PAP as Third Protocol Stack Fragment — Governance Overlap and Identity as Lock-In Vector Sierra and Meta announced the Personal Agent Protocol (PAP) on October 6, 2026, a third protocol layer for AI agent infrastructure that adds OAuth-based identity and authentication governance on top of the Model Context Protocol (MCP) and A2A. PAP defines session permissions and three access tiers — guest, read-only, and write — and its founding partners include Walmart, Stripe, Shopify, Genesys, Rocket, and Instinct, while OpenAI and Anthropic were absent from that initial list. The PAP v0.1 specification, design workshops, and reference implementations are slated for late October 2026, and the protocol's centralized identity governance raises vendor lock-in concerns for builders whose agents must authenticate to reach enterprise systems. The emergence of the Personal Agent Protocol PAP signals a fundamental shift in AI infrastructure: the battle for the agent ecosystem is moving from raw capability to strategic gatekeeping. The New Protocol Triad The announcement of the Personal Agent Protocol PAP by Sierra and Meta on October 6, 2026, marks the formalization of a three-layer stack for AI agent infrastructure. While the industry has spent the last year focused on tool interoperability and agent-to-agent communication, PAP introduces a critical third pillar: identity and authentication governance. To understand the current landscape, one must view the stack as a functional hierarchy. At the base, the Model Context Protocol MCP https://forkast.news/glossary/model-context-protocol-mcp/ manages tool interoperability, boasting over 500 million monthly SDK downloads. Above it, A2A Agent-to-Agent protocols facilitate communication between autonomous entities, supported by over 150 organizations. PAP now sits as the governance layer, defining how personal agents authenticate with and interact with businesses. Governance Overlap and Fragmentation The introduction of PAP creates a complex governance overlap. Unlike MCP, which focuses on the mechanics of data exchange, PAP is an OAuth-based standard designed to manage session permissions and access tiers-specifically guest, read-only, and write access. This creates a potential friction point: how does the PAP identity layer reconcile with the existing MCP OAuth implementations we covered when credential theft vulnerabilities surfaced in the Python SDK https://forkast.news/anthropics-official-mcp-python-sdk-had-an-oauth-credential-stealing-flaw-that-let-any-malicious-server-hijack-your-login/ ? The risk of fragmentation is non-trivial. With three distinct protocols-MCP, A2A, and PAP-each governed by different consortia and stakeholders, developers face a fragmented integration landscape. Notably, OpenAI and Anthropic were absent from the initial list of founding partners, which includes Walmart, Stripe, Shopify, Genesys, Rocket, and Instinct. This absence suggests that the industry is not yet aligned on a unified standard for agent identity. Identity as a Lock-in Vector The primary motivation behind PAP is to reduce the friction of agents being blocked by enterprise firewalls, a response to incidents like Amazon’s restriction of Meta’s Muse agent. However, the mechanism of resolution-centralized identity governance-introduces a new form of vendor lock-in. Whoever controls the PAP standard effectively controls the gate to the enterprise. If businesses begin to reject agents that do not adhere to the PAP standard, the protocol ceases to be a mere convenience and becomes a mandatory gatekeeper. This mirrors the historical evolution of web identity protocols, but with higher stakes: the ability for an agent to perform a transaction on behalf of a user. As covered in our commerce analysis of this same announcement https://forkast.news/sierra-and-metas-personal-agent-protocol-gives-commerce-a-common-front-door-for-those-willing-to-open-it/ , the ability to execute transactions is the ultimate value driver for agents. By controlling the identity layer, the architects of PAP gain significant leverage over which agents can participate in the digital economy. Builder Implications For enterprise architects and agent builders, the immediate future is one of cautious observation. The PAP v0.1 specification, along with planned design workshops and reference implementations, is slated for late October 2026. Builders must evaluate how their current MCP testing infrastructure https://forkast.news/mcp-won-the-protocol-war-now-the-community-needs-testing-infrastructure/ and development workflows will need to adapt to accommodate this new authentication layer. Furthermore, as we noted during the recent developer summit https://forkast.news/mcp-dev-summit-toronto-opens-today-the-protocol-stack-seeks-its-missing-coordination-layer/ , the industry is already struggling with coordination gaps. Adding a third protocol stack fragment increases the overhead for agent deployment significantly. As the ecosystem matures, the interplay between these protocols will define the boundaries of the agent economy. Whether PAP becomes the universal standard or merely another siloed solution depends on whether major players like OpenAI and Anthropic join-and whether businesses choose a single gate or many. A note on verification: This analysis is based on the October 6, 2026, announcement of the Personal Agent Protocol. The protocol is currently at the v0.1 specification stage with no production deployments yet reported. OpenAI and Anthropic are not confirmed participants. Sierra is the primary commercial entity driving PAP, and readers should contextualize accordingly.