Key Takeaways
- Meta and Sierra are developing a protocol for authenticating personal AI agents when they interact with businesses.
- Walmart, Shopify, Stripe, and other companies are participating in the proposed protocol’s development.
- The framework would allow businesses to define permissions for AI agents acting on behalf of customers.
- The protocol remains under development, with its first specification expected later in October.
Meta and AI company Sierra are working with several companies on a proposed standard for how personal AI agents interact with businesses online. The Personal Agent Protocol is intended to give businesses a way to identify AI agents, authenticate them, and control what they can access when acting on users’ behalf.
The initiative comes as personal AI tools such as Meta’s Muse increasingly handle tasks that traditionally required people to navigate websites themselves, including shopping, bookings and customer service. Companies have struggled to distinguish authorized AI agents from automated traffic, and existing anti-bot systems can also block legitimate requests. The proposed protocol aims to address these issues by establishing a common system for interactions between personal agents and businesses.
Meta, Sierra And Companies Develop Personal Agent Protocol
Meta and Sierra are developing the Personal Agent Protocol with partners including Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. Sierra said the protocol is intended to define how personal agents authenticate with businesses and what those agents can do. The Sierra announcement says the system is designed to handle authentication, give consumers control over access, and provide companies with visibility into what personal agents do through websites, APIs, or company-operated agents.
The proposal uses OAuth-based authentication and is intended to give consumers control over the access granted to their agents. Businesses can also decide whether an agent can interact through a website, an API, or the company’s own AI agent. Sierra said it plans to publish the version 0.1 specification later in October, along with a reference implementation for developers. The need for a standard has become more visible as AI agents move from answering questions to taking action. Meta’s Muse, for example, can perform tasks on behalf of users, but websites may not always recognize the agent as a distinct visitor type. Traditional anti-bot systems can also interfere with agents even when a user has authorized them to perform a task.
Amazon’s decision to block Muse from shopping on its site provides a recent example of the issue. A discussion on Reddit had users discussing how browser-based AI agents can be difficult to distinguish from human users because they can operate through the same browser environment and user connection.
The protocol does not mean businesses would automatically have to accept every AI agent. Instead, its stated purpose is to establish a consistent way for companies to set the conditions under which agents can interact with their services.
Proposed Standard Would Give Businesses More Control Over AI Agents
The proposed protocol is designed to give businesses more control over what personal AI agents can access and what actions they can take. Sierra says the system will use authentication to connect an agent with a business while allowing consumers to decide what access they grant to their personal agents. Businesses would then define which functions an agent can use through a website, an API, or the company’s own AI agent. Sierra’s announcement says the protocol is intended to provide a consistent way for these interactions to take place.
The proposed system is based on OAuth, which would let an agent authenticate on a user’s behalf without being treated as an unidentified automated visitor. Next Web’s report on the protocol notes that businesses would be able to determine whether an agent can interact through their website, an API, or a company-operated agent. The Next Web also reports that the protocol’s first version is expected later in October. This distinction matters because businesses may want to support AI agents without giving them unrestricted access. Under the proposed approach, a company could set boundaries around what an authenticated agent can do, while the user controls the permissions granted to the agent. That could cover actions such as accessing information, interacting with customer-service systems, or completing other tasks on a user’s behalf. The protocol is also being developed with commerce in mind, although payments are not part of the initial specification.
Sierra says it could add payment capabilities through a future extension. The company’s initial focus is authentication, consumer control, and visibility into agent activity rather than creating a complete payment system. The need for those controls is already visible in how companies are responding to AI shopping agents. Amazon, for example, has blocked Meta’s Muse from shopping on its platform, citing concerns around unauthorized access and how the agent interacted with the service.









