AI Agents Will Soon Shop for You. Only 3% Trust Them.
On 6 October, Meta and the AI company Sierra published something that sounds dull and is not: an open standard for letting AI agents log into businesses and act on your behalf. The founding partners include Walmart, Shopify and Stripe.
Walmart owns Flipkart. Flipkart’s Big Billion Days opens in two days. And Google is already testing a Buy button inside Gemini in India, with a wider rollout promised for later this month, deliberately timed to the festive season.
So this is not a distant Silicon Valley story. The plumbing for AI agents that shop for you is being laid in India right now. Here is what it does, and the one number that should make you slow down.
Table of Contents
What the protocol lets AI agents do
The standard is called the Personal Agent Protocol, and it is built on OAuth — the same mechanism behind every “Sign in with Google” button you have ever tapped.
That comparison is the clearest way to understand it. Today, when you log into a site with Google, you grant a limited, revocable permission. The protocol does the same thing for AI agents: it gives them a way to identify themselves to a business, state what they are trying to do, and be granted a specific level of access.
The permission levels run roughly like this:
| Permission level | What AI agents can do | Risk to you |
|---|---|---|
| Guest access | Check availability, look up policies, read public information. No account needed. | Minimal |
| Signed-in, read-only | See your orders and account details, but change nothing. | Privacy only |
| Signed-in, write access | Place an order, change a booking, cancel something. | Your money |
Businesses can plug in through their website, through an API, or by handing off to their own company agent. A v0.1 specification is promised later this month, with a reference implementation to follow.
In plain terms: the industry is agreeing on how AI agents prove who they are and what they are allowed to do. That is genuinely necessary work. You cannot have them buying things without it.
Why India is where this gets real first
Three things are converging here, and the timing is not an accident.
Walmart is a founding partner, and Walmart owns Flipkart. Whatever this standard enables, India’s second-largest e-commerce platform sits inside the coalition building it.
Google is already running the experiment. Gemini and AI Mode in India show a Buy button on some Flipkart listings — currently smartphones, electronics and mobile accessories, for a limited set of users. Tapping it opens a Flipkart-branded checkout without leaving the AI. Google has said it intends to widen this later in October, ahead of the festive season. We looked at that test in detail when it first appeared.
The festive sale is the perfect testing ground. Millions of people making price-sensitive decisions across thousands of listings in a few days is exactly the problem these systems are supposed to solve.
India is not an afterthought in this. It is arguably the live pilot.
The number nobody puts on the slide
Here is the part the press releases leave out.
Surveys of US adults put trust in AI agents completing a purchase at around 3%. Among people who already use AI tools regularly, about a third say they would never let software shop for them at all.
Read that next to the partner list. Walmart, Shopify, Stripe and Meta are building rails for a behaviour that almost nobody currently wants. That is not necessarily wrong — plenty of technologies were built before demand existed, and UPI itself looked unnecessary to most Indians in 2016. But it does reframe the announcement. This is infrastructure betting on a future, not a response to users asking for something.
And the trust number is not irrational. The thing you are being asked to delegate is spending your money, to a system that cannot be fully explained, on a platform that profits from you spending more.
What could go wrong when AI agents spend for you
Four things worth thinking about before you grant anything write access.
The incentives may not be yours. An assistant built by a company that earns commission on a sale is not a neutral shopping companion. Sponsored placement inside AI answers is already arriving. Ask who pays for the agent before trusting what it recommends.
Write access is a big step. Read-only is a research tool. Write access means something can commit your money without you looking at the screen at the moment of purchase. The gap between those two permissions is much larger than one word suggests.
Errors become harder to unwind. If you buy the wrong thing yourself, you know what happened. If an agent bought it, you are reconstructing a decision you did not make, and the dispute process is not yet designed for that question.
The “universal” standard is not universal yet. Amazon, OpenAI and Anthropic are not in the founding group. A standard missing the largest retailer and two of the largest AI companies is a proposal, not a settlement. Expect competing approaches before anything converges.
Where AI agents would genuinely earn their place
None of this means the idea is bad. There are real jobs these systems could do well, and they mostly sit on the read-only side of the line.
- Comparing honestly across platforms. Checking one product across Flipkart, Amazon and a price-history tracker is tedious, and software is good at tedious.
- Catching the fine print. Bank offer caps, exchange terms, delivery windows — the details buried in terms pages that cost people real money every festive season.
