Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

AI Agents Get a Front Door: Meta and Sierra’s Personal Agent Protocol Wants Bots to Stop Pretending to Be You (AI Trends, 7 October 2026)

  1. Home   »  
  2. AI Agents Get a Front Door: Meta and Sierra’s Personal Agent Protocol Wants Bots to Stop Pretending to Be You (AI Trends, 7 October 2026)

AI Agents Get a Front Door: Meta and Sierra’s Personal Agent Protocol Wants Bots to Stop Pretending to Be You (AI Trends, 7 October 2026)

October 7, 2026October 7, 2026 admincybersecurityTagged agentic commerce, AI agent permissions, AI agent security, AI agents, AI liability, AI security, AI trends, bot traffic, Meta Muse, OAuth, Personal Agent Protocol

What’s trending in AI on 7 October 2026: Personal AI agents have a manners problem. Most of them shop, book and file claims by pretending to be a person: they load your pages, click through your forms, type in a customer’s stored password and, when that fails, ring your support line. Businesses cannot tell a helpful assistant from a scraper, and the fights are getting expensive. Amazon blocked Meta’s new Muse agent last month and is still in court with Perplexity. Now Sierra and Meta, with Walmart, Shopify, Stripe, Genesys and others, have proposed the Personal Agent Protocol (PAP): an open standard for how a customer’s AI agent signs in to a business, what it is allowed to do, and how the business sees it coming. Below: how PAP works, why it arrived now, how it compares with rival protocols, what version 0.1 leaves out, and a scorecard for deciding what to open to agents.

Key takeaways

  • A front door instead of a disguise. PAP, announced on 6 October 2026, lets a personal agent announce itself, start a session as a guest and, once the customer signs in, act with read-only or write access the customer chooses.
  • Built on OAuth, not new crypto. Sessions use the same authorization standard behind “Sign in with Google,” and a session follows the customer across a business’s website, APIs and its own AI agent.
  • Born from a fight. Amazon cut off Meta’s Muse agent on 20 September, saying it did not identify itself and appeared to store customer credentials. PAP is the industry’s attempt to make that argument unnecessary.
  • Version 0.1 is not here yet. The spec is due later in October. Payments, push notifications and finer permissions are future extensions, and no licence or governing body has been published.
  • The big labs are missing. OpenAI and Anthropic are not partners, and Stripe, Shopify and Walmart already back rival protocols from Visa, Google and OpenAI. Plan for several doors, not one.
AI agents get a front doorTitle card. Headline: AI agents get a front door. Subhead: Meta and Sierra’s Personal Agent Protocol wants agents to sign in as agents instead of pretending to be you. Three tags: built on OAuth; guest, read-only or write access; v0.1 spec due in October. Illustration of a shop front with two entrances: a labelled front door with a badge reader where a small agent icon waits, and a side window where a disguised bot is climbing in, crossed out. YOUR BUSINESS AGENTS SIGN IN HERE disguised bot AI TRENDS · 7 OCTOBER 2026 AI agents get a front door Meta and Sierra’s Personal Agent Protocol wants agents to sign in as agents, not pretend to be you. Built on OAuth Guest, read-only or write access v0.1 spec due later in October Source: Sierra and Meta announcement (6 Oct 2026), via The Next Web and CMSWiredelana.co
Today most agents come in through the window, wearing the customer’s clothes. PAP proposes a labelled door.

1. What Meta and Sierra announced

On 6 October 2026, Sierra co-founders Bret Taylor and Clay Bavor published the Personal Agent Protocol, which Sierra describes as an open standard for how personal AI agents authenticate with businesses and what those businesses let them do. Meta is co-developing it. Sierra names Genesys, Instinct, Rocket, Shopify, Stripe and Walmart as industry partners. Meta’s own list also includes Decagon, and contact-centre vendor NiCE says it is co-developing the protocol too, according to CMSWire. Anyone will be able to implement it.

The problem it targets is simple to describe. Sierra points out that most personal agents today work the way a person does: they open web pages and click through forms, and when that breaks they fall back to a phone line or web chat. That is slow, fails often and looks almost exactly like the bots businesses pay to block. A declared connection could finish the task in seconds and tell the business who is asking.

