On October 6, Meta and Sierra — Bret Taylor’s company — published the Personal Agent Protocol: an open standard for how your personal AI agent introduces itself to a business, proves it’s acting for you, and gets permission to act. Walmart, Shopify, and Stripe signed on as founding partners.
It’s the latest entry in a fast-growing list of agent protocols, and the list is getting confusing. MCP, A2A, ACP, AP2, UCP, PAP — a bowl of alphabet soup where every acronym claims to be the standard. Here’s the field guide: what each protocol does, who defines it, whether it’s public, and how much of the world actually uses it.
The protocols
| Protocol | What it connects | Defined / supported by | Public? | Adoption |
|---|---|---|---|---|
| MCP (Model Context Protocol) | Agent ↔ tools and data | Anthropic; now under the Linux Foundation’s Agentic AI Foundation | Yes, open spec | Dominant — 97M+ monthly SDK downloads, 10,000+ servers, supported by every major model provider |
| A2A (Agent-to-Agent) | Agent ↔ agent (discovery and delegation) | Google; donated to the Linux Foundation | Yes, open spec | Growing — 150+ organizations including Microsoft, AWS, and SAP |
| Personal Agent Protocol | Agent ↔ business (authentication and permissions) | Meta + Sierra; founding partners include Walmart, Shopify, Stripe, Rocket, Genesys, Instinct | Yes, open proposal | Day zero — v0.1 spec due October 2026, reference implementation to follow |
| AP2 (Agent Payments Protocol) | Agent payments | Yes | Early — payments-focused, built on verifiable digital credentials | |
| UCP (Universal Commerce Protocol) | End-to-end shopping journeys | Yes | Early — commerce-specific, aimed at AI shopping surfaces | |
| Visa Trusted Agent Protocol | Agent purchases | Visa | Open to network participants | Live — agents can buy from roughly 175 million merchants |
| ACP (Agent Communication Protocol) | Enterprise agent messaging | IBM (BeeAI framework) | Was open | Folded into A2A under the Linux Foundation in 2025 — no longer a separate concern |
| ANP (Agent Network Protocol) | Decentralized agent-to-agent | Community | Yes | Niche — the choice of decentralization purists |
How they’re different: capability sets, not wars
The most important thing to understand is that these protocols don’t compete. They do different jobs:
- MCP answers: what tools and data can this agent touch?
- A2A answers: how do agents find each other and hand off work?
- Personal Agent Protocol answers: how does a business know this agent acts for a real customer — and what is it allowed to do?
- AP2 / Visa answer: how does money move?
The “protocol wars” framing mispredicts. Nobody wins by beating MCP at tools or A2A at delegation. And “layers” overstates it too — these don’t form a strict stack where each depends on the one below. The accurate frame is capability sets with defined seams: they compose where they meet — the Personal Agent Protocol names MCP and OpenAPI as access pathways, and an agent reached over A2A gets to tools through MCP — but each stands on its own. The contested ground is commerce, where UCP, Visa, and the Personal Agent Protocol’s planned payments extension are all courting the same merchants. (Stripe and Shopify, notably, are in both the Visa and PAP camps.)
Who’s defining them — and why that matters
Follow the governance, not the press releases:
- Foundation-governed (MCP, A2A under the Linux Foundation) gets broad trust and broad adoption. Nobody worries the spec will be weaponized against them.
- Vendor-defined (Google’s AP2/UCP, Visa’s protocol) moves fast inside its own ecosystem and gets side-eyed outside it.
- Consortium-defined (Meta + Sierra’s PAP) is the interesting middle: open for anyone to implement, but steered by its founders. Note the politics — Bret Taylor co-founded Sierra and chairs OpenAI’s board, yet OpenAI is conspicuously absent as a founding partner.
There’s also a regulatory signal worth watching: NIST launched an AI Agent Standards Initiative in February 2026. It isn’t minting a competing protocol; expect it to bless the existing open standards — which is exactly what makes foundation governance the safer long-term bet.
What this means for your enterprise
Four things I’d take to the architecture review:
1. Identity first. Strip away the acronyms and every one of these protocols is about identity and permission: who is this agent, who authorized it, what can it touch. Your agent IAM strategy is now as important as your human IAM — and most enterprises don’t have one.
2. Every protocol you expose is attack surface. I wrote recently about exposed MCP servers repeating the S3-bucket era. The Personal Agent Protocol’s tiered access — guest, read-only, write — is the right instinct, but as one commentator put it, it hands you a question most stores have never written down: what does “write access” actually mean at your business? Answer that before the spec answers it for you.
3. Don’t pick a winner; build to compose them. MCP for tool access, A2A for agent delegation, PAP-style authentication at the business boundary, and a payments rail where money moves. The enterprises that win will be protocol-agnostic with translation at the seams.
4. Kill the password-sharing. Today’s shopping agents sign in with the customer’s actual password — the worst habit in the ecosystem. PAP replaces that with OAuth on the business’s side: the agent never holds credentials it shouldn’t have. If your threat model still assumes every login is a human, it’s already out of date.
The bottom line
The agent economy needs plumbing before it needs genius. These protocols are the plumbing — identity, permission, discovery, payment — and they’re being laid right now, mostly in the open, mostly by consortia and foundations.
The question for your enterprise isn’t which agent to buy. It’s which protocols you’ll speak — and whether you’ll have an answer, before your customers’ agents start knocking, to what “write access” means at your front door.
Freshness disclosure: the protocol landscape moves monthly. The Personal Agent Protocol was a proposal at publication time (October 2026); check the spec status before making decisions on it.