Safety & Risk 2026-10-07

Meta, Sierra, Walmart and Stripe Propose a 'Personal Agent Protocol' So Businesses Can Tell Which Bot Is Acting for Whom

On October 6, Sierra and Meta announced Personal Agent Protocol, an open standard being developed with Genesys, Instinct, Rocket, Shopify, Stripe and Walmart. It gives a personal agent like Meta's Muse an OAuth-based session with a business, with the customer choosing read-only or write access and the company setting what the agent may do. The v0.1 spec is due later this month; OpenAI and Anthropic have not signed on.

On October 6, 2026, Sierra co-founders Bret Taylor and Clay Bavor announced Personal Agent Protocol, which Sierra calls "an open standard Meta and Sierra are developing along with industry partners at Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart that defines how personal agents interact with businesses." Sierra says it is "open for anyone to implement" and plans to publish a v0.1 specification later this month, followed by design workshops and a reference implementation.

The problem it targets

Sierra's post describes how personal agents work today: they use websites "the way people do," loading pages and clicking through forms, and fall back to a support line or web chat when that fails. For the business on the other end, that means it can't tell a customer's agent from a scraper. CNBC reports that Amazon has blocked Meta's agents over scraping concerns, and that Taylor -- who is also OpenAI's chairman -- put it bluntly: "Companies will know when it's a personal agent versus an actual person. For a lot of companies there's a risk: you don't want just a random bot that isn't acting on behalf of a person to have access to this service." His summary of the current state: "It is kind of chaos until such a standard exists."

How the protocol is meant to work

  • Discovery on the website. A personal agent finds what a company offers and how to reach it.
  • Guest, then signed-in sessions. The agent can start as a guest (enough to check stock or a returns policy). For account tasks the customer signs in on the company's page or uses credentials already set up with their agent, and decides whether the agent gets read-only or write access.
  • OAuth underneath. The session is built on OAuth and carries across channels, so a question asked before sign-in and an order change afterward belong to the same visit.
  • Three routes, chosen by the company. Its regular website; its APIs, "built on standards such as MCP and OpenAPI"; or its own agent, for tasks that need conversation such as a warranty claim.
  • Planned, not yet specified: finer-grained per-action permissions, push notifications (a flight delay, a shipped order) and payments extensions that would let an agent complete a purchase "without sharing credit card information."

Why Meta wants it

David Singleton, vice president of engineering and consumer products at Meta Superintelligence Labs and Stripe's former technology chief, told CNBC that Muse already has millions of US users who use it for things like "signing their kids up for classes" and "scheduling that dentist appointment that you have been putting off for six months," and that "We need a mechanism to have it go faster and smoother." He compared the effort to email: "We're defining rails that we hope personal agents and business agents can run over for the future."

The adoption constraint is permissions and trust, not plumbing. Retailers have to decide what an authenticated agent may do on an account, and who carries the loss when it does the wrong thing. That question gets sharper given Muse's recent record: SiliconANGLE notes 404 Media's report that Meta rushed to fix security vulnerabilities in Muse just before launch, and WIRED's report that it builds profiles of the people in a user's life.

What remains uncertain. OpenAI and Anthropic are not participants yet; Taylor told CNBC he expects them to join and would be "really disappointed" otherwise. Amazon is not on the list. There is no spec text to evaluate until v0.1 ships, and the parts that matter most for safety -- per-action limits and payments -- are still listed as future extensions.

Personal Agent Protocol, announced October 6 by Sierra and Meta with Walmart, Stripe, Shopify and others, would give personal agents an OAuth session with businesses in which customers choose read or write access and companies set the limits -- but the spec isn't out until later this month, OpenAI, Anthropic and Amazon aren't in it, and per-action permissions and payments are still future work.