MachineEconomy.ai

The Machine Economy: The Second Reading

The second monthly reading of the Machine Economy Index. A month on, the machines are being built faster than ever — and the world still cannot see who they are, or hold them to account.

Published: 2026-08-31

MEILRRSsecond reading

What this is

Last month we published the first reading of the Machine Economy Index (MEI) — a composite index built from 14 metrics across four components (Payment, Physical, Legal, Macro), each weighted equally and combined with a geometric mean rather than an average, so that a weak component cannot be papered over by a strong one. Every input is fetched from a primary source on a fixed cadence; every bound, anchor and weight is published; every metric we rejected is on the record with the reason.

This is the second reading. A single month is a short time in the life of an index like this, and the honest headline is that most of it did not move. That is itself a finding, and we will come to it. But underneath the flat composite, three things happened in August that are worth a report: the payment layer began to look like real infrastructure — and began to fracture; Europe's largest scheduled legal remedy was quietly cut back again; and we took a hard measurement of the one identity rail the machine economy has, and found that most of what it counts is not real.

That last one is where this report spends its time.

Where things stand

The Machine Economy Index reads 31.8 out of 100 (31 August 2026), against 31.7 a month ago on the same basis. As we said last time, the composite is the least interesting number here.

ComponentAugJul*What it measures
Payment3738Machine-to-machine settlement — on-chain volume, transaction counts, identity
Physical5251Compute and storage capacity, and how much is being used
Legal1212Whether the world's legal systems have caught up. GDP-weighted.
Macro4342Adoption — developer and enterprise

* A note on the July column, because we would rather explain it than have you catch it. The report we published in July read 32.6, with Payment at 43. These are not those numbers. Between the two readings we revised how one metric — agent-registry activity — is measured, and backdated the revision across the whole history so the series stays consistent with itself (this is version 1.2 of the methodology; the change and its full disclosure are on the methodology page). The July column above is July restated on today's basis, so the month-over-month comparison is like-for-like. The single largest effect of that revision falls on Payment, and it is the reason Payment reads 37 rather than higher — not because machine payments shrank. They did not; on-chain volume rose. We explain exactly why below, because the reason is one of this month's findings.

So the real month-over-month picture is small and, in three of four components, slightly up. Physical rose a point. Macro rose a point. Legal did not move at all. And Legal not moving is not an accident of a quiet month — we spent August verifying it, jurisdiction by jurisdiction, and it is the correct reading. More on that below, too.

The property that governed the July report still governs this one: because Legal is the lowest component and the geometric mean is most sensitive to the weakest input, the fastest way to move this index remains legal infrastructure, and nothing that happened in August changed that. The balance gap — the distance between the arithmetic mean (36.2) and the geometric mean (31.8) — sits at 4.3, essentially where it was. The machine economy's foundations are as uneven as they were a month ago.

Identity — the rail that counts phantoms

This is where the reading matters most this month, and it is a finding we can make because we measure it directly rather than take anyone's word for it.

The machine economy has, at present, essentially one public, on-chain identity rail: the ERC-8004 agent registry. It is how an autonomous agent can, in principle, be identified — given a persistent handle, a content record, a way for a counterparty to know who it is dealing with. Last month we reported roughly 1,900 identity events over thirty days and said, plainly, that agent identity was early: the infrastructure exists; it is barely used.

This month we looked much harder, because in early August something happened that made the looking necessary. Over about two days, roughly 1,130 fresh addresses registered on ERC-8004 in a mechanical burst — empty content records, lockstep timing, funding traceable to a handful of sources. It was not adoption. It was manufactured. It was also not, as far as we can tell, aimed at us — the registry is simply cheap to write to, and someone wrote to it at scale.

That event forced a question we then answered for the whole registry, not just the burst: how much of ERC-8004's activity is real breadth, and how much is manufactured? The registry's own raw count cannot tell you — it counts a genuine new agent and a scripted empty shell identically. So we measure it the way the rest of the index measures cheap-to-write signals: we cap how much any single actor can contribute. An agent economy is broad when many independent actors show up, not when one actor shows up many times. Manufactured breadth has two signatures — many registrations from one address, or many from one content source — so we cap both, at the same threshold, and count what remains.

Here is what the current thirty-day window actually contains.

