Sierra and Meta propose a standard for personal AI agents
Sierra and Meta announced the Personal Agent Protocol, an open standard for how shoppers' AI agents deal with businesses. Version 0.1 is due later in October.
4 min read

By the numbers
- ways a business can connect: web pages, APIs or its own agent
- 3
- first spec, promised for later in October 2026
- v0.1
- named partners besides Sierra, including Meta, Shopify, Stripe and Walmart
- 7
Sierra and Meta announced the Personal Agent Protocol on October 6, 2026, a proposed open standard for how a shopper's AI agent should deal with a business. Sierra says the first spec, version 0.1, will arrive "later this month," according to Sierra's announcement. No spec exists yet. Today agents often act like a person clicking through a website, and the standard aims to replace that with a clear set of rules.
What the protocol covers
The Personal Agent Protocol, or PAP, sets rules between a personal AI agent and a company. It covers how the agent proves who it works for, how much control the customer keeps, and how much the company can see. Sierra says it is "open for anyone to implement."
A session works like this, according to Sierra and The Next Web:
- It starts on the company's own website, where the agent finds what the company offers.
- A guest agent can do light tasks, such as checking stock or a returns policy.
- For account tasks, the customer signs in. The customer then chooses read-only or write access.
- Companies set the limits on what agents can do.
- Sessions are built on OAuth, the common sign-in standard, and carry across channels. A question asked before sign-in and an order change made after count as one visit.
Three ways to connect
A business picks one of three routes, Sierra says:
| Route | How it works |
|---|---|
| Web pages | The agent uses the company's regular pages, which are set up to be read by agents. |
| APIs | The company offers open APIs built on MCP, the Model Context Protocol, or OpenAPI. |
| The company's own agent | The personal agent hands the conversation to the business's agent, for tasks like a warranty claim. |
Who is involved
Sierra names Meta as co-developer, with Genesys, Instinct, Rocket, Shopify, Stripe and Walmart as partners. Four executives are quoted in Sierra's post:
- "Brands need a trusted way to know who an AI agent represents, what it's authorized to do," said Tony Bates, chairman and CEO of Genesys.
- Shawn Malhotra, chief technology officer of Rocket Companies, said: "Nobody else has the data, technology and homeownership ecosystem to make that possible."
- Mani Fazeli of Shopify said the protocol "helps establish how agents and merchants can work together."
- Kevin Miller, head of payments at Stripe, said: "We're contributing to the Personal Agent Protocol to give businesses a standard way to recognize their customers' agents."
Forkast notes that Amazon, OpenAI and Anthropic are not on the list. The Next Web adds that Stripe and Shopify have already joined a different protocol, Visa's Trusted Agent Protocol, which Microsoft and Worldpay also joined. Partner lists vary between outlets, so check Sierra's page for the current names.
What is not ready yet
PAP is a proposal. Sierra, The Next Web and Forkast all say that payments are not part of the first version. Sierra lists them, along with finer permissions and push notifications such as flight delays, as future extensions. Forkast says payments are left to existing financial systems.
None of the sources names a licence or a governing body. Sierra says it will publish version 0.1 later in October and host design workshops. It also plans a reference implementation, a working example for developers.
Bret Taylor of Sierra told CNBC, as Forkast quotes him: "It is kind of chaos until such a standard exists." David Singleton of Meta Superintelligence Labs, also via CNBC, said: "We're defining rails that we hope personal agents and business agents can run over for the future."
What this means for developers
If you build shopping, support or commerce software, the standard may matter within months.
- Read the v0.1 spec when it lands. Until then, nothing is fixed. Do not build on details from announcements.
- Look at your existing APIs first. Two of the three routes use MCP or OpenAPI. A clean, documented API is the cheapest way to be ready.
- Design for guest and signed-in modes. Decide which actions an unknown agent may take, such as stock checks, and which need a login.
- Plan for several standards. Shopify and Stripe appear in more than one protocol. Keep your agent layer thin so you can support whichever standards win.
- Log what agents do. The protocol promises companies visibility into agent activity. Start recording agent sessions now so you can compare them with the spec.
The release to watch is version 0.1. It will show whether the standard adds real rules or only restates how OAuth and APIs already work.
Sources
Related articles

OpenAI Agents API adds computer use in a hosted browser
OpenAI's Agents API, in public beta since September 10, gained computer use at DevDay on September 29, 2026: agents can drive an OpenAI-hosted browser.

Google Cloud's Gemini agent can route work to Claude
Google Cloud unveiled the Gemini agent on October 8, a work agent in private preview that runs jobs on Gemini or Claude and can keep working for hours or days.

Meta open-sources Muse Gadgets for ESP32 and Pi hardware
Meta released Muse Gadgets on October 2: open-source ESP32 and Linux kits for building hardware around its Muse agent, plus 5,000 free Home Link dongles.
The weekly digest
One email every Friday with the week's top stories from all six desks: AI, dev tools, coding, the tech industry, startups and what's next. Free, no spam.