Sierra frames the goals for three groups. Consumers want speed, dependability and confidence that the agent acts in their interest. Brands want to see when an agent is acting for a customer and to control what it can do. Genesys chief executive Tony Bates summed up the pitch in Sierra’s post: “Personal AI is creating a new front door to the enterprise.”

Agents have been gaining identities all autumn. In AI Agents Just Got Employee IDs, Phone Numbers and Inboxes we covered agents getting identities inside companies. PAP is the outward-facing version: an identity for the agent your customer brings to you.

2. How PAP works, step by step

The detailed specification is not out yet, but Sierra’s announcement lays out the flow clearly enough to plan around:

  1. Discovery. The agent starts on the company’s website, where it learns what the business offers to agents and how to reach it.
  2. Guest session. For anonymous tasks, such as checking stock or reading a returns policy, the agent can open a session without any account.
  3. Sign-in. For anything tied to the customer’s account, the customer signs in on the company’s own page, or uses credentials already stored with their agent.
  4. Access level. The customer chooses read-only or write access. The business sets the outer limits of what agents may do at all.
  5. One visit, many channels. Sessions run on OAuth and carry across channels, so a question asked as a guest and an order changed after sign-in count as the same visit.
How a Personal Agent Protocol session worksFlow diagram in five steps. Step 1: discovery on the company website. Step 2: guest session for anonymous tasks like stock checks. Step 3: customer signs in on the company page. Step 4: customer chooses read-only or write access. Step 5: one OAuth session carries across website, APIs and the company’s agent. Below, three channel boxes: website pages, APIs via MCP or OpenAPI, and the company’s own AI agent for conversational tasks such as warranty claims. How a PAP session works The flow Sierra and Meta describe ahead of the v0.1 specification 1Discover oncompany site 2Guest session:stock, returns 3Customer signs inon your page 4Read-only orwrite access 5One OAuth sessionacross channels The business picks the channel WebsiteAgent uses your normalpages, now declared APIsConnects through MCPor OpenAPI interfaces Your own agentAgent-to-agent chat fortasks like warranty claims Source: Sierra, “Introducing Personal Agent Protocol” (6 Oct 2026)delana.co
Steps 3 and 4 are where control changes hands. They are also where your security review should start.

Two design choices stand out. First, the business decides how it is reached: through its ordinary web pages, through APIs built on the Model Context Protocol (MCP) or OpenAPI, or through its own customer-service agent for conversational jobs such as a warranty claim. Second, sign-in happens on the business’s page, not inside the agent. That keeps the business in charge of authentication and, if implemented well, means the agent receives a scoped token rather than the customer’s password. This is the same principle we recommended in “Allow Always” Is the New “I Agree”: give agents narrow, revocable permissions instead of the keys to everything.

Meta has also described the rules its own agent, Muse, applies. Before acting, Muse asks whether one honest person doing the task by hand would behave the same way at the same scale, and whether the system would still work if every Muse user made the same request. It says it asks the user before sign-ins, reservations and purchases. Constellation Research analyst Larry Dignan expects the tests to fail eventually. Either way, they are Meta’s policy, not part of the protocol.

3. Why now: the Muse block and the Perplexity case

PAP did not appear in a vacuum. Meta launched Muse on 8 September 2026, and Meta’s David Singleton has said it has millions of US users, a figure that has not been independently verified. On the evening of Sunday 20 September, Amazon began blocking it. Amazon told reporters that Muse did not identify itself while browsing and appeared to capture and store customer credentials. Meta’s launch materials say Muse cannot see people’s passwords or payment methods, which sit in secure storage the agent uses without reading.

Amazon’s fight with Perplexity shows how messy the legal route is. Amazon won a preliminary injunction against Perplexity’s Comet agent in March 2026, then lost it on 4 August, when the Ninth Circuit ruled that the user, not the AI company, was the one accessing Amazon’s computers under federal anti-hacking law. Rehearing was denied on 10 September. Amazon’s amended complaint of 21 September alleges that Comet for iOS copies the user’s session cookie to Perplexity’s cloud and counts at least 185,712 Comet sessions on Amazon.com by mid-June.

