Meta and Sierra Propose AI Agent Rules: Customers Grant Access, Businesses Set Limits
The Personal Agent Protocol would connect agents through websites, software interfaces or business agents. Its first specification is planned for later in October.
Loading page…
The Personal Agent Protocol would connect agents through websites, software interfaces or business agents. Its first specification is planned for later in October.
Listen to this story
The Personal Agent Protocol proposes a common way for AI agents to act across business services, with authorization divided between the customer and each company. Customers would grant read-only or write access, while businesses define permitted actions and connection methods; the design uses OAuth and supports website, API, or business-agent routes. Meta and Sierra announced the proposal on October 6, 2026, but the first specification is still pending, so the rules and implementation details are not yet settled.
Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart are named partners; Sierra says any company will be able to implement the protocol.
The v0.1 specification, design workshops, and a reference implementation are planned for later in October.
Sierra says direct connections could avoid agents’ slow page navigation, but the announcement offers no performance test or measured results.
Meta and Sierra are developing shared rules for AI assistants acting on customers’ behalf, with authority split between the customer and the business. Announced October 6, 2026, the Personal Agent Protocol would let people authorize account access while companies decide what agents can do. The first specification is planned for later this month.
Genesys, Instinct, Rocket, Shopify, Stripe and Walmart are named partners. Sierra says the protocol will be open for anyone to implement, rather than reserved for the companies developing it. The announcement describes a proposed design, with the specification still to come.
Sierra’s design starts with an agent discovering what a company offers on its website and beginning a session for its user. A guest session could handle questions about product availability or returns. Account-specific tasks would require the customer to sign in or use credentials already configured with the personal agent.
The session would use OAuth, an established standard for authorizing access. Customers would choose read-only or write access. Businesses, meanwhile, would set the parameters for permitted actions and choose how agents connect. Customer authorization and business permission are separate parts of the proposed arrangement.
Sierra describes today’s workflow as agents loading pages, clicking forms and sometimes turning to support calls or web chat. It argues that a direct connection could complete tasks securely in seconds, avoiding slow navigation and failed attempts. That is the developers’ proposed benefit, not a reported performance test.
The session is designed to continue across channels and sign-in. A question asked as a guest and an order change made after authentication would remain part of the same visit, rather than becoming disconnected interactions.
Sierra co-founder Bret Taylor told CNBC the standard should help businesses distinguish agents representing people from unauthorized bots and see what those agents do. He said OpenAI and Anthropic were not participating, although he expected them to join. That expectation is not a commitment from either company.
The partners plan to publish the v0.1 specification later in October, hold design workshops and release a reference implementation to help developers get started. Sierra also identifies possible extensions: finer limits on individual actions, notifications about flight delays or shipped orders, and purchases without sharing credit-card information. Those are future possibilities, not confirmed features of the first specification.
Loading discussion...
Join the conversation
Explain where different rules would be justified.
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.