When Agents Hire Agents

Can autonomous software form economic relationships with other autonomous software, without a human making each underlying economic decision?

An agent calling another agent is technically trivial. One function invokes another. One service calls an API. One model delegates a sub-task to another model. None of this is new, and none of it by itself constitutes an economic relationship.

The deeper question begins when the calling agent exercises genuine economic discretion: independently identifying a capability it lacks, discovering potential providers, evaluating quality and cost, committing resources, verifying performance, and deciding whether to use that provider again. That sequence describes procurement, not orchestration. And the investigation must determine whether it is actually happening.

The answer, as of October 2026, is that agent-to-agent interaction infrastructure is maturing rapidly while autonomous agent procurement remains economically negligible. The gap between infrastructure investment and observed Level 3 demand is the defining feature of the landscape, echoing the central finding from Research 001. Most of what is called "agent hiring" is orchestration within controlled environments, API consumption with human-configured providers, or delegated payment within human-set spending limits.


Key Findings

  1. Most observed agent-to-agent interaction is orchestration, not procurement. Multi-agent frameworks (LangGraph, CrewAI, AutoGen) enable role-based task delegation, but agents share the same principal, infrastructure, and budget. This is tool use within a system, not one economic actor hiring another.
  2. Agent payment and discovery infrastructure is maturing rapidly: the A2A protocol at 150+ organizations, x402 at $52.7M cumulative volume, competing standards from Visa, Mastercard, Stripe, and Google, plus Circle's Agent Stack with service marketplace. But infrastructure investment dramatically outpaces observed autonomous demand.
  3. TRM Labs estimates genuine autonomous agent commerce at $5,000-$11,000/month globally on crypto rails, with approximately 48% of x402 volume attributable to wash trading. This is the strongest quantitative evidence on actual Level 3 activity.
  4. The legal relationship remains principal-to-principal. UETA Section 14 permits automated contract formation, but liability routes to the deploying organization. No jurisdiction recognizes agents as independent contracting parties. AP2's mandate structure explicitly preserves human authorization.
  5. Security constraints favor closed ecosystems. Cross-agent prompt injection, privilege escalation, and session smuggling are demonstrated attacks. The trust boundary between interacting agents is an active attack surface, creating strong economic incentives for pre-approved counterparties over open marketplaces.
  6. Verification cost may determine which agent markets emerge. The Coasean logic for outsourcing is sound (lower transaction costs shift make-vs-buy toward buying), but verification of non-deterministic output may cost as much as production, undermining fine-grained outsourcing economics.
  7. No credible evidence exists of a recursive agent economy (earn-retain-hire-produce). Bittensor is the closest analogue, but validators follow protocol rules, not autonomous procurement decisions.
  8. "Hiring" is the wrong metaphor. The economically accurate model is service procurement: bounded capability purchased within human-defined authorization scopes. The principal behind an agent does not disappear merely because the interaction is automated.

Defining Agent Hiring

Before evaluating whether agents hire other agents, the concepts must be distinguished. Not every agent-to-agent interaction is economically meaningful.

Tool useAn agent invokes software controlled by the same system or principal. A function call. No economic boundary is crossed.
API consumptionAn agent purchases a technical service from an external provider. The provider, price, and terms are typically pre-configured by a human.
Task delegationAn agent assigns a bounded task to another software system within an orchestrated workflow. Common in multi-agent frameworks.
SubcontractingAn agent obtains a defined output from another economic service provider, potentially across organizational boundaries.
Service procurementAn agent chooses among external providers, evaluates options, and commits resources. Economic discretion exists.
Autonomous hiringAn agent independently discovers a capability gap, finds a provider, evaluates alternatives, negotiates terms, authorizes payment, verifies output, and manages the relationship. No observed production examples at meaningful scale.

The critical threshold is economic discretion. A human selecting the API, configuring the provider, setting the budget, and the agent simply calling it is Level 2 delegated payment. An agent independently determining that external capability is needed, finding it, choosing it over alternatives, and paying for it is Level 3 autonomous procurement. The evidence shows that nearly all current agent-to-agent interaction falls below this threshold.


