What’s trending in AI on 7 October 2026: Personal AI agents have a manners problem. Most of them shop, book and file claims by pretending to be a person: they load your pages, click through your forms, type in a customer’s stored password and, when that fails, ring your support line. Businesses cannot tell a helpful assistant from a scraper, and the fights are getting expensive. Amazon blocked Meta’s new Muse agent last month and is still in court with Perplexity. Now Sierra and Meta, with Walmart, Shopify, Stripe, Genesys and others, have proposed the Personal Agent Protocol (PAP): an open standard for how a customer’s AI agent signs in to a business, what it is allowed to do, and how the business sees it coming. Below: how PAP works, why it arrived now, how it compares with rival protocols, what version 0.1 leaves out, and a scorecard for deciding what to open to agents.
Key takeaways
- A front door instead of a disguise. PAP, announced on 6 October 2026, lets a personal agent announce itself, start a session as a guest and, once the customer signs in, act with read-only or write access the customer chooses.
- Built on OAuth, not new crypto. Sessions use the same authorization standard behind “Sign in with Google,” and a session follows the customer across a business’s website, APIs and its own AI agent.
- Born from a fight. Amazon cut off Meta’s Muse agent on 20 September, saying it did not identify itself and appeared to store customer credentials. PAP is the industry’s attempt to make that argument unnecessary.
- Version 0.1 is not here yet. The spec is due later in October. Payments, push notifications and finer permissions are future extensions, and no licence or governing body has been published.
- The big labs are missing. OpenAI and Anthropic are not partners, and Stripe, Shopify and Walmart already back rival protocols from Visa, Google and OpenAI. Plan for several doors, not one.
1. What Meta and Sierra announced
On 6 October 2026, Sierra co-founders Bret Taylor and Clay Bavor published the Personal Agent Protocol, which Sierra describes as an open standard for how personal AI agents authenticate with businesses and what those businesses let them do. Meta is co-developing it. Sierra names Genesys, Instinct, Rocket, Shopify, Stripe and Walmart as industry partners. Meta’s own list also includes Decagon, and contact-centre vendor NiCE says it is co-developing the protocol too, according to CMSWire. Anyone will be able to implement it.
The problem it targets is simple to describe. Sierra points out that most personal agents today work the way a person does: they open web pages and click through forms, and when that breaks they fall back to a phone line or web chat. That is slow, fails often and looks almost exactly like the bots businesses pay to block. A declared connection could finish the task in seconds and tell the business who is asking.
Sierra frames the goals for three groups. Consumers want speed, dependability and confidence that the agent acts in their interest. Brands want to see when an agent is acting for a customer and to control what it can do. Genesys chief executive Tony Bates summed up the pitch in Sierra’s post: “Personal AI is creating a new front door to the enterprise.”
Agents have been gaining identities all autumn. In AI Agents Just Got Employee IDs, Phone Numbers and Inboxes we covered agents getting identities inside companies. PAP is the outward-facing version: an identity for the agent your customer brings to you.
2. How PAP works, step by step
The detailed specification is not out yet, but Sierra’s announcement lays out the flow clearly enough to plan around:
- Discovery. The agent starts on the company’s website, where it learns what the business offers to agents and how to reach it.
- Guest session. For anonymous tasks, such as checking stock or reading a returns policy, the agent can open a session without any account.
- Sign-in. For anything tied to the customer’s account, the customer signs in on the company’s own page, or uses credentials already stored with their agent.
- Access level. The customer chooses read-only or write access. The business sets the outer limits of what agents may do at all.
- One visit, many channels. Sessions run on OAuth and carry across channels, so a question asked as a guest and an order changed after sign-in count as the same visit.
Two design choices stand out. First, the business decides how it is reached: through its ordinary web pages, through APIs built on the Model Context Protocol (MCP) or OpenAPI, or through its own customer-service agent for conversational jobs such as a warranty claim. Second, sign-in happens on the business’s page, not inside the agent. That keeps the business in charge of authentication and, if implemented well, means the agent receives a scoped token rather than the customer’s password. This is the same principle we recommended in “Allow Always” Is the New “I Agree”: give agents narrow, revocable permissions instead of the keys to everything.
Meta has also described the rules its own agent, Muse, applies. Before acting, Muse asks whether one honest person doing the task by hand would behave the same way at the same scale, and whether the system would still work if every Muse user made the same request. It says it asks the user before sign-ins, reservations and purchases. Constellation Research analyst Larry Dignan expects the tests to fail eventually. Either way, they are Meta’s policy, not part of the protocol.
3. Why now: the Muse block and the Perplexity case
PAP did not appear in a vacuum. Meta launched Muse on 8 September 2026, and Meta’s David Singleton has said it has millions of US users, a figure that has not been independently verified. On the evening of Sunday 20 September, Amazon began blocking it. Amazon told reporters that Muse did not identify itself while browsing and appeared to capture and store customer credentials. Meta’s launch materials say Muse cannot see people’s passwords or payment methods, which sit in secure storage the agent uses without reading.