The raw registry activity is 3,719 events. After capping manufactured breadth on both axes, the figure the index publishes is 732. The gap — roughly 2,987 events, about 80% of the raw count — is breadth that collapses under the cap because it is not independent: it comes from the same addresses, or points at the same content, over and over.

The shape of it is stark. There are 1,748 distinct addresses in the window — but only 263 distinct content origins among them. Real, independent agents do not share content records; each has its own. A registry where seven addresses appear for every one distinct piece of content is a registry full of empty shells and forks. Nearly half — 49.2% — of all raw activity points to a single, identical origin. A quarter — 24.6% — comes from one wallet.

The conclusion is not that the identity rail is broken, and it is not that measuring it is pointless. It is the opposite. The rail is doing exactly what a readiness metric should: telling us the truth about the state of agent identity, which is that the layer exists, real adoption is still forming, and most of the activity on it today is manufactured. That is a finding about the machine economy, not a flaw in the instrument. The reason we cap manufactured breadth and publish the capped number — rather than the flattering raw one, or dropping the metric because it is noisy — is precisely so the index says something true. An index that reported 3,719 and called it adoption would be lying. We report 732, and we can show you the 2,987 that is not real.

This is also why Payment reads 37 and not higher this month. The revision that produced these figures — capping the registry on content-origin as well as address — is what version 1.2 of the methodology does, and applying it compressed the registry's contribution to the Payment component. That is a more honest number arriving, not a decline in machine payments. The payments themselves grew, as the next section shows.

Payment — becoming infrastructure, and starting to fracture

The Payment component scores 37. Beneath it, the machine payment rail did something new in August: it started to look like infrastructure that the rest of the software world builds on — and, at the same time, it split into two competing ideas about what a machine payment even is.

The volume first, from our own measurement. Over the last thirty days, roughly $1.43 million settled on-chain through the x402 protocol, across approximately 20.4 million transactions. Do the division: the average machine payment is now about seven cents ($0.070), up from about five in July. The nanopayment pattern we flagged last month is not only holding, it is running at higher volume — total on-chain settlement is up meaningfully month-over-month.

What changed in August is who is building on it. Amazon Web Services brought its agent platform's payment feature to general availability with native support for x402 — meaning an enterprise agent running on AWS can pay for a third-party API without a human procurement team wiring up billing for each vendor. The Internet Engineering Task Force — the body that standardises how the internet works — has an active draft for discovering x402 payment terms over DNS, the same way a browser finds a mail server. And there are live production deployments of agents transacting autonomously for real goods: one lets an enterprise agent discover and retire carbon credits on-chain, programmatically, within limits its owner sets — a task that used to take humans days of bilateral negotiation.

Last month we described x402 as "one protocol wide" and admitted it under a dominance clause because it was essentially the entire publicly verifiable on-chain machine-payment rail. It still is that. But a protocol that AWS supports natively, that the IETF is standardising, and that real businesses are settling through is no longer just a promising experiment. It is becoming a rail.

And here is the fracture. A protocol that moves money autonomously is not the only way to let an agent pay. Google's Agent Payments Protocol (AP2), donated in 2026 to the FIDO Alliance, takes the opposite approach: rather than settling value on-chain, it attaches cryptographic proof of human authorization to an otherwise ordinary card-rail transaction — a signed "mandate" that says a specific person approved this purchase under these constraints. Its latest version adds flows for the agent to transact with no human present at the moment of purchase, once the initial mandate is signed.

These are two genuinely different philosophies. x402 removes the human from the loop and settles instantly and irreversibly. AP2 keeps a human's signed consent at the root and rides the existing card networks, with their chargebacks and dispute resolution. Neither has solved the question that actually matters: who is liable when an autonomous agent, acting on a cryptographically valid instruction, does the wrong thing. In August a security analysis of AP2, published as an academic preprint, made the problem concrete: because the protocol's signed mandate covers only the final transaction and not the context the agent used to build it, an attacker who poisons that context — the catalogue the agent read, the tool results it trusted — can get a human or an agent to cryptographically sign a mandate for a purchase that was quietly altered. The signature is valid. The transaction is fraudulent. The law has no settled answer for what happens next.

