Chapter 11
The Empire of Protocols (July–December 2026)
Chapter 11 The Empire of Protocols (July–December 2026)
The quarterly earnings report filed by Anthropic’s Model Context Protocol division for the period ending August 31, 2026, was a seventeen-page PDF of unadorned financial tables and explanatory notes. It contained no product screenshots, no visionary statements from leadership, and only a single, sparingly used corporate logo. Its narrative was told in metrics.
The first, presented in bold on page three, was 73%. This was the division’s “protocol coverage,” defined as the percentage of enterprise AI agent deployments—across all major model providers—that incorporated at least one MCP-compliant component for inter-agent communication or tool invocation.
The second defining figure, on page five, was 58%. This represented the portion of the division’s total revenue attributed to “trust and compliance features,” a line item elaborated in an appendix. The features were listed plainly: “Permission Prompt Management,” “Guaranteed Sandboxed Execution,” and “Transactional Rollback Guarantees.”
Each was offered in three service packages—Basic, Professional, Enterprise—with pricing based on a per-million “trusted interactions” model. The document did not describe software capabilities. It cataloged a licensing regime.
The independent harness layer, embodied in this report, was no longer selling tools. It was selling certified adherence to a communication standard, with quantifiable trust as the premium commodity.
Years earlier, this outcome would have answered a persistent, nagging question. Why maintain an independent harness layer if the model’s API spoke the same language and could natively orchestrate actions?
By the second half of 2026, the answer was inscribed in these financial statements. The independent layer no longer sold language or orchestration. It sold certification. It sold guarantees.
It sold legally enforceable promises about system behavior, all wrapped in the lingua franca of a protocol it controlled. The companies that had built the harness had pivoted from constructing the machinery of work to owning the rules of the road and charging tolls for the safest, most verifiable lanes.
This was the empire of protocols: a moment of apparent, lucrative stability built entirely on the economics of rent collection. Its consolidation represented the harness layer’s supreme technical achievement and its most glaring commercial vulnerability.
The scaffolding paradox, temporarily obscured by the rush to standardize, was now presenting its invoice.
By the second half of 2026, the harness layer had achieved what its earliest architects could scarcely imagine. It was no longer a collection of frameworks and glue code but a genuine industry-wide protocol layer, as essential to enterprise AI as TCP/IP had been to the internet.
Its components were invisible infrastructure, but its economics were starkly, undeniably visible. This dominance emerged not from the decree of any standards body but from a brutal, market-driven convergence that unfolded over the preceding eighteen months. Through 2025 and into early 2026, three protocol stacks had vied for supremacy. Anthropic’s Model Context Protocol (MCP), released on November 25, 2024 and widely licensed thereafter, was marketed as the secure, enterprise-ready choice. The open-source Agent Protocol thrived on community development and vendor-neutral idealism. A late-arriving, Google-backed contender, the Universal Agent Framework (UAF), promised deep integration with the Gemini model suite and the Google Cloud ecosystem.
Formal consortia and standards committees were left watching from the sidelines, their deliberate processes outpaced by the sheer velocity of commercial adoption and integration.
The duopoly that solidified by July 2026 was enforced by this adoption, not by any statute.
The Google-backed UAF, despite considerable technical investment and the weight of its sponsor, failed to gain critical traction outside Google’s own walled garden. Enterprises, having lived through the platform wars of the prior decades, viewed its deep ties to a single vendor with instinctive suspicion. Developers found its tooling complex and its ecosystem sparse compared to the vibrant, if chaotic, networks growing around the alternatives. By mid-year, the UAF had effectively retreated, becoming an internal protocol for Google’s own services.
The real contest narrowed to two camps: the MCP stack and the Agent Protocol stack. Yet the Agent Protocol of mid-2026 was a different entity from its idealistic origins. The open-source core remained, maintained by a dedicated community. But around it had crystallized a constellation of commercial entities—venture-backed forks, service providers, and consulting firms—that offered “certified” AP distributions.
These bundled the open-source protocol with proprietary management dashboards, forensic audit logs, and the same tiered trust features that Anthropic monetized in its MCP division. Their value proposition was compliance without the perceived lock-in of a single corporate steward, but their revenue model was identical: rents extracted from every agent-to-agent and agent-to-tool interaction that required verified, billable security.
