On September 16, Google started handing out keys to the house. Not to one assistant, and not to its own: Google Home’s new MCP server lets any third-party AI agent that speaks the Model Context Protocol connect to a real household, read its device states and event history, and act on its inhabitants’ behalf. Taylor Lehman, group product manager at Google Home & Nest, described the integration plainly: it “allows any AI agents that support MCP, including Google Antigravity, Claude, Hermes or Open Claw, to securely work with all of the devices and event history in your Google Home ecosystem.”

Read that sentence as a commerce event, because it is one. A platform sitting on millions of households just standardized programmatic access for agents it does not own, does not operate and, by Google’s own documentation, cannot fully predict. The rollout is limited, US-only for now, gated behind a Google Home Premium Advanced subscription at $20 a month or $200 a year, with access granted over the coming weeks through a Google Cloud project and OAuth credentials. The developer docs still label it Early Access, and the server endpoint lives in a preprod sandbox. Limitations acknowledged. Milestone anyway.

What Google Actually Shipped

Per the official Home MCP documentation, the server exposes five core capabilities to any connected agent:

  • Structure discovery: list accessible homes with list_homes
  • Resource discovery: enumerate devices, layouts, traits and command schemas with list_home_resources
  • State monitoring: check real-time connectivity and trait states with list_home_states
  • Device control: execute parameterized commands with run_home_actions
  • Historical analysis: query past state changes and event logs with list_home_history

The Verge’s Jennifer Pattison Tuohy sketches what that means in practice: cross-camera analysis (“ask your agent what your kid did when they got home from school”), consumption accounting (“how many loads of laundry you did last week or how long the lights were left on”), voice delivery over Nest speakers when a task completes, and agent-built custom dashboards. This sits alongside, not instead of, Gemini for Home. Google is positioning itself as the infrastructure layer other agents build on, in much the same way AWS became infrastructure for software businesses.

That last capability, list_home_history, is the one commerce teams will read twice. Event history over a smart home is not a novelty feature. It is a running log of consumption: how often the washer runs, how many hours the air purifier has logged, when the thermostat works hardest, how fast the water filter degrades. Every one of those signals maps to a replenishment cycle. The home has always been where products get used up. Now it is becoming the system that notices.

The Guardrails Google Did Build

To its credit, Google did not ship this naively. The launch comes with real, engineered physical safety constraints:

  • Prohibited actions: Home MCP “enforces rate limits and safety protections, such as prohibiting sensitive actions like unlocking doors.”
  • Rate limits: how fast an agent may act is capped at the protocol level.
  • Informed consent for the household: the docs instruct users connecting a shared home to inform other household members “that your agent can control devices and access home data,” or to spin up a separate home for testing.
  • Revocable access: an agent’s connection can be cut at any time from the Google Home app or the account page.

And then there is the warning label, worth quoting in full because of how rare this kind of candor is: “Connecting a real-life home to an AI agent allows that agent to control devices on your behalf. Home MCP enforces rate limits and safety protections… However, depending on your agent, connecting it to Home MCP can result in unexpected or even undesired behavior.”

Physical risk got engineering: prohibited actions, throttles, disclosure, kill switches. That is a serious answer to a serious question. It makes the unanswered question next to it conspicuous.

The One Thing Nobody Guarded: The Purchase

Here is the asymmetry at the center of this launch. Google built hard technical constraints around what an agent may physically do to a house. It built none around what the agent may economically do on behalf of the people inside it.

Nothing in Home MCP stops the household from asking the very same agent, the one holding list_home_history access to the laundry room, to also restock detergent. Nothing verifies the shelf that agent shops from. The agent cannot unlock your front door, and it can be instructed to buy a lock for it off a product page whose placement was auctioned and whose reviews may be manufactured. The door is guarded. The wallet is not.

This is not hypothetical stacking. The substrate underneath agent shopping is publicly documented as contested terrain on two layers. The placement layer: on August 31, the FTC and 22 state attorneys general sued Amazon alleging its sponsored auction was covertly converted so advertisers paid their own full bid roughly 80 percent of the time by 2024. The reputation layer: Amazon’s own trust reporting says it blocked more than 275 million suspected fake reviews in 2024, and AI-generated text keeps raising the flood line. An agent reading that corpus inherits both contaminations as ground truth, because nothing in its stack is built to do otherwise.

Google’s own warning fills the vacuum with a shrug: “depending on your agent,” behavior may be “unexpected or even undesired.” For a thermostat setpoint, that is a comfort issue. For an autonomous reorder decision made against a manipulated review corpus, it is a purchase made on forged evidence, at household scale, on a schedule.

