Meta and Sierra launch Personal Agent Protocol - open standard for AI shopping agents
TECH

Meta and Sierra launch Personal Agent Protocol - open standard for AI shopping agents

32+
Signals

Strategic Overview

  • 01.
    On October 6, 2026, Meta and Sierra announced the Personal Agent Protocol (PAP), an open standard governing how personal AI agents authenticate with businesses and what those businesses let them do, developed with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart.
  • 02.
    The protocol runs on OAuth: an agent starts as a guest with read-only access and upgrades to write access once the customer signs in, with sessions carrying across a website, MCP/OpenAPI calls, or a company's own agent.
  • 03.
    As of the announcement there was no published specification, license, governing body, or reference implementation; a v0.1 spec is promised later in October 2026, with payments, push notifications, and finer-grained permissions deferred to future extensions.
  • 04.
    On the same day, Decagon separately open-sourced a related protocol, the Personal Agent Consent & Trust Protocol (PACT), co-developed with Instinct and also built on OAuth.

Deep Analysis

How the OAuth Tiering Actually Works

PAP is not a new payments rail or a new browser API - it is an open standard meant to dictate how AI agents interact with businesses, developed by Meta and Sierra together with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart[1]. Structurally it's a permissioning layer bolted onto OAuth: a personal agent first shows up at a business as a guest with read-only access. Only once the human customer signs in does the agent get upgraded to write access, and that authenticated session is designed to persist across channels, whether the agent is hitting the company's website directly, calling it through MCP or OpenAPI, or routing through the company's own in-house agent[2]. Meta frames this as deliberately unglamorous infrastructure rather than a product: Meta Superintelligence Labs VP David Singleton, a former Stripe CTO, described it as "rails that we hope personal agents and business agents can run over for the future"[3]. The pitch is that businesses get an audit trail and an on/off switch for agent access, and agents get a consistent way to prove who they are acting for - the exact thing that was missing when Amazon caught Muse browsing without identifying itself.

The Amazon Blockade That Forced the Issue

The direct trigger for PAP sits twelve days earlier. Meta launched Muse on September 8, 2026, giving it the ability to open a browser, fill out forms, and complete checkout on a user's behalf[4]. On September 20, Amazon began blocking Muse from shopping on its site, telling users the integration violated its Conditions of Use because Meta had never disclosed or sought authorization and the agent did not identify itself as AI while browsing[4]. Amazon's own framing was that third-party agents making purchases "should operate openly and respect service provider decisions about whether or not to participate"[6]. Amazon was far from alone - reporting around the same period found Yelp, eBay, Zillow, Pizza Hut, Adidas, United Airlines, and Delta all restricting or blocking automated agent traffic, turning a single platform fight into an industry-wide access problem[5]. The stakes for Meta are not small: Citigroup estimates Muse could generate roughly $27 billion in revenue by 2030, split between transactions and subscriptions, and already counts 6.6 million cumulative downloads and 1.8 million daily active users[7]. A standard that gets agents let back in the door is worth building fast.

A Land Grab Dressed as a Standard

The same day PAP was unveiled, Decagon open-sourced its own, overlapping Personal Agent Consent and Trust Protocol (PACT), co-developed with Instinct and also built on OAuth[8]. That is not a coincidence so much as a signal: multiple companies are racing to be the ones whose identity and consent layer other agents end up authenticating through - and the reaction on X made that land-grab dynamic visible in real time, with both Bret Taylor's and Decagon's own announcement posts drawing strong engagement. PAP itself joins an already crowded field - Visa and Cloudflare back a rival Trusted Agent Protocol, Google has its own Universal Commerce Protocol, and OpenAI backs an Agentic Commerce Protocol built with Stripe - and Stripe and Shopify are each hedging by participating in several of these camps simultaneously[9]. The handful of early YouTube explainers covering the launch made the same point, slotting PAP alongside several other agent-trust and agent-payments efforts that happened to launch the same week, including AgentMail's AgentID, Decagon's PACT, and HTTP 402 agent payments. Commentary around the launch put the underlying tension bluntly: whoever writes the authorization standard effectively decides who gets to walk through the door, even as every participant insists the layer is neutral. Constellation Research's Larry Dignan is skeptical the spec's ethical safeguards survive contact with agents that find it advantageous to route around them, and points out that no European retailer, bank, or payment company has joined PAP or its rivals yet[10].

