Open-Source Agent Protocols Cross 100 Million Daily Automated Tasks
An open standard that lets software agents pass tasks to one another is now handling a reported 100 million automated actions a day, its maintainers say. Here is what that means, and what to be careful about.

boltCore Drivers
- check_circle100 million daily actions, maintainers sayThe figure is self-reported and counts very small tasks alongside complex ones.
- check_circleA common language for agentsThe protocol defines how one automated assistant asks another to do a job and reports back.
- check_circlePermissions are the weak spotSecurity researchers warn that chained agents can multiply the damage from a single mistake.
Software that acts on your behalf, booking a meeting, reconciling an invoice, reordering office supplies, has been around for years in narrow forms. What is changing is that these automated assistants increasingly talk to each other. In this launch-edition explainer, an open-source protocol designed to let one AI agent hand a task to another has crossed what its volunteer maintainers describe as 100 million automated actions a day.
That number is impressive, but it needs unpacking before it means much.
What an agent protocol is
Think of it as a shared etiquette. The protocol sets out how one agent describes a job (“find three available meeting slots next week”), how another agent accepts or declines it, what information can be passed along, and how results and errors are reported. Because the standard is open, developers building very different tools can make them cooperate without custom integrations for every pair.
- Task requests: a structured description of what needs doing and by when.
- Capabilities: each agent declares what it can do and what access it needs.
- Receipts: every completed or failed task produces a record that humans can audit.
Reading the 100 million figure
The maintainers compile the count from voluntary telemetry sent by participating services, so it cannot be independently checked. It also treats every action equally. Checking a calendar counts the same as filing an expense report, and a single human request might trigger dozens of small agent-to-agent steps. A more useful measure would be how many completed human goals the protocol supports, and nobody is reporting that yet.
The number tells you adoption is real. It doesn’t tell you how much value is being created, or how often things go wrong. — a researcher who studies automated systems
Where people already meet agent chains
Most people will never see the protocol directly. They will notice it when a travel assistant rebooks a cancelled train and then asks the hotel’s booking agent to shift the reservation, or when an accounting tool asks a supplier’s system for a missing invoice. In small businesses, chains of agents now handle routine back-office work such as matching receipts to card payments, chasing overdue invoices with polite reminders, and updating stock counts. The appeal is obvious: less copying and pasting between systems, fewer forgotten follow-ups.
The open nature of the standard is part of its appeal for developers. Because no single company controls it, smaller tool makers can join without paying licensing fees, and users are not locked into one vendor’s ecosystem. That openness also means there is no central authority to vet every agent that speaks the protocol, which brings us to the main worry.
The security question
The more agents can call one another, the more one bad instruction can travel. Security researchers have flagged several concerns: an agent that was granted broad access might pass that access to another it shouldn’t trust, malicious instructions hidden in a document could be relayed down a chain, and errors can compound when no human checks the intermediate steps. The protocol includes permission scopes and receipts, but those only help if developers configure them carefully and someone actually reads the logs.
For ordinary users, the practical point is simple: any assistant that can act for you should ask before doing anything costly or irreversible, and should show you what it did. Tools that cannot explain their actions deserve caution.
The bottom line for now
Agent protocols are plumbing. Good plumbing is invisible and makes everything else easier; bad plumbing floods the house. The maintainers deserve credit for building receipts and permission scopes into the standard from the start, but the safety of any given chain depends on choices made by many different developers. For the moment, the sensible stance is curiosity paired with caution: use agent features that save real time, keep approvals switched on for anything that spends money or sends messages, and review the activity log now and then.
What to watch next
The maintainers are working on a revision that would require explicit human approval for payments, deletions and messages sent to outside contacts. Watch for whether major tool builders adopt that stricter default, and whether anyone begins publishing independent data on error rates. Those two things will say more about whether agent-to-agent automation is ready for everyday life than any daily action count.
About this story: this is an illustrative launch-edition scenario. Organizations and people in it are fictional or unnamed, and figures are attributed within the story. Our standards.
Written by
Kaito Tanaka
Compute & AI Reporter — launch-edition house byline. About our bylines • Report an error