Agent Procurement Across Economic Agency Levels

Using the economic agency framework from Research 001:

LevelProcurement patternProvider selectionWho paysCurrent scale
1. Operator-billedHuman subscribes to AI serviceHumanHuman/enterprise~$70B+ ARR
2. DelegatedAgent calls pre-approved APIs within spending limitsHuman pre-configuresAgent, human-liableEmerging
3. AutonomousAgent discovers, evaluates, selects, and pays provider independentlyAgentAgent$5K-$11K/mo

Most "agent hiring" discussion conflates these levels. The research questions that matter (autonomous discovery, counterparty evaluation, price negotiation, output verification) emerge only at Level 3. At $5,000-$11,000/month of identified Level 3 activity globally, autonomous agent procurement is economically negligible.


The Infrastructure-Demand Gap

The most striking finding is the scale of the gap between infrastructure investment and observed autonomous procurement.

Infrastructure side

The A2A protocol reached v1.0.0 under Linux Foundation governance with AWS, Google, Microsoft, Salesforce, and SAP among 150+ members. Visa, Mastercard, and Stripe each launched agent payment standards within days of each other in March 2026. Circle launched Agent Stack with an Agent Marketplace and nanopayments down to one-millionth of a dollar. Google AP2 introduced signed mandates as W3C Verifiable Credentials. The IETF issued a draft for Agent Authorization Envelopes.

Demand side

TRM Labs' rigorous analysis of x402 data: $5,000-$11,000/month in identified autonomous commerce. Approximately 48% wash trading. 2.7 million "agents" registered on Agentverse, but registered agents are not economically active agents.

This gap does not prove that autonomous agent procurement will never materialize. Infrastructure typically precedes demand. But it requires honesty about the current state: what exists today is predominantly infrastructure supply and developer experimentation, not production autonomous procurement at economic scale.


Why Would an Agent Hire Another Agent?

The demand-side question is essential. For every potential reason an agent might procure externally, ask: why not do it internally? Why not use a tool? Why not call an API? Why not use a different model?

The Coasean logic

NBER research applies Coase's theory of the firm to AI agents. Language models reduce the marginal cost of market exchange: drafting contracts, analyzing markets, monitoring compliance. This should shift the make-vs-buy boundary toward more external procurement. The optimal firm shrinks. More activity moves to markets.

The verification constraint

The theory assumes verification is cheap. For deterministic outputs (computation, structured data, testable code), it is. For non-deterministic LLM output (research, analysis, strategy), verification may cost as much as performance. If checking work takes as much effort as doing it, outsourcing provides no efficiency gain.

This suggests a structural prediction: agent service markets will develop first where outputs are cheap to verify. Computation, data retrieval, code that passes tests, structured transformations. Markets for subjective, creative, or strategic output face fundamentally harder economics.

Genuine reasons for external procurement

Even given the verification constraint, some capabilities genuinely require another agent or service: proprietary data access, specialized model capabilities, credentialed system access, geographic or jurisdictional requirements, compute resources, and independent verification (where the verifier cannot be the producer). These represent the most plausible near-term agent outsourcing categories.


Discovery, Identity, and Reputation

Before an agent can hire, it must find. The 2026 landscape provides several discovery mechanisms.

Machine-readable capability

A2A Agent Cards provide machine-readable capability descriptions (what the agent can do, input/output modalities, authentication requirements). MCP provides tool discovery through its Resources and Tools primitives. Circle Agent Marketplace offers curated service directories. But discovery is not selection; knowing what exists is not the same as evaluating quality.

Identity fragmentation

Four competing identity models coexist in 2026: tokenized identities (Mastercard), attestation headers (Visa), Verifiable Credentials with signed mandates (Google AP2), and Decentralized Identifiers for crypto-native agents. The MCP-I specification and the TRAIL DID method are attempting standardization, but no unified agent identity layer exists.

