On October 6, 2026, Meta, Walmart, Stripe and Sierra published an open standard for how AI agents interact with businesses online. Bret Taylor — Sierra co-founder, OpenAI chairman — is leading it. The “personal agent protocol” answers a question businesses have been asking loudly: is this visitor an agent or a human, and if an agent, whose?

It is a big deal, and it arrived with friction already burning around it: Amazon blocking Meta’s Muse crawler, a lawsuit against Perplexity for disguising its bots. Identity chaos is real, and the new standard addresses it.

But read the coverage closely and notice what it does not contain. Nowhere in the protocol’s scope is the question: should this purchase proceed?

The stack is closing from the bottom

Map the announcements of the last six weeks and a pattern appears:

  • Identity. Web Bot Auth gives agents cryptographic identity (Ed25519 key pairs storefronts can verify).
  • Consent. The UCP census verified agentic-commerce capability on more than 17,000 storefronts.
  • Execution. Shopify Checkout WebMCP exposes cart, update and complete to agents as first-class tools.
  • Recognition. The personal agent protocol standardizes how businesses recognize and admit agents.

The largest commerce and AI companies on earth have now standardized, between them, everything an agent needs to transact. And every one of those protocols ends at the same place: an unverified star rating.

An agent that can prove who it is, hold a user’s consent, and execute payment can still be steered by a brushed rating, an expired-domain storefront, or a price that moved between consideration and checkout. The protocol makes the agent a verified actor in a marketplace whose evidence layer remains unaudited.

The missing layer is a ruleset, not a platform

The gap is not another company or consortium. It is a small, checkable set of conditions that should all be true before any autonomous checkout proceeds:

  1. The listing resolves to a stable identity with a fresh evidence snapshot.
  2. The review corpus passes authenticity filtering — no velocity anomalies, no brushing patterns.
  3. Composite trust meets the principal’s stated floor.
  4. The seller’s record is clean of unresolved counterfeit flags.
  5. The price sits within a consistency band of its trailing median.
  6. The storefront, for merchant-direct purchases, is agent-ready and non-decayed.
  7. No revocation or watch entry is in force.
  8. The decision itself is logged — verdict, evidence, spec version — before execution.

Failures should not be silent: a hard failure blocks, a soft one asks the principal. And a user’s blanket consent should never waive the evidence rules — consent answers permission, not truth.

We wrote it down

Today GoBuy is publishing that ruleset as an open, machine-readable specification — GPV-1, the Pre-Purchase Verification Specification — with normative rules, default thresholds, JSON schemas, and a reference implementation on our keyless MCP server (check_product_trust()).

It is deliberately modest in governance and aggressive in clarity: single maintainer, semantic versioning, no certification body, no conformance marks. It becomes a standard when implementations adopt it, not when a committee blesses it. The reference boilerplate — a secured shopping agent you can stand up in five minutes — follows this week.

The personal agent protocol standardized how businesses recognize agents. GPV-1 standardizes how agents recognize a good purchase. The stack needs both.

Read the spec: docs.gobuy.ai/standard — machine-readable form at docs.gobuy.ai/standard/v1.json.

Background: The Verification Gap — our September position paper on why agentic commerce needs an evidence layer.