Amazon’s fight with Perplexity shows how messy the legal route is. Amazon won a preliminary injunction against Perplexity’s Comet agent in March 2026, then lost it on 4 August, when the Ninth Circuit ruled that the user, not the AI company, was the one accessing Amazon’s computers under federal anti-hacking law. Rehearing was denied on 10 September. Amazon’s amended complaint of 21 September alleges that Comet for iOS copies the user’s session cookie to Perplexity’s cloud and counts at least 185,712 Comet sessions on Amazon.com by mid-June.
Together, the two stories make PAP’s case. Courts will not stop customers sending agents, and blocking every agent turns away paying customers. What businesses lack is a way to tell a declared agent from a disguised bot, and to give it limited access. Taylor, who also chairs OpenAI’s board, put the current state bluntly, as quoted by Implicator: “It is kind of chaos until such a standard exists.”
4. PAP, TAP, UCP, ACP, MCP: which protocol does what?
PAP joins a crowded field. Stripe, Shopify and Walmart, three of its headline partners, already back other agent standards.
| Protocol | Led by | Main question it answers | Status |
|---|---|---|---|
| Personal Agent Protocol (PAP) | Sierra and Meta, with Walmart, Shopify, Stripe, Genesys and others | How does a customer’s agent sign in, and what may it do on the customer’s account? | Announced 6 Oct 2026; v0.1 spec due later in October |
| Trusted Agent Protocol (TAP) | Visa, co-developed with Cloudflare | Is this visiting agent a vetted one, or a malicious bot? (signed requests checked against Visa’s registry) | Announced Oct 2025; Stripe and Shopify have joined |
| Universal Commerce Protocol (UCP) | Google, with Shopify, Target, Walmart, Etsy and Wayfair | How does an agent run a full purchase, from discovery to checkout, returns and loyalty? | Unveiled Jan 2026; backed by Visa, Mastercard, Stripe and American Express |
| Agentic Commerce Protocol (ACP) | OpenAI, co-developed with Stripe | How does a chat assistant complete a checkout with a merchant? | Released Sept 2025 |
| Model Context Protocol (MCP) | Originated at Anthropic; widely adopted | How does an agent call a business’s tools and data? | Established; one of the API routes PAP supports |
The overlap matters less than it looks. TAP answers “is this agent who it claims to be?”, PAP answers “what has the customer let it do here?”, and UCP and ACP answer “how does the purchase actually happen?” A mature setup may well use more than one. The practical risk for a business is building deep integrations for the first protocol that knocks, then finding its customers’ agents speak a different one. Keep agent-permission logic in your own systems and treat each protocol as an adapter.
The traffic is coming either way. Adobe data cited by VentureBeat showed AI-driven traffic to US retail sites up more than 4,700% in the year to October 2025, and Gartner, via CMSWire, predicts that by 2028 80% of organisations will see agents consume most of their APIs. As we argued in AI Is Starting to Pay for the Web, the bots are customers now and need a door policy.
5. What version 0.1 leaves out
PAP is an announcement, not yet a standard. Several gaps deserve attention before anyone builds on it:
- No payments. Paying without sharing card details is listed as a future extension. Yet agents already buy things today: Muse, for example, pays with saved cards through Stripe’s Link. The Next Web notes that Europe’s strong customer authentication rules were written for a person approving a named payee and amount, with no carve-out for software approving on someone’s behalf.
- Coarse permissions. The first version offers read-only or write. “Write” on a retail account could mean changing an address, cancelling an order or redeeming loyalty points. Finer permissions are on the roadmap, without a date.
- No published governance. As of 7 October, Implicator reports, there is no specification, licence or governing body. CMSWire adds that it is unclear whether the spec will stay neutral about which vendor’s agent handles the conversation, which matters because Sierra, Decagon, Genesys and NiCE all sell customer-service agents.
- Missing labs. OpenAI and Anthropic are not partners. Taylor said, according to Implicator, that he expects them to take part and would be disappointed if competitors did not use it.
- Thin European presence. The Next Web observes that Stripe is the only named partner with a European headquarters, and no European retailer, bank or payment company has joined.
None of this makes PAP a bad idea, only an early one. Prepare what helps under any protocol (an agent policy, scoped tokens, good logging) and wait for the spec before committing engineering time.
6. The security and privacy questions to ask
Declared, scoped and logged beats disguised and unlimited, so PAP is good news for security. It also creates targets: a write token for your site is worth stealing, and the agent holding it can be tricked. We saw earlier today, in Encrypted Prompts Beat the Guardrails, how a web page can steer an agent into leaking secrets. An agent holding tokens for a dozen retailers invites the same tricks.
Questions to put to anyone proposing an agent integration:
- Where does the customer sign in? On your page, with your multi-factor checks, is the right answer. An agent that collects and replays passwords is the pattern Amazon objected to.
- What does the token allow, and for how long? Short-lived, narrowly scoped tokens limit the damage if an agent is hijacked.
