The Standard That Decides What Your AI May Do Was Finalized in July. Nobody Voted.
A handful of companies now own the rulebooks for software that shops and pays as you. Here's who wrote them, what they leave out, and the ordinary alternative already running.
I should admit up front how little I ever cared about this.
For most of my working life I have built on technical standards the way you walk across a floor — total confidence, infrequent curiosity. I have argued for an hour about whether a field should be a string or an integer. And I never once opened the page that says who is allowed to change the document, who can overrule them, and what happens to me if I disagree. It did not occur to me that there was such a page. A standard felt like weather — the condition you shipped into.
Then, a couple of weeks ago, I read one of these documents end to end and hit the part where it explains its own vocabulary: the little legal-sounding glossary that says MUST means mandatory and MAY means optional. This is written in the grammar of law, I thought. Somebody wrote it. Somebody decided it. And I have no idea who, or how, or whether I could have said a word.
So I went and found out. It is not a scandal — nobody is hiding in a bunker. It is duller and, I think, more consequential: the rules for how machines act on your behalf are being written right now, competently, in public view, by people who owe you nothing and were never asked to.
One disclosure before we go further, since this piece is an argument about who gets to watch a process. It was drafted with AI assistance, and the assistant in question is made by Anthropic — the company that wrote the Model Context Protocol and donated it to the foundation this article goes on to examine. Everything factual below is linked to a primary source, precisely so you need not take my word for it. Nor its word.
What actually shipped on July 28
A protocol is a rulebook for how two pieces of software talk. Not what they say — how: which messages exist, what each field means, and crucially, what one side is permitted to ask the other to do. When your assistant reaches into your bank, both ends agreed in advance on the shape of that conversation, and the document describing the agreement is the specification.
The Model Context Protocol — MCP, the plumbing that connects AI assistants to your tools and data — published a new specification on July 28, 2026. The standard that shipped that day rebuilt the protocol's core, turning a bidirectional stateful protocol into a request/response stateless one, locking in a formal extensions framework, and hardening how an agent proves who it is — including RFC 9207 issuer validation and a move away from Dynamic Client Registration toward client metadata documents.
Translated: this is the release where the industry decided how software acting as you should identify itself to the systems it touches. That is the door.
The process was, by industry standards, generous. The release candidate was locked on May 21, 2026, ten weeks before final publication — and the announcement is precise about who that window was for: SDK maintainers and client implementers, to validate the changes against real workloads. If you found a problem, the stated route was to open an issue in the specification repository.
Ten weeks. Aimed at implementers. And the mechanism for public objection was: file a ticket. I am not being sarcastic — a ticket is a real channel, and more openness than most commercial software offers. But it is not a comment period, and it is not a docket. No obligation to answer, no clock that must run out before the thing is final, and nowhere to go if they say no.
Who is allowed to change it
MCP has a published governance document, which already puts it ahead of most of the industry. It says final authority sits with Lead Maintainers, who can veto any decision by Core Maintainers or Maintainers, appoint and remove Core Maintainers, and administer all project infrastructure. The document names the role: Benevolent Dictator for Life. That is not my characterization. It is theirs, in the open.
Below them sit Core Maintainers, who can veto Maintainer decisions by majority vote, resolve disputes, and appoint or remove Maintainers. So there is voting here — I want to be exact, because my own headline needs the qualifier. There is voting among appointed Core Maintainers, whose membership attaches to the person rather than the employer and carries no term limit. What does not exist anywhere in the document is a community vote, an election, or an appeal. The franchise, such as it is, belongs to people selected by other people who were selected. The two current Lead Maintainers are named on the page — David Soria Parra and Den Delimarsky — and I have no criticism of either. The argument does not depend on anyone behaving badly.
Above it sits a legal wrapper. MCP has been established as a Series of LF Projects, LLC, and governance changes must also be approved by LF Projects. Anthropic donated the protocol in December 2025, framing the move as ensuring vendor neutrality and long-term independence under the same stewardship that supports Kubernetes, PyTorch and Node.js. The Linux Foundation announced the Agentic AI Foundation the same day, anchored by MCP alongside Block's goose and OpenAI's AGENTS.md. Neutral stewardship is real and good — but look at how the foundation is funded. Membership is tiered corporate sponsorship, and per contemporaneous reporting, the Platinum tier reads Amazon, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft and OpenAI.
I am not alleging capture; I am pointing at a structure. The document governing how software acts on your behalf is stewarded by a foundation whose top tier is eight of the largest technology companies on earth, and decided by maintainers with no term limits who answer to no appeal. If a state agency worked this way, we would all have opinions about it. And it is the document that decides: the specification says so itself, defining the authoritative protocol requirements and interpreting MUST, SHOULD and MAY as described in BCP 14 — the Internet Engineering Task Force's own convention for binding technical obligation. The spec borrows the IETF's grammar of obligation without inheriting the IETF's process. Hold that thought.
