Decagon's PACT Protocol Wants Consent to Be a Standard

AI agents are getting good enough to act on your behalf, and almost nothing about that is standardized. When you ask an assistant to book a table, cancel a subscription, or check an order, the business on the other side has no reliable way to know who is asking or what the customer actually authorized. In October 2026, a company called Decagon tried to fix that by open-sourcing a protocol for it.
The specification is called PACT, short for Personal Agent Consent and Trust Protocol. Decagon built it with a partner called Instinct, based it on existing standards including A2A and OAuth, and released it into the open. The company also joined the Personal Agent Protocol working group, which is trying to shape how agents and businesses talk to each other across the industry.
The problem PACT is trying to solve
Think about what happens today when an agent acts for a person. The agent contacts a service, presents some credential, and makes a request. The service has to decide whether to trust it. Usually the answer rests on a shared API key or a login, which tells the service almost nothing about the human behind the agent. Did the customer authorize this specific action? Did they authorize it once, or permanently? Can the agent read data, or only submit requests? There is no common language for any of it, so every integration improvises.
PACT's answer is to standardize the handshake. It gives businesses a way to verify a personal agent's identity and the specific permissions the customer granted it. The word specific is doing a lot of work there. The point is not just to confirm that an agent is legitimate, but to confirm what it is allowed to do on this particular errand.

Why a consent protocol matters more than it sounds
This looks like plumbing, and plumbing rarely makes headlines. But it decides whether the agent economy works at all. Consider a few of the questions any business will ask before letting an agent act on its systems. Is this thing really acting for the person it claims to represent? What can it touch? Who is liable if it does something wrong? Without answers, the safe move is to refuse, and a lot of AI agent demos die at exactly that point.
A shared protocol lowers that barrier. If a business can verify an agent's identity and the scope of its permissions through a standard mechanism, the decision to allow it becomes routine instead of bespoke. The second-order effect is what makes it strategically interesting: whoever defines the standard shapes which agents get accepted, and the businesses that adopt it get to onboard agents without building a custom integration for each one.
Building on what already exists
The choice to sit on top of A2A and OAuth is a sensible one. OAuth already handles delegated authorization for countless apps, and the mental model is familiar: a user grants scoped access, and the provider issues a token that reflects it. A2A handles agent-to-agent communication. PACT adds the missing piece, which is a way to express a personal agent's identity and its customer-granted permissions in a form both sides can verify.
Reusing existing standards is also a survival strategy. Standards that ask everyone to adopt something entirely new tend to stall, because the cost of switching outweighs the benefit until the network is large. A protocol that extends tools developers already use faces a much lower adoption hill. Decagon is betting that being easy to adopt beats being technically superior.
What is still open
An open-sourced protocol is a starting point, not an outcome. Adoption depends on whether other companies find it worth implementing, and on whether the working group converges on something close to it or splinters into competing specs. History is not encouraging here. Plenty of well-designed standards never caught on, and the ones that did usually had a large player pushing them.
There is also a deeper tension the protocol cannot resolve on its own. Consent sounds simple until you ask how it should work in practice. Should a customer approve every action, or grant a general permission and trust the agent to stay within it? A model that asks too often becomes useless. A model that asks too rarely becomes a security risk. PACT gives businesses a way to check permissions, but it does not settle how granular those permissions should be, and that decision will shape how much people actually trust agents with real tasks.
How it fits with the other agent efforts
PACT is not arriving in a vacuum. A2A, which Google introduced, handles how agents talk to one another. Anthropic's Model Context Protocol standardizes how agents reach tools and data. OAuth remains the default for delegated access between apps. Each of these solves part of the puzzle, and none of them was designed with a personal agent acting for a consumer in mind.
That gap is precisely where PACT aims. The existing standards assume a developer building an integration and a service accepting it. PACT assumes a customer with an agent, a business that has to trust the agent, and a permission that has to be provable rather than assumed. It is a narrow problem, but a growing one, because the whole promise of personal agents depends on businesses being willing to let them in.
The competitive stakes are easy to miss because the work sounds so dry. Whoever sets the consent layer sits between every customer and every business that wants to serve them through an agent. That is a position with real leverage, and it explains why multiple large players are moving in the same space at once. Decagon's decision to open-source its proposal rather than keep it proprietary is a bid to become the default before anyone else does.
The bigger fight behind the plumbing
Several efforts are converging on the same problem at once. Google, the builders of A2A, Microsoft, and a growing list of startups all want a piece of agent-to-business communication, and each has its own idea of how trust should work. The winner will not necessarily be the best-designed protocol. It will be the one that enough businesses implement, because a consent standard is only useful when both sides of a conversation speak it.
Decagon's contribution is a concrete proposal in a space that badly needed one. Whether PACT becomes the standard or just one input into it, the release makes an important point. The hard part of putting agents to work was never the model. It was everything around it: identity, permission, and trust. Someone has to build that, and the companies that do will decide how much of this agents-run-everything future actually arrives.
Related articles
AI Short Drama Hit the Hot Search, and Live-Action Shoots Fell 70%
Only one of the top 20 titles on a major Chinese drama chart was made with real actors. AI costs about a tenth as much to produce, and it is rewriting the whole pipeline.
The AI Reunion Wave China Can't Decide How to Feel About
AI tribute films brought departed public figures back to Chinese screens and pulled in hundreds of thousands of likes. Then the backlash arrived, and it was about consent.
Apple Published an Open Multimodal Model and Barely Told Anyone
Apple's research-first release slipped past the mainstream, but the model's fine-grained visual grounding says a lot about where its AI stack is heading.
OpenCut and the Open-Source CapCut Moment
A free, MIT-licensed video editor keeps climbing GitHub's trending list, and its road map includes an MCP server for AI agents. The tools around AI media are catching up to the models.