- Can the customer see and revoke it? A list of connected agents in the account settings, with a revoke button, should be standard.
- Which actions need a fresh human “yes”? Changing a delivery address or cancelling a large order should trigger confirmation sent to the customer, not to the agent.
- What gets logged? Every agent action should be recorded with the agent’s identity, so disputes can be settled with evidence rather than guesswork.
Phishers will follow. In The Fake “Claude Ads” Portal Is a Trap we showed how a fake “Connect” button became a credential-theft tool. Expect fake “connect your agent” pages, and tell customers where your real one lives.
7. The agent front-door scorecard
Use this ten-question scorecard to see how ready your business is for customers’ agents, whichever protocol wins. Give yourself one point for each “yes.” Score it with e-commerce, security and privacy in the room.
- Do you know how much agent traffic you already get? Check bot-management and analytics reports for declared AI agents and automated browsers.
- Is there a written agent policy? One page stating which agents are welcome, which tasks are open to them and which are not.
- Is your public information agent-ready? Stock, prices, hours and returns policy that a guest agent can read accurately without scraping.
- Do customers sign in only on your own pages? No flows that encourage handing passwords to a third party.
- Can you issue scoped, short-lived tokens? Your identity provider supports OAuth scopes that separate reading from changing.
- Have you mapped your write actions by risk? A list of every account change an agent might make, each marked low, medium or high.
- Do high-risk actions trigger human confirmation? Sent to the customer’s own phone or email, not answered by the agent.
- Can customers see and revoke connected agents? In their account settings, in one click.
- Are agent actions logged and attributed? So that a disputed order shows which agent did what, and when.
- Does your support team have an agent playbook? Agents that fail on the website will call or chat, so staff need to know how to verify and handle them.
Scoring: 8 to 10 means you are ready to pilot PAP or a similar protocol once the spec lands. 4 to 7 means fix the gaps in identity and logging first, because they matter under any standard. 0 to 3 means start with questions 1 and 2 this month: you cannot set a door policy for traffic you cannot see. For the wider governance picture, see AI Agent Security in 2026: The Risk Nobody Owns.
8. What to watch next
The v0.1 specification. Due later in October, followed by design workshops and a reference implementation. Watch how agents prove identity, how scopes are defined and how revocation works; Meta says those pieces are still being designed.
Whether OpenAI, Anthropic and Google sign up. A standard for personal agents without the makers of the most-used assistants would be a standard for some agents.
Payments and regulators. The payments extension is where agents meet consumer-protection rules, and the question of who pays when an agent with write access gets an order wrong. We covered the liability debate in “The AI Did It” Is No Longer a Defense, and it applies here in full.
Frequently asked questions
What is the Personal Agent Protocol?
It is a proposed open standard, announced by Sierra and Meta on 6 October 2026, for how a consumer’s personal AI agent signs in to a business, identifies itself and completes tasks. Sessions are built on OAuth, and the customer chooses whether the agent gets read-only or write access.
Who is behind PAP?
Sierra and Meta lead development. Sierra lists Genesys, Instinct, Rocket, Shopify, Stripe and Walmart as partners; Meta’s list also names Decagon, and NiCE says it is co-developing the protocol. OpenAI and Anthropic are not partners so far.
Can I implement PAP today?
Not yet. The v0.1 specification is due later in October 2026, followed by design workshops and a reference implementation. You can prepare now by setting an agent policy, supporting scoped OAuth tokens and logging agent activity.
Does PAP handle payments?
No. Payments that complete purchases without sharing card details are listed as a future extension, along with push notifications and finer-grained permissions. Version 0.1 covers sign-in, access levels and sessions.
How is PAP different from Visa’s Trusted Agent Protocol?
Visa’s protocol, built with Cloudflare, helps a merchant verify that a visiting agent is a vetted one by checking signed requests against Visa’s registry. PAP focuses on what a signed-in customer has allowed the agent to do on their account. The two could be used together.
Should my business block AI agents instead?
Blocking undeclared bots is reasonable, but blocking all agents increasingly means turning away customers. A US appeals court ruled in August 2026 that the user, not the AI company, was the one accessing Amazon in the Perplexity case. A clear policy that welcomes declared agents with limited, revocable access is a more durable position.
Sources
- Sierra: Introducing Personal Agent Protocol (6 Oct 2026)
- The Next Web: Sierra announces Personal Agent Protocol, an open standard for personal AI agents (6 Oct 2026)
- Implicator: Meta and Sierra draft a sign-in standard for AI agents (Oct 2026)
- CMSWire: Genesys, NiCE join Sierra, Meta on open standard for personal AI agents (Oct 2026)
- Constellation Research: Meta, Sierra pitch Personal Agent Protocol (7 Oct 2026)
- The Next Web: Amazon blocks Meta’s Muse and accuses Perplexity of misleading a court (Sept 2026)
- VentureBeat: Visa launches Trusted Agent Protocol to secure AI shopping (Oct 2025)
- Oscilar: Google’s Universal Commerce Protocol explained (2026)
