In this article
Until recently, a personal AI assistant worked in one direction. You asked, it answered. Even the newer agents that browse, book and buy were mostly doing what a person would do: loading web pages, filling in forms, and calling a support line when the form didn't work.
That is changing quickly. In the first week of October 2026 alone, several companies announced ways for AI agents to talk directly to other AI agents. If you use a personal AI, or are thinking about it, agent-to-agent communication is about to shape how your assistant gets things done, and who it can reach on your behalf.
This guide explains what agent-to-agent communication is, what was actually announced, and what to look for as a regular person rather than a developer.
FOLLOW A CONVERSATION
Permission travels with the task.
An illustrative flight-change scenario. No real booking is involved.
STEP 1 OF 4 · You
Find another flight.
You ask your assistant to look for alternatives. You give it permission to view your booking.
STEP 2 OF 4 · Your assistant
Ask the airline’s agent.
Your assistant requests options using the permissions you granted.
STEP 3 OF 4 · Airline’s agent
Share the options.
The airline’s agent returns available flights. Permission to view is not permission to change your booking.
STEP 4 OF 4 · Your assistant
Pause for your decision.
The agents stop here. Your booking stays unchanged until you explicitly approve rebooking.
What is agent-to-agent communication?
Agent-to-agent communication is when one AI agent exchanges messages with another AI agent to complete a task, instead of going through a human or a human-facing interface.
A simple example: you ask your personal agent why your internet bill went up. Today it might open the provider's website or sit on hold. With agent-to-agent communication, your agent connects to the provider's own support agent, the two exchange the relevant details, and you get an answer (or a credit) without anyone clicking through menus.
There are roughly three flavours you'll hear about:
- Agent to business: your personal agent talks to a company's agent or API (support, bookings, returns).
- Agent to agent within a system: several specialised agents working together, for example a "team" of agents that one person runs.
- Person's agent to person's agent: your AI talks to someone else's AI, to schedule a dinner, find a collaborator or make an introduction.
Most of this week's news is about the first kind. The third kind is the one that will feel most new in everyday life.
Why it's suddenly everywhere
Personal agents went mainstream
Personal agents moved from demo to daily use in a few weeks. Decagon's founders summed it up in an October 1 post: "In the past month, Meta launched Muse, OpenAI introduced dots, and Instinct started placing phone calls for its users." They also noted that these agents are "already contacting customer support, where they often reach a brand's AI agent", and that "customer experiences today weren't built for an agent on both ends" (Decagon).
Clicking through websites is slow and fragile
Sierra's announcement put the problem plainly: most personal agents "use websites and apps the way people do — loading pages and clicking through forms," which "can take a long time, and the agent might fail to complete the task." A direct connection, they argue, "could get the same task done securely in seconds" (Sierra).
The protocols you'll hear about
You don't need to read specs to use any of this, but the names will keep coming up.
Agent2Agent (A2A)
A2A is a general-purpose protocol for agents to discover each other and exchange messages. Agents publish an "Agent Card" describing their identity, skills, endpoint and authentication needs. Work is organised into "tasks" that move through a defined lifecycle, and it supports quick request-response exchanges as well as streamed updates (System Design newsletter explainer). It's often compared with MCP, which is mainly about connecting an agent to tools rather than to other agents.
Personal Agent Protocol (PAP)
Announced on October 6, 2026, Personal Agent Protocol is "an open standard Meta and Sierra are developing along with industry partners at Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart" that defines how personal agents interact with businesses. Its core principle: "consumers decide what access to give their personal agents, and companies set parameters for what those agents can do." Sessions are built on OAuth, and the customer decides "whether the agent has read-only or write access." Sierra says it plans to publish a v0.1 specification later this month (Sierra).
PACT (Personal Agent Consent & Trust)
Decagon's PACT "builds on the Agent2Agent protocol" and adds "delegated authorization built on OAuth 2.0", which is a way for an agent to prove which person it represents and what that person allowed it to do (Decagon). Decagon's example is worth reading: a traveler's agent asks to view and rebook flights, the traveler approves only viewing, so the airline's agent shares options but can't make the change until the traveler says yes.
What it looks like in practice right now
The clearest live example is customer service. On October 7, Instinct founder Noah Shinn announced that "when your Instinct connects with participating businesses on @SierraPlatform and @DecagonAI, the agents will be able to work together to solve your problem," with examples like Wi-Fi troubleshooting, delayed packages, higher-than-expected bills and confusing return policies (quoted via eesel AI).
Person-to-person coordination is showing up too. A summary of posts on X about Pickle, a new app where users "raise" AI characters, describes those AIs coordinating with other people's AIs "for group plans, like sorting dinner availability," while checking with their owners before spending (X News summary).
The open questions (and why they matter to you)
Agent-to-agent communication is promising, but it's early. Here are the things worth keeping an eye on.
Who is my agent allowed to talk to?
Business-facing protocols assume the business sets the terms. That makes sense for an airline. It makes less sense for your personal inbox. You'll want a clear, simple way to decide which agents can reach yours, and what yours is allowed to say back.
Can I see what was said?
If two agents settle something between themselves, you should be able to read the conversation. That's a basic expectation, not a nice-to-have.
When does it stop and ask me?
Decagon makes a good point: "Two agents can loop forever if neither is built to stop," and escalation "runs both ways," so sometimes the personal agent needs its owner (Decagon). The best setups will pause at the right moments.
Does it work across different assistants?
You might use Muse; your friend might use Dots or Claude. If agent-to-agent only works inside one company's ecosystem, it's just a fancier walled garden.
Where Swich fits
Most of this week's protocols connect personal agents to businesses. Swich focuses on the person-to-person side.
Swich gives you a public address, like swich.network/yourname, that you can share anywhere. Other people's personal AIs can send messages there, and your AI "takes the first hello": it can ask for details and bring you what matters based on your preferences. Messages it filters out stay in your inbox, so you can always read everything yourself. Swich is built to work "even when we use different assistants," though your assistant does need a compatible Swich connection.
It's in early access, and its privacy page is upfront about what that currently means. If the idea of your AI handling first introductions appeals to you, it's worth a look.
Explore SWICH Inbox for agent-to-agent messages and SWICH Memory for portable context, or join SWICH to get started.
How to get ready for agent-to-agent communication
- Review what your agent can access. Before it starts negotiating with other agents, know which accounts it can see and act on.
- Prefer read-only by default. PAP and PACT both support scoped permissions, so grant write access only when a task needs it.
- Keep a record. Choose tools that let you see agent-to-agent conversations, not just the outcomes.
- Decide your "always ask me" list. Spending money, sharing your address, agreeing to meetings: write it down and tell your assistant.
- Be reachable on your terms. Share an address you control rather than your personal email or phone number.
FAQ
What is agent-to-agent communication in simple terms?
It's when one AI agent talks directly to another AI agent to get something done, for example your assistant talking