The road to a sign-in standard for agentsTimeline from August to October 2026. 4 August: Ninth Circuit lifts Amazon’s injunction against Perplexity’s Comet, ruling the user is the one accessing Amazon. 8 September: Meta launches Muse. 10 September: rehearing denied. 20 September: Amazon blocks Muse, citing undeclared browsing and stored credentials. 21 September: Amazon files amended complaint against Perplexity. 6 October: Sierra and Meta announce the Personal Agent Protocol. Later in October: v0.1 specification due. Ten weeks from courtroom to protocol Key moments in the fight over who lets AI agents in, 2026 4 AugCourt: the user,not Perplexity,accesses Amazon 8 SepMeta launchesMuse agent 10 SepRehearingdenied 20 SepAmazon blocksMuse 21 SepAmendedComet complaint 6 OctPAP announcedby Sierra + Meta Late Octv0.1 specdue Amazon’s complaint: agents that act for customers should operate openly and respect a business’s choice to opt out. Sources: The Next Web, Implicator, CMSWire (Sept to Oct 2026)delana.co
The court said the customer is the one knocking. PAP tries to make the agent say so out loud.

Together, the two stories make PAP’s case. Courts will not stop customers sending agents, and blocking every agent turns away paying customers. What businesses lack is a way to tell a declared agent from a disguised bot, and to give it limited access. Taylor, who also chairs OpenAI’s board, put the current state bluntly, as quoted by Implicator: “It is kind of chaos until such a standard exists.”

4. PAP, TAP, UCP, ACP, MCP: which protocol does what?

PAP joins a crowded field. Stripe, Shopify and Walmart, three of its headline partners, already back other agent standards.

ProtocolLed byMain question it answersStatus
Personal Agent Protocol (PAP)Sierra and Meta, with Walmart, Shopify, Stripe, Genesys and othersHow does a customer’s agent sign in, and what may it do on the customer’s account?Announced 6 Oct 2026; v0.1 spec due later in October
Trusted Agent Protocol (TAP)Visa, co-developed with CloudflareIs this visiting agent a vetted one, or a malicious bot? (signed requests checked against Visa’s registry)Announced Oct 2025; Stripe and Shopify have joined
Universal Commerce Protocol (UCP)Google, with Shopify, Target, Walmart, Etsy and WayfairHow does an agent run a full purchase, from discovery to checkout, returns and loyalty?Unveiled Jan 2026; backed by Visa, Mastercard, Stripe and American Express
Agentic Commerce Protocol (ACP)OpenAI, co-developed with StripeHow does a chat assistant complete a checkout with a merchant?Released Sept 2025
Model Context Protocol (MCP)Originated at Anthropic; widely adoptedHow does an agent call a business’s tools and data?Established; one of the API routes PAP supports
Compiled from Sierra, The Next Web, Implicator, VentureBeat and Oscilar. Descriptions simplified; the protocols overlap in places.

The overlap matters less than it looks. TAP answers “is this agent who it claims to be?”, PAP answers “what has the customer let it do here?”, and UCP and ACP answer “how does the purchase actually happen?” A mature setup may well use more than one. The practical risk for a business is building deep integrations for the first protocol that knocks, then finding its customers’ agents speak a different one. Keep agent-permission logic in your own systems and treat each protocol as an adapter.

The traffic is coming either way. Adobe data cited by VentureBeat showed AI-driven traffic to US retail sites up more than 4,700% in the year to October 2025, and Gartner, via CMSWire, predicts that by 2028 80% of organisations will see agents consume most of their APIs. As we argued in AI Is Starting to Pay for the Web, the bots are customers now and need a door policy.

5. What version 0.1 leaves out

PAP is an announcement, not yet a standard. Several gaps deserve attention before anyone builds on it:

  • No payments. Paying without sharing card details is listed as a future extension. Yet agents already buy things today: Muse, for example, pays with saved cards through Stripe’s Link. The Next Web notes that Europe’s strong customer authentication rules were written for a person approving a named payee and amount, with no carve-out for software approving on someone’s behalf.
  • Coarse permissions. The first version offers read-only or write. “Write” on a retail account could mean changing an address, cancelling an order or redeeming loyalty points. Finer permissions are on the roadmap, without a date.
  • No published governance. As of 7 October, Implicator reports, there is no specification, licence or governing body. CMSWire adds that it is unclear whether the spec will stay neutral about which vendor’s agent handles the conversation, which matters because Sierra, Decagon, Genesys and NiCE all sell customer-service agents.
  • Missing labs. OpenAI and Anthropic are not partners. Taylor said, according to Implicator, that he expects them to take part and would be disappointed if competitors did not use it.
  • Thin European presence. The Next Web observes that Stripe is the only named partner with a European headquarters, and no European retailer, bank or payment company has joined.

