By Jordan Vale

personal-agent-protocol-sierra-meta hero

An AI helper that books the dentist, compares car insurance, and orders the birthday gift is useful only if you know whose bot is at the checkout — and what you actually allowed it to do. That permission question is the everyday stake behind a new open standard for personal agents.

The handshake. On October 6, Sierra — the enterprise AI company co-founded by Bret Taylor and Clay Bavor — and Meta said they are developing an open standard called Personal Agent Protocol with industry partners including Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. Instead of an agent loading web pages and clicking through forms the way a person would (or calling support when that fails), the idea is a direct, signed-in session on your behalf.

How it works, in plain words. The protocol starts on a company’s website: the agent discovers what is offered and how to reach it, then opens a session. It can begin as a guest — enough, Sierra says, to check stock or ask about returns. When a task needs your account, you sign in on the company’s page or use credentials already set up with your agent. You decide whether that agent gets read-only or write access. The company decides what agents are allowed to do at all.

OAuth, not a mystery door. That session is built on OAuth — the same kind of authorization pattern behind “Log in with Google.” Sierra’s post says the session can carry across channels, so a question asked before sign-in and an order change afterward count as one visit. From there the agent might use the site’s regular pages, its application programming interfaces (APIs), or the company’s own agent for messier jobs like a warranty claim.

Why businesses want rails. Taylor told CNBC that without a shared rulebook, “it is kind of chaos.” Companies need to know when a personal agent — not a random scraper — is acting for a real person. David Singleton of Meta Superintelligence Labs compared the bet to email: a standard everyone can use to talk to each other. Meta’s own personal agent, Muse, has become a high-profile example of the boom; Amazon has blocked some agents over scraping worries, which is part of the mess this protocol is meant to calm.

Who is in — and who is not. The founders’ list is consumer-heavy: retailers, payments, shop platforms, and contact-center software. CNBC reports that OpenAI and Anthropic have not joined for now. Taylor, who is also chairman of OpenAI, said he expects big AI labs to participate and would be “really disappointed” if competitors ignore an open standard.

Ink, not pencil: the v0.1 specification and a reference implementation are planned for later this October — they are not published yet. Ideas such as finer permission limits, push alerts to your agent (a delayed flight, a shipped order), and payments that finish without sharing your card number are described as future extensions, not shipping features today.

Why regular people should care

Everyday AI trust is the product. If helpers shop and book for you, the quiet question is simple: did you open that door, and how wide? A clear permission handshake — read versus write, guest versus account — is how “it just did that” moments stay on your side of the line. Without it, companies block bots, agents fake being human, and you lose both speed and a paper trail of what was allowed.

What's next

What to watch. Whether the October v0.1 draft and reference code land on schedule, whether OpenAI and Anthropic (or other agent builders) join, and whether more retailers and banks adopt the same rails. For now the stake is everyday: agents that act for you need a handshake you can understand — before card-free payments and deeper permissions leave the slide deck.

← Back to AI