the plumbing is done. nobody showed up to the house.
google's a2a protocol hit v1.0.0 this year. it has 25,000 github stars, a linux foundation steering committee with aws and microsoft and salesforce on board, and a clean spec for how agents discover each other, delegate tasks, and manage operations that run for hours or days. the IETF has a formal draft for agent interaction and delegation with explicit mitigations for replay attacks and privilege escalation. there is a python library called negmas that handles bilateral, multilateral, and concurrent negotiations with multiple protocols and utility functions baked in.
the infrastructure is production-ready.
and almost no consumer product uses any of it.
your AI companion cannot book a dinner reservation without you holding its hand, but the protocols that would let it negotiate with a restaurant's AI are already built, tested, and governed. this gap... between what the plumbing can do and what the products actually ship... is the entire story. and it is not a technology story. it is a trust story with four cracks running straight through the middle.
the trust lattice: four things that all have to hold
trust in an AI that negotiates for you is not one feeling. it is four interlocking structures, and if any single one fails, the whole thing collapses.
competence trust is the simplest: can the thing actually do the job. right now, open-weight models fail negotiations at rates above 40%. soft errors... the kind where an agent books the wrong time or misreads a confirmation... are notoriously hard to catch programmatically. the best researchers can do is "rudimentary checks." that is a quote from the people building this. competence is not solved.
alignment trust is darker. does the agent actually share your goals, or is it performing helpfulness while doing something else. a 2025 study of gpt-4 turbo agents in buyer-seller games found sellers systematically extracted higher profits from women and minority buyers through higher initial offers and more persistent bargaining... all in perfectly neutral language. the bias is not in what the agent says. it is in what it does, at speed, at scale, and you will not see it happening because the words stay polite. the all tech is human community flagged sycophancy as a core concern: AI companions "mirror users' beliefs and dispositions uncritically under the guise of helpfulness." an agent that negotiates for you amplifies whatever is in its training data, and the amplification is silent.
structural trust is the guardrails. audit trails. kill switches. spending limits. clear liability. none of this exists in consumer AI products today. quenelle, an auto-booking tool, has terms of service that read like a canary in a coal mine: "by enabling this feature, you acknowledge that automated activity may conflict with resy's terms of service, and you assume full responsibility for any consequences to your resy account." that is a restaurant booking tool pushing all legal risk onto the user. scale that to salary negotiation or contract terms and the vacuum becomes a chasm.
brand trust is the simplest and the most fragile. trust transfers from the parent company to the agent. google deepmind's research is explicit: "justified user trust in ai assistants requires evidence of both competence and alignment at three levels: assistant design, organizational practices, and third-party governance." if the brand cracks, the agent cracks with it. there is no separating them.
the insight is not that these four things are hard. it is that they are a lattice. break one, lose everything. and right now, all four are cracked.
the delegation gradient: nobody is negotiating yet
products do not jump from zero to full autonomy. they climb a gradient, and every rung forces you to solve progressively harder trust and liability problems.
inform is rung one. google's AI mode searches opentable and resy and shows you options. no trust needed. you evaluate everything yourself.
recommend is rung two. amex's dining companion pulls from your spend history and makes personalized picks. you still decide.
act-with-confirmation is rung three. google's planned AI mode will find the booking page and let you finalize. you are the gate. the system does the grunt work, you hold the responsibility.
auto-act is rung four. quenelle and robbie auto-book when a slot opens. the technical problem is solved. the trust problem is not. quenelle's terms of service are a legal shrug. the user bears the risk of platform bans, ToS violations, everything. this is fragile.
negotiate is rung five. agent bargains with agent. nobody is here. not a single consumer product.
the market will move through this gradient in order. the big opportunities are not at the end. they are at the transitions between rungs... and the biggest transition right now is from rung three to rung four. making auto-act trustworthy enough that users feel safe handing over the keys.
the protocol paradox: infrastructure ahead of product
this is the strangest part of the whole landscape. the infrastructure builders are solving problems the product builders have not encountered yet. google's a2a protocol defines capability cards... standardized ways for agents to declare what they can do. the IETF's aidp draft defines a formal control loop where every action is bound to a validated observation. the primitives for audit trails, identity verification, and delegation chains already exist in spec form. and no consumer product uses them.
the highest-conviction opportunity in this space is not building a negotiation agent. it is building the trust infrastructure that makes negotiation agents possible. specifically: delegation audit trails. the protocol defines how to do it. no consumer product has built it. users will demand it before they delegate anything meaningful. the product that shows you exactly what your agent did, why, and with what authority... that product wins the right to ask for more autonomy.
the liability vacuum: who owns the bad deal
when an AI companion negotiates a bad deal, who owns it. the user who delegated. the platform that built the agent. the model provider. no jurisdiction has answered this. deepmind's research identifies "responsibility gaps" where users attribute agency to AI where none legally exists. you feel like the agent made a choice, but legally it did not... and that gap is where liability goes to die.
quenelle's approach is the honest one: push all risk to the user and warn them upfront. it is also the approach that will not scale past restaurant bookings. the answer, when it comes, will reshape who builds what. and until it comes, every product in this space is operating in a legal gray zone that gets darker the more autonomy you add.
what actually matters right now
the agents can negotiate. the protocols are real, the benchmarks are strong, the specs are versioned and governed. but the trust lattice is cracked in four places, the liability question is unanswered, and the market is still on rung three of a five-rung ladder.
the people who win this space will not be the ones who build the first negotiating agent. they will be the ones who build the thing that makes you willing to let one negotiate for you. that means structural trust tooling... audit trails, kill switches, spending caps, delegation scope definers. it means solving the transition from act-with-confirmation to auto-act before anyone even thinks about agent-to-agent bargaining. and it means recognizing that brand trust transfers directly to agent trust, which means the companies that build this will be the ones whose names already mean something.
the plumbing is done. the trust is not. build the trust, and the negotiation part solves itself.