None of this makes PAP a bad idea, only an early one. Prepare what helps under any protocol (an agent policy, scoped tokens, good logging) and wait for the spec before committing engineering time.

6. The security and privacy questions to ask

Declared, scoped and logged beats disguised and unlimited, so PAP is good news for security. It also creates targets: a write token for your site is worth stealing, and the agent holding it can be tricked. We saw earlier today, in Encrypted Prompts Beat the Guardrails, how a web page can steer an agent into leaking secrets. An agent holding tokens for a dozen retailers invites the same tricks.

The agent access ladder: what to open at each rungA three-rung ladder. Bottom rung, guest: anonymous questions such as stock, prices and returns policy; low risk; main control is rate limits and bot verification. Middle rung, read-only: order history, account details, loyalty balance; medium risk because it exposes personal data; controls are customer sign-in on your page, short-lived tokens and logging. Top rung, write: change orders, addresses, bookings or redeem points; high risk; controls are step-up confirmation for sensitive actions, per-action limits and easy revocation. A side note says payments are not in PAP v0.1. The agent access ladder What to open at each rung, and the control that has to come with it WRITE · high riskChange orders, addresses or bookings; redeem points.Control: step-up confirmation for sensitive actions, per-action limits, one-click revoke. READ-ONLY · medium riskOrder history, account details, loyalty balance (personal data).Control: sign-in on your page, short-lived scoped tokens, per-agent access logs. GUEST · low riskStock, prices, opening hours, returns policy.Control: rate limits, bot verification, accurate public data. Access levels from Sierra’s PAP announcement; controls are Delana’s recommendations. Payments are not in v0.1.delana.co
Each rung up the ladder should cost the agent a little more proof and give your customer a little more control.

Questions to put to anyone proposing an agent integration:

  • Where does the customer sign in? On your page, with your multi-factor checks, is the right answer. An agent that collects and replays passwords is the pattern Amazon objected to.
  • What does the token allow, and for how long? Short-lived, narrowly scoped tokens limit the damage if an agent is hijacked.
  • Can the customer see and revoke it? A list of connected agents in the account settings, with a revoke button, should be standard.
  • Which actions need a fresh human “yes”? Changing a delivery address or cancelling a large order should trigger confirmation sent to the customer, not to the agent.
  • What gets logged? Every agent action should be recorded with the agent’s identity, so disputes can be settled with evidence rather than guesswork.

Phishers will follow. In The Fake “Claude Ads” Portal Is a Trap we showed how a fake “Connect” button became a credential-theft tool. Expect fake “connect your agent” pages, and tell customers where your real one lives.

7. The agent front-door scorecard

Use this ten-question scorecard to see how ready your business is for customers’ agents, whichever protocol wins. Give yourself one point for each “yes.” Score it with e-commerce, security and privacy in the room.

  1. Do you know how much agent traffic you already get? Check bot-management and analytics reports for declared AI agents and automated browsers.
  2. Is there a written agent policy? One page stating which agents are welcome, which tasks are open to them and which are not.
  3. Is your public information agent-ready? Stock, prices, hours and returns policy that a guest agent can read accurately without scraping.
  4. Do customers sign in only on your own pages? No flows that encourage handing passwords to a third party.
  5. Can you issue scoped, short-lived tokens? Your identity provider supports OAuth scopes that separate reading from changing.
  6. Have you mapped your write actions by risk? A list of every account change an agent might make, each marked low, medium or high.
  7. Do high-risk actions trigger human confirmation? Sent to the customer’s own phone or email, not answered by the agent.
  8. Can customers see and revoke connected agents? In their account settings, in one click.
  9. Are agent actions logged and attributed? So that a disputed order shows which agent did what, and when.
  10. Does your support team have an agent playbook? Agents that fail on the website will call or chat, so staff need to know how to verify and handle them.

