
Summary
AI agents are beginning to shop, book travel and manage bills on users’ behalf, yet anti-bot systems and unclear permissions can prevent them from completing tasks. Sierra and Meta are working with major technology and commerce companies on a Personal Agent Protocol, while parallel efforts are emerging around agent-enabled payments.
Agents are becoming execution layers
Consumer AI agents are moving into a phase that looks materially different from conventional chatbots. Meta’s Muse, ChatGPT’s Dots, Instinct and other personal agents are designed not merely to answer questions, but to take actions on a user’s behalf. Those actions can include searching for products, booking flights, making restaurant reservations, ordering groceries, arranging transportation and paying bills.
That shift is the foundation of what the industry often calls agentic commerce. Instead of navigating every page and form themselves, users describe an outcome and let an agent coordinate the steps across websites and applications. Hark’s recently released Hark Pro illustrates the direction. The service is available on the web and through mobile apps, and the company says it can purchase groceries, book cars, pay bills and refill a child’s lunch card. Its hardware products are not expected until 2027, but the software layer is already being offered.
The commercial challenge, however, is not simply whether an AI model can plan a sequence of actions. The agent also has to be recognized by the business on the other side, allowed to access the relevant information and given an appropriate level of authority when accounts, orders or payments are involved. Those mechanisms remain fragmented.
Anti-bot defenses make capability unreliable
A recent dispute involving Amazon and Meta’s Muse highlighted the problem. Amazon blocked Muse from its retail site, preventing the agent from browsing the product catalog or making purchases. The issue is not limited to one company or one agent. Users have reported similar failures on other retail websites, sometimes without knowing whether the merchant intended to restrict the agent.
Some blocks are deliberate. A business may want to control automated access, protect commercial data or limit transaction risk. Other failures can result from conventional anti-bot defenses designed to stop spam, scraping, credential abuse and malicious traffic. Such systems were generally built before authorized personal agents became a mainstream product category. They may have no reliable way to distinguish an assistant acting under a customer’s instruction from a bot attempting to evade security controls.
That uncertainty creates an unusual customer experience problem. When an agent cannot complete a task, the user may not know whether the retailer rejected the request, whether the agent lacked the right credentials or whether a routine security system misclassified the activity. TechCrunch reported complaints that Muse could not complete a purchase on Walmart’s website. Walmart said the restriction was not intentional and noted that it had partnered with Muse. The episode illustrates how a technical block can be interpreted as a commercial refusal even when that was not the merchant’s objective.
For agentic commerce to work at scale, websites need a consistent way to identify an authorized agent, understand whose interests it represents and determine what it may do. Agents and merchants also need to communicate failure states clearly. A generic error message is not enough when a task may involve a purchase, a cancellation or a change to an existing order.
Personal Agent Protocol focuses on identity and permission
Sierra and Meta are developing the Personal Agent Protocol with Genesys, Instinct, Rocket, Shopify, Stripe and Walmart. The companies have described it as an open standard for how personal agents authenticate with businesses and how businesses specify the actions those agents are allowed to perform. A version 0.1 specification is expected later this month, according to the source material.
A central design element is the use of OAuth-based sessions. An agent could begin as a guest, for example to check inventory or read a returns policy. After the customer signs in, the customer or the business could determine whether the agent receives read-only access or permission to perform write actions such as creating or changing an order.
This approach is important because “authenticated” should not automatically mean “fully authorized.” An agent may need to read product information without being able to purchase anything. It may be able to prepare an order but require a separate confirmation before submitting it. It might also be allowed to modify delivery details only within a defined session. Separating identity from permission gives businesses more room to apply risk controls.
The proposal also addresses continuity across channels. A user may ask a question before signing in and then make a change to an order after authentication. If those steps belong to the same visit, the business and the agent need a way to preserve context while maintaining an accurate record of when authorization was granted and what it covered.
