Blog

Why Enterprise Retail Will Not Buy a Black Box: Open Infrastructure and the Economics of Agent Networks

Published

September 13, 2026

Author

Pranay Rajput

Type

Insights Article

Reading Time

8 min

There is a $100 million lesson sitting in recent supply chain history that almost nobody in the AI industry has absorbed.

TradeLens, the shipping network built by Maersk and IBM, was not a bad product. It reached roughly sixty percent of global containerised trade, tracked tens of millions of containers and it had the technology, the anchor participant and the capital.

It shut down in early 2023, because Maersk’s competitors would not run their trade on infrastructure owned by Maersk.

That sentence is the most important thing an enterprise architect can know about the coming decade of agent networks. TradeLens did not fail on latency, throughput, or cryptography. It failed on ownership. Every participant could see that joining meant handing structural advantage to a rival, and no amount of engineering quality outweighs that calculation.

We are about to watch the same mistake repeat, at larger scale, with better graphics.

The walled garden problem, stated precisely

The common version of this argument is that enterprises reject proprietary AI platforms. That version is not true, and stating it that way will lose you the room. Large retailers run enormous proprietary stacks quite happily and will continue to.

The accurate version is narrower and more useful.

Enterprises will buy proprietary intelligence. They will not accept proprietary interoperability.

A retailer is perfectly willing to license the best forecasting model on the market, because if a better one appears in three years they can swap it. What they will not do is allow the layer that defines how they identify a product, prove who they are, and form a commitment with a supplier to be owned by a vendor. That layer is not a feature. It is the terms of trade for their entire supplier base, and handing it to a software company means renegotiating their commercial position every renewal cycle.

This distinction has a practical consequence that should shape every architecture decision you make: the boundary between what can be proprietary and what must be open falls exactly where switching costs become structural rather than technical.

Identity, product identity, and the protocol by which commitments are formed must be open, because the cost of changing them later is not a migration project, it is a renegotiation with every counterparty you have. Everything above that line is a legitimate place to compete on quality.

The vendors who understand this are already moving. The industry’s agent protocols have been migrating into neutral foundations rather than staying under corporate control, which is a reasonable signal about where the people building this expect the market to end up.

Three layers, and where the money is

The architecture that results has three distinguishable layers, and their economics are entirely different from each other.

The network layer is where participants are identified, discoverable, and able to prove things about themselves. This layer must be open, standards-aligned, and owned by no participant, for the TradeLens reason. It is also, correctly, where almost no money is made. Attempting to monetise this layer is what kills networks before they reach critical mass.

The application layer is where agents actually do work: negotiating supply, pricing perishables, rebalancing inventory, managing exceptions. This is where domain expertise lives and where genuine differentiation is possible. A markdown agent that understands produce is a different asset from one that understands electronics, and that difference is defensible. What a markdown agent actually does

The operations layer is where enterprises actually spend. Monitoring, health checks, incident response, upgrade management, and above all the contractual guarantee that when this breaks at two in the morning during a peak week, somebody is accountable.

That third layer is the one that outside observers consistently undervalue and enterprises consistently pay for. A Fortune 500 retailer is not primarily buying software. They are buying the ability to name a party who is responsible when the software fails. Open source does not remove that need. It relocates it, from a licence agreement to a service agreement, and the service agreement is frequently worth more.

Why giving the foundation away is the commercial strategy

This is the part that boards struggle with, so it is worth stating directly.

An open, free, neutrally governed base layer is not a concession to idealism or a marketing position. It is the only configuration in which the network reaches the scale that makes the upper layers valuable at all.

The value of an agent network to any participant is a function of how many counterparties are on it. A retailer’s buying agent is worth very little if it can transact with four suppliers. The economics only work when it can reach most of the supplier base, which means the cost and the political risk of joining must approach zero for the supplier.

Any friction at the base layer, whether a licence fee, a data condition, or the knowledge that a competitor owns the rails, is subtracted from adoption. And adoption is the entire asset.

So the commercial logic runs backwards from the usual instinct. You make the foundation free and neutral precisely because you intend to make money, not despite it. Revenue comes from managed hosting for participants who do not want to operate infrastructure, from auditability and compliance tooling for regulated enterprises, from domain-specific agents that require real expertise to build, and from service guarantees that carry real penalties.

None of those require owning the protocol. All of them get more valuable as more participants join a protocol nobody owns.

