This series started with a small claim: an agent is only as useful as what it can reach, and it reaches across two boundaries that are different enough to need two protocols. Five parts later, MCP and A2A are no longer mysterious; they are just JSON-RPC, a handshake, some primitives, and a task lifecycle. So this final part does the thing the others deliberately did not: it looks forward. What is actually built, what is still missing, and where a field this young is likely to go. I will mark my confidence on each claim, because the further out we look the softer the ground gets, and pretending otherwise would betray the whole point of grounding the earlier parts in specifications.
What is already settled
Start with the parts I am confident about, because they are load-bearing. The three-boundary stack from part five is real and working today: agents reach down to tools, across to peers, and up to users, and the lower two boundaries have mature protocols.1 MCP is the default way an agent reaches a tool, adopted across essentially every major client, and its data layer is stable. A2A is the emerging default for agent-to-agent delegation, with a v1.0 spec and enterprise production use. If you are building now, you can treat the tool boundary as solved and the peer boundary as solid-but-moving, and that is genuinely new: two years ago neither boundary had a standard at all.
That is the floor. Everything below is built on it, and everything below is less settled.
The unsolved problem of identity
Here is the first hard gap, and I hold it with high confidence because the specs themselves point at it. When your agent delegates a task to a peer it found on the open web, how does it know that peer is who it claims to be, and that it is safe to hand work to? A2A’s signed Agent Cards let a client verify that a card belongs to the agent it names, which is a real start.2 But cryptographic identity is not the same as trust: a verified agent can still be incompetent, compromised, or hostile. There is no standard yet for agent reputation, for attestation of behavior, or for the equivalent of a certificate authority that vouches for what an agent will do with your data. This is the layer that infrastructure efforts like AGNTCY are reaching for, and I would bet strongly that agent identity and trust, not the wire protocols, is where the next two years of hard standards work actually happens.
Discovery at internet scale
Identity’s sibling problem is discovery. A2A’s well-known Agent Card path is excellent when you already know an agent’s domain: you fetch /.well-known/agent-card.json and read off its skills.3 But that assumes you know where to look. There is no agent equivalent of a search engine or a package registry, no directory you can query for “an agent that can do X, that I am allowed to use, that others have found reliable.” My best understanding is that discovery is currently solved only within trust boundaries you already control, an enterprise’s own agents, a vendor’s catalog, and that open-web discovery is mostly aspirational. Whether the answer is a registry, a search protocol, or something woven into the identity layer is, I think, genuinely undecided.
Security compounds as the web connects
Part three’s lethal trifecta does not stay constant as this stack grows; it gets worse, and I am confident about the direction even if not the magnitude. Every server an agent connects to adds capabilities, and every peer it delegates to widens the surface, so the odds that some agent in a chain ends up with private data, untrusted content, and an exfiltration path at once rise with connectivity.4 None of the protocols solves this at the protocol level today; the spec guidance is essentially “do not assemble the trifecta,” which is hard to guarantee across a multi-agent system you do not fully control. I would guess the response over the next couple of years looks like standardized sandboxing, permission scopes that travel with a delegated task, and provenance tracking for where context came from. That is a prediction, not a report, and it could easily be wrong in its specifics; what I am confident of is that security has to move from advice to mechanism, because advice does not scale to a web of agents.
The economic layer agents will need
Now I am on softer ground, and I will say so. If agents routinely delegate to agents they did not build, sooner or later some of those peers will want to be paid, metered, or rate-limited per caller, which means agents need a way to transact. There is early work on agent-to-agent payment and authorization flows, and it is plausible that a standard layer for “this agent is authorized to spend up to X with that agent” emerges on top of the auth models the protocols already have. I hold this loosely: it is an inference from how every other open platform eventually grew a payments layer, not something the current specs mandate. Treat it as a direction to watch rather than a prediction I would stake much on.
Will the two foundations converge?
The governance split from part five is the question I am least certain about, so I will give a range rather than an answer. Today MCP sits under the Agentic AI Foundation and A2A under the Linux Foundation proper, with overlapping corporate casts and a faint air of rivalry.5 6 One path is convergence: both are under the broad Linux Foundation umbrella, both serve different boundaries, and coordinated stewardship would serve everyone. Another path is drift, where the Anthropic-and-OpenAI axis and the Google-anchored A2A camp pull their adjacent standards in different directions and builders pay an integration tax. I would put more weight on coexistence than on either a clean merger or an open split, but my confidence here is low, and this is the variable I would revisit first if I were writing a follow-up in a year.
A dated, falsifiable forecast
Vague prediction is cheap, so here is a concrete one you can hold me to, stated so it can be proven wrong. By the end of 2027, I expect: MCP remains the dominant tool-access protocol with no serious challenger displacing it; A2A is the most common agent-to-agent protocol in enterprise multi-agent systems, though not universal; at least one widely-adopted standard exists for the agent-to-user edge, whether AG-UI or a successor; and agent identity or discovery has produced at least one real, cross-vendor standard that did not exist in 2026. I am fairly confident on the first two, less so on the third, and genuinely uncertain on the fourth, which is exactly why it is the interesting one. If three of those four hold, the thesis of this series, that the agentic web is built boundary by boundary rather than by one protocol, will have aged well. If they do not, the most likely reason is the governance question above resolving in a way I did not expect.
Takeaways
The series opened on reach, and it closes there too. An agent is still only as useful as what it can touch, and the story of the agentic web is the story of those reaches becoming standard:
- The boundaries are permanent; the protocols are young. Down to tools, across to peers, up to users will always be three different problems. MCP and A2A fill the first two well today; the rest of the stack is still forming.
- The frontier moved up the stack. The wire formats are largely solved. The unsolved work is identity, trust, discovery, security as mechanism, and eventually economics, the layers that decide whether agents can safely meet strangers, not just talk to ones they already know.
- Bet on boundaries, hold predictions loosely. Adopt the mature edges now, design for the emerging ones, and treat anyone selling a single unified agent protocol with suspicion, because the whole shape of this field argues against one.
The first part of this series said the agentic web would be built out of more than one protocol, because an agent faces more than one kind of boundary. Everything since has been the detail under that claim. The boundaries were the permanent thing; the protocols are how we are learning, in public and a little messily, to let a reasoning system safely reach past itself. That reach is still the whole product, and it is still mostly ahead of us.
Footnotes
-
The complementary, stacked relationship between A2A (agent-to-agent) and MCP (agent-to-tool) is described in A2A and MCP; the user-edge protocol AG-UI is documented at docs.ag-ui.com. ↩
-
Signed Agent Cards, which let a client cryptographically verify a card’s ownership, landed in A2A’s v1.0 spec in 2026. See the A2A GitHub releases. ↩
-
A2A discovery via the Agent Card at a well-known URL is defined in the A2A key concepts. ↩
-
Simon Willison, The lethal trifecta for AI agents, which becomes more likely to assemble as an agent connects to more tools and peers. ↩
-
MCP joined the Agentic AI Foundation, co-founded by Anthropic, Block, and OpenAI, in December 2025. See MCP joins the Agentic AI Foundation. ↩
-
A2A was donated to the Linux Foundation in June 2025. See the Linux Foundation A2A launch. ↩