Businesses would have several integration choices. An agent could work through the company’s website, use APIs built around standards such as MCP and OpenAPI, or interact with an agent operated by the business itself. That flexibility recognizes that companies have different technical architectures. A platform with mature APIs may prefer structured access, while another business may continue to rely primarily on its website.
Payments are not part of the initial core scope and are described as a future extension. That sequencing reflects the additional complexity of financial actions. A payment flow must address confirmation, authentication, refunds, disputes, fraud controls and the allocation of responsibility when an agent misunderstands an instruction.
A parallel standards race is emerging around payments
Sierra and Meta’s proposal is not the only effort to define how agents interact with businesses. Visa has been developing a Trusted Agent Protocol and has connected it with ChatGPT so that agents can transact across a large merchant network. Microsoft, Stripe, Shopify and Worldpay have also joined that effort.
Stripe and Shopify are now associated with both initiatives. Their participation illustrates the unsettled state of the market: there is clear demand for common infrastructure, but no single framework has yet become the default. The competing approaches may differ in their treatment of credentials, merchant interfaces, confirmation steps and liability.
For businesses, however, a successful agent payment is not simply a transaction that reaches an authorization endpoint. Several questions must be answered. Did the user authorize one purchase or a category of purchases over a period of time? Can the agent change the product, amount or delivery address? When is a new confirmation required? If the agent interprets an instruction incorrectly, which party is responsible? If a credential is compromised, how quickly can access be revoked and the affected activity investigated?
These questions are more difficult than in conventional e-commerce because an agent may browse multiple sites, handle several tasks at once and infer future actions from email, calendars or previous instructions. Greater automation increases the need for granular permissions and durable records. A long-lived login session with broad authority is unlikely to provide an adequate control model for higher-risk actions.
Wallets and custody systems face a new control problem
The rise of agentic commerce also has implications for payment wallets and custody infrastructure. A consumer agent may need access to stored payment credentials, account logins or one-time authorization tokens. The practical security questions include how credentials are isolated, how permissions are minimized, how approval policies are enforced, how activity is logged and how access is revoked.
Hark says its service stores card details and passwords in an encrypted vault that the company cannot see into. That kind of architecture may reduce exposure, but its real-world protection depends on key management, account recovery, device security and the controls used by connected websites. The fact that an agent can complete an action does not mean it should retain the same authority as the user indefinitely.
Institutional wallets and custody systems could face even more structured versions of the same issue. One agent might be allowed to read balances and invoices but not change a destination address. Another might be able to prepare a payment request while requiring a person or policy engine to approve final execution. Separating preparation, authorization and settlement may become a basic design requirement for agents interacting with financial systems.
The challenge is not unique to any one wallet provider. It is a question of how existing security and compliance controls can be expressed in a machine-readable way without making ordinary tasks unusably complex. The more valuable the asset or the more consequential the action, the more important it becomes to preserve clear approval boundaries and an auditable history.
Trust will determine whether the model scales
The competition in personal agents is expanding beyond model quality. Meta and Hark are shipping software that attempts to perform real-world tasks. Sierra and Meta are proposing a common language for agents and businesses. Visa is approaching the problem through a payment-network framework. Together, these efforts suggest that identity, authorization and interoperability may become as important as task planning.
The decisive question is not how many actions an agent can perform. It is whether each action occurs under a permission that is clear, revocable and verifiable. Websites need to separate legitimate, user-authorized agents from harmful automation. Users need visibility into what their agents are doing. Payment and custody providers need controls that balance convenience with authentication, monitoring and liability management.
If common rules emerge, agents could become a new interaction layer above websites, APIs and payment networks. Businesses would be able to state what an agent may access, users would be able to grant narrower permissions and service providers could record the chain of authorization behind a transaction.
If standards remain fragmented, or if agents cannot explain why a task failed and who is responsible, merchants and customers may continue to treat them as unpredictable automated traffic. The next phase of agentic commerce will therefore be determined less by whether agents can click through a website and more by whether the surrounding infrastructure can make their actions understandable, controlled and accountable.
Source: link