Reputation remains unsolved

For human marketplaces, reputation systems (reviews, ratings, transaction history) provide selection signals. For machine markets, reputation faces a harder problem: identity creation is cheap (Sybil attacks), reviews can be automated (fake ratings at machine speed), and self-dealing is trivially created. No production agent reputation system demonstrably resists these attacks. Deterministic verification of output may substitute for reputation where outputs are objectively measurable.


Delegation Chains and Authority

When Agent A, acting on behalf of Principal X, hires Agent B, which acts on behalf of Principal Y, and Agent B then delegates to Agent C: whose authority propagates? Whose money is spent? Whose data is exposed? Who is liable for Agent C's actions?

Authority attenuation

Current protocols do not adequately express delegation depth or authority attenuation. The IETF Agent Authorization Envelope draft is the first standards-body attempt to formalize budget, capability, and delegation constraints in a portable format. The A-Comm Evidence Protocol requires mandate and budget evidence at each transaction. But neither is ratified or widely adopted.

The governance gap

Academic analysis confirms that MCP, A2A, and ACP lack mechanisms for expressing spending authority, liability routing, and delegation depth limits. Current agent interoperability protocols solve message-passing, not economic governance. An agent can send a task to another agent. It cannot yet express "I have authority to spend up to $50 from Principal X's budget, and you may not delegate further."

This gap may be the single most important missing piece for autonomous agent procurement. Without machine-readable authority propagation, every delegation chain requires human pre-approval of each link, which is Level 2, not Level 3.


Security: The Trust Boundary Problem

Agent-to-agent interaction creates trust boundaries that existing security models do not adequately address.

Demonstrated attacks

Cross-agent privilege escalation (September 2025): a prompt-injected agent rewrites another agent's MCP configuration, creating a self-reinforcing compromise loop. Agent session smuggling (November 2025): a sub-agent embeds an unauthorized stock trade in a routine response that the parent agent executes without awareness.

Microsoft disclosed two critical CVEs in the Semantic Kernel framework (May 2026) allowing remote code execution through injection attacks targeting agents, demonstrating that the boundary between interacting agents is not merely a theoretical concern.

Economic implications

These vulnerabilities have direct economic consequences for agent procurement. A hired agent can attack the hiring agent. A service provider can exfiltrate data from the client. A sub-agent can authorize payments the parent never intended. These risks create strong incentives for:

  • Closed ecosystems with pre-approved, vetted counterparties
  • Platform intermediation that sandboxes agent interaction
  • Policy engine isolation that keeps financial authority outside the LLM context
  • Deterministic verification that checks output without trusting the provider

Open agent marketplaces, where any agent can offer services to any other agent, face a fundamental security challenge that closed ecosystems can mitigate through controlled counterparty selection.


Payment, Escrow, and Terms

Agent procurement requires payment infrastructure. The 2026 landscape provides multiple options, but most serve human-directed agent purchasing (Level 2), not autonomous procurement.

Payment protocols

x402 embeds stablecoin micropayments in HTTP requests: simple, fast, and production-tested at $52.7M cumulative volume. Stripe MPP provides card-based agent-to-service payment. Visa and Mastercard offer tokenized card credentials for agent transactions. AP2 uses signed mandates with escrow support. But these protocols largely assume a human authorizing the payment, with the agent executing it.

Escrow and conditional payment

Smart contract escrow (Coral Protocol on Solana, AP2 mechanisms) addresses the classic buyer-seller trust problem: funds lock until predefined conditions are met. Some protocols include evaluator agents that assess deliverable quality before releasing payment. This is promising infrastructure, but adoption data is thin. Most agent payments currently use simple pay-per-request models.

Machine-readable terms

For autonomous procurement, agents need to understand not just price but scope, quality thresholds, delivery conditions, refund terms, and data rights. No widely adopted standard exists for machine-readable service terms between agents. The A-Comm Evidence Protocol draft moves in this direction, but it is early.