Now ask the same question of a card network
If the foundation model looks loose, the alternative on offer is not "more democratic." It is a corporation.
Visa unveiled its Trusted Agent Protocol on October 14, 2025 — the date matters only because a fair amount of secondary coverage has the month wrong. It addresses agent-driven commerce with new specifications using agent-specific cryptographic signatures.
Two careful notes, because this is where the coverage tends to slide. You will read in places that Visa issues a "Verified Agent ID"; that exact phrase does not appear in Visa's own announcement, which names no issuing authority for agent identity at all. There is a signature — who vouches for the thing doing the signing is not stated. And Visa did not do this alone: it was created in partnership with Worldpay and Cloudflare, according to reporting published the day of the announcement.
The release does say, plainly, that while these initial specifications apply to the Visa network in this phase, the wider problem requires an open, ecosystem-wide approach. That is an honest sentence and I credit it. But read the terms attached to the document. Accessing, downloading or using the specification means agreeing to Visa's own product terms, and while the reference code is public, the repository is not open source in any conventional sense: its license file points back to the Visa Developer Center Terms of Use, GitHub classifies the license as unrecognized, and it contains no contribution guide and no governance document at all.
What does participation look like in practice? On the issue tracker, nine issues are open and none are closed. One, opened July 17, 2026, is titled "Correctness/dispute layer as the next primitive after identity verification" — somebody asking in public the exact question this essay is about: once you have proven who the agent is, what happens when it gets something wrong? Zero comments.
Meanwhile, the rulebook that actually binds money has already moved. Visa publishes a public edition of the Visa Core Rules, dated April 18, 2026, governing participation of its financial-institution clients in the Visa system — with the qualifiers Visa itself supplies: proprietary and competitive information has been omitted from the public copy along with certain security details, and it must not be duplicated without prior written permission. Inside that redacted copy, the definitions are written. An Agentic Transaction is an e-commerce transaction undertaken by an Agentic Payment Provider on a cardholder's behalf, completed without direct interaction between the cardholder and the merchant. And then the line I read three times: initiators of Agentic Transactions are not considered Merchants for the purposes of the Visa Rules.
Participate is the operative word, and it is doing a lot of work: you participate at the discretion of the party that wrote the rules and publishes only part of them.
Four rulebooks, four owners, one machine
Fine, you might say: two documents, two governance models, pick one. It is worse than that. There isn't one door — there are several, and each belongs to somebody.
Google announced its Agent Payments Protocol on September 16, 2025, with more than 60 other companies collaborating, including American Express, PayPal, Etsy and Salesforce. Its design deserves credit: a chain of signed Mandates from intent to cart to payment, creating what Google calls a non-repudiable audit trail, explicitly framed as a foundation for accountability. Somebody, at least, is building the receipt. Mastercard Agent Pay arrived earlier still, on April 29, 2025, introducing Mastercard Agentic Tokens built on the network's existing tokenization. And the Agentic Commerce Protocol is jointly governed by OpenAI and Stripe as Founding Maintainers, which Stripe describes as an open standard — co-developed, open source, Apache 2.0 licensed and community-designed.
Each is competent; several are genuinely well-intentioned. Not one was ratified by anything resembling a public process, and every one will end up describing, in machine-readable form, what software is allowed to do while wearing your name.
The part where somebody objected
One small episode is more revealing than any structural argument I can make. It looks like a technical dispute; it is a governance story underneath.
On May 28, 2026, an account filed an issue against the MCP specification arguing that the standard is expensive by construction. The measurement was specific: in a typical Claude Code session with twenty to thirty registered MCP tools, the tool schemas alone occupy 15 to 30 KB of context window before a single user message is sent, heavy tools costing roughly a thousand tokens each just to describe — about fifteen cents per conversation in first-turn schema cost on frontier-model pricing with no caching, before anyone types anything. In English: every conversation begins with the machine reading a verbose introduction to every tool it might use, and you pay for that reading, in money and in the room left over for your actual problem.
The issue was locked and converted to a discussion under fourteen hours later, with no reply on the thread. Zero comments. Its status field reads "completed," which is an artifact of the conversion, not a fix.
The spec-level route had already been tried. A formal proposal on exactly this problem, filed September 30, 2025, was closed as dormant on June 26, 2026, with a courteous note pointing the authors at the contributor Discord to gauge community interest.