The boardroom decisions that precipitated this industry-wide pivot were remarkably uniform in their strategic direction. At the companies whose fortunes were tied to the harness layer—the surviving orchestration platforms, the middleware specialists, the monitoring startups—the strategy sessions of early 2026 converged on a single imperative: the pivot from tool-building to protocol compliance enforcement. The logic was coldly economic and born of observed history. Building a better tool-calling library was a feature race with diminishing returns, especially as model vendors like OpenAI and Anthropic incorporated similar primitives directly into their APIs. Building a compliance and certification regime around a communication standard, however, created a different kind of moat.
If a company could become the entity that certified an enterprise agent deployment as “MCP-Compliant” or “AP-Enterprise Certified,” it inserted itself into the procurement cycle not as a vendor of tools but as a vendor of assurance. It became a required sign-off, a necessary stamp for risk-averse committees.
This was the inner mechanism of the protocol empire: the metering of trust, once a technical challenge of sandboxes and verification algorithms, had been refined into a precise, tiered pricing lever.
Permission prompts—the system checks that asked a human “Should Agent A be allowed to execute Tool B on System C?”—were no longer just safety features. Under the Professional and Enterprise tiers of both the MCP and commercial AP offerings, they became billable events. Service-level agreements guaranteed not just security, but performance: prompt delivery and decision logging within specified milliseconds. Sandboxed execution guarantees were sold as insurance policies; the fine print stipulated financial liability for the protocol provider if an agent action escaped its defined sandbox and caused operational or financial damage.
Rollback guarantees, which ensured a complex multi-agent workflow could be atomically reverted to a prior known-good state, commanded the highest price. Trust, quantified, packaged, and underwritten, had become a recurring revenue stream. The engineering of human-machine trust, once the harness layer’s raison d’être, was now its primary business model.
This commodification transformed the relationship between the harness layer and its enterprise customers. A global logistics firm deploying an agentic system to optimize container shipments and customs clearance no longer purchased a software license for an orchestration framework. It purchased a “Protocol Compliance License” for its swarm of interacting agents, with add-on subscription modules for “High-Stakes Permissioning” and “Financial-Grade Rollback.” The cost scaled directly with the volume of “trusted interactions.” More autonomy, flowing through more agents, demanded more units of measured, monetized trust. The harness companies argued this aligned incentives perfectly: they profited only when their clients’ systems operated safely and reliably at scale.
Detractors within the enterprise IT departments increasingly called it a tax on automation, a toll paid for the privilege of using the intelligence they were already purchasing from the model labs.
The consequences of this new model radiated outward, restructuring the ecosystem. For enterprise adopters, the dominance of two major protocol stacks brought a palpable, welcome clarity. The grinding interoperability problems of 2024 and 2025—where agents built with one framework could not communicate with tools or data sources configured for another—largely subsided. Teams could now mix and match components from different vendors, provided everything spoke the common language of MCP or a compliant dialect of the Agent Protocol. This interoperability directly served the ground-truth law. The law, which held that agents landed first where feedback was verifiable, had found its purest early expression in coding, where a compilation error or a passing test suite provided immediate, unambiguous feedback. Now, in the era of multi-agent orchestration, the same principle applied to coordination.
An ordering agent could hand off a task to an inventory agent via a standardized protocol message; the successful update of the inventory database served as the verifiable feedback that kept the larger operational loop on track. The protocol standards made this cross-vendor, cross-system handoff technically possible; the commercialized trust tiers, with their guarantees and liabilities, made it organizationally permissible for risk-averse enterprises to rely on it.
For the harness companies themselves, the protocol pivot brought a final, feverish peak of valuation, influence, and perceived indispensability. They were no longer mere toolmakers or framework vendors. In their own positioning and in the eyes of many enterprise buyers, they had become the gatekeepers to the autonomous enterprise. Their sales teams carried quota targets based on “protocol adoption points” and “trust revenue attainment.” Their engineering roadmaps deemphasized flashy new capabilities in favor of compliance tooling—ever-finer-grained audit logs, more legally rigorous liability frameworks, deeper integrations with enterprise identity management and governance systems. Their market power seemed, for a moment, unassailable.
They sat athwart the critical junctions where AI systems interacted with the world and with each other, charging for safe passage.
