The Agentic Post
Breaking
Digital Twins and Physical AI  ·  Humanoid Robots in Manufacturing  ·  AI Data Centers and Water Usage  ·  The AI Chip Supply Chain, Explained  ·  What Is Fine-Tuning? A Plain Explainer  ·  Meta and Sierra Want to Give AI Agents a Front Door to Stores  ·  
Home/Business/Enterprise Adoption
Meta and Sierra Want to Give AI Agents a Front Door to Stores

Meta and Sierra Want to Give AI Agents a Front Door to Stores

Enterprise Adoption

Sierra and Meta launched the Personal Agent Protocol, an OAuth-based open standard for how personal AI agents sign in to businesses, backed by Walmart, Shopify and Stripe, with payments left for later.

Sierra and Meta announced the Personal Agent Protocol on October 6, 2026: an open standard for how personal AI agents sign in to businesses and what those businesses allow them to do. Founding partners are Walmart, Shopify, Stripe, Rocket, Genesys and Instinct. A v0.1 specification is due later in October. Payments are not in the first version.

What problem does it solve?

Right now an AI agent shopping for you mostly pretends to be you in a browser. The store cannot tell an agent from a person, cannot see what it is doing, and has no clean way to give it limited access. That is why Amazon blocked Meta’s Muse from its store and insists outside agents identify themselves. The protocol gives agents a front door instead of a disguise.

How does it work?

Sessions are built on OAuth, the same standard behind "Sign in with Google." An agent can start as a guest, checking stock or a returns policy without logging in. Once the customer signs in, they decide whether the agent gets read-only or write access. The session carries across channels, so a question asked before sign-in and an order changed afterwards count as one visit.

The business chooses how agents reach it: through its normal website, through its APIs using standards such as MCP and OpenAPI, or through an agent of its own that talks to yours. Sierra’s founders Bret Taylor and Clay Bavor framed the aim as handling authentication and showing companies what agents are actually doing on their sites.

What is missing?

The parts that matter most for shopping. Payments, push notifications and fine-grained permissions are all listed as future extensions rather than part of v0.1. So at launch an agent can authenticate and act, but the protocol does not yet govern how it pays. Meta’s Muse currently pays using saved cards through Stripe Link, outside this standard.

Europe is a specific gap. EU rules require strong customer authentication for payments, written for a person approving a named amount to a named payee, and there is no carve-out for software approving purchases on someone’s behalf. Stripe, with a Dublin headquarters, is the only partner with a European base, and no European retailer, bank or payment company has joined.

Is this a standards war?

It is shaping up as one. Visa already runs a rival, the Trusted Agent Protocol, which plugged into ChatGPT in June to let agents buy from about 175 million merchants, with Microsoft, Stripe, Shopify and Worldpay signed up. Stripe and Shopify are now in both. That is sensible hedging for them and a sign that nobody yet knows which standard wins.

For businesses, the practical takeaway is not to pick a side yet, but to start planning for agent traffic as a distinct kind of visitor: one you can identify, scope and log. The incidents we have covered, from agents that would not take no for an answer to OpenAI’s always-on Dots, all point the same way. Agents are arriving faster than the rules they will work under.

Read The Next Web’s report on the launch.

Up Next
Anthropic Opens Mythos to More Defenders in Three Tiers

Anthropic Opens Mythos to More Defenders in Three Tiers

AI Safety

Anthropic merged Project Glasswing into an expanded Cyber Verification Program with three access tiers, and said Glasswing partners found at least 129,000 verified vulnerabilities between April and July.

Anthropic expanded its Cyber Verification Program on October 6, 2026, merging it with Project Glasswing into a single programme with three access tiers. Each tier gives vetted security professionals fewer cyber blocks on Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1. Anthropic also disclosed that Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026, more than 33,000 of them rated critical or high severity.

Why do security teams need a special programme at all?

Because Anthropic’s public models deliberately block most cyber work. Cybersecurity is dual use: the steps that let a defender prove and patch a flaw are the same steps an attacker uses to exploit it. So the generally available versions of Opus 5.5, Fable 5.1 and Sonnet 5.5 refuse a lot of legitimate security tasks. The programme is how verified defenders get those blocks lifted, in proportion to how much they need.

What are the three tiers?

  • Defense Access: incident response, malware reverse-engineering, and validating vulnerabilities. Open to in-house security teams, critical infrastructure operators of any size such as regional hospitals or local utilities, smaller security firms, open-source maintainers, and individual researchers with a track record. Anthropic aims to answer applications within a few days.
  • Red Team Access: adds authorised penetration testing. Organisations only, review takes a few weeks, and applicants sit in Defense Access meanwhile. Actions that could cause physical harm or mass disruption, such as deploying ransomware, stay blocked.
  • Specialized Access: fewest blocks, for a small set of organisations authorised to test systems where failure could hurt people or disrupt markets, such as flight software, power grids, telecoms and interbank payments. Reviewed in collaboration with the US government. Existing Glasswing members move here automatically.

Do the tiers actually work?

Anthropic tested Opus 5.5 on CyScenarioBench, ten multi-stage cyber operation challenges, five attempts each per tier. Without the programme, every task was blocked on the first prompt. In Defense Access, 46 of 50 attempts were blocked at some point. In Red Team Access, nothing was blocked and Opus completed 34 of 50, matching its 67.6% success rate with no safeguards. That is Anthropic grading its own controls, but the spread between tiers is the behaviour you would want.

How credible are the 129,000 vulnerabilities?

Treat it as a lower bound with soft edges. The figure comes from survey data from 33 partner reports, Anthropic says the real number is likely at least five times higher, and fewer than half of partners disclosed how many flaws they had patched. Anthropic’s own open-source scanning found another 5,500 between April and October. The scale is plausible, and partners such as Booz Allen and Comcast have described months or years of work compressed, but the methodology is self-reported.

Is there a privacy catch?

Yes. Enrolled organisations must allow data retention so Anthropic can monitor for misuse, which is a real cost for teams handling sensitive incidents. Anthropic says a feature called Enterprise Frontier Safeguards, due later this fall, will let eligible organisations keep that data in cloud infrastructure they control. The programme runs on the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry, but on Amazon Bedrock only for customers eligible for that new feature.

The timing is pointed. Mistral launched Large 4 the same day, highlighting that Opus 5.5 scores near zero on one vulnerability test because it refuses. This is Anthropic’s answer: the capability exists, gated by verification rather than open weights. It extends the same logic as Google’s Fairwind programme, and lands a week after Microsoft warned that attackers now weaponise flaws in under 24 hours.

Apply or read the details in Anthropic’s announcement.