To be fair — and MCP's own rules insist on this distinction, so I will too — dormant is not the same as rejected. Their guidelines say so explicitly: a dormant proposal simply didn't find a sponsor, and the idea may still be valid. But look at what the sponsor rule requires. To advance you must find a Core Maintainer or Maintainer willing to sponsor the proposal, and the sponsor — not you — is responsible for updating its status. Your idea moves if an insider agrees to carry it. If nobody does, it doesn't die; it stops, quietly, for six months, and then gets a polite note.
Then the coda. Two days after the specification was finalized, somebody posted a reproducible benchmark against the current release: a 72-tool surface costing 33,709 tokens, about 17 percent of a 200,000-token context window, sitting there whether or not the task touches any of it. The post notes that both earlier threads closed without a spec-level answer, and asks whether there is appetite to revisit it now that there is a reproducible number to argue from. As of my reading it has zero replies.
And the thing that actually fixes it? It exists, it works, and it is not in the standard. Anthropic's tool search loads tools on demand instead of up front; by the company's own documentation, a typical multiserver setup that would consume around 55,000 tokens in definitions is typically reduced by over 85 percent.
Sit with that shape. A cost imposed by the standard, measured by outsiders, raised three times through sanctioned channels, and solved — for real, and well — by one vendor's client feature. The fix travels with the vendor, not the standard. The power that donating a protocol to a neutral foundation was supposed to distribute quietly re-collects in whoever ships the client.
Let me argue the other side properly
Two thousand words of suspicion is enough. Here is the counter-case at its strongest, because this piece is worthless if it only stacks the deck.
MCP's process is more open than I have made it sound. The same governance document reserves no seats for companies — membership is for individuals, not companies, the exact principle open-standards people spend their careers defending. Contributions are made under Apache 2.0, and no contributor has to assign copyright. Decisions and their supporting discussions must be recorded and made transparently available — on the Discord server, which the same page notes may also have private channels. And anyone can file a proposal: the guidelines call proposals the primary mechanism for collecting community input, kept as versioned files in the public repository, with the author responsible for building consensus and documenting dissenting opinions. Compared to a specification you may not reproduce without written permission, that is most of the difference.
Nobody snuck anything through. The release candidate was announced, the schema was readable, and anyone could have objected for sixty-eight days.
The vendor fix is a real fix, not a fig leaf. The trade-off it navigates is genuine — the same documentation notes that an assistant's ability to pick the right tool degrades once you exceed thirty to fifty available tools, and loading a focused set on demand keeps selection accuracy high across thousands. Stripping descriptions to save tokens would cost accuracy. Somebody had to engineer around that, and did.
And maybe private standard-setting is simply better at this. The market case, at its strongest from Adam Thierer of the R Street Institute: agencies should enforce existing laws as needed rather than issue broad new edicts against hypothetical harms, and should lean on multistakeholder negotiation and evolving consensus-based standards. His summary line is hard to dismiss — the best AI law may be one that already exists. The Center for Data Innovation argues in parallel that regulators should start by updating the rules written for human-initiated transactions.
That is a serious position and I hold part of it. But notice what it claims: that consensus-based standards beat rigid regulation. It says nothing about what happens when the "consensus" is eight sponsors and two maintainers with no term limit, and the objection procedure is a Discord invite. Multistakeholder governance is a real tradition with real machinery — and the machinery is the part everyone skips.
The boring alternative is already running down the hall
None of this requires inventing anything. The alternative to a spec finalized behind a ticket queue is ordinary, it is old, and the internet you are reading this on runs on it.
The IETF — the body that standardizes the actual internet — writes its own process down as a standard, and that document is blunt about disclosure. RFC 2026 requires each organization involved in developing and approving internet standards to publicly announce, and maintain a publicly accessible record of, every activity forming part of the standards process. Not a summary. Every activity.
Before a standard advances, the steering group must send a Last Call notice to the entire IETF, by email, so the general internet community can review it — a floor of two weeks, and no shorter than four when the proposal did not come from a working group, on the theory that outsider proposals deserve more review time, not less. And if you lose, you can appeal: any involved party may bring it to the relevant Area Director; then to the steering group as a whole; then to the Internet Architecture Board; and finally to the Internet Society Board of Trustees, whose president must acknowledge the appeal within two weeks. Four escalating levels, with a clock on the last one.
Who is allowed in? There is no membership in the IETF. That is a quotation, not a paraphrase. Anyone can participate by signing up to a working group mailing list or registering for a meeting; the only fee is meeting registration, with options in place to keep it from becoming a barrier; participants take part as individuals, including the ones being paid to be there. In a given year, over 7,000 people actively participate.