For the model vendors—OpenAI, Anthropic, Google, and their peers—the rise of this powerful, independent protocol layer was a development of profound ambiguity. On one hand, it solved their most pressing adoption hurdle. Enterprises remained deeply reluctant to grant raw, unstructured model API access to their core operational systems. The protocol providers, with their tiered trust offerings, safety guarantees, and compliance packaging, made the model vendors’ powerful but unpredictable products palatable to corporate risk and security offices. The harness layer, in this reading, was a necessary go-between, a translator of raw capability into manageable, accountable enterprise IT. On the other hand, these same providers were inserting themselves as a lucrative middle layer, capturing significant value and setting de facto terms for how models were used. The model labs watched as companies built billion-dollar businesses on top of their foundational models, businesses whose revenue came from selling trust the labs themselves did not directly provide.
The labs’ strategic response began to follow the familiar, relentless pattern of the scaffolding paradox. If a harness innovation proved essential and valuable, the model vendors would move to absorb it, integrating its functionality directly into their own offerings. The paradox had previously played out with chain-of-thought prompting (absorbed into training data by mid-2023), tool-calling formats (standardized into APIs by June 2023), and memory (internalized into context windows by late 2024). Now its final, most commercial act was beginning: the absorption of the trust-and-compliance business itself. The model vendors started to ask why they could not provide these guarantees natively, as a feature of their API service—bundling basic safety oversight with inference tokens in a single price—cutting out the intermediary and capturing the premium themselves. Anthropic’s corporate position was the most intricate of all. As the originator and primary steward of MCP—the protocol it had released just two years earlier—its semi-autonomous MCP division was both a model vendor and a protocol overlord. This duality created persistent internal tension.
The broader company’s mandate was to sell Claude model subscriptions and API calls. Sometimes these goals were perfectly aligned. A multinational bank adopting MCP as its internal agent standard would, naturally, tend to use Claude models given the protocol’s native optimizations and the simplicity of a unified vendor relationship. Often, however, the goals conflicted. If a third-party harness company built a superior multi-agent orchestration platform on top of MCP but optimized it for OpenAI’ forty-four models, Anthropic found itself in the bizarre position of licensing its protocol—and collecting trust revenue—to facilitate a ecosystem that primarily enriched a direct competitor. The triumphant 73% protocol coverage metric in the earnings report masked this simmering strategic contradiction. The open-source Agent Protocol ecosystem faced a different, more public strain. Its commercial entities lived in perpetual tension with the volunteer community that maintained the core open standard. The push to monetize trust features—to create the “AP-Enterprise” certified distribution with its proprietary add-ons—required building commercial moats around the open core.
Every feature added to the commercial tier, from advanced audit trails to liability contracts, was a feature deliberately withheld from the free, community version. Purists within the project accused the commercial forks of betraying the original ethos, of creating a two-tiered system where the essential tools for safe, trustworthy operation were locked behind paywalls. The commercial entities countered that without a sustainable revenue model, there would be no one to provide the robust support, legal liability, and enterprise sales channel that large-scale adoption demanded. This debate was never resolved; it was merely managed, a low-grade fever in the ecosystem. The protocol politics of this period were thus not the open warfare of rival standards, but the subtle, grinding politics of consolidation and control within the victorious camps. Whoever defined the interface owned the ecosystem, as the old axiom held. By late 2026, the interface was defined by MCP and the commercial AP specification. But ownership was fragmented. Anthropic owned MCP but sought to govern it as a neutral-seeming standard.
A cabal of venture-backed companies owned the lucrative AP enterprise extensions but relied on a community-owned core. This fragmentation created points of leverage and vulnerability. It meant that no single entity had complete control over the full stack of protocol and trust services, leaving seams that the model vendors could exploit. The economic pressure points became increasingly visible as 2026 progressed. The harness companies’ business model was based on recurring revenue from protocol compliance and trust services. This revenue was directly tied to the volume of agent interactions. Yet the cost of the underlying computational resource—the model inference tokens—was borne by the customer and flowed to the model labs. As the model labs advanced their own native tool-calling and orchestration capabilities, they began to offer bundled pricing: a certain number of tokens plus “basic safety oversight” for a single price. This was a direct, if initially clumsy, assault on the harness layer’s trust revenue. Why pay a separate protocol provider for sandboxing guarantees if the model API now included a similar, if lighter, warranty?
The first major crack in the protocol empire’s façade appeared not in a startup’s failure but in a Fortune 500 company’s quiet migration announcement. In November 2026—a year almost to the day after Anthropic had published MCP’s release notes—a multinational logistics firm that had been an early and flagship adopter of the MCP stack for its global supply chain agents issued a brief technical update to its investor relations page. The update stated that the company was consolidating its AI agent infrastructure onto a “vendor-native orchestration platform” to reduce complexity and “streamline cost structures.” There was no fanfare, no condemnation of MCP or Anthropic specifically; indeed OpenAI had spent much of late 2024 denying it would ship GPT-5 at all before quietly filing for that trademark in July 2023 and confirming development months later—a reminder that even dominant labs moved through cycles of denial before absorption became inevitable.