That is the state of the machine payment layer at the end of August: real enough that AWS and the IETF are building on it, contested enough that two incompatible models are competing to define it, and immature enough that the hardest question — liability for autonomous acts — is unanswered on both. The rail is being laid and argued over at the same time.

Physical — the rail that works, and the vendor it rests on

The Physical component scores 52, up a point, and remains the strongest of the four. The machines are still being built, faster than ever.

The clearest single measure of that is Nvidia's data-centre segment, which we track as the best verifiable proxy for compute capacity formation. In results reported on 26 August 2026 for its second fiscal quarter (ended 26 July 2026), Nvidia's data-centre revenue reached $89.02 billion, part of $96.22 billion in total revenue — figures we take directly from the company's own SEC filing. Whatever else is true about the machine economy, the compute underneath it is being manufactured and sold at a scale that has no precedent.

Decentralised compute and storage continue to transact. The Akash network cleared roughly 29,000 leases and settled about $276,000 in spend over thirty days, with utilisation of its GPU capacity running high. Filecoin holds substantial raw storage capacity — about 1,416 pebibytes — with utilisation around 42%, a meaningful fraction doing real work.

The caveat we placed on this component last month stands unchanged, and we restate it because it is still the largest weakness in our own construct. Nvidia's revenue measures one vendor's sales. If the largest buyers shift toward their own captive silicon, true compute capacity could rise while our metric falls — quietly, in the right-looking direction. Nothing we saw in August triggered the review threshold we pre-committed to (Nvidia's merchant share falling below 60%), but the risk is structural and we continue to watch it. What Physical measures is merchant-market compute capacity formation, not total compute; captive silicon remains a declared gap.

Legal — a month of motion, and no movement

The Legal component scores 12. It did not move, and we can now say that with more confidence than a quiet month would normally justify — because in August we re-verified every jurisdiction in the model against primary sources, one at a time, and confirmed that not one of the status calls changed.

That verification is itself the month's most useful legal finding, because August looked, from a distance, like a very busy month for machine-economy law. It was busy. It just did not move readiness, and the gap between those two things is the point.

There was motion everywhere. Italy gave final approval to the implementing decrees for its AI law. Latvia issued the first binding legal acts admitting participants to its regulatory sandbox. Several US states advanced legal wrappers for decentralised organisations. Stablecoin frameworks continued to mature across jurisdictions. Read the headlines and you would think the legal rails were being laid quickly.

Now apply the test the LRRS actually uses. It does not ask whether a jurisdiction is busy; it asks whether the world's economy operates under law that can accommodate an autonomous economic agent. On that test, the findings from July are unchanged, and we confirmed each against its primary source:

No jurisdiction on earth recognises an autonomous agent as such. Not one. The one sovereign that vests the management of a company in a smart contract remains the Marshall Islands, and it remains too small to draw on a GDP-weighted map. The category that would measure genuine legal personhood for an autonomous agent is empty worldwide — and the discernible trend in the largest economies is away from it, not toward it: the notable US legislative activity we could verify moves to foreclose AI legal personhood and assign liability to the humans behind the software, not to grant the agent standing of its own.

And Europe deferred its own remedy again — further than we knew last month. In July we reported that the EU's Digital Omnibus had pushed the deadline for member states to run operational AI sandboxes from August 2026 to August 2027. Verifying the August picture against the Regulation's own text, we found the deferral was broader than the sandbox deadline alone. 2 August 2026 was the EU AI Act's headline application date — the day the Act was meant to bite. What actually took effect that day was its lightest layer: the Article 50 transparency obligations, which require that a system disclose when a person is interacting with an AI rather than a human, that synthetic content be machine-readably marked, and that emotion-recognition use be disclosed. Those are real, and for the machine economy they matter — an agent dealing with a person must now, in the EU, say that it is not one.

But the substantive obligations — the risk-management, technical-documentation, and human-oversight rules that would actually govern how high-risk autonomous systems operate — did not take effect on that date. The Digital Omnibus deferred them to 2 December 2027. So the day Europe's AI Act was supposed to arrive, the transparency labels went live and the substance was pushed back another sixteen months. The pattern we identified in July — the largest scheduled improvement in the world's legal readiness slipping to the right — is not a one-time event. It is the shape of the thing.

