← Blog

Who Makes Money When Agents Shop?

Mihir Wagle 6 min read
aiassistantsecommercetollsagents

Disclaimer. This post is my personal opinion. It does not represent the views of my employer or any current or former employer, and it does not draw on any confidential, proprietary, or non-public information. Every factual claim comes from publicly available sources that I have cited. Wherever I describe how a company's systems or incentives work, those same public sources and general industry knowledge shape those descriptions. The predictions here are mine alone - they may well be wrong!

Sierra and Meta announced the Personal Agent Protocol today: an open standard, built on OAuth, for how a consumer's personal AI agent authenticates with a business and what that business lets it do. Founding partners are Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. A v0.1 spec is due later this month.

The announcement is interesting not for who's in it, the usual e commerce players, but for who isn't.

The personal agent protocol is the on-ramp, not the toll booth

Open protocols don't make money (HTTP didn't make Netscape a cash cow), they route it. So who makes money once agents can talk to businesses with a standard handshake?

Sierra's pitch is that every business accepting personal agents needs a customer service agent (from Sierra obviously!), and Sierra sells exactly that, priced per resolved outcome. Meta's pitch is distribution: if Meta AI is the default personal agent in WhatsApp and Instagram, Meta owns the consumer relationship and the intent data.

I don't believe either holds - first nobody will standardize on Sierra. An open handshake commoditizes the business-side agent by design. If any agent can talk to any business, it can be easily displaced by a cheaper one.

And Meta won't be allowed to win the consumer side either. Google has Gemini. OpenAI has ChatGPT with its own agent and checkout. Apple controls the iPhone. None of them will route users through a Meta-led standard without joining it or shipping a rival. The likely outcome is a protocol war, then convergence on something nobody fully owns, the way we got OAuth instead of Yahoo BBAuth.

So who signed up?

Look at who's in the deal. Stripe and Shopify take a percentage on every transaction regardless of which agent brings it. Walmart competes on price and it wants to be in the agentic game.

Look at who's not: Amazon. There are some theories why. Amazon just blocked Muse, so I did not expect them to join.

Here's my hot take. Whoever monetizes the experience hates agents; whoever monetizes the transaction loves them. Amazon' makes a lot of money on sponsored listings ($68.6 billion in advertising revenue in 2025, per Amazon's Q4 earnings), Prime subscriptions, and their rather good private label (I love me some Amazon Basics shirts, don't mind). A personal agent that queries the catalog and picks the cheapest item meeting the ask, and then checks out destroys all three. It's also a perfect ad blocker that also comparison-shops against Walmart in the same breath.

So any reasonable person would predict that Amazon blocks external agents and pushes Alexa as the only agent allowed inside the walled garden, it sued Perplexity to keep the Comet shopping agent off its store.

I think that prediction is wrong, and the reason is the buy box. Those who don't live and buy online marketplaces might ask - what's the buy box? Its the top featured offer you see on an item's detail page.

The buy box is the moat

The Featured Offer algorithm that decides who wins the buy box is, interestingly, an auction over structured, machine-readable attributes. Amazon's own Seller Central documentation names them: price, shipping speed, Prime eligibility, stock, and seller performance, with Order Defect Rate, Cancellation Rate, and Late Shipment Rate weighted most heavily. Underneath those metrics sits years of seller-level history across hundreds of millions of seller-item pairs. No agent can reconstruct that from the outside. It is the single most valuable input to "which offer should I buy."

Add Amazon's pricing engine, which actively reprices against competitors. For in-stock mainstream items, an agent that comparison-shops across merchants usually lands back on Amazon anyway. Walmart and Target might be comparable at best.

So Amazon doesn't need to fear an open agent protocol. If the protocol handles authentication and permissions, and the buy box answer stays Amazon's, the protocol doesn't commoditize Amazon. It delivers agents to Amazon's referee.

What changes is the shape of the ad business, not its existence. Today sellers pay to compete for human attention on a results page. In the agentic version, sellers compete for the buy box on verifiable attributes: a tighter delivery window, a longer warranty, a cleaner return policy, a lower defect rate. The seller's job shifts from making a pretty listing to making the best structured offer, something they already do and now they need to do better. Amazon already gives its sellers repricers, they could potentially make them more "agent ready". The ad dollars become auction dollars. Amazon keeps the referee role and keeps charging for it, and the human never sees a banner.

No other retailer runs a multi-seller marketplace at that scale, so no other retailer can hand an agent a pre-cleared answer. The buy box moat is really the logistics-and-trust moat wearing a UI.

Does the agent care that the referee is conflicted?

Amazon rates its own private label inside the buy box. That's Moody's rating a bond it also underwrites. Does the agent care?

My answer: the agent just wants the answer. Its principal is a human who wants the task done. Verifying Amazon's ranking against ten other sources is cost without payoff. Moody's survived 2008 because nobody could replace the data, and the same structure holds here.

However, the moment one agent vendor can show "we saved you 8 percent versus taking the buy box" across a million purchases, that becomes the pitch, and the user's loyalty shifts to the agent. A human can't audit the buy box. An agent operator with aggregate data across millions of users can.

But that audit only works if the vendor also holds fulfillment and quality data on the alternatives. Saving 8 percent on a worse seller is no bargain. That's the data moat again, and it may hold indefinitely.

So "the agent just wants the answer" is not a free pass for Amazon, bit a discipline it needs to keep, too much greed and agents win.

What would change my mind

Amazon's price leadership is also maintained by what the FTC calls anti-discounting: demoting sellers who list cheaper elsewhere. The FTC 2023 complaint attacks exactly that. If they have to remove that clause, the buy box becomes a trust moat rather than a price moat. Much smaller.

Two years from now, is any agent vendor marketing itself on beating the buy box? If not, the referee won.

Bottom line

The Personal Agent Protocol is a toll road, where the toll collectors that are indifferent to which agent shows up do fine: Stripe, Shopify, and the trust-and-audit layer every business will need once strangers' agents act on its systems. Sierra and Meta are fighting over a rapidly commoditizing layer. Amazon, the company conspicuously not in the room, is the one whose moat an agent protocol can't touch, because the buy box was built for machines before anyone called them agents.

Sources

Enjoyed this post?

Get new ones delivered straight to your inbox. No spam, ever.

Comments