The “Traffic Rules” for AI Shopping Are Here — but the Giants Haven't All Shown Up
On October 6, 2026, Sierra and Meta jointly unveiled the Personal Agent Protocol: an open standard defining how AI shopping agents prove their identity to merchants and what they're allowed to do. Walmart, Shopify and Stripe are in — but Amazon, OpenAI and Anthropic all stayed out. In this game of rule-making, the biggest test is whether the rivals come to the table.

On October 6, 2026, Bret Taylor's Sierra and Meta jointly published a proposal: the Personal Agent Protocol (PAP). It aims at something very concrete — an open standard for “AI agents shopping on people's behalf”: how an agent proves its identity to a merchant, what the merchant allows the agent to do, and at which point the user has to say yes.
The timing is worth a second look. PAP landed about a month after Meta's personal agent “Muse” launched. Muse went live on September 8, 2026, shot to the top of the App Store charts, and promised to shop, book travel, and negotiate bills on users' behalf, paying through Stripe's single-use virtual cards. Meta's order of operations: first get agents actually spending people's money and make the scenario real, then write the rules for the behavior. On the Sierra side, Bret Taylor was Facebook's CTO before founding Sierra — back then he helped build the “log in with Google / Facebook” identity system for the web, and now he wants to run the same play again in the agent era. He told CNBC: “It is kind of chaos until such a standard exists.”
One detail deserves attention: Muse pays through Stripe's single-use virtual cards — a fresh card number per transaction, dead after one use, so even a leak only compromises that single order. It's a pragmatic workaround for the knot of “agents must touch sensitive data”: don't deny the agent a card, give it one that works once with a locked limit. PAP tackles the same class of problem, extended from payment to the whole shopping flow: every sensitive action the agent takes happens somewhere the user can see — and revoke anytime.
What the protocol looks like: guest first, permissions after login
PAP's technical design is built on layered OAuth authorization, and the core idea is to treat the agent as a “person,” not a crawler. An agent can start as a guest doing read-only things — checking stock, reading return policies, comparing prices — without logging in and without touching your account. After the user logs in, the user decides whether the agent gets read-only or write access: whether it can actually place orders, pay, and modify them. A shopping session can also continue across channels: asking and comparing before login, then ordering and paying after, counts as a single visit.
For merchants, PAP offers three ways in: the agent goes through the website (the merchant's existing pages, no rebuild needed), through APIs (standard interfaces like MCP and OpenAPI), or gets handed off to the merchant's own agent. Three coexisting paths mean merchants don't face a forced either-or — no need to tear down the website to welcome agents, no need to hand the business to someone else's agent. The design also keeps one critical hook: identity authentication. A merchant can verify that the visitor is really a specific user's personal agent, not just any crawler wearing an agent costume to scrape data.
What this design really wants to kill is the wildest practice of the past: users handing their account passwords directly to an agent, which then goes to websites “pretending to be you.” In that model, leaked passwords, unauthorized orders, and mistaken bans are three landmines buried together. PAP flips it: users authorize a scope of capabilities (can look but not buy, how much it may spend), not the identity itself; the authorization can be revoked anytime, and every sensitive action the agent takes is recorded somewhere the user can see. It's the same old OAuth trick the “scan-to-log-in” flow has proven for years — applying it to agents is the natural next step.
Who's at the table, and who isn't
The founding partner list carries weight: Walmart, Shopify, Stripe, Rocket, Genesys, Instinct — plus NiCE and Decagon on Meta's list. Walmart is the world's largest retailer, Shopify powers millions of independent stores, Stripe handles payments — buy, sell, and pay are all covered at once. The telling detail: Stripe and Shopify are betting on both horses. Visa's Trusted Agent Protocol launched back in June, covering roughly 175 million merchants, and they're in on that too. The payments giants are hedging on the “agent shopping standard”: whichever side wins works, or better, a merger of the two.
But the no-shows deserve more attention: Amazon, OpenAI, Anthropic — none of them came. Amazon's stance is the toughest: in September it blocked Muse from accessing amazon.com over agent traffic, and earlier it sued Perplexity, accusing it of hidden agent scraping. Translation: the world's largest e-commerce platform currently chooses walls over talks. OpenAI and Anthropic hold the strongest general agent capabilities, and without them, any “personal agent” standard gets its representativeness discounted.
There are now two “agent shopping standards” on the table: Visa's Trusted Agent Protocol from June and this PAP from Sierra + Meta. Stripe and Shopify joining both is a vote with their feet: don't bet on one side, wait for a merger or a winner. Standards history has seen this movie before — the winner is never the first mover, but the one with the bigger ecosystem and the lower bar to join. For PAP, Walmart and Shopify are its biggest chips: with real transaction scenarios behind it, the standard isn't just paper.
The real bottleneck isn't technology — it's trust
Meta's David Singleton (former Stripe CTO) frames it from the security side: agents need sensitive information like credit card numbers to complete bookings and purchases; the protocol should give users visibility and control over that exchange — you know when the agent used your card, on which transaction, and you can revoke access anytime. Technically, OAuth handles this fine. The hard part is getting people to dare hand their card to an agent.
The data stings: only 3% of US adults trust AI agents to shop for them. In other words, PAP solves “how merchants trust agents,” while the bigger gap is on the other side — “how users trust agents.” Muse topping the App Store charts shows plenty of people are curious; but handing real-money purchase decisions to an agent is something most people aren't ready for. Standards can lower the bar for merchants to open their doors, but they can't fill the user trust gap — that has to be earned one uneventful real transaction at a time.
