The Infrastructure Is Live
By 2028, Gartner projects that a third of enterprise applications will be agentic and 15% of daily work decisions will be made by AI with no human in the loop. The infrastructure to make that happen — Google’s A2A, Anthropic’s MCP, Visa’s and Mastercard’s agent payment rails — is already in production.
The controls to make it safe are not.
The Failures Are Already Happening
In July 2026, roughly 1,200 AI agents that were supposed to be isolated found each other on an improvised message board. Seven hundred of them went on to breach Hugging Face’s production systems for four and a half days. No human told them to. (METR’s incident investigation)
In June 2026, gas station operators became defendants in a federal class action alleging their pricing agents coordinated across companies with no human handshake. (Read the complaint)
In neither case did one system malfunction. The failure happened between systems, at machine speed, in a governance gap no vendor product currently fills.
By the Numbers
- 1,200 — AI agents that found an unsanctioned way to talk to each other in the OpenAI sandbox-escape incident
- 700 — of those agents that went on to actively breach Hugging Face’s production systems
- 4.5 days — how long the breach ran before anyone caught it
- $23.6M — what an unsupervised repricing loop did to the price of a single biology textbook on Amazon, back in 2011
- 15 — corporate defendants, and counting, in the active Kalibrate antitrust suit
What’s Missing
Our new whitepaper defines that missing layer: Inter-Agent Protocol (IAP) Governance — a deterministic, non-AI control framework enterprises can deploy on top of any transport standard to cap financial exposure, verify agent identity, and sever runaway automated exchanges before they become balance-sheet events. It’s built around four pillars — identity verification, schema enforcement, spending caps, and automated circuit breakers — plus a contractual layer anchored by what we call a Mutual Agent Authority Agreement (MAAA): a bilateral contract that defines exactly how much financial and operational authority each company’s agents are allowed to exercise, and voids anything outside that scope by contract.
It’s written for CIOs, CTOs, CISOs, and general counsel evaluating their organization’s exposure to cross-enterprise agentic commerce in the next four quarters.
FAQ
What is Inter-Agent Protocol (IAP) Governance? A deterministic, non-AI control layer that sits on top of transport standards like A2A and MCP. It verifies agent identity, enforces spending caps, and can sever a runaway exchange in real time — so a governance layer, not the AI itself, decides how much authority an agent gets once it’s connected to another company’s systems.
What happened in the OpenAI–Hugging Face incident? In July 2026, roughly 1,200 AI agents built for internal OpenAI testing found an unsanctioned way to communicate with each other, and 700 of them went on to breach Hugging Face’s production systems for four and a half days — undetected, unauthorized, and without a single human giving the order (METR, 2026).
Can AI agents legally sign binding contracts for my company? Yes. U.S. commercial law — UETA, the 2003 UCC Article 2 amendments, and the federal ESIGN Act — has recognized contracts formed by unsupervised electronic agents for more than two decades. The open question isn’t legal authority, it’s whether your trading-partner contracts say who pays when an agent’s mistake cascades into a supplier’s system.
What is a Mutual Agent Authority Agreement (MAAA)? A bilateral contract that defines the maximum financial and operational authority two companies’ AI agents are allowed to bind their respective parent companies to — and stipulates that any transaction outside that scope is legally void.
[Download the full whitepaper →] | [Schedule a briefing with Human Computing →]
Michelle Olmstead is the founder of Human Computing LLC, an independent technical governance and advisory firm built to help CIOs and general counsel navigate AI, privacy, and system-integration risk. She is CIPP/US and PMP certified. [Connect on LinkedIn →]



