Skip to content

AI Governance

Customers' AI agents are starting to show up at your business. Here is what to decide before the standard arrives.

On October 6, 2026, Sierra and Meta announced Personal Agent Protocol, an open standard still being written, for how a customer's personal AI agent connects to a business. The direct answer for an owner: you do not need to adopt anything yet, because the specification is not out. But the underlying question is already live. When an AI agent acts for your customer, what should it be allowed to see and do?

By Fabio Rabelo · Founder, ATLACIS ·

What happened

Sierra, the enterprise AI company co-founded by Bret Taylor, announced Personal Agent Protocol on October 6, 2026. Sierra says Meta and Sierra are developing it with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. It is described as open for anyone to implement. The problem Sierra describes is simple. Most personal agents use websites the way a person does: loading pages and clicking through forms. When that fails, they may call the support line or open the web chat. A direct, authenticated connection could do the same job faster. As Sierra describes the design, the customer decides what access their agent gets, and the company sets what the agent may do. The agent can start as a guest, for example to check stock or a returns policy. For account access, the customer signs in and chooses read-only or write access. Sessions are built on OAuth, an established authorization standard. The company then chooses the route: its website, its APIs through standards such as MCP and OpenAPI, or an agent of its own. A version 0.1 specification is planned for later in October. Sierra lists finer permissions, push notifications, and payments as possible future additions. Meta's Muse agent is the consumer context. CNBC reports that OpenAI and Anthropic are not participating now, though Taylor said he expects them to join.

Why it matters for business owners

Most AI advice for owners is about the agents you deploy. This is about the agents other people deploy at you. CNBC reports that Muse has millions of users in the US and that Amazon has blocked Meta's agents over scraping worries. Whatever you think of that dispute, it shows the direction. Customers will send software to book, return, ask, and buy on their behalf, and some of it will reach your site whether or not you planned for it. Taylor put the business risk plainly to CNBC: you do not want a random bot that is not acting for a person to have access to your service. The harder part is that, today, most companies cannot tell which kind of visitor they have.

What owners should not misunderstand

Do not read this as a finished standard. It is an announcement and a plan. There is no published specification, and the future additions, including payments, are not part of the first version. Do not assume it covers everyone. OpenAI and Anthropic are not on board at announcement, and other agent standards exist in the market. Several partners are in more than one effort. You may end up supporting more than one, or none. Do not assume it is neutral yet. The people writing it also sell agent products. That is normal for early standards, and Sierra says it welcomes other partners, but it is a reason to wait for the specification and see who governs it. And do not assume a standard removes your decisions. It gives you a way to recognize and limit an agent. What you allow is still yours to decide.

The operational lesson

Access is a business decision, not a technical default. If an outside agent can read your order status, change a booking, or start a return, someone in your company should have decided that on purpose. Right now, for most businesses, those things are decided by accident: whatever your website and support team happen to allow. The protocol Sierra describes puts the choice with the company, which is the right place for it. But that only helps owners who know their own answer. Which actions are safe for an automated visitor? Which need a human? Which should never be offered at all?

What a serious business should do next

Start with a short, plain list of what customers can do with you: check status, change an order, request a refund, update account details, buy. Mark each one as fine for an automated agent, human only, or not sure. Then look at what you can already see. Can your team tell an automated visit from a person in your logs or support tickets? If not, that is the gap to note. Ask your website, e-commerce, and support vendors one question in writing: what is your plan for customers' AI agents, and what controls will we have? Their answers will tell you whether you will be given choices or defaults. Then wait for the v0.1 specification before building anything. If you do not run an online storefront or customer accounts, this may be a watch item for now, not a project. Nothing here is legal or security advice. If agents would touch payments or personal data, involve the people who own those areas.

The Atlacis view

Atlacis helps owners slow down before an AI decision, map the workflow and the risk, and choose the simplest setup that fits. Standards like this one are a good reason to do the mapping first. A protocol can carry a request. It cannot tell you which requests your business should say yes to. If you want help working out where outside agents fit in your customer workflows, and where they do not, that is a good conversation to have before any build.

The short version

  • On October 6, 2026, Sierra and Meta announced Personal Agent Protocol, a draft open standard for how customers' AI agents interact with businesses. A v0.1 specification is planned for later in October.
  • As described, customers set what access their agent has, and companies set what agents may do, through their website, APIs, or an agent of their own.
  • It is not finished, not yet backed by OpenAI or Anthropic, and written by companies that also sell agents. Wait for the specification before building.
  • The decision that is yours now: which customer actions an outside agent may take, which need a person, and which you do not offer.
Tags:AI agentsAI governanceAI access controlcustomer experienceMetabusiness AI
FAQ

Common questions

Do I need to do anything about Personal Agent Protocol now?
Probably not beyond awareness. The specification is not published yet. The useful step today is deciding which customer actions you would allow an automated agent to take, and asking your website and support vendors about their plans.
What is Personal Agent Protocol?
It is an open standard Sierra and Meta are developing with partners including Shopify, Stripe, and Walmart. It aims to handle authentication and give companies visibility into what customers' personal AI agents do through their websites, APIs, or company agents.
Will this let AI agents make payments at my business?
Not in the first version, according to Sierra. Payments are listed as a possible future extension, along with finer permissions and push notifications.

Make better AI decisions, starting with one call.

Book a free AI Fit Call. We will tell you what to use, what to avoid, and where to start. No jargon, no pressure.