Meta — the same company that suppressed the Hunter Biden laptop story and handed Americans' data to intelligence agencies — is now leading a coalition to write the industry rules for how AI agents handle your money online.
The initiative, called the "Personal Agent Protocol," would define how personal AI bots authenticate with businesses, what permissions they get, and what companies can see about what they're doing. Sierra co-founder Bret Taylor, who also chairs OpenAI, is leading the effort. Meta vice president of engineering David Singleton told CNBC the group is "defining rails that we hope personal agents and business agents can run over for the future," comparing it to email standards. Partners include Walmart, Stripe, Shopify, Genesys, Instinct, and Rocket. A v0.1 specification is due this month.
The stake for ordinary Americans is straightforward: whoever writes the protocol controls how AI agents access your bank account, your credit cards, and your shopping history. And the outfit volunteering to write those rules has a track record of abusing trust.
Meta's own personal AI agent, Muse, launched just four weeks ago and has already been a privacy disaster. According to Gizmodo, 404 Media reported that Meta engineers worked overtime to patch "multiple severe security vulnerabilities" before launch — and researchers still found problems after. Amazon locked Muse agents out of its platform entirely over concerns about how the agent handled customer credentials. Wired reported this week that Muse creates and updates "a page for every person in the user's life" hourly.
This is the company that wants to set the standard for safe agentic commerce.
The protocol uses OAuth sessions, letting agents start as guests and escalate to read-only or write access once a customer signs in. The business decides whether the agent works through its website, its APIs, or an agent of its own. Notably, payments are listed as a "future extension" — not part of the first specification. TNW reported that Sierra explicitly deferred payments, in part because Europe's strong customer authentication rules were written for humans approving specific transactions, not software acting on someone's behalf.
There is already a rival standard. Visa's "Trusted Agent Protocol," announced in June, plugs agents into roughly 175 million merchants. Microsoft, Stripe, Shopify, and Worldpay signed on. Stripe and Shopify are now straddling both camps — hedging their bets while two tech giants fight to control the rails.
Six major global banks, including Capital One and Bank of America, issued a paper last month warning that agentic commerce could increase scams, fraud, and disputes. They flagged the obvious conflict: agents could prioritize products or payment methods based on higher commissions rather than what the customer actually needs. The banks called for industry-wide standards around transparency, safety, privacy, choice, and interoperability before agentic commerce goes mainstream.
Gizmodo highlighted those bank warnings and Muse's security problems. TNW focused on the technical architecture and the competing Visa standard. The Verge offered a brief summary that buried the privacy concerns entirely.
The question isn't whether agentic commerce needs rules. It's whether the people who spent a decade censoring Americans and vacuuming up their data should be the ones writing them.








