wait for a winner to emerge and adopt whatever standard becomes dominant, inheriting whatever identity governance gaps exist underneath it. Or they can spend this window building the registry, lifecycle management, and zero-standing-privilege discipline that makes any future protocol safer to adopt, regardless of which one wins. Given that the population driving this problem already outnumbers the humans managing it by twelve to one, the second path isn't optional readiness work to get to eventually. It's the only version of this transition that doesn't leave an enterprise's most exposed identities ungoverned right up until the moment something goes wrong.
Getting ahead of cross-organizational agent risk starts with fixing the identity governance gap inside your own walls before extending trust outward. The Complete Agentic AI Readiness Assessment includes frameworks for building a non-human identity registry, implementing lifecycle management and zero-standing-privilege access, and evaluating which emerging payment and trust protocols fit your organization's risk posture. Get your copy on Amazon or learn more at yourdigitalworkforce.com. For organizations preparing for agent-to-agent transactions across company boundaries, our AI Blueprint consulting helps design identity governance architectures, evaluate agentic commerce protocols, and build the control planes that make external agent relationships as accountable as internal ones.

