Your Next Coworker Has Its Own Login
In one week, Google gave its Gemini agent its own email and audit trail, Meta and Sierra started a login standard for shopping agents, and a fraud company began checking agent identities. AI agents are getting their own names, and systems built for people now have to tell an agent from a person.

For years, the AI agent in your company had no name tag of its own. It borrowed yours. It logged in with a person's password and ran on a person's API key, and when it did something, the record said a person did it. This week that started to change, from three directions at once.
Google gave its new Gemini agent its own email address. Meta and Sierra started writing a login standard for shopping agents. And a fraud company started selling checks on agent identities, before most stores even know agents are visiting. Put together, the message is simple: AI agents are getting their own identities. Everything built for humans will soon be asked whether it can tell an agent from a person.
Google hands the agent a badge
At its Gemini at Work event on 8 October, Google launched a unified enterprise Gemini agent, according to TechCrunch. It takes "objectives, not just instructions," plans the work and hands parts of it to subagents. It connects to Workspace, Microsoft 365, Slack, Jira, BigQuery, Postgres, Snowflake and any MCP server, inside or outside the company network.
The detail that stopped me: each agent gets its own Workspace account. That means its own email address, its own calendar, its own Drive, and an audit trail attributed to the agent, not a person. You can tag it, email it or add it to a group chat. Google also added real-time spend caps and a model picker. The picker defaults to automatic but lets users choose Anthropic's Claude, and open models are promised later. Early testers named include On, Shopify and PayPal. Businesses get it first and consumers later.
Think about what a new hire gets on day one: a badge, an inbox, a desk and a company card with a limit. Google just gave software the same starter kit. That is more than a feature. It is a decision about what an agent is.
When the audit log says "the agent did it" instead of naming an employee, the agent stops being a tool someone used. It becomes a coworker someone has to manage.
Shopping agents get a front door
Two days earlier, on 6 October, Sierra and Meta announced the Personal Agent Protocol, or PAP, as reported by The Next Web. The partner list reads like a who's who of the systems that run online shopping: Genesys, Instinct, Rocket, Shopify, Stripe and Walmart.
PAP is built on OAuth, the same "Sign in with..." system you already use without thinking about it. It works like a hotel. An agent can walk into the lobby as a guest to check whether something is in stock or read the returns policy. If the customer then signs in, they hand the agent a key card and choose what it opens: read-only or write access. The business decides which entrance the agent uses. That can be its website, its APIs (MCP or OpenAPI), or the business's own agent.
A v0.1 spec is due later in October. Payments, finer permissions and push notifications are listed as future extensions. PAP is not the only door being built, either. Stripe and Shopify are also part of Visa's rival Trusted Agent Protocol. According to the coverage, neither OpenAI nor Anthropic had signed on to PAP.
The fraud industry is already here
This is the part that makes it real. On 8 October, Riskified announced Agent Identity Risk Intelligence. In that announcement: orders placed through Meta's Muse already arrive on Shopify tagged as agent-originated. Agent shoppers are not a forecast. They already have their own tag in the order data.
Riskified's argument is worth thinking about. A login proves an agent was authorized. It does not prove the person behind it is honest. An authorized agent can still be acting for a stolen account or a refund-fraud ring. And agents never get tired. Riskified expects them to routinely check for price drops, cancel and claim refunds "every day for every order." Its beta for enterprise merchants opens in December 2026, with general availability in 2027.
A return policy written for humans quietly assumes people are a little lazy. Most of us never chase a two-dollar price drop. An agent will chase every one of them, forever, at no cost to itself.
Why this matters even if you never build an agent
Everything else depends on identity. You cannot audit what you cannot name. You cannot cap spending for something that has no account. You cannot set permissions for a visitor you cannot recognize. This week, three separate players made the same bet: agents need names.
- If you run a business system, expect someone to ask "can an agent log in to this?" Google's design assumes the answer is yes.
- If you run a store, your discount, refund and price-match rules are about to be tested at machine speed. Policies that only worked because people get tired deserve a second look.
- If you care about accountability, agent-attributed audit trails are good news. When software did something, the record can finally say so.
What excites me is that this is the boring, necessary work that makes agents trustworthy. Flashy demos get the attention, but badges, key cards and logs are what let a company actually hand over the keys. The open question is which door wins: PAP, Visa's protocol, or something else. Watch for the PAP v0.1 spec this month. That is when this stops being an announcement and becomes something developers can build on.
One signal a day. No noise.
A 3-minute read when something genuinely shifts in AI, automation, or defense tech. Free, most weekdays.
Free, most weekdays. No spam, unsubscribe anytime.Sources
- TechCrunch - Google brings agentic AI to Gemini, starting with businesses - https://techcrunch.com/2026/10/08/google-brings-agentic-ai-to-gemini-starting-with-businesses
- The Next Web - Sierra and Meta announce the Personal Agent Protocol - https://thenextweb.com/news/personal-agent-protocol-sierra-meta
- Yahoo Finance - Riskified launches Agent Identity Risk Intelligence - https://uk.finance.yahoo.com/news/riskified-launches-agent-identity-risk-120000989.html
Quick answers
What is Google's new Gemini agent?
It is a unified enterprise agent Google launched on 8 October 2026. It takes objectives, plans the work, hands parts of it to subagents and connects to tools like Workspace, Microsoft 365, Slack, Jira, Snowflake and any MCP server. Each agent gets its own Workspace account, with an email address, calendar, Drive and an audit trail attributed to the agent.
What is the Personal Agent Protocol (PAP)?
PAP is an OAuth-based standard announced by Sierra and Meta on 6 October 2026, with partners including Shopify, Stripe and Walmart. It lets a shopping agent act as a guest, or act for a signed-in customer who grants it read-only or write access. A v0.1 spec is due later in October.
Are AI shopping agents already placing real orders?
Yes. According to Riskified's 8 October announcement, orders placed through Meta's Muse already arrive on Shopify tagged as agent-originated.
Why does agent identity matter for fraud?
A login proves an agent is authorized, not that the person behind it is honest. Riskified warns that authorized agents can act for stolen accounts or refund-fraud rings, and can repeat refund and price-drop claims at machine speed. Its agent identity product enters beta in December 2026.