The past few weeks have seen the AI fight pivot to personal agents. SpaceX’s Grok Bot arrived in August, Meta followed with Muse in early September, OpenAI has been building toward an agent of its own, and newer names like Instinct have emerged alongside them. Each of these agents shows up at a business carrying some version of the same credential, the say-so of the person who sent it, and for most of September the market ran on the assumption that this was enough. The user approved the task, the agent held the login, and the booking or the purchase or the cancellation would go through. Amazon ended that assumption on September 20, when it told customers that Muse would no longer be allowed to shop for them. The user’s yes had met a second party with a vote.
The block and the privacy worry are the same problem seen from two ends. Amazon’s objection was that Muse moved through account pages and purchase history without identifying itself, which the company described to GeekWire as an undisclosed third party in customer accounts. Users are arriving at the same discomfort from the other side. Wired reported that Muse builds profiles of everyone in a user’s life, including people who never signed up, 404 Media reported that Meta raced to close security holes just before launch, and Business Insider found early adopters deleting their agents after privacy scares. The person deciding what to hand an agent and the business deciding whether to let it in are asking one question, which is who else is in the room once the agent is. Neither has a good way to answer it yet.
Four stories this week sit on one side or the other of that door. They are not the same fight. Two concern how an agent gets in, one concerns what the person sees once it has, and one runs in the opposite direction, a platform charging for the way out. What connects them is the gap between permission and admission. In each case the user grants the first and somebody else controls the second.
Meta and Sierra draft the handshake and leave the veto with the business
Source: SiliconANGLE, October 6, 2026
Meta and Sierra announced the Personal Agent Protocol, described as an open standard for how personal agents interact with businesses, with Genesys, Instinct, Rocket, Shopify, Stripe and Walmart as partners. The announcement lays out the mechanics. An agent discovers what a company offers from its website and opens a session, first as a guest and then, when a task needs account access, through a sign-in the customer controls, with read-only or write permission. Sessions run on OAuth. The company chooses whether the agent works through its web pages, its APIs or an agent of its own. The first written draft, a v0.1 specification, is promised later this month.
The timing follows a refusal. Amazon blocked Muse from its marketplace within two weeks of the agent’s launch, saying it did not identify itself as an agent as Amazon’s terms require and that it could move through account pages and purchase history. Amazon’s statement asked that such agents “respect service provider decisions about whether or not to participate.” The legal footing for that refusal is less settled than the statement suggests. In August the Ninth Circuit vacated the preliminary injunction Amazon had won against Perplexity’s Comet shopping agent, finding Amazon unlikely to prove a federal anti-hacking violation because it was users, not Perplexity, who accessed Amazon’s systems. The suit continues on remand, and Amazon’s terms still require agents to identify themselves.
Why it matters
The protocol proposes an answer to the question Amazon raised, and the answer leans Amazon’s way. Sierra’s own summary is that consumers decide what access to give their agents and “companies set parameters for what those agents can do.” Among participants, consent from the user is required and not sufficient. The business decides which routes exist, what a guest can see, and what a signed-in agent may change. What the outline does not address is the case that started the fight, a user-authorized agent at a business that has not joined and does not want it there. The Ninth Circuit’s reasoning treats that agent as the user’s tool. Amazon’s block treats it as an unwelcome third party. The protocol gives willing parties a way around that argument and leaves the argument itself open.
Meta is the company that got turned away, and its response was to co-author a handshake with merchants in which the merchant holds the stronger hand. It is a trade. Meta sets aside the claim that user permission should be enough, a claim the Ninth Circuit had just given some weight, and in return it gets a door that opens on published terms instead of a block notice. Amazon, the one party that has exercised the veto against a popular agent, is not on the list. For now the protocol is a statement of who is willing to be let in on someone else’s conditions.
ChatGPT starts building the interface inside the answer
Source: TechCrunch, October 7, 2026
OpenAI rolled out GPT-6 in ChatGPT with a feature it calls Intelligent UI. Answers can now arrive as working interfaces, with tappable buttons, task-specific calculators, interactive charts and editable graphs composed alongside the text. TechCrunch reports the rollout began Wednesday for Plus, Pro, Business and Enterprise users and reaches the free and Go tiers Thursday, and that users who want fewer visuals can dial them back.
OpenAI’s post says GPT-6 composes these answers from a library of native components it was trained to arrange. It puts ChatGPT’s audience at more than 1.2 billion people a week and says the goal over time is for software to adapt to people rather than the reverse.
Why it matters
The intermediary now controls presentation as well as discovery. Chatbots have offered images, tools and structured answers for some time, but the format was largely fixed, and the destination still owned the page where the task got finished. With a component library and a model trained to compose from it, more of that page gets assembled in the conversation, from parts OpenAI designed. One of the launch examples is a Sunday roast plan with photographs, a guest-count control that recalculates the shopping list, and a cooking timeline with checkboxes. That is a recipe page, and in the version OpenAI published no recipe publisher appears on it.
The limits are worth stating. The feature applies to the chat experience, the announcement says nothing about outside parties supplying components, and none of it shows that standalone applications are going away. What it does show is where the form of an answer is now decided. A business that passes the handshake in the first story still arrives inside a room someone else is drawing. Whoever composes the screen decides how a source looks, how much of it shows, and whether the person ever has a reason to leave.