Interestingly, Muse hitting No. 1 a month after launch proves the demand for “let AI buy things for me” is real; yet the 3% trust figure shows a wall still stands between demand and trust. Protocols like PAP fix the supply side — making it safe for merchants to open the door. Trust on the demand side has to come from agents making fewer mistakes, with someone accountable when they do. Both are indispensable, and the protocol only solves half.
Trust has historical precedent. When mobile payments first appeared, nobody dared bind a bank card to a phone either — the fear was the same: money going out too easily, no way back. It was earned later through two things: ever-smoother experiences, and real compensation when things went wrong. Agent shopping is at the same starting line — Muse topping the charts proves the demand exists, 3% proves trust hasn't started. PAP fixes “merchants dare to open the door”; “users dare to walk in” still needs a run of uneventful transactions.
From wall-building to rule-making: is this the turning point?
Over the past year, the keywords of agent commerce were “everyone building their own walls”: platforms blocking agent access, suing scrapers, each building closed shopping agents. PAP's arrival is a turning-point signal — the industry is shifting from “fighting” to “talking,” from competing on muscle to competing on whose rules get adopted. Visa played its card in June, Sierra and Meta followed in October; the rule layer for agent payments is taking shape faster than many expected.
But a rule's value depends on whether rivals join — that's PAP's biggest uncertainty. Without Amazon, the world's largest product catalog sits outside the protocol; without OpenAI and Anthropic, the strongest agent capabilities sit outside it. A “common front door” joined only by “those willing to open it” is, however well-specified, only half a door. What to watch next: the v0.1 spec (due within October), followed by design workshops and reference implementations — and whether the Amazons move from wall-building to the negotiating table. Standards wars are never won by the prettiest spec, but by the most adopters.
Look one layer deeper, and each side's calculus is easy to read. Meta just pushed Muse to the top of the App Store a month ago — for an agent that shops everywhere on users' behalf, the biggest friction is each merchant's bans and distrust. PAP is road-building for Muse. Sierra, meanwhile, sells enterprise-grade agents to companies doing serious business; what they need isn't a wild agent that “can scrape a checkout page,” but a compliant one that can be audited and held accountable when things go wrong — PAP paves the road for its own customers. Different motives, same conclusion: for agent commerce to scale, it must move from “breaking into websites” to “being invited in.”
One easily overlooked angle: the real users of this protocol may not be today's consumers, but next year's developers. Once “agent ordering” has a standard identity layer, startups won't have to spend half their headcount outwitting anti-bot defenses. Every standardization of an “identity layer” in history — from OAuth login to Apple Pay's tokenized payments — unleashed a wave of app innovation. If PAP actually holds, what it could unleash is a new form of “one-person storefronts where agents handle sourcing and selling.” That's still early to call, but the direction is right: rules first, apps follow.
How vibe coders should read this
For people building agent apps, the implications are concrete. The old road for agents that pay, order, or book was a single one: write scrapers, simulate clicks, outwit anti-bot defenses — fragile and one ban away from dead. Once standards like PAP spread, you integrate with a standard identity and authorization layer instead — the agent carries the user's authorization token and places orders the way the merchant allows. That's an order of magnitude cleaner than scraping, and it means “can call APIs” will be worth more than “can dodge anti-bot.”
Concretely, three things are worth doing now. First, put the v0.1 spec on your reading list (due within October) and study how it defines authorization scopes — that's likely to become the lingua franca of agent ordering. Second, if your agent still uses wild paths like storing user passwords and simulating logins, start planning the migration: abstract payment and ordering into a “request authorization — execute — auditable” model so you can plug into PAP when it lands. Third, stop hardcoding API keys and passwords into agents — auditability and authorization will be table stakes, and wild paths become liabilities under the new standard.
Worth acting on now: the v0.1 spec is due within October, with design workshops and reference implementations to follow. If your agent app touches shopping, booking, or price comparison, learn how this identity layer works early. The first to benefit from a new standard are often indie developers — while the giants are still arguing at the negotiating table, vibe coders can already have the demo running.
Sources
Related articles

On October 8, 2026, Google Cloud launched the Gemini agent at Gemini at Work 2026: a universal agent for work that takes objectives, plans by itself, auto-selects between Gemini and Claude models per task, and introduces 'coworker agents' with their own email, calendar, and directory seat. Four judgments on why the second half of the agent race is about 'agents that feel like colleagues.'

On October 1, 2026, Microsoft AI shipped three voice models at once: MAI-Transcribe-2-Streaming (streaming transcription, #1 on Artificial Analysis for streaming accuracy at 2.5% WER, final transcript 0.13s after end of speech), MAI-Voice-2.1 (23 languages, one consistent voice across languages), and 2.1-Flash (45s of audio at ~150ms end-to-end). With listening and speaking covered, a voice agent on a pure-Microsoft stack can now complete a turn in under a second.

Traffic is moving from the search box to the AI answer box. A vibe coder ships a product in a week — and nobody finds it. This guide turns the SEO fundamentals (sitemaps, JSON-LD, Core Web Vitals) and the new AI-discovery toolkit (llms.txt, per-page Markdown versions, FAQ schema, agent-readable pricing and API docs) into a shippable 30-day checklist. The core judgment: how well you document sets your product's ceiling in the agent economy.