This is why an earlier version of this index did not credit jurisdictions for laws that oblige someone else to build a framework, and why Legal reads 12. A readiness score that rose every time a legislature announced an intention, and never fell when the intention was postponed, would be measuring press releases. Ours measures what is in force. In August, what is in force did not change.

Macro — developers ready, employers arriving slowly

The Macro component scores 43, up a point, and the split we described last month persists.

Developer adoption remains high. Downloads of the Model Context Protocol SDK and the major Python agent frameworks run into the hundreds of millions per month — over 200 million and 140 million respectively over thirty days. People are building agents at scale.

Enterprise adoption is arriving, slowly. The US Census Bureau's business survey now puts AI use at about 22.4% of firms; Eurostat's EU equivalent sits near 20%. The US figure has ticked up from the roughly 20.6% we cited in July — real, if modest, movement — but the underlying picture is the same one the index surfaced last month: the people building agents are far ahead of the businesses deploying them. These are among the slowest-moving inputs we track, drawn from national statistical agencies, and a point of movement in a month is more than they usually show.

What we cannot see

Our blind spots are unchanged from July, and we continue to publish them rather than let you discover them. The most consequential remain: closed-rail machine payments (agents paying via corporate cards, cloud billing, and metered APIs — probably larger than everything we measure on the Payment rail, and invisible to us); off-chain machine payments such as Lightning / L402, which settle off-chain by design and cannot be measured; captive silicon, the hyperscaler-designed accelerators our merchant-market compute proxy cannot see; and energy, embodied machines, and digital-asset property law, each a real part of the machine economy with no Tier-1, high-cadence source, or no home in our current five legal categories. Each has, on the methodology page, a statement of the source that would close it.

One boundary is worth naming freshly this month, because August put it in sharp relief. Our identity metric measures whether independent agents are being registered. It cannot, and does not try to, measure whether a registered agent is competent, honest, or accountable. The rail we measure gives an agent a name; it does not vouch for it. The gap between "an agent can be identified" and "an agent can be trusted" is real, and the events of August — a registry filling with phantoms, a payment protocol whose valid signatures can be poisoned — are two different views of the same unsolved problem. We measure the first. The second is a gap, and an important one.

What we are watching

Three dated things, stated so we can be judged on them.

2 December 2027. The EU AI Act's high-risk obligations, deferred there by the Digital Omnibus. This is now the substantive test of whether Europe's framework arrives, distinct from the sandbox deadline (2 August 2027) we were already watching. If the high-risk regime takes effect on schedule, it is one of the largest known future movements in the world's legal readiness. If it slips again, we will say so.

The next sandbox admissions. Two EU member states — Italy and Lithuania — have frameworks in force and are the likeliest to admit their first participants and cross from "enacted" to "operational" in our model. We are watching for the admitting instruments, because our rule is that "operational" requires evidence that someone was actually let in, not merely that a law exists.

The liability question on both payment rails. Neither the settle-on-chain model (x402) nor the signed-mandate model (AP2) has a settled answer for who is liable when an autonomous agent acts, validly, on a bad instruction. It is the question the whole payment layer is building around and has not answered. We are watching for the first jurisdiction, court, or standard that does.

How to check us

Everything in this report is derived from data you can pull yourself, or from primary sources you can read.

  • The live index and every component, updated daily: /mei
  • Every metric, its value, its source, and when it was last fetched: /data
  • The full methodology, including the version 1.2 revision to the identity metric and why we made it: /methodology
  • A public API, free and unauthenticated: /api

The findings in this report that rest on outside events — Nvidia's results, the AWS and IETF developments, the EU AI Act's application dates, the security analysis of AP2 — are drawn from primary sources: company results, official standards records, the Regulation's own text, the published paper. The findings that rest on measurement — the state of agent identity, the volume of machine payments, the readiness of the law — are drawn from the index, which you can check. We looked into a number of other developments this month that we could not confirm against a primary source, and we have left them out.

If we have made a mistake, we would like to know. The index is not the argument. The index is the instrument. Everything above is what it currently reads.


The Machine Economy Index is published by MachineEconomy.ai. Figures in this report are as of 31 August 2026. The index is recomputed daily; the live value will differ. Component figures for July are restated on the current (v1.2) methodology basis for like-for-like comparison; the originally published July report read 32.6 on the prior basis.