Unregulated AI shopping bots have created a specific problem for online retailers: automated agents placing orders, hoarding inventory, or exceeding buyer purchase limits without any reliable way for merchants to tell whether a real person authorized the transaction. An open standard announced by Meta, Sierra, Genesys, Instinct, Rocket, Shopify, Stripe and Walmart attempts to fix that at the protocol level.
The standard is called the Personal Agent Protocol. It is designed to govern the handshake rules between a user's AI agent—a shopping assistant acting on their behalf—and a merchant's systems. Sierra, which co-developed the standard, says version 0.1 and a reference implementation will be published later this month. The full technical specification is not yet publicly available.
For online merchants and consumers, the protocol introduces identity and authorization rules intended to prevent autonomous AI bots from triggering accidental purchases or inventory hoarding. Retailers who implement the standard would be able to distinguish legitimate AI agents acting for verified users from scraping bots. Consumers would gain controls to set automated spending limits and define what their agents are authorized to do on their behalf.
Merchants evaluating adoption should note that Sierra has described businesses as free to route agent communications through their own websites, APIs, or their own agent implementations—no single platform is designated as a required transport layer.
Related context on how AI agents are acquiring permissions across commercial platforms is in Karmactive's comparison of [OpenAI Dots and Meta Muse](https://www.karmactive.com/openai-dots-vs-meta-muse-ai-agents-app-permissions/), and reporting on [AI agent security incidents](https://www.karmactive.com/openai-anthropic-ai-agent-security-incidents-2026/) covers the documented risks of poorly governed agentic access.
How does the Personal Agent Protocol protect users from unauthorized purchases?
The protocol is designed to require identity verification and explicit user-defined authorization parameters for agent-initiated transactions, preventing bots from acting without verified account-holder approval. The full technical specification will be published by Sierra later this month, at which point the exact mechanism can be confirmed.
A timeline for merchant adoption has not been published.
(function () {
var btn = document.getElementById('karmactivePushBtn');
var status = document.getElementById('karmactivePushStatus');
if (!btn) return;
function setStatus(msg) {
if (status) status.textContent = msg;
}
function fallback() {
setStatus('Push notifications are not supported in this browser. Try the email option above.');
}
btn.addEventListener('click', function () {
try {
/* OneSignal v16+ deferred SDK */
if (window.OneSignalDeferred && Array.isArray(window.OneSignalDeferred)) {
setStatus('Opening notification prompt...');
window.OneSignalDeferred.push(function (OneSignal) {
if (OneSignal && OneSignal.Notifications && typeof OneSignal.Notifications.requestPermission === 'function') {
OneSignal.Notifications.requestPermission()
.then(function () {
setStatus('You will receive push notifications when new articles are published.');
})
.catch(fallback);
} else {
fallback();
}
});
return;
}
/* OneSignal direct object */
if (window.OneSignal && OneSignal.Notifications && typeof OneSignal.Notifications.requestPermission === 'function') {
OneSignal.Notifications.requestPermission()
.then(function () {
setStatus('You will receive push notifications when new articles are published.');
})
.catch(fallback);
return;
}
/* Older OneSignal SDK */
if (window.OneSignal && typeof OneSignal.push === 'function') {
setStatus('Opening notification prompt...');
OneSignal.push(function () {
if (typeof OneSignal.showSlidedownPrompt === 'function') {
OneSignal.showSlidedownPrompt();
} else {
fallback();
}
});
return;
}
fallback();
} catch (e) {
fallback();
}
});
})();