Trust Gap and What Comes Next

PAP is launching into a market that does not trust agentic commerce yet: only 3 percent of US adults say they trust AI agents to complete purchases, and about a third of active AI users say they would never allow an agent to buy anything for them[6]. That skepticism shows up in public conversation too, though not quite where you'd expect: direct discussion of the protocol itself has been thin so far, and the broader Reddit conversation has centered less on PAP as a technical standard and more on its root cause, the Amazon/Muse dispute, with sentiment split between sympathy for Amazon's stated data-access concerns and skepticism that Amazon's real motive is competitive self-interest. A smaller, more analytical thread has gone further, framing the standoff as the first real-world test case for agent-permission conflicts and asking which layer - user, platform, or agent - ultimately gets final say. Banks got there first with caution rather than code - six major banks published voluntary trusted agentic commerce principles on September 22, with Bank of America's Mark Monaco warning that building confidence "will require thoughtful approaches to identity, authorization, fraud prevention, liability management and customer protection"[11], while Crone Consulting's Richard Crone argues banks risk losing control of discovery and payment selection to AI agents and large language models if they move too slowly[11]. PAP itself is further behind than the announcement suggests: there is no published v0.1 specification yet (promised later in October 2026), no license, no governing body, and no reference implementation, with payments and fine-grained permissions explicitly pushed to a later extension[9]. The most pointed irony is that Sierra's Bret Taylor chairs OpenAI's board yet OpenAI has not joined PAP, instead backing its own Agentic Commerce Protocol with Stripe - Taylor has said he would be disappointed if OpenAI and Anthropic built around something else rather than adopting this standard[6].

Historical Context

2026-09-08
Meta launched Muse, a personal AI agent capable of opening a browser, filling out forms, and completing checkout on behalf of a user.
2026-09-20
Amazon began blocking Meta's Muse agent from shopping on Amazon.com, warning users that unauthorized AI agent access violates its Conditions of Use, and said Meta never disclosed or sought authorization for the integration.
2026-09-22
Bank of America, Capital One, ING, NatWest, Commonwealth Bank of Australia, and ASB Bank published joint, voluntary principles for trusted agentic commerce covering transparency, safety, privacy, choice, and interoperability.
2026-09-23
Muse gained the ability to shop and check out on Shopify-powered stores via Shop Pay, even as Amazon kept it blocked.
2025-09
Google launched its own Agent Payments Protocol with over 50 participants, an earlier entrant in the fragmented agentic-commerce standards landscape.
2026-10-06
Personal Agent Protocol announced; the same day, Decagon and Instinct separately open-sourced a related PACT (Personal Agent Consent and Trust Protocol).

Power Map

Key Players
Subject

Meta and Sierra launch Personal Agent Protocol - open standard for AI shopping agents

ME

Meta

Co-founding partner; maker of Muse, the personal shopping agent that triggered the dispute with Amazon

SI

Sierra (Bret Taylor, Clay Bavor)

Co-founding partner and lead drafter of the protocol; Taylor also chairs OpenAI's board

ST

Stripe

Founding partner providing payments infrastructure, also participates in rival Visa Trusted Agent Protocol and OpenAI's Agentic Commerce Protocol

AM

Amazon

Not a participant; blocked Meta's Muse agent from shopping on Amazon.com on September 20, 2026 over unauthorized access and non-disclosure concerns

OP

OpenAI and Anthropic

Not yet participants in PAP despite Taylor's OpenAI board chairmanship; OpenAI instead backs its own Agentic Commerce Protocol with Stripe