The boardroom calculus that drove this industry-wide pivot was not merely reactive; it was steeped in historical precedent. Executives who had lived through earlier platform wars—the battles over operating systems, web protocols, and cloud APIs—recognized a familiar pattern. When a technical layer becomes essential but undifferentiated, competitive advantage migrates upward to control points: certification, compliance, and legal assurance. The decision to cease competing on tool functionality and instead compete on protocol governance was a conscious flight from commoditization. One surviving orchestration platform, in an internal strategy memo later cited by analysts, framed it starkly: “We cannot win a features race against the model labs’ own R&D budgets. We can win a trust race, because they cannot afford the liability.” This logic transformed product roadmaps into governance frameworks. Engineering teams that once sprinted to release new agent capabilities were redirected to draft service-level agreement language, design forensic audit systems, and negotiate indemnity clauses with corporate insurers. The harness layer was not just selling safety; it was selling a transfer of risk, a financial instrument wrapped in code.
Within Anthropic, the duality of being both model vendor and protocol steward generated not just tension but explicit strategic fault lines. Internal memoranda from this period reveal competing key performance indicators for different divisions. The MCP division was measured on protocol adoption growth and trust-feature revenue—metrics that thrived on a broad, multi-vendor ecosystem. The core model business was measured on Claude API call volume and market share—metrics that benefited from exclusive, deeply integrated customer relationships. This conflict often played out in negotiations with major enterprise clients. A deal team from the model side would push for an all-Anthropic stack, offering discounts on inference in return for exclusivity. Simultaneously, the MCP division’s sales arm would advocate for the same client to adopt MCP as its neutral standard, licensing it to orchestrate agents from multiple model providers—including competitors—because that scenario generated higher-margin trust revenue. The company’s leadership attempted to balance these forces by positioning MCP as an “open ecosystem,” but its technical optimizations for Claude models and its licensing terms subtly favored its own stack. This inherent contradiction meant Anthropic’s protocol dominance was always partially self-cannibalizing, a reality the triumphant coverage metric conveniently obscured.
The commercial fragmentation within the Agent Protocol ecosystem created a different structural vulnerability. Because no single entity owned the full stack—the core standard remained a community commons—the commercial forks competed ruthlessly with each other to offer the most compelling enterprise add-ons. This competition accelerated feature development but also led to a proliferation of incompatible “AP-Enterprise” extensions. A certified distribution from one vendor might include a proprietary permissioning workflow that could not interoperate with the audit log format of another. Enterprises that chose the Agent Protocol path for its vendor neutrality thus sometimes found themselves locked into a specific commercial fork anyway, simply to maintain internal consistency. This fragmentation undermined the very interoperability the protocol was meant to guarantee at scale. It also provided an opening for the model labs. They could, and did, approach these competing commercial AP vendors with offers to create “preferred” integrations—deals where the vendor’s tooling would be optimized for one lab’s models in exchange for joint sales support or revenue sharing.
The empire of protocols had reached its zenith on the strength of a simple, powerful idea: that trust could be standardized, metered, and sold as a service independent of raw intelligence. It had made the harness layer legible, valuable, and, for a time, seemingly indispensable. But in doing so, it had made the layer’s function perfectly clear to the more powerful entities above it in the stack. The protocol layer’s success had drawn a map for its own absorption. The logistics firm’s migration was not an anomaly; it was a signal. It demonstrated that the model vendors were learning not just to mimic the harness layer’s technical functions, but to replicate its economic proposition: selling units of trust, now bundled directly with units of intelligence. The pressure this exerted on the harness companies was existential. Their entire pivot to protocol compliance and rent extraction had been a climb to a higher stack level—a flight from the earlier absorption of their tool-calling and orchestration functions. Now, the ground beneath this new plateau was shifting.
The rent they collected was being reassessed as a redundant surcharge. The empire still stood, its protocols woven throughout the infrastructure of global enterprise AI. But its economic foundations were now being audited by its own largest suppliers, and the audit was yielding a troubling conclusion. The value was portable. The trust could be baked in. The middle layer, for all its cleverness and necessity, was beginning to look like a temporary configuration of economic forces, not a permanent architecture.