- Watching a price over time. Telling you a phone is at its genuine 30-day low rather than wearing a badge.
- Handling the aftermath. Returns, warranty claims, chasing a refund. Unglamorous work most people put off.
Notice that every one of those ends with you deciding. The useful version of this technology does the research and hands you the choice. The version being built towards is the one that also presses the button, and that is where the 3% lives.
What to do about it right now
Practically, today: nothing. There is no agent you need to set up and nothing to opt into. But three habits are worth forming before the choice arrives.
- Treat write access as a separate decision from read access. When a prompt offers both, it is one tap. The consequences are not comparable.
- Check what a recommendation costs the recommender. If an answer leads to a purchase and someone earns on it, that is a fact about the answer.
- Keep doing the arithmetic yourself on big purchases. Our notes on UPI versus card offers and on what box MRP does to a discount are exactly the kind of judgement no agent can yet be trusted to make for you.
If you are shopping this week, our running list of Big Billion Days phone deals is the human version.
The Honest Fine Print
The 3% trust figure for AI agents is US data. We have not found an equivalent Indian survey. Indian attitudes to new payment technology have historically been far more willing than Western ones — UPI is the obvious example — so the Indian number could be considerably higher. Treat 3% as a signal about where the technology currently stands, not a prediction about Indian users.
The protocol is at version 0.1 and not published yet. The specification is promised “later this month”. We are describing an announcement, not a working system you can use.
Google’s Flipkart test is separate from this protocol. Google is not a founding partner here, and the technology behind its Buy button may be different. We have grouped them because they point the same direction, not because they are the same project.
We do not know how any of this will handle disputes. No announcement we have seen explains what happens when an agent buys the wrong thing. That is a genuine gap, not an oversight on our part.
Meta’s involvement is worth noting. A company whose business model is advertising is helping define how agents talk to merchants. That may be fine. It is also a thing to keep an eye on.
No affiliate links, no paid placement. We earn nothing from anything mentioned here.
Bottom Line
Meta, Walmart, Shopify and Stripe have agreed on how AI agents should identify themselves and be granted permission to act. It is sensible groundwork and it will probably matter.
But it arrives with Amazon, OpenAI and Anthropic outside the tent, a specification that has not been published, and a trust level of roughly 3%. The rails are being laid well ahead of the passengers.
For Indian buyers the practical advice this week is unchanged: use AI to research, read the offer terms yourself, and keep your finger on your own button. The moment worth paying attention to is not when AI agents offer to help you find a phone. It is when they offer to buy it.
FAQ
What are AI agents in shopping?
Assistants that can act on your behalf with a retailer — looking up products, checking your account, and in their fuller form placing orders — rather than just answering questions and leaving you to shop yourself.
What is the Personal Agent Protocol?
An open standard published on 6 October 2026 by Meta and Sierra, with Walmart, Shopify, Stripe, Genesys, Instinct and Rocket as partners. Built on OAuth, it defines how AI agents identify themselves to a business and what permissions they are granted. Version 0.1 is due later this month.
Can AI agents buy things for me in India today?
Not generally. Google is testing a Buy button on some Flipkart listings inside Gemini and AI Mode for a limited set of users, mostly on phones and electronics, with a wider rollout signalled for later in October. The Personal Agent Protocol itself is not live.
Is it safe to let AI agents make purchases?
That depends on permissions. Read-only access is low risk. Write access lets something commit your money without you seeing the screen at that moment, and dispute processes for agent-made purchases are not yet established. Around 3% of US adults say they trust AI agents to complete a purchase.
Which companies are not part of this standard?
Amazon, OpenAI and Anthropic are absent from the founding group. Their absence means the standard is a proposal rather than an industry settlement, and competing approaches are likely.
Does this affect the Big Billion Days or Great Indian Festival sales?
Not directly this year. The protocol is not live and Google’s Flipkart test reaches only some users. But the festive season is clearly the target for wider rollout, so expect more of it by next year.
How do I keep control if I use AI agents to shop?
Grant read-only access where possible, treat write access as a separate decision rather than part of the same prompt, check whether the recommender earns on the sale, and do the final price arithmetic yourself on anything expensive.
Sources: protocol details via Sierra, with analysis and the trust figures via Forkast; Google’s Flipkart test via TechCrunch. The specification was unpublished at the time of writing and details may change.