I watched an AI agent finish a purchase before the buyer could read the terms, and you feel that small, cold shock of having control yanked away. The vendor treated the agent’s click as gospel, and the user was left asking who actually signed off. Personal agents are a freight train without a conductor.
I’ve covered tech standards long enough to know when platforms are racing to set the rules—and when they’re racing to own them. Meta, paired with Walmart, Stripe and AI startup Sierra, is trying to do both: publish a personal agent protocol that tells businesses how to recognize approved AI-driven purchases and how those agents should identify themselves.
Amazon locked Muse out—so merchants are already reacting
Amazon barred Meta’s Muse agents from shopping on its site after the agents failed to reveal their identity, raising alarms about credential handling and account security.
That move is the practical, immediate consequence of a new commercial actor: AI agents that can act on customers’ accounts. Meta’s Muse launched with agentic commerce features on Sept. 8 and instantly attracted scrutiny. Engineers reportedly raced to patch vulnerabilities before launch, and post‑launch research kept flagging privacy and security gaps.
You can feel the tension between speed and safety: companies want the convenience agents promise, while retailers and payment processors demand clear signals about who — or what — is transacting.
What is agentic commerce?
Agentic commerce is when software agents act on behalf of users to shop, pay, schedule, or negotiate—sometimes with full access to accounts and credentials. The upside is convenience; the downside is that a mistaken or malicious action can move real money or commit to services without an obvious human sign-off.
Walmart, Stripe and Sierra signed on—so who writes the rules?
Meta has recruited heavy hitters: Walmart and Stripe appear in discussions, and Sierra’s Bret Taylor is leading protocol formation.
Taylor—who also serves as OpenAI’s chairman—told CNBC that the industry will be “chaos until such a standard exists.” He wants a set of rails for personal and business agents, analogous to how email standards let systems interoperate. Meta frames the protocol as a way to give businesses the visibility they need to accept or reject agent-driven requests.
I’m watching who gets a seat at the table. When Meta helps author the protocol, it gains influence over an economy that could touch payments, retail, advertising and personal data flows.
How will personal agent protocol protect consumers?
Proposals from banks and industry groups focus on transparency, privacy, safety, choice and interoperability—principles that would let you see what an agent does and choose how much access you grant.
Last month, six major banks including Capital One and Bank of America published a paper urging industry-wide standards and consumer protections. Their argument: without guardrails, agentic commerce could raise scams, fraud and disputes, and agents might favor merchants or payment methods that pay higher commissions over customer needs.
Meta says standards will smooth adoption—but the risks are visible
Citigroup recently estimated Muse could generate roughly $27 billion (€25 billion) in revenue before 2030 if adoption accelerates.
That projection explains the urgency. If Muse or its competitors become the dominant way people shop online, merchants and platforms will want clear, machine-readable proof that a request came from an authorized personal agent—not a credential-stealing script.
But the path is rocky. Wired reported Muse builds hourly profiles for people in a user’s life; 404 Media and TechCrunch highlighted pre-launch fixes and ongoing privacy questions. Those are not abstract concerns: they are operational headaches for banks, retailers and payment networks.
Can Muse read private messages without permission?
Researchers and outlets have reported instances where Muse’s behaviors raised privacy flags. Meta has disputed some claims, and the company says it patched vulnerabilities, but the headlines show how quickly trust can fray when agents touch personal data.
Regulators, banks and merchants want visibility—here’s what that looks like
Major banks want protocols that give them audit trails, user consent records and predictable signaling so disputes and fraud can be triaged faster.
I expect the final protocol to include identity assertions from agents, scope-limited credential handoffs, and machine-readable consent records that merchants and banks can verify automatically. That’s not just good engineering; it’s the kind of documentation retailers need to avoid being liable for purchases they never intended to accept.
If implemented, these controls could make agents safer. If they’re written by platforms with commercial stakes, they might favor behaviors that benefit platform owners over end users.
Meta’s stake is obvious—Muse is a business play
Meta built Muse to be a personal assistant with commerce capability; merchants see both risk and opportunity.
Meta wants smoother agent commerce so more people use Muse to shop. That translates into data, transactions and new revenue channels. But when a platform writes the rules, the standards can shape competitive advantage as much as safety outcomes.
Muse has the power to be helpful—and it has shown the power to misstep. Muse is a loose cannon.
Standards matter because they define who gets to move money and why. You should expect a fight over those definitions, between platforms, banks, retailers and regulators. I’ll be watching which players push for strict visibility and which prefer lightweight signals that speed adoption at the cost of clarity.
Who ends up setting the protocol will decide whether agentic commerce becomes a secure utility or a new vector for scams—so which side of that bet are you on?