On October 6, 2026, Meta and Sierra, together with six companies including Walmart, Stripe, Shopify, and Rocket, released the Personal Agent Protocol (PAP). This is the first time major technology companies have jointly released an industry standard focused on the issue of "trusted identity" for AI agents.
Factual Reconstruction
According to a report by tech.yahoo.com, Bret Taylor said that companies currently have no reliable way to determine whether a visitor is an AI agent or a human user, and that "until standards emerge, it is chaos." David Singleton pointed out that consumers need to provide agents with sensitive financial and personal data, so governance mechanisms are indispensable. He compared the protocol to email: "It works because everyone can communicate with each other using the same standard."
The report also mentioned that Amazon had previously blocked Meta's Muse agent from access, citing concerns about website scraping. A similar situation occurred with Perplexity's agent, and Amazon filed a lawsuit over it.
Mechanism Breakdown
The core of PAP is OAuth-based tiered identity authentication, which allows personal AI agents to obtain different permission levels—"visitor/read-only/write"—when interacting with businesses. This directly responds to companies' need for visibility into agent behavior, enabling platforms to track the specific operations agents perform on behalf of real users.
The launch of the protocol echoes the usage scenarios of Meta's Muse agent, which already has millions of users, with users using agents to complete daily tasks such as registering for events and finding gifts. The protocol is intended to make these operations faster and smoother.
Industry Impact
The participation of six founding partners shows the urgent demand in retail and payments for agent identity standards. If widely adopted, the protocol could reduce friction when businesses interact with AI agents while providing a technical reference for regulatory discussions.
OpenAI and Anthropic are not currently participating, but Taylor said he looks forward to them joining and that he would be "very disappointed" if competitors do not adopt it.
Strategic Assessment
[Analysis] From the perspective of WDCD compliance evaluation, agent identity standardization directly addresses the core question of "whether an agent is authorized to do this," and is highly compatible with the evaluation framework. The protocol's launch comes at a time when discussions on agent regulation in Europe and the United States are heating up, and it may become an important node in the transition of AI agents from feature implementation to a trust system. The future competitive landscape may revolve around the speed of protocol adoption, but the specific direction still needs to be observed through the actual responses of various parties.
© 2026 Winzheng.com 赢政天下 | 转载请注明来源并附原文链接