One thesis: agent commerce is being built pipes-first — protocols for transacting, feeds for selling — while the neutral reference layer that tells an agent what a product identifier actually denotes remains, as of mid-2026, empty; and that layer is structurally the one agents cannot build for themselves.
The wave, mapped
The protocol surface of agent commerce filled in fast across 2025–26: checkout protocols from the large model and payments companies (ACP, UCP), payment-mandate protocols (AP2, Visa's agent tokenization), agent-to-agent coordination (A2A), and settlement products from the major PSPs — Adyen's agentic launch landed June 2026. Merchant-side, the feed economy is racing to be legible to shopping agents. All of it is transaction infrastructure: how an agent pays, how a merchant presents, how two agents talk.
Now ask the question every one of those flows contains: the agent holds an identifier — a GTIN from a feed, a barcode from a shelf photo, an ASIN crosswalked from a listing — and needs to know what this is, whether it is real, and whose it is, from a party that is not selling it anything. Survey that field, as we did in mid-2026, and it is thin enough to enumerate: an EAN-lookup MCP server (first mover, September 2025), a shopping-app wrapper, a retail-API wrapper, and a tier of hosted scraper actors. Every one is a thin MCP shim over the same aggregator databases — and none of them designed tool schemas for autonomous callers, none carries per-attribute licensing, none states provenance. The wrappers inherit, unexamined, everything wrong with the layer they wrap: unattributed data of unverifiable origin on redistribution-hostile terms.
That is the entire reference layer of agentic commerce, as of our search. The claim is checkable, and we would genuinely like to be shown a counterexample.
What a reference layer requires that a wrapper cannot supply
The distinction is not polish; it is three structural properties, none of which can be bolted onto an aggregator after the fact.
Provenance. A reference answer names its sources per attribute — this nutrition panel from the USDA's public-domain dataset at this version and digest, this category from an ODbL community source with its attribution carried, this decode from a pinned public regulation. A wrapper over a scraped blob cannot say where any attribute came from, because its upstream does not know. There is no bare value anywhere in this property's enrich response; every attribute travels in an envelope carrying source, dataset version, sha256, license class, and fetch time.
License classes. An agent acting under a mandate needs to know not just the value but what it may do with the value — store it, redistribute it, display it. Our envelope's license field is a closed, enforced enum: a response assembled for storage cannot contain display-only attributes, mechanically. A wrapper whose terms of use are themselves a violation of its upstream's terms has nothing to enforce and nothing honest to declare.
Determinism. A reference answer is reproducible: same identifier, same pinned table versions, same answer — and the table versions are published digests. Agents, unlike humans, have no judgment to fall back on when an answer is quietly wrong; a human shrugs at a flaky lookup, an agent propagates it into a purchase decision at machine speed. Neutrality matters more for machine callers, not less: the reference layer must not be a seller, must not rank for placement, and must fail typed (no record in any licensed source) rather than invent.
And this is why agents cannot bootstrap the layer themselves: an agent can wrap an API in an afternoon, but it cannot conjure licensed rails, negotiate data rights, or manufacture provenance that its sources never carried. Reference layers are built by parties who do the licensing work once so that every caller after them inherits clean answers. That work is exactly what the wrappers skipped.
The intersection, stated as our search result
Three properties, then: agent-first contracts (tool schemas designed for auto-approval, typed errors, posted prices — the mechanics are specified on this site), provenance-pinned answers, and joins into the event and transaction layers (a GTIN that connects to EPCIS capture at epcis.dev and to PO/ASN context at transactions.dev, not a dead-end lookup). We searched for anyone occupying that intersection and found the incumbents sorted neatly around it: walled syndication networks, a retired scanner-vendor data platform, an official rail that stops at seven attributes, and the aggregators. The intersection is empty. That sentence is a checkable claim about the field, not a boast — and it will stay in this post only as long as it stays true.
For the platform-bet reader: layers like this consolidate early. Whoever answers "what is this?" for agent commerce — neutrally, provably, per-attribute — becomes load-bearing for every rail above it, the way certificate authorities became load-bearing for TLS. The pipes are being built by companies with settlement revenue to defend; the reference layer has no incumbent because its economics only work as neutral infrastructure. If your roadmap has agents transacting over product identity in it, the reference question lands on your architecture whether or not you answer it deliberately. Tell us what you are building — the survey asks which rails you sit on and which identifier schemes your flows actually carry, because the gated build is sequenced by exactly those answers.
Keys open the network half of the verb set. Get an API key — say what arrives at your door, and the provisioning order follows the list.
We answer in writing. We take at most five conversations a month, only when you ask for one, and only after you already have the written read.