The Standard Just Got Its Own Market Number

The Home MCP launch is also the clearest signal yet that MCP has crossed from developer curiosity to infrastructure category. On September 14, SNS Insider published its sizing of the Model Context Protocol market: valued at $1.20 billion in 2025, projected to reach $28.36 billion by 2035, a 37.22 percent CAGR. The segment structure tells the story of where this is going:

  • AI Agents & Automation is already the leading application, at 34.72 percent share in 2025, with AI Assistants growing fastest at a 40.42 percent CAGR.
  • Integration platforms lead components at 32.47 percent, but Security & Governance solutions are the fastest-growing segment at a 44.56 percent CAGR, which is the market’s way of saying the industry knows the trust layer is behind.
  • North America holds 42.36 percent of the market; the US alone was $0.45 billion in 2025, headed toward $10.27 billion by 2035.
  • The named players are no longer startups: Anthropic, Microsoft, OpenAI, Google, AWS, IBM, Salesforce, Databricks, Cloudflare.

Sit the two September announcements side by side and the shape of the next decade appears. The plumbing that connects agents to systems is becoming a $28 billion market, and the first thing a major platform connected it to, after code editors and enterprise apps, was the family home. The connection layer is being standardized, productized and priced. The verification layer that decides what those agents should trust when they act has no market size, because it barely exists.

The Agents Are Ready Even If the Trust Rails Are Not

It would be comforting to file home agents under “early.” The capability data says otherwise. Retailgentic’s State of Agentic Commerce update, published this week, documents what it calls an entirely new category, “Personal Agents”: horizontal assistants built for email, calendars and travel that increasingly anchor on and tout their shopping abilities. The enabling curve is computer use. On aggregated browser-use benchmarks, models scored around 457 in February 2026 and score roughly 1720 today, a 4 to 5 times improvement in ten months, with current models completing 93 to 96 percent of tasks that are, in the analysis’s words, “much much more complex than buying something online.”

The same report lands a line every merchant should sit with: “Researching→Finding→Buying a product on a consumer website is child’s play with the right context, memory, tools.” That is why the five questions retailers are now asking about personal agents are not whether but how: should we block them, how do we track their transactions, how do we optimize for them, where are they going, and how do they differ from answer-engine commerce.

Blocking is the tell. Merchants do not ask whether to block a channel they think is weak. The buying loop is effectively solved. What remains unsolved is judgment: which product, from which seller, on whose word. A model that can complete any checkout can also complete a checkout it was steered into by whoever optimized the page it read. Capability has outrun verification, and the gap widens every benchmark cycle.

The Home Agent Needs a Trust Rail, Not a Disclaimer

When the agent’s context includes your laundry count, its recommendations will be correct about timing and blind about merit. Fixing that does not require slowing the agents down. It requires giving them a verified substrate to act on, the same way Home MCP gave them a guarded substrate to act with:

  • Filter before scoring. A score computed on a contaminated review corpus is precise about the wrong thing. Smart Score runs 0 to 100 on review quality and authenticity, and only after manipulated and low-information reviews are removed. The agent should read a cleaned corpus, not the raw one.
  • Curate before presenting. An agent handed thousands of ranked listings inherits the auction that ranked them. GoBuy’s top seven verified products per category give the agent a shortlist that can be inspected, not a shelf that can only be trusted.
  • Require persistence, not a snapshot. The GoBuy Verified badge demands a filtered score of 80 or above held for 90 days, which is exactly the property an agent-triggered reorder loop needs: products that stayed good between orders, not products that spiked before one.
  • Deliver it in the agent’s native protocol. This is what MCP is for. Agents consult GoBuy over MCP at gobuy.ai/api/mcp before recommending or purchasing, and the Chrome extension injects the same trust panel onto Amazon pages, so the human auditing the agent’s choices sees the same evidence the agent acted on.

Google drew the right line this week: the agent may not unlock the door. Someone now has to draw the equally obvious one: the agent may not buy on unverified evidence either, or if it does, the household should be able to see that it did.

What to Watch

Five signals over the next two quarters. First, whether Home MCP graduates from preprod sandbox and Premium Advanced gating to general availability, and whether the prohibited-actions list grows. Second, the first documented case of a home-connected agent autonomously reordering a product later shown to ride manipulated reviews, the incident that converts this argument from analysis to headline. Third, whether Google extends UCP-style checkout into the Home agent surface, completing the loop from event history to purchase without a human in it. Fourth, whether the Security & Governance segment of the MCP market, growing faster than the protocol itself at 44.56 percent, produces anything that verifies product truth rather than only access control. Fifth, whether personal agents ship with any independent trust layer wired in before the holiday season, when 72 days out, every retailer is now optimizing for them.

The house is open to the agents. The shelf is not ready for them. Verify before anything in your home buys: gobuy.ai, with agent integration docs at gobuy.ai/agent-docs.