When Ethan Byrd arrived in San Francisco last spring with plans to build "the future of communication infrastructure," he wasn't pitching faster networks or novel compression algorithms. His target was more prosaic, and perhaps more urgent: figuring out how autonomous software agents actually talk to one another. His solution? Email addresses. For robots.
The concept sounds almost deliberately anachronous—managed inboxes for AI, complete with DKIM signatures and spam filters—until you spend time with the engineers trying to coordinate fleets of enterprise agents across organizational boundaries. Then it starts to make a certain kind of sense.
Byrd's startup, Primitive, emerged from Y Combinator's most recent batch selling what the company calls "developer primitives": authenticated email infrastructure purpose-built for agents. Think hosted addresses, inbound webhooks, send APIs, and serverless functions to process incoming messages. The platform handles the arcane hygiene of modern email—SPF records, DMARC alignment, one-click unsubscribe headers—requirements that Gmail and other providers now enforce so that agent-to-agent messages don't end up quarantined by spam filters.
It's infrastructure that feels oddly retro and strangely prescient at once.
The multi-agent systems market was valued at $7.71 billion in 2025 and is projected to reach $153.6 billion by 2033, according to Grand View Research. Gartner estimates that by the end of 2026, up to 40% of enterprise applications will include task-specific AI agents, up from less than 5% a year ago. But as agent deployments accelerate, a question that initially seemed trivial has become existential: How do these things coordinate when they span different companies, different clouds, different security perimeters?
A Fracturing Protocol Landscape
The answer, for now, is fracturing into competing camps.
On one side sits the Model Context Protocol, or MCP—donated to the Linux Foundation's AI & Data Foundation late last year and now woven into Microsoft's product line, from GitHub to Copilot Studio to Windows 11 itself. Google added gRPC transport support for MCP in February. Zendesk, Atlassian, and others have followed with integrations in recent months.
On the other: Agent2Agent, Google's protocol, also donated to the Linux Foundation. The A2A project reportedly surpassed 150 member organizations earlier this year, with production deployments across AWS, Microsoft, and Google Cloud. Version 1.0 shipped in March, according to the project's roadmap.
The MCP Dev Summit in April—attended by roughly 1,200 developers—saw speakers from Uber, AWS, Docker, and Kong coalesce around a new architectural pattern: MCP Gateways and Registries functioning as a control plane for agent-to-tool communication. Kong shipped its MCP Registry in February. TrueFoundry launched an Agent Gateway in early June. Redpanda introduced what it calls an "AI Gateway / Agentic Data Plane" in March.
Meanwhile, Confluent took a different approach entirely. Its Streaming Agents platform, which went generally available in February with A2A integration, positions Kafka and Flink as the communication backbone—governed by immutable, replayable logs. AWS published a blog post around the same time demonstrating agent collaboration using its Amazon Nova agents with structured A2A message passing.
It's a landscape in rapid motion, with no obvious winner. Which is part of what makes Primitive's bet on email so intriguing.
The Case for Anachronism

Somewhere between enterprise protocols and event-driven architectures, email has quietly reemerged as agent infrastructure. Not metaphorically—literally.
Primitive's pitch is straightforward enough: agents get real email addresses, managed inboxes, and APIs for sending and receiving. The platform opens SMTP connections directly to recipient mail servers, returning synchronous delivery metadata—the remote server's 250 OK response, queue IDs—in the same API call. It verifies domains with DKIM, SPF, and DMARC. It complies with the sender requirements Gmail and Yahoo began enforcing in February 2024, including complaint rates under 0.3%.
Byrd, who previously co-founded Actual AI (which raised $3.2 million in October 2025), assembled a four-person team for Primitive and raised an undisclosed pre-seed round. The company frames email as something that already works, that compliance departments understand, and that maps cleanly to existing audit frameworks.
They're not alone in the category. Ironpost markets itself as "Email for AI Agents." Daimon.email, AGmail.ai, HII Mail, and Distrans are building similar services. Traditional email API providers like Resend, Mailgun, and Postmark have inbound features, but weren't designed around agent workflows—the stateful, timestamped threads and human-in-the-loop approval gates that multi-agent systems increasingly require.
The use case is less about marketing blasts and more about durable coordination. Per-agent inboxes function as audit logs. Email becomes the mechanism for external handoffs, approval workflows, compliance reviews—the kinds of interactions that need to survive intact for debugging sessions or regulatory inquiries weeks later. It's slower than synchronous protocols, less structured than event streams, but it maps to infrastructure that enterprises already trust.
One research note described it as "repurposing human channels" for external coordination. Which is perhaps another way of saying: sometimes the old stuff still works.
Security Gaps Widen

The rapid protocol adoption has exposed vulnerabilities that weren't initially obvious.
OX Security reported RCE-class vulnerabilities in MCP implementations in April, triggering several CVEs. LangChain and LangGraph frameworks reportedly suffered security incidents in February and April that exposed categories of enterprise data, according to TechRadar Pro. The identity layer, in particular, remains immature.
Gartner warned in late May that applying uniform governance across AI agents would lead to enterprise failures. The research firm called for agent-specific security testing, approval workflows with audit trails, and dedicated incident response plans—infrastructure that largely doesn't exist yet.
Researchers have floated proposals. The Agent Identity Protocol, for verifiable delegation across MCP and A2A. A unified Agent Communication Protocol for secure, federated orchestration. "MCPThreatHive" for automated threat intelligence. These are academic projects, not production standards. Meanwhile, enterprises are deploying multi-agent systems at scale. Grab detailed a multi-agent AI system for engineering support in May. IBM Research published a preprint describing multi-agent architecture for real-time analytics leveraging Kafka and Flink.
Forrester's "The State of Agentic AI, 2026" report, released in early June, notes that platforms, pricing models, and professional services are all reshaping around autonomous multi-agent systems. The firm emphasizes that long-horizon agents—those capable of operating autonomously over extended periods—are now practical, but organizations must close the "chase-catch gap" through orchestration and control.
What that means in practice is still being figured out.
Governance Lags Behind Deployment

The infrastructure is consolidating, somewhat, around a dual-layer model: MCP for agent-to-tool communication, A2A for agent-to-agent messaging, with identity overlays and enterprise gateways serving as control planes. Event-driven architectures are gaining traction in regulated industries—SecOps, financial services—where auditability and replay matter.
Email occupies an odd middle ground in this stack. It's an afterthought in most protocol discussions, yet it solves problems that synchronous APIs and event streams don't cleanly address: external coordination across organizational boundaries, compliance-friendly audit trails, natural integration points for human approvals.
What's missing is the governance layer above the protocols themselves. Agent-specific security testing. Differentiated approval workflows. Incident response infrastructure that operates at enterprise pace. The EU AI Act obligations begin phasing in from August, with high-risk and general-purpose AI systems facing staged requirements through 2027 and 2028. FCC rules around AI-generated voices in robocalls and TCPA consent requirements are already in force.
The companies building infrastructure today aren't just competing on latency or throughput—they're competing on how well their abstractions map to the regulatory environment enterprises actually operate in.
Which is perhaps why a Y Combinator-backed startup building email infrastructure for agents doesn't sound quite so retro after all. Or maybe it does, and that's precisely the point. In a landscape fragmenting into competing protocols and immature identity layers, sometimes the most pragmatic move is to reach for the thing that already works—even if it was invented in 1971.
Byrd's bet is that when autonomous agents need to talk across corporate firewalls, compliance boundaries, and regulatory regimes, they'll do it the same way humans have for decades: with an email address and an inbox. The future of agent communication, in other words, might look a lot like the past.
