Sierra and Meta, together with eight partner companies, presented the Personal Agent Protocol on October 6, 2026, an open standard for collaboration between personal AI agents and businesses. The OAuth-based system governs how agents identify themselves at online shops and in customer service, and what rights they get in the process.
Three access levels regulate what agents may do
The protocol builds on OAuth, an established method for granting access on the web. A personal agent can start by retrieving information such as stock levels or return conditions as a guest, without the user needing to log in.
Only once a customer account is linked does the agent get either read access, say to order history, or write access to change or place orders. Each grant stays tied to a single customer session that carries across channels.
If an agent starts a booking on the website and later switches to the app, the customer should not have to identify themselves again under the concept.
Businesses can offer access in three ways. The first option is the regular website, the second an interface built on the MCP or OpenAPI standards.
A dedicated company agent is the third route, meant for matters that need a conversation, such as a complaint. According to Sierra, businesses face no licensing costs, since the standard is open and free to implement.
It is not yet known when German or European retail platforms will join – so far every named partner is from the US market, and no European rollout date has been set.
Walmart, Shopify and Stripe back the standard
Sierra names Genesys, Instinct, Rocket, Shopify, Stripe and Walmart as partners. Meta's own announcement adds NiCE and Decagon to the list.
Genesys CEO Tony Bates welcomes a shared framework for customer-service agents, according to the company statement. Shopify executive Mani Fazeli sees benefits for merchants who want to open their shops to automated purchases.
A first version 0.1 of the technical specification is due later in October, to be followed by design workshops and a reference implementation for developers who want to connect their own agents or shop systems.
Meta is no newcomer to opening its own systems to agents. Back in July 2026, the company made advertising accounts accessible to AI assistants through the Ads MCP Server.
The new protocol extends that approach across all of commerce. Meta also says it is meant to keep agent behavior predictable. The yardstick is a comparison with how an honest person would act: an agent is supposed to behave the way a human with the same permissions would.
Amazon had earlier blocked Muse over missing identification
The push responds to a concrete problem. Amazon had blocked Meta's AI assistant Muse from its own shop in September because the agent failed to identify itself as such while shopping automatically.
That exact identification gap is what the new protocol is meant to solve technically. Amazon itself, however, is no more part of the founding coalition than OpenAI or Anthropic.
Without the largest retail platform and two of the biggest assistant makers, the standard's reach stays limited for now. The announcement joins the dossier on personal AI agents, which tracks further disputes and developments between agents and retail platforms.
There is also a trust problem. According to a survey cited by Forkast, only three percent of US adults would trust an AI agent to shop on their own. The figure is independently unverified, but it points to a gap between the technical infrastructure and how people actually use it day to day.
What matters next is whether more major platforms sign on once the October specification lands. It also remains open how businesses in the EU should handle the write access the protocol grants agents over orders and customer data. Sierra and Meta have not yet addressed data-protection requirements outside the US.