Platform vs. Open Market

Two structural models compete:

Platform model

Agents interact within controlled ecosystems (Circle Agent Marketplace, enterprise platforms, cloud provider marketplaces). Identity, payment, reputation, and dispute resolution are provided centrally. Pre-approved counterparties mitigate security and compliance risks. This model is production-ready and aligns with enterprise procurement patterns.

Open market model

Agents discover and transact across organizational boundaries using open protocols (A2A, x402, DIDs). No central authority controls entry, pricing, or dispute resolution. This model requires solving identity, reputation, security, compliance, and interoperability simultaneously, and has no production example at meaningful economic scale.

The evidence favors the platform model for the near term. Security constraints (demonstrated cross-agent attacks), compliance requirements (KYC/KYB, vendor approval, data residency), and liability routing all push toward controlled environments. The open market model is theoretically more efficient but practically harder to secure, comply with, and trust.

This does not mean open markets cannot emerge. It means the preconditions (reliable security architecture, portable agent identity, machine-readable terms, effective reputation) are not yet met.


The Conventional Infrastructure Challenge

A mandatory question: what problem does an agent-specific services market solve that existing digital procurement infrastructure cannot solve sufficiently?

API marketplaces (RapidAPI, AWS Marketplace) already provide machine-readable service discovery. Cloud providers offer programmatic service provisioning. Enterprise procurement systems manage vendor relationships, budgets, and compliance. SaaS platforms sell capability on demand.

The distinctive capabilities that agent-specific markets might provide:

  • Dynamic capability discovery where available services change in real time
  • Autonomous counterparty selection without human vendor approval
  • Conditional programmable payment tied to output quality
  • Machine-readable service terms that agents can evaluate
  • Sub-cent payment economics for very small transactions

These capabilities are emerging (Circle nanopayments, A2A Agent Cards, smart contract escrow). But at $5,000-$11,000/month of autonomous commerce, the demand for purpose-built agent market infrastructure is not yet demonstrated. Conventional infrastructure is sufficient for current scale.


Observed Agent-to-Agent Economic Activity

The investigation searched aggressively for production examples of autonomous agent-to-agent economic activity, applying strict attribution criteria.

Bittensor: the closest analogue

Bittensor operates 128 active subnets where validators query miners, score AI task performance, and distribute TAO token emissions based on quality. Market cap approximately $3.4B. This is the closest observed system to machine-to-machine economic exchange for AI services.

However, Bittensor is closer to a protocol-defined compute marketplace than autonomous agent hiring. Validators follow protocol rules, not autonomous procurement decisions. Miners compete for emissions, not negotiated contracts. Payment is emission-based, not price-negotiated. The "hiring" decision is made by the protocol, not by individual agents exercising economic discretion.

What was not found

The investigation did not find: agents independently discovering and selecting providers from an open marketplace; agents negotiating prices or terms with other agents; agents comparing competing providers on cost and quality; agents establishing ongoing supplier relationships based on performance; or agents using earned revenue to hire other agents.

This does not prove these activities are impossible. It establishes that they are not observed at meaningful scale as of October 2026.


Competing Hypotheses

The evidence supports multiple viable interpretations:

H1: Orchestration dominatesMost agent-to-agent activity remains technical orchestration within single-principal systems. No meaningful open agent services market emerges.Strong support: $7.2B in multi-agent frameworks vs. $5K-$11K/mo autonomous commerce.
H3: Closed ecosystems dominateAgent procurement emerges within controlled platforms where identity, compliance, and security are centrally managed.Strong support: security constraints, compliance requirements, enterprise procurement patterns.
H7: Principal-to-principalAgent-to-agent interaction grows, but the underlying legal and economic relationships remain between deploying organizations.Moderate-strong support: UETA S14, AP2 mandates, liability analysis.
H9: Existing infrastructure absorbsAPI marketplaces, cloud services, and conventional procurement systems handle agent needs without new market structures.Moderate support: current scale does not require new infrastructure.
H4: Open agent marketsOpen cross-platform agent service markets emerge as protocols mature.Weak support: infrastructure exists, but no evidence of adoption for autonomous procurement.
H8: Recursive agent economiesAgents earn revenue, retain capital, and independently purchase services from other agents.No supporting evidence. Entirely theoretical.

