Daniel Reyes, YuSMP Group
Daniel Reyes Principal Engineer (AI/ML), YuSMP Group · LLM systems, agents and AI tooling for US and EU products
A line of humanoid robot assistants holding glowing tokens waits beside a softly lit arched doorway with a translucent key card, illustrating AI agents requesting authorised access to a business

The announcement in brief

On 6 October 2026 Sierra and Meta proposed the Personal Agent Protocol (PAP), an open, OAuth-based standard for how personal AI agents identify themselves to businesses and act on a customer’s behalf. Genesys, Instinct, Rocket, Shopify, Stripe and Walmart are named as founding partners. A v0.1 specification is planned for later in October.

The idea is simple: customers decide what an agent may do for them, companies decide what agents may do on their systems, and both sides can see what happened. Agents would connect through a company’s existing website, its APIs, or the company’s own customer-facing agent.

For retailers and e-commerce platforms, this is the first serious attempt to replace today’s choice between blocking AI agents outright and letting unidentified bots act as logged-in customers.

What is the Personal Agent Protocol?

PAP is a proposed agent-to-business standard. A “personal agent” here means an assistant that acts for one consumer — checking stock, managing an order, booking a return — as opposed to a company’s own support bot. Sierra, the customer-service AI company co-founded by Bret Taylor, frames the protocol around three goals: handle authentication, keep consumers in control, and give companies visibility into what agents are doing on their channels.

It is deliberately not a new transport. Sierra’s announcement says agents should be able to work through what businesses already run: ordinary web pages, APIs described with OpenAPI or exposed through the Model Context Protocol (MCP), or conversations with a company’s own agent. PAP sits on top as the identity and permission layer.

How would an agent sign in to a business?

The published design follows a tiered model. An agent can act as a guest for low-risk questions such as product availability or a returns policy. When a task needs the customer’s account, the customer signs in and chooses whether the agent gets read-only access or permission to make changes, through an OAuth grant the business already understands. That session is meant to carry across channels, so an agent that started on the website can continue through an API or the company’s agent without re-authenticating.

Sierra lists finer-grained permission controls, push notifications for status updates and payment extensions as future work. Those are exactly the pieces that will decide whether PAP is usable for checkout, so the v0.1 draft is worth reading closely when it appears.

Why are agents getting blocked in the first place?

Because most websites cannot tell a helpful agent from a scraper or a credential-stuffing bot. TechCrunch reports that users of agentic browsers and assistants keep hitting bot walls on retail, travel and marketplace sites, many of them unintentional side effects of anti-bot tooling.

Some blocks are deliberate. Bloomberg reported on 21 September that Amazon had begun blocking Meta’s Muse shopping agent, saying it accessed the store without authorisation and without identifying itself as automated. Meta’s position, as quoted by TechCrunch, is that turning away a personal agent means turning away the customer behind it. PAP is Meta’s attempt to turn that dispute into a shared rulebook.

Who is missing, and does it matter?

Amazon, OpenAI and Anthropic were not among the launch partners, although Taylor — who also chairs OpenAI’s board — said he expects AI companies to join. Without the largest US marketplace and the most widely used assistants, PAP is one of several competing approaches to agent commerce, alongside vendor-specific checkout and payment programmes.

Still, Walmart, Shopify and Stripe cover a large share of US online checkout between them, and Shopify alone powers millions of merchant storefronts. If Shopify ships PAP support at platform level, many merchants could get it without writing code, which would put pressure on everyone else to accept the same handshake.

What it means for US & EU software teams

Agents become a customer channel you have to design for. Until now, the practical options were to block automation or tolerate it blindly. A standard identity layer makes a third option realistic: let declared agents in, with scoped permissions and an audit trail, and keep blocking the rest. That is a product decision as much as a security one.

Your API surface matters more than your page markup. PAP points agents at OpenAPI and MCP interfaces. Retailers whose stock, order and returns logic only exists behind server-rendered pages will either be scraped or skipped. Clean, documented endpoints with sensible OAuth scopes become a sales asset.

Consent and logging are compliance artefacts. In the EU, an agent acting on a signed-in customer’s account touches GDPR questions about lawful basis, purpose limitation and data minimisation; PSD2 strong customer authentication still applies to payments. US merchants face PCI DSS scope and state privacy laws. A protocol that records who granted which permission, and what the agent did with it, makes those obligations easier to evidence — if you store the records.

Do not build to a draft. Nothing is final until v0.1 is out and partners ship implementations. The safe move now is to fix the foundations that any agent standard will need.

How to prepare before the spec lands

  1. Map agent-worthy journeys: stock checks, order status, returns, rebooking. Decide which should work for a guest agent and which need a signed-in customer.
  2. Audit OAuth scopes on your customer APIs. Separate read from write, and avoid all-or-nothing tokens that would hand an agent full account control.
  3. Document public APIs with OpenAPI and evaluate an MCP server for the journeys above, so agents have a sanctioned path that is not your HTML.
  4. Tune bot management so it can distinguish declared, authenticated agents from anonymous automation, rather than challenging every non-human session.
  5. Log agent actions with the grant that authorised them, and decide retention with your privacy and fraud teams.
  6. Read v0.1 when it ships and check what your commerce platform, payment provider and contact-centre vendor commit to support.

Frequently asked questions

What is the Personal Agent Protocol?

The Personal Agent Protocol (PAP) is an open standard proposed by Sierra and Meta on 6 October 2026 that defines how personal AI agents authenticate with businesses and what those businesses allow them to do. It is built on OAuth, lets customers grant an agent read-only or write access, and lets companies see and limit what agents do on their websites, APIs or company-run agents.

Who is backing the Personal Agent Protocol?

Sierra and Meta lead the effort, with Genesys, Instinct, Rocket, Shopify, Stripe and Walmart named as founding partners. Amazon, OpenAI and Anthropic were not among the initial partners at launch; Sierra co-founder Bret Taylor said he expects more AI companies to join.

Is the Personal Agent Protocol specification available yet?

Not yet. As of 7 October 2026 the partners have published the principles and design direction. A v0.1 specification is planned for later in October 2026, followed by design workshops and a reference implementation. Detailed permissions, push notifications and payment extensions are listed as future work.

Should e-commerce teams implement it now?

Not in production. The specification is a draft-in-progress and may change. Teams can prepare by cleaning up OAuth scopes, documenting public APIs with OpenAPI or exposing them through MCP, separating guest and signed-in capabilities, and making bot management able to tell declared agents from anonymous scrapers.

Sources

Sierra — Introducing Personal Agent Protocol (6 October 2026)
CNBC — Meta joins with group of companies to tame ‘chaos’ of doing business with AI bots (6 October 2026)
TechCrunch — The next hurdle for AI agents: getting websites to let them in (6 October 2026)
Bloomberg — Amazon blocks Meta’s Muse AI agent from its retail site (21 September 2026)
SiliconANGLE — Meta teams up with Bret Taylor’s Sierra on new standards for AI agent commerce (6 October 2026)