The mechanics are comically unglamorous. The Tao of the IETF, the community's own orientation guide, describes a working group as really just a mailing list with a bit of supervision and facilitation; you join by subscribing, all lists are open to anyone, and anyone can post. And the decision rule will sound familiar: there is no formal voting there either — disputed topics are settled by rough consensus. Which is why the comparison is fair rather than cheap. Both bodies decline to hold elections; the difference is what surrounds the absence of a vote. Rough consensus is a judgment call made in a public room, about arguments you can read, by a chair you can appeal against. Anyone can write a draft and submit it, and the deliberation happens in a public tracker.
Then my favorite artifact in all of standards-land. The IETF maintains a public list of appeals against its steering group's decisions, appeal and response attached, running from 2002 to a filing dated July 8, 2026 — a complaint, as it happens, about the steering group removing an appeal process. They publish the complaints about their complaints procedure. Appeals continue up to the Internet Architecture Board, and even appeals the board declines to process get a public acknowledgment and a brief explanation of why. A refusal to hear you gets written down, in public, with a reason.
The W3C runs the same machinery in its own dialect. Its process document says individuals who disagree strongly with a decision should register a Formal Objection with the chair, and sets review periods at 28 days minimum; its guidance for the W3C Council holds that council decisions form an important part of the public record precisely because they are the hardest cases, so the team report, the decision and the supporting rationale all go into that record. And this is not a museum piece. A council formed April 7, 2026 heard a formal objection to a digital-credentials specification over a paywalled normative reference, and published a report resolving to overrule the objection and let the reference stand. The objector lost, and the losing is dated, reasoned and published, which is the entire point.
Nor is the IETF standing aside from AI. It chartered an AI standard being written in the open — the AI Preferences working group, standardizing building blocks for expressing preferences about how content is collected and processed for AI model development and use, with the invitation stated as, subscribe to the mailing list. Its page carries named chairs, a public list and dated milestones, including specifications due to the steering group in August 2026.
So the honest comparison is not "closed corporation versus open utopia." It is two ways of writing rules that both decline to hold elections, where one has a public record, a waiting period, four levels of appeal and a published file of everyone who said the process itself was broken — and the other has a ticket queue and a Discord server.
Just imagine: it is 2031 and your agent got it wrong
It is a Tuesday in 2031. Your assistant has had standing authority over the household account for two years. It reorders the specialist formula your daughter needs, renews the insurance, pays the parking tickets you would otherwise forget. You have not thought about it in months, which is the highest compliment you can pay software.
Then it buys the wrong thing — a substituted formula from a reseller whose listing looked identical to the machine and wouldn't have to you. Six hundred dollars gone, and a week of a small person being unwell. So you complain.
The merchant says it fulfilled exactly what was requested, and produces a cryptographically signed request to prove it — which it does prove, because that is what signatures are for. Your assistant's vendor says its client behaved correctly against the specification in force that Tuesday. Your bank says the transaction carried a valid mandate. And somewhere in the stack, quietly, a rulebook says the party that initiated it isn't a merchant for the purposes of those rules — so the machinery you have relied on your whole adult life, the chargeback, the ombudsman, the regulator who takes complaints about shops, has nothing obvious to grip. Every participant is telling the truth. Every one is compliant. And no field in any of these documents carries the sentence you actually need to say: I object, here is why, and someone has to answer me.
Now imagine the same Tuesday in the other world. The protocol has a dispute primitive, because somebody proposed one in 2026 and it went to a Last Call instead of a Discord server. There is an appeal path with a name and a clock. And when the vendors argued over who eats the six hundred dollars, they argued in a public archive that a journalist, a regulator, or a stubborn parent can still read four years later. Same technology, same signatures — and the only difference is process, decided now, by people who mostly do not know you are watching.
What the people who study this actually say
I am not the first to notice this, and the people who got here before me are better qualified.
One of the two chairs of that AI Preferences working group is Mark Nottingham, a long-time standards participant whose preferred way of thinking about standards bodies these days is as regulators. His point is uncomfortable for everyone: the legitimacy of such a body is not based on democracy — inherently they have no demos, so they cannot be democratic in the sense that a state is. They draw instead on other sources, which he groups as input legitimacy (who participates), output legitimacy (what impact they have) and throughput legitimacy (what processes assure fair and good outcomes). He made the same argument in the IETF's own literature: RFC 9518 says the IETF has features that arguably provide considerable legitimacy — open participation and representation by individuals rather than by companies, plus a well-defined process with multiple layers of appeals and transparency. "Arguably" is his word and it stays his word. The honest version of this does not claim the old bodies are perfect; it claims they are accountable in a way you can check.