Grok Bot keeps the user and rents the model
Source: The Next Web, October 7, 2026
Elon Musk said on X this week that Grok Bot, the agent app SpaceX’s AI unit launched in August, will no longer run only on the company’s own models. It will send tasks to outside ones including Anthropic’s Claude Opus 5.5, Midjourney and Suno, on the principle of “whatever is most likely to give you the best outcome.” The Next Web notes that Musk gave no detail on which jobs go to which supplier, and that the post came a day after users reported trouble reaching Grok. No commercial terms have been disclosed.
Why it matters
This is an announced strategy, sourced to one post, and it should be read at that weight. It does not show that back ends are interchangeable or that SpaceX has stopped caring about its own models. What it concedes is narrower and more useful. A company that has spent heavily on computing to train its own models has said in public that the thing it intends to keep is the Bot’s relationship with the person, and that the model behind any given task is a sourcing decision.
The consequence for rights holders sits one layer down. Musk named an image model and a music model alongside Claude, and nothing in the announcement says whether the Bot will tell its user which supplier made a picture or a song, or on what licensing terms that supplier operates. Routing does not have to erase provenance, but it adds a layer where provenance has to be carried forward on purpose, and the party the user deals with is now the agent, not the model.
Meta puts a monthly price on the outbound link
Source: Press Gazette, October 7, 2026
Meta is testing a limit of two free external links a month for selected Facebook pages and professional profiles, as part of the Meta One subscription it announced in September. Press Gazette reports the trial pricing as $49.99 a month for eight links, $149.99 for 20 and $499.99 for unlimited. Links in comments count toward the cap, which closes the usual workaround, and URLs posted past the limit render as plain text. Links to other Meta properties, affiliate partner links and links inside ads are exempt.
News publishers are excluded for now, Press Gazette understands, as they were from a similar test late last year. Meta has not said how it defines a news publisher, and the outlet is aware of small publishers that have been told they hit the limit. Social media consultant Matt Navarra’s summary to the outlet was that “Meta owns the tap and now it’s putting a price on that tap.”
Why it matters
Set this beside the first story. In the same week, Meta asked merchants to recognize its agent at their doors and tested a tariff on the door out of its own platform. The two positions are consistent as long as you don’t expect symmetry. Every operator in this market wants free passage for its own agent and a priced or conditional passage through its own surface. Meta happens to be large enough to hold both positions in public at once.
The exemption list is the informative part. Links that stay inside Meta, links that pay Meta a commission and links that are bought as advertising pass freely. What gets metered is the unpaid referral, which for twenty years was the consideration platforms offered publishers in exchange for their content. The news carve-out softens that for one category without defining the category, and a carve-out that exists at the platform’s discretion is a setting. None of this is agent governance, and it should not be read as a forecast of it. It is the same platform instinct applied at a different gate, and it shows how readily access becomes a tier when one party holds the switch.
It also points at a question Muse users should be asking. The links that pay Meta a commission are the ones that travel freely. An agent built by a company whose business is advertising has an obvious incentive to sell placement inside it, whether or not Muse ever does. Six banks, Bank of America and Capital One among them, asked the industry for agent standards last month and named that risk directly, agents steering toward products or payment methods that carry higher commissions. Citigroup estimates Muse could bring Meta as much as $27 billion in revenue by the end of the decade, as the company pushes to become the front door to online shopping. An agent that can be sponsored is worth less to the person relying on it unless the sponsorship is disclosed and can be switched off, and nothing announced this week says how either would work.
Permission is not admission
These are four separate assertions of authority, not four stages of one transaction, and for media operators they add up to two roles at once. In the protocol’s terms a streaming service or a publisher with accounts is a business. It gets to set parameters, which means it should know what a guest agent may read, what a signed-in agent may do on a subscriber’s behalf, and what it wants recorded when that happens, before the protocol’s first written draft makes default choices for it. In the interface’s terms the same company is a supplier whose work may be rendered in a layout it did not design, with or without a route back. Building an in-house agent addresses neither role. An owned agent improves the experience inside your own property. It does nothing about being a guest in someone else’s.
For a subscription business, the account is where several of these claims currently meet. Identity, authorization, entitlements and the transaction record all run through it. An agent can summarize a show or restate a recipe without asking anyone. For controlled playback, a plan change or a purchase, it generally needs a session the business grants. That is where the operator still holds a lever, and it is where the terms should be written, including terms the user can read. The person who sent the agent is asking the same question from the other side, what it exposed and to whom, and an operator that can answer that plainly offers something a block notice does not.
Closing note
Meta and Sierra say they will publish the first written draft of the Personal Agent Protocol, a v0.1 specification, later this month, along with a reference implementation for developers. Three details in that document will say more than the announcement did. Whether a business that declines an agent has to give a reason the agent can pass back to its user. Whether the specification names a neutral home, or stays with the companies that wrote it. And whether the action-level permissions Sierra lists as a possible later extension arrive at all, since a subscription business needs more than read and write to tell browsing a catalog apart from acting on an account.
Outside the document, watch Amazon. It can join, publish terms of its own, or keep blocking, and each choice tells the other large destinations what refusal costs. Watch whether Meta ever defines the news publisher it has exempted. And watch whether OpenAI’s component library takes parts from anyone else.
User permission was the first thing the agent market built, because it was the easy half. The harder half is everyone else with a claim on the transaction, the business behind the door, the platform drawing the screen, the company paying for placement. This week several of them started writing down their conditions, and nobody has yet decided whose will prevail.