VI

Visa and Cloudflare

Backers of a rival Trusted Agent Protocol addressing agent identity, consumer recognition, and payment data directly

Fact Check

11 cited
  1. [1] Meta joins with group of companies to tame 'chaos' of doing business with AI bots
  2. [2] Personal Agent Protocol introduced: visibility into what AI agents do
  3. [3] Sierra and Meta's Personal Agent Protocol gives commerce a common front door for those willing to open it
  4. [4] Amazon blocks Meta's Muse AI agent from shopping on its site
  5. [5] The next hurdle for AI agents: getting websites to let them in
  6. [6] Meta and Sierra's Personal Agent Protocol, explained
  7. [7] Citigroup: Meta's Muse could generate over $27 billion by 2030
  8. [8] Personal Agent Protocol and PACT announcements roundup
  9. [9] Meta-Sierra Personal Agent Protocol: OAuth guest/read-write access vs UCP, ACP, Trusted Agent Protocol, and retail banks
  10. [10] Meta, Sierra pitch Personal Agent Protocol to govern how personal AI agents deal with business
  11. [11] Are banks falling behind on agentic commerce standards?

Source Articles

Top 5

THE SIGNAL.

Analysts

“Says the current lack of a standard is chaotic and hopes rival AI labs eventually adopt PAP: "It is kind of chaos until such a standard exists."”

Bret Taylor, Sierra co-founder and OpenAI board chairman
Advocate for the standard

“Describes PAP as foundational technical rails intended for both personal and business agents: "We're defining rails that we hope personal agents and business agents can run over for the future."”

David Singleton, Meta Superintelligence Labs VP (former Stripe CTO)
Meta's technical framing

“Says the spec is very early but could mature quickly like MCP did, while doubting Meta's proposed ethical safeguards will hold once agents find it advantageous to bypass them; notes no European retailer, bank, or payment company has joined this effort or rivals. Says the tension is that "consumers want speed, dependability and trust, brands want visibility and control."”

Larry Dignan, Constellation Research analyst
Cautiously skeptical

“Argues banks risk ceding control of discovery, payment selection, and account opening to AI agents and LLM providers if they move too slowly: "The market is racing faster than a white paper can chase: banks risk losing customers not only to AI, but to competitors and large language models using AI to control discovery, payment selection and account opening."”

Richard Crone, Crone Consulting
Critical of banks' slower pace relative to tech and payments players

“Argues third-party agents should operate transparently and respect a merchant's decision on whether to allow access at all: "We think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate."”

Amazon spokesperson
Defends the block of Muse
The Crowd

“Today we’re announcing Personal Agent Protocol — an open standard @Meta and @SierraPlatform are developing along with industry partners at @Genesys, @instinct, @RocketOTD, @Shopify, @stripe, and @Walmart. It will help define how personal agents interact with businesses and is”

@@btaylor2811

“Today, we're open-sourcing the Personal Agent Consent & Trust Protocol (PACT), co-developed by @Instinct. We're also joining the Personal Agent Protocol working group by @Muse. Built on A2A and OAuth, PACT enables businesses to verify who a personal agent is acting for and what”

@@DecagonAI1022

“Today we’re announcing Personal Agent Protocol — an open standard @Meta and @SierraPlatform are developing along with industry partners at @Genesys, @instinct, @RocketOTD, @Shopify, @stripe, and @Walmart. It will help define how personal agents interact with businesses and is”

@@SierraPlatform857

“Amazon bars Meta's Muse AI from shopping on its site”

@u/joe4942360
Broadcast
Codex Auto-Review Is Now Free, and AI Shopping Agents Get Rules | AI News, this is good title

Codex Auto-Review Is Now Free, and AI Shopping Agents Get Rules | AI News, this is good title

Meta, Shopify, Stripe and Walmart Announce Rules for AI Agents

Meta, Shopify, Stripe and Walmart Announce Rules for AI Agents

Your next customer is an AI agent

Your next customer is an AI agent