Then there is the measurement. A gap analysis by Richard Kang and Yudho Diponegoro, submitted June 30, 2026, compared five agent interoperability protocols against the primitives a governed community would need — and found that voting and dissent preservation are universally absent across all five. Not weak. Absent, in all of them. No protocol, they write, encodes the full set of primitives required for governed agent communities.
Scope that exactly: when they graded MCP line by line they were looking at MCP v1.1, schema dated November 25, 2025 — not the July 2026 specification this article opened with. On that version they rated human escalation absent, and audit partial: sessions maintain connection state, but there is no tamper-evident event log, no hash chain and no replay guarantee. Partial is not nothing, and I will not tell you these protocols can express no accountability at all. What I will tell you is that the ability to record dissent — the thing every human institution builds early — is the thing none of them built.
Nor is the idea hard or new. A 2025 paper on authenticated delegation from MIT-affiliated researchers had already sketched what a door for agents would need: a way for third parties to know on whose behalf an agent is acting, built by extending OAuth 2.0 and OpenID Connect with agent-specific credentials. Somebody wrote down the design; the standards shipped without it. And the lawyers are arriving from the other direction: writing in The Regulatory Review, legal scholars observe that our entire regulatory apparatus for consumer protection assumes a human is doing the shopping — and that when an AI agent shops on our behalf, that premise may collapse. Their hedge, not mine.
Which puts the whole spectrum in one paragraph. From the market side, R Street and the Center for Data Innovation say the answer is existing law plus consensus standards. From the consumer side, Ben Winters of the Consumer Federation of America says Americans are desperate for bold legislative action on AI that protects their data, pocketbooks, livelihood and communities — and that the 2026 federal bill on offer fails to do any of it. One side says the rules should come from the standards process, the other says Congress. Right now neither is producing an appeal you can file.
What does this mean for you?
You are not going to join a working group. Fine. Here is what is available, in rough order of effort.
Ask the dispute question before you hand over the card, not after. Not "is it secure" — security is fine, signatures work. Ask: if this buys the wrong thing, who do I call, and what rule obliges them to answer? If the answer is a support email address rather than a named procedure, you have learned something.
Ask your bank or card issuer, in writing, how an agent-initiated purchase is treated for disputes. The rulebooks have already defined the category and decided that whoever initiates such a transaction isn't a merchant under those rules. Get it on paper while the category is new and they still have to think about it.
Read one governance page. Find the governance page for the protocol your assistant speaks, and look for three things: who can overrule a decision, whether membership has a term limit, and whether there is any appeal. Four minutes, and it will change how you read every product announcement.
Notice which fixes live in the standard and which live in one vendor's product. The token problem in this piece is solved brilliantly — by a client feature. Anything solved that way is something you lose when you switch providers — a lock-in you can see coming.
Prefer the bodies that publish their losses. An organization that publishes the objections it overruled, dated and reasoned, behaves differently from one that closes a thread. It is the most reliable signal an outsider gets.
Say the word "appeal" to anyone who will listen — your representative, a regulator's consultation, the consumer group taking comments. How an agent signs a request is settled enough; what happens when it is wrong is wide open, and that is not a technical question at all. And if you build things, file the issue anyway. Remember what the invitation is at the older bodies: subscribe to the mailing list. There is no membership — not a slogan, a rule.
The lesson, as I see it
I spent twenty years treating standards as weather, because they used to describe machines talking to machines. Whether a header field was optional never determined whether anyone would answer me when something went wrong.
That era ended quietly, and I would date it at roughly now. Once a protocol describes software acting as a person — spending your money, accepting your terms, agreeing on your behalf — the specification stops being engineering and becomes something closer to administrative law. It defines a category of actor, assigns it permissions, and, by omission, decides which grievances are even expressible. A rulebook with no field for objection has not stayed neutral on objections. It has answered.
The good news is unusually concrete: the alternative already exists, it is unglamorous, and its central innovation is nothing more exotic than writing things down where people can read them. A mandatory waiting period. An appeal with a clock. A published file of everyone who said you got it wrong. None of that requires a treaty or a new agency — only a decision that legitimacy is worth the inconvenience.
My vote? Ask for the boring machinery, loudly and early, while these specifications are young enough to grow it. The signatures will get sorted out — that is engineering, and engineers are good at it. What will be almost impossible to retrofit is the right to be heard when the machine acting in your name gets it wrong. We had that right in the world of paper. We won it slowly. And nobody in this story has yet written it down for the world of agents.
Somebody is always writing the standard. The only real question is whether you get to read the argument — so send this to anyone who still thinks that's a developer problem.






