Personal Agent Protocol: Meta, Sierra Set AI Shopping Rules

Personal Agent Protocol: Meta, Sierra Set AI Shopping Rules

Meta is joining Walmart, Stripe and Sierra Technologies to write a common rulebook for AI agents that shop and transact online. The proposal is called the Personal Agent Protocol. Its aim is to let businesses tell whether an agent knocking on their door is actually authorized to act for a real user.

Sierra is the enterprise AI company co-founded by Bret Taylor, who was previously co-CEO of Salesforce. Taylor introduced the standard in a blog post. He said it is being designed to handle authentication, give consumers more control, and show companies what personal agents are doing on their websites, through their APIs or when talking to their own company agents. He added that anyone can implement it.

What the protocol is meant to fix

Agentic commerce is the idea that people will hand routine purchases to an AI agent instead of clicking through a checkout themselves. Many AI companies are betting on it. That includes Meta, which launched its personal agent Muse last month. The approach comes with obvious questions: what happens when software gets access to someone's money and is turned loose on the open web?

David Singleton, vice president of engineering and consumer products at Meta Superintelligence Labs, described the effort to CNBC as defining "rails" that personal and business agents can share. He compared it to email, which works because everyone uses the same standard to reach each other.

Taylor was more direct. He told CNBC there "will be chaos until such a standard exists" that gives retailers visibility into what personal agents do on their sites. Taylor also chairs OpenAI Group PBC, and he said he expects OpenAI to support the standard later on.

The banks asked first

The timing looks like a response to pressure from the financial sector. Last month, six major banks, including Bank of America and Capital One, published a paper asking the AI industry to set out standards, policies and consumer protections. Their framework rests on five principles: transparency, safety, privacy and data, choice and interoperability.

The banks laid out specific worries:

  • Fraud and disputes. Wider agent adoption could bring more scams, fraud and contested transactions.
  • Conflicts of interest. Agents might favor certain products or payment methods because of incentives such as higher commissions, not because they serve the user best.

Muse is under scrutiny

Meta has a direct stake in agentic commerce, and its own product has given critics plenty to work with. Muse quickly became one of the most downloaded apps in Apple's App Store. On Monday, however, 404 Media reported that Meta engineers had to rush to fix several serious security vulnerabilities before launch. Researchers have since raised further privacy and security concerns, and questions about private messages have followed the agent since its debut.

Amazon has banned Muse from its retail platform. The company said the agents did not identify themselves, which raised concerns about how they would handle customers' account data and credentials. This week, Wired reported that Muse builds profiles of every person in a user's life, including people who have never used the app.

The commercial upside is large. A Citigroup report published this week estimated that Muse could bring Meta more than $27 billion in revenue by the end of the decade, as the company tries to become the "front door" to online shopping. Singleton said Meta hopes the standard will make commerce agents easier for consumers to adopt, trust and use.

Our Take

The Amazon ban is the clearest sign of what this protocol is really for. It addresses the problem of agents that won't say who they are. A shared identity and authorization layer could give retailers a reason to let agents in rather than block them. That matters as more platforms push agents into checkout, from TikTok's one-click shopping assistant to Meta's own efforts.

Readers should keep the source of this standard in mind. It comes from companies that profit from agent purchases, and the banks' concern about commission-driven choices is not something an authentication spec can solve on its own. Several things are worth watching: whether OpenAI actually signs on, whether Amazon engages, and whether the protocol reflects the banks' five principles or only the parts that suit merchants.