B2A vs B2A2C
After I left Nubank, I started a few things: writing, advisory and some pet projects to truly learn GenAI as an engineer instead of an executive.
In one of my pet projects, I have agents building ML models that forecast the NFL season based on real data from many different sources, to learn how to tame them for that type of work.
Often enough, my agents got stuck with the lack of available data to improve the model. As they wanted to get unblocked, they asked me to “just buy it” so we keep moving.
I often held them back. But when they got really stuck, I went and bought some of these precious API keys myself so work could continue.
Why did I as a human have to enter a website and put my credit card info? The agents seemed to know what they needed, but had no way to pay for it.
I don’t even know if I trust them to have it, but I also didn’t trust them to code for me a couple months ago.
Companies are starting to think about selling to agents, but mostly the shopping kind: an agent buying on behalf of a person, which is what I call B2A2C. It books a flight, fills the cart, buys food, etc.
The human-first assumptions survive there, because there is a human at the end of that chain with goals, a wallet and taste.
There is a huge opportunity in what to sell to agents that want to build directly. Think of things that your agents get stuck on: data, access, insights, inference from other models, conviction, taste.
Maybe even some human judgement by the minute? That might be part of the next wave of the gig economy. But more on that on another post.
Anyway, making the real B2A concrete at a high level: AEO is already gaining market share over SEO, then vibe coding tools get their own wallets tokenizing payments, then companies start selling products for agents as end users, with a bunch of new tech-nerdy plumbing underneath.
As an example of what needs to change one level deeper: the way the purchase is currently done gets an agent an API key. This is so last year, right?
I am thinking of a combination similar to mTLS plus tokens: a certificate authority who manages trust and the budget. Certificates for each agent, issued when they spin up to manage identity and authentication, and short-term permission tokens for authorization.
Can you guess why? An API key is a long-lived password, unscoped, identical for everyone holding it, and useless for proving who authorized what. Not a lot of real supervision for a fast-moving world where output is what agents optimize for.
Similar movements will be done in other areas. Payments already went through this once: card numbers became tokens, and holding the string stopped being the same as holding the authority.
And the pricing moves as the business model evolves: the real B2A looks more like marginal pricing than upfront with a high-floor, very similar to what the cloud did for computing. That one deserves its own post too.
Founders and VCs are thinking hard about the protocol the agent uses to pay. The more interesting question is what agents will be paying for and how they earn the trust to do so.
For now, agents know all about the price of something, but have a hard time understanding its value.