,

A Field Guide to Agent Protocols

On October 6, Meta and Sierra — Bret Taylor’s company — published the Personal Agent Protocol: an open standard for how your personal AI agent introduces itself to a business, proves it’s acting for you, and gets permission to act. Walmart, Shopify, and Stripe signed on as founding partners. It’s the latest entry in a…

On October 6, Meta and Sierra — Bret Taylor’s company — published the Personal Agent Protocol: an open standard for how your personal AI agent introduces itself to a business, proves it’s acting for you, and gets permission to act. Walmart, Shopify, and Stripe signed on as founding partners.

It’s the latest entry in a fast-growing list of agent protocols, and the list is getting confusing. MCP, A2A, ACP, AP2, UCP, PAP — a bowl of alphabet soup where every acronym claims to be the standard. Here’s the field guide: what each protocol does, who defines it, whether it’s public, and how much of the world actually uses it.

The protocols

Protocol What it connects Defined / supported by Public? Adoption
MCP (Model Context Protocol) Agent ↔ tools and data Anthropic; now under the Linux Foundation’s Agentic AI Foundation Yes, open spec Dominant — 97M+ monthly SDK downloads, 10,000+ servers, supported by every major model provider
A2A (Agent-to-Agent) Agent ↔ agent (discovery and delegation) Google; donated to the Linux Foundation Yes, open spec Growing — 150+ organizations including Microsoft, AWS, and SAP
Personal Agent Protocol Agent ↔ business (authentication and permissions) Meta + Sierra; founding partners include Walmart, Shopify, Stripe, Rocket, Genesys, Instinct Yes, open proposal Day zero — v0.1 spec due October 2026, reference implementation to follow
AP2 (Agent Payments Protocol) Agent payments Google Yes Early — payments-focused, built on verifiable digital credentials
UCP (Universal Commerce Protocol) End-to-end shopping journeys Google Yes Early — commerce-specific, aimed at AI shopping surfaces
Visa Trusted Agent Protocol Agent purchases Visa Open to network participants Live — agents can buy from roughly 175 million merchants
ACP (Agent Communication Protocol) Enterprise agent messaging IBM (BeeAI framework) Was open Folded into A2A under the Linux Foundation in 2025 — no longer a separate concern
ANP (Agent Network Protocol) Decentralized agent-to-agent Community Yes Niche — the choice of decentralization purists

How they’re different: capability sets, not wars

The most important thing to understand is that these protocols don’t compete. They do different jobs:

  • MCP answers: what tools and data can this agent touch?
  • A2A answers: how do agents find each other and hand off work?
  • Personal Agent Protocol answers: how does a business know this agent acts for a real customer — and what is it allowed to do?
  • AP2 / Visa answer: how does money move?

The “protocol wars” framing mispredicts. Nobody wins by beating MCP at tools or A2A at delegation. And “layers” overstates it too — these don’t form a strict stack where each depends on the one below. The accurate frame is capability sets with defined seams: they compose where they meet — the Personal Agent Protocol names MCP and OpenAPI as access pathways, and an agent reached over A2A gets to tools through MCP — but each stands on its own. The contested ground is commerce, where UCP, Visa, and the Personal Agent Protocol’s planned payments extension are all courting the same merchants. (Stripe and Shopify, notably, are in both the Visa and PAP camps.)

Who’s defining them — and why that matters

Follow the governance, not the press releases:

  • Foundation-governed (MCP, A2A under the Linux Foundation) gets broad trust and broad adoption. Nobody worries the spec will be weaponized against them.
  • Vendor-defined (Google’s AP2/UCP, Visa’s protocol) moves fast inside its own ecosystem and gets side-eyed outside it.
  • Consortium-defined (Meta + Sierra’s PAP) is the interesting middle: open for anyone to implement, but steered by its founders. Note the politics — Bret Taylor co-founded Sierra and chairs OpenAI’s board, yet OpenAI is conspicuously absent as a founding partner.

There’s also a regulatory signal worth watching: NIST launched an AI Agent Standards Initiative in February 2026. It isn’t minting a competing protocol; expect it to bless the existing open standards — which is exactly what makes foundation governance the safer long-term bet.

What this means for your enterprise

Four things I’d take to the architecture review:

1. Identity first. Strip away the acronyms and every one of these protocols is about identity and permission: who is this agent, who authorized it, what can it touch. Your agent IAM strategy is now as important as your human IAM — and most enterprises don’t have one.

2. Every protocol you expose is attack surface. I wrote recently about exposed MCP servers repeating the S3-bucket era. The Personal Agent Protocol’s tiered access — guest, read-only, write — is the right instinct, but as one commentator put it, it hands you a question most stores have never written down: what does “write access” actually mean at your business? Answer that before the spec answers it for you.

3. Don’t pick a winner; build to compose them. MCP for tool access, A2A for agent delegation, PAP-style authentication at the business boundary, and a payments rail where money moves. The enterprises that win will be protocol-agnostic with translation at the seams.

4. Kill the password-sharing. Today’s shopping agents sign in with the customer’s actual password — the worst habit in the ecosystem. PAP replaces that with OAuth on the business’s side: the agent never holds credentials it shouldn’t have. If your threat model still assumes every login is a human, it’s already out of date.

The bottom line

The agent economy needs plumbing before it needs genius. These protocols are the plumbing — identity, permission, discovery, payment — and they’re being laid right now, mostly in the open, mostly by consortia and foundations.

The question for your enterprise isn’t which agent to buy. It’s which protocols you’ll speak — and whether you’ll have an answer, before your customers’ agents start knocking, to what “write access” means at your front door.

Freshness disclosure: the protocol landscape moves monthly. The Personal Agent Protocol was a proposal at publication time (October 2026); check the spec status before making decisions on it.