Scoring: 8 to 10 means you are ready to pilot PAP or a similar protocol once the spec lands. 4 to 7 means fix the gaps in identity and logging first, because they matter under any standard. 0 to 3 means start with questions 1 and 2 this month: you cannot set a door policy for traffic you cannot see. For the wider governance picture, see AI Agent Security in 2026: The Risk Nobody Owns.

Reading your front-door scoreThree score bands. Zero to three: get visibility first, measure agent traffic and write an agent policy this month. Four to seven: fix identity and logging, scoped tokens, confirmation for risky actions and revocation. Eight to ten: ready to pilot PAP or a similar protocol when the v0.1 specification lands. Reading your front-door score One point per “yes” on the ten-question scorecard 0–3Get visibility firstMeasure agent traffic.Write a one-page agentpolicy this month. 4–7Fix identity and logsScoped tokens, confirmationfor risky actions, and arevoke button for customers. 8–10Ready to pilotJoin the PAP workshops ortest a protocol adapterwhen v0.1 is published. Delana scorecard based on Sierra’s PAP design and CMSWire’s contact-centre guidancedelana.co
Most of the points come from identity basics you need whichever protocol wins.

8. What to watch next

The v0.1 specification. Due later in October, followed by design workshops and a reference implementation. Watch how agents prove identity, how scopes are defined and how revocation works; Meta says those pieces are still being designed.

Whether OpenAI, Anthropic and Google sign up. A standard for personal agents without the makers of the most-used assistants would be a standard for some agents.

Payments and regulators. The payments extension is where agents meet consumer-protection rules, and the question of who pays when an agent with write access gets an order wrong. We covered the liability debate in “The AI Did It” Is No Longer a Defense, and it applies here in full.

Frequently asked questions

What is the Personal Agent Protocol?

It is a proposed open standard, announced by Sierra and Meta on 6 October 2026, for how a consumer’s personal AI agent signs in to a business, identifies itself and completes tasks. Sessions are built on OAuth, and the customer chooses whether the agent gets read-only or write access.

Who is behind PAP?

Sierra and Meta lead development. Sierra lists Genesys, Instinct, Rocket, Shopify, Stripe and Walmart as partners; Meta’s list also names Decagon, and NiCE says it is co-developing the protocol. OpenAI and Anthropic are not partners so far.

Can I implement PAP today?

Not yet. The v0.1 specification is due later in October 2026, followed by design workshops and a reference implementation. You can prepare now by setting an agent policy, supporting scoped OAuth tokens and logging agent activity.

Does PAP handle payments?

No. Payments that complete purchases without sharing card details are listed as a future extension, along with push notifications and finer-grained permissions. Version 0.1 covers sign-in, access levels and sessions.

How is PAP different from Visa’s Trusted Agent Protocol?

Visa’s protocol, built with Cloudflare, helps a merchant verify that a visiting agent is a vetted one by checking signed requests against Visa’s registry. PAP focuses on what a signed-in customer has allowed the agent to do on their account. The two could be used together.

Should my business block AI agents instead?

Blocking undeclared bots is reasonable, but blocking all agents increasingly means turning away customers. A US appeals court ruled in August 2026 that the user, not the AI company, was the one accessing Amazon in the Perplexity case. A clear policy that welcomes declared agents with limited, revocable access is a more durable position.


Sources

  • Sierra: Introducing Personal Agent Protocol (6 Oct 2026)
  • The Next Web: Sierra announces Personal Agent Protocol, an open standard for personal AI agents (6 Oct 2026)
  • Implicator: Meta and Sierra draft a sign-in standard for AI agents (Oct 2026)
  • CMSWire: Genesys, NiCE join Sierra, Meta on open standard for personal AI agents (Oct 2026)
  • Constellation Research: Meta, Sierra pitch Personal Agent Protocol (7 Oct 2026)
  • The Next Web: Amazon blocks Meta’s Muse and accuses Perplexity of misleading a court (Sept 2026)
  • VentureBeat: Visa launches Trusted Agent Protocol to secure AI shopping (Oct 2025)
  • Oscilar: Google’s Universal Commerce Protocol explained (2026)

Post navigation

Previous: Encrypted Prompts Beat the Guardrails: GitHub Copilot CLI Leaked a Secrets File in 28 Seconds, and GitHub Says It’s Not a Bug (AI Trends, 7 October 2026)

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC