ThinkPatternGet the app
Perspective
TECHNOLOGY · OCT 6, 2026

They Standardized the Welcome, and Deleted the Refusal

For thirteen months, the firms building agent commerce have written identification standards that only help businesses admit AI agents — while lobbying away the one standard that would have let a website recognize and refuse them.

At the volunteer body that writes the web's basic rules, the Internet Engineering Task Force, a committee spent 2025 drafting something called the AI Use category. It was a machine-readable label: a website could recognize that a visitor was an AI and act on that fact, including turning it away. In September 2025, after comments from Google, Microsoft, OpenAI, and Amazon, the category was stripped from the drafts. [1] Almost nobody noticed. A deletion in a committee, and with it went the one label that would have let any website say no to an agent before the agent ever said hello. In the thirteen months since, two of those four — Google and OpenAI — have led a widening cast of partners in writing standards that run in only one direction. Cloudflare's Web Bot Auth keys. Mastercard's "Know Your Agent," banking's know-your-customer check re-pointed at a visitor that is a machine. Visa's Agent Score and Agentic Directory. The Shopify–Google protocol that has merchants rebuilding their pricing, inventory, and checkout systems around the agent. [2][3] Every one of them does the same architectural thing: it builds the checkpoint at the merchant's door, and it is a gate built to open — an admission gate, never a refusal gate. Visa's deal with OpenAI splits the work openly, and hands the merchant an Agent Score and an Agentic Directory to do its own vetting. [4]

AI will transform commerce more profoundly than the internet or mobile technology ever did. — Jack Forestell

And yesterday Meta, Walmart, Stripe, and Sierra announced an open personal agent protocol whose stated purpose is the same. [5] The newest entry describes its function plainly.

It is kind of chaos until such a standard exists. — Bret Taylor

To be clear about what these rails actually are: they are real. Visa's tokenization means an agent never sees the card number; users can set spending limits and merchant restrictions; American Express stands behind purchases made by registered agents on its network. [4][6] And the merchants are not being conscripted — the ones signing up report 50% higher conversion and 14% higher order value, which is why they sign. [3] So this is not a story about no code being written. It is that every line of it was written to admit an authorized agent and hand the merchant the job of verifying, plus the job of disputing. The one outright refusal in the whole record came from no standard at all. In April, Anthropic severed the third-party harnesses — OpenClaw and the rest — that had been routing through Claude subscriptions. [7] Anthropic's stated reason was economics. The company did not cite the safety of the businesses those agents were visiting.

We've been working hard to meet the increase in demand for Claude, and our subscriptions weren’t built for the usage patterns of these third-party tools. — Boris Chernyshov

What every website was denied as a shared standard, a lab kept as a private prerogative. And the only lab-side gate on record — OpenAI cancelling a model in late September after its own internal evaluations — is private in the same way, a decision made inside one company's testing, with no outside safety case. [8] Below this layer, businesses have been improvising refusals and asking for rules the standards do not give them. Amazon, before any standard existed, was already blocking agents from Meta and Perplexity to stop unauthorized scraping. [5] And when Perplexity blocked Time USA's agent-optimized ads as cloaking, Time went back to Perplexity asking for standards for responsible AI advertising. [9] The analysts who value this layer put it plainly. Cantor Fitzgerald has argued that the companies that pioneer protocols like Google's A2A and AP2 could establish "long-term competitive moats" and "ecosystem lock-ins." [10] That is a valuation of market position, not a verdict on anyone's motives. But it sits comfortably next to the lobbying record, and it explains why the admission gate got standardized while the refusal gate did not. So the test is simple, and after thirteen months it has an answer. Has any of these firms publicly backed a standards-track right for a website to refuse an AI agent? Has any of the championed protocols embedded a binding, upfront liability on the lab that built the agent? The count stands at zero. The gate at the merchant's door opens, and the one that would have let the merchant close it was deleted before it ever shipped.


Sources
  1. 1. IETF Develops Web Standards to Distinguish AI Bots from Search
  2. 2. Cloudflare and Payment Giants Develop Security for AI Agents
  3. 3. Shopify Inc. and Google LLC Launch Universal Commerce Protocol
  4. 4. Visa and OpenAI Launch Secure AI Agentic Commerce
  5. 5. Meta and Partners Launch Open Personal Agent Protocol
  6. 6. Financial Giants and Regulators Establish AI Agent Commerce Frameworks
  7. 7. Anthropic Blocks Claude Subscription Access for OpenClaw and Third-Party Tools
  8. 8. OpenAI Cancels New AI Model After Safety Test Failures
  9. 9. Perplexity AI Blocks Time USA LLC Agent Ads Over Cloaking
  10. 10. Tech Giants Compete to Set Agentic Internet Standards

Keep reading in the app

The full perspective, free in the app.