Meta and Sierra Want to Give Your AI Agent a Handshake: Inside the Personal Agent Protocol
If 2025 was the year AI agents learned to think, 2026 is the year they are learning to knock. On October 6, at Sierra Summit in San Francisco, Sierra co-founders Bret Taylor and Clay Bavor announced the Personal Agent Protocol (PAP) — an open standard co-developed with Meta that defines how a personal AI agent authenticates with a business, what it is allowed to do once inside, and how the whole interaction stays trustworthy. The founding partner list reads like a commerce and infrastructure dream team: Walmart, Shopify, Stripe, Rocket, Genesys and Instinct.
It is a quietly enormous announcement. The race to build agentic commerce has so far produced a thicket of incompatible approaches, defensive walls, and outright bans. PAP is the most credible attempt yet to replace that chaos with a common handshake.
The Problem: Agents Are Customers Now
Personal AI agents are no longer a futuristic demo. People already use them to schedule appointments, book flights, shop for car insurance, and reorder groceries. But the way these agents interact with businesses is comically primitive: most of them browse websites the way a human does — loading pages, reading forms, clicking buttons. When that fails, the agent may try the company's support line or web chat, a path that can take an enormous amount of time and still end in failure.
Businesses, meanwhile, have responded with suspicion. Reports of account suspensions for users relying on AI agents have surfaced across major platforms, and several large retailers and services currently prohibit unauthorized automated traffic outright. The status quo is bad for everyone: consumers get blocked, and companies lose a customer who arrived ready to spend.
How the Protocol Works
The design of PAP is deliberately boring — and that is its strength. Sessions are built on OAuth, the same battle-tested standard you use whenever you sign in to an app with your Google or Apple account. An agent can start as a guest to do lightweight things like checking stock availability or a return policy. When the customer signs in, they explicitly grant the agent either read-only or write access, and the session carries across channels — a question asked before sign-in and an order change made afterward are part of the same visit.
Just as importantly, the protocol gives businesses three doors to open: agents can interact through the company's website, its APIs (via MCP or OpenAPI), or the company's own AI agent. The company decides which door exists and what a guest agent versus a signed-in agent may read or change. Meta's David Singleton, VP at Meta Superintelligence Labs and former CTO of Stripe, compared the ambition to email: "We're defining rails that we hope personal agents and business agents can run over for the future."
The Missing Names Tell the Story
For all the heavyweight backing, what is absent is just as telling. OpenAI, Anthropic, Amazon and Google are not on the partner list. Stripe and Shopify are notably hedging their bets — both have already joined Visa's Trusted Agent Protocol, while Walmart and Shopify also participate in Google's Universal Commerce Protocol, and Stripe co-developed the Agentic Commerce Protocol with OpenAI back in 2025.
That fragmentation is the real obstacle. If every major player backs a different standard, the industry simply rebuilds the compatibility mess it was trying to escape. Sierra says it welcomes all partners and will host design workshops, but whether the protocol becomes the "email of agentic commerce" or just another entry in a crowded field depends on those missing giants.
Trust, Payments, and the Hard Questions
The protocol's tiered permission model is a genuine step forward for consumer trust. But hard problems remain on the roadmap. Payments, notably, are listed as a future extension rather than part of the first specification — and for good reason. As early analyses pointed out, a payment approved by software on someone's behalf has no carve-out from strong customer authentication rules, which were written assuming a human approving a specific payee and a specific amount.
There are also open governance questions. At launch, no specification, licence, or independent governing body had been published. The v0.1 spec and a reference implementation are due by the end of October, and developers are wise to wait for that text before writing PAP-specific code.
Why It Matters
The Personal Agent Protocol is not a product launch — nothing shipped on October 6. But it marks a strategic shift in how the industry thinks about AI agents: from adversarial scraping and blocking to standardized, permissioned access. For developers, it signals that OAuth-style agent authentication is likely to become a core competency. For businesses, it offers a way to welcome agent traffic on their own terms — deciding what agents can see, do, and buy. And for consumers, it hints at a near future where your AI assistant is a first-class customer, not a suspicious bot to be shown the door.
The rails are being laid. The next few months — the v0.1 spec, the reference implementation, and whether OpenAI and Google decide to board the train — will determine whether your next checkout is done by you, or for you.
Top comments (0)