Is any of this actually proven

A reasonable architect should be sceptical here, given the graveyard referenced above and Gartner’s projection that more than forty percent of agentic AI projects will be cancelled by the end of 2027 on cost, unclear value or inadequate risk controls.

The honest answer has two parts.

The pattern is proven. India’s Open Network for Digital Commerce, built on the open Beckn Protocol, has processed over 350 million transactions across more than four hundred cities, with hundreds of thousands of sellers and over a hundred independent buyer applications. It is not a platform and not an intermediary. It is a set of open specifications that independently operated systems use to transact with each other, owned by no participant.

That is precisely the configuration TradeLens lacked, operating at national scale, in production, today.

The application of that pattern to enterprise retail supply chains in North America is new, and anyone telling you otherwise is overselling. The protocol substrate is hardened. The retail use case is early.

I think that combination is the right risk profile for a large enterprise in 2026. You are not betting on unproven infrastructure. You are betting that a proven infrastructure pattern reaches your category, and you are choosing whether to be among the participants who set its conventions or among those who inherit them.

What a serious architect should still be worried about

Three things, and a vendor who does not raise them unprompted is not being straight with you.

The cold start is real. A network with no counterparties has no value, and the first mover subsidises everyone who follows. This is why the anchor participant question matters more than any technical consideration. The practical path is not to launch an open network and hope, but to begin where a single organisation controls both sides of the transaction, prove the governance model there, then extend outward to the counterparties who are most ready.

The agent security surface is genuinely immature. Independent scanning of widely used agent tool servers has found critical vulnerabilities in a substantial proportion of them, frequently shipping with insecure defaults and no security documentation at all. Cross-organisational agent messaging means accepting instructions that originated outside your trust boundary, which is a class of risk most enterprise security teams have not yet modelled. This is not a reason to wait. It is a reason to insist that authority be scoped, time-limited and revocable rather than ambient.

Governance is a permanent cost, not a launch task. Someone has to arbitrate disputes, evolve the specification, and decide what happens when two participants disagree about what was committed. Networks that treat this as an afterthought discover in year three that the vendor with the largest engineering team has become the de facto governor, and the neutrality that attracted participants quietly evaporates.

One clarification on language

A note for anyone writing about this, including us.

The word that gets used for these networks is “permissionless,” and for enterprise retail it is both inaccurate and counterproductive.

These networks are open, but participation is governed. There are organisations that facilitate a given network, participants who are admitted to it, and policies that apply across it. That is federation, not anarchy.

The distinction matters commercially because no retailer wants an unvetted counterparty transacting against their systems. “Open and federated with governed participation” describes what actually exists and removes an objection. “Permissionless” describes something no enterprise wants and creates one.

The decision in front of you

The question is not whether autonomous agents will negotiate commercial terms across organisational boundaries. That is already happening in adjacent markets at meaningful scale.

The question is whether the conventions get set by an open foundation that your suppliers can join without strategic cost, or by whichever vendor reaches critical mass first and then prices accordingly.

Maersk built the better product and lost, because it forgot that infrastructure owned by a competitor is not infrastructure. It is leverage.


FAQ’s

Why would an enterprise prefer open agent infrastructure over a proprietary platform? Enterprises will buy proprietary intelligence but resist proprietary interoperability. The layers governing identity, product identity and how commitments are formed determine the terms of trade with an entire supplier base, so vendor ownership there creates structural rather than technical switching costs.

If the base layer is free, where does the revenue come from? Managed hosting, compliance and auditability tooling, domain-specific agents that require real expertise, and service guarantees with contractual accountability. Enterprises pay for someone to be responsible when systems fail, and open source relocates that need rather than removing it.

What killed TradeLens and why does it matter here? TradeLens reached roughly sixty percent of global containerised trade but shut down in early 2023 because competitors would not build their trade on infrastructure owned by Maersk. It failed on ownership, not technology, which is why neutral governance of the base layer is a commercial requirement rather than a philosophical one.

Are these networks permissionless? No. They are open and federated. Participation is governed by facilitating organisations, admitted participants and network-wide policies, which is what enterprise counterparties require.

What is the biggest unaddressed risk? Agent security. Independent scanning has found critical vulnerabilities in a substantial proportion of widely used agent tool servers, often with insecure defaults. Cross-organisational agent messaging means processing instructions from outside your trust boundary, which requires scoped, time-limited and revocable authority rather than standing permissions.

We use cookies to enhance your experience, analyze site traffic and deliver personalized content. Learn more about who we are, how you can contact us, and how we process personal data in our Privacy Policy.