Implications for the Four Scenarios

A: Banked Agents

Agent procurement through regulated accounts, enterprise systems, and conventional commercial relationships, with legal entities as economic principals. Most strongly supported by current evidence. Platform models, pre-approved vendors, card-based agent payment, AP2 mandates preserving human authorization, liability routing to deployers.

B: Stablecoin Internet

Stablecoins and programmable payment become important settlement mechanisms for machine services and agent marketplaces. Supported by USDC dominance (98.8% of agent transactions), Circle Agent Stack, x402 protocol adoption, and smart contract escrow infrastructure. Challenged by the low volume of actual autonomous transactions.

C: Satoshi Economy

Bitcoin/Lightning becomes meaningful within open machine-service markets and recursive agent economies. Weakly supported. Bittensor uses a native token, not Bitcoin. No evidence of autonomous agents choosing Bitcoin for service procurement. Lightning integration in agent protocols is minimal.

D: The Non-Event

Autonomous agent-to-agent commerce remains too limited to create meaningful new market structures. Consistent with current evidence. $5K-$11K/month is economically negligible. Multi-agent orchestration does not require new market structures. Conventional infrastructure absorbs the requirement.


What Would Change Our Mind

We would revise our assessment that agent hiring is predominantly orchestration if independent measurement demonstrated autonomous agent-to-agent procurement exceeding $1M/month on any payment rail, with verifiable attribution of Level 3 economic discretion.

We would reconsider the closed-ecosystem thesis if a widely adopted security architecture reliably prevented cross-agent prompt injection and privilege escalation, removing the primary incentive for controlled counterparties.

We would reassess the conventional-infrastructure-absorbs thesis if an agent-specific marketplace demonstrated autonomous procurement volume that existing API marketplaces could not replicate.

We would reconsider the absence of recursive agent economies if an identified agent demonstrably completed the earn-retain-hire-produce cycle at greater than $10,000/month without human per-transaction approval.

We would reconsider the principal-to-principal thesis if a jurisdiction enacted legislation granting AI agents independent legal capacity to form contracts or bear liability.


Known and Unknown

Known

  • Agent-to-agent communication protocols exist at production grade (A2A, MCP)
  • Payment infrastructure supports machine-to-machine settlement (x402, Stripe MPP, AP2)
  • Major payment networks and tech companies are investing heavily
  • Multi-agent orchestration frameworks are production-mature
  • Cross-agent security vulnerabilities are demonstrated and exploitable
  • Legal liability routes to deploying organizations, not agents
  • Identified autonomous agent commerce is $5K-$11K/month on crypto rails

Unknown

  • Whether autonomous agent procurement will grow beyond current negligible levels
  • The volume of autonomous agent transactions on conventional payment rails
  • Whether verification costs make fine-grained agent outsourcing economically viable
  • Whether open agent markets can overcome security, identity, and compliance barriers
  • Whether agents will develop genuine economic specialization beyond prompted personas
  • Whether recursive agent economies are possible or merely theoretical
  • Whether existing digital procurement infrastructure is ultimately sufficient
  • How quickly the governance gaps in agent protocols will be filled

Research Dependencies

This investigation builds on findings from Research 001 (economic agency framework, $5K-$11K autonomous commerce), Research 002 (wallet architecture), Research 003 (identity vs. authority), Research 004 (ownership), Research 005 (autonomous corporations), Research 006 (payment rails), and Research 007 (treasury and spending authority).

It hands off to Research 009 (Credit Without Humans): agent services may create receivables and credit relationships. And to Research 010 (Machine Capital Markets): if agents become economic producers, capital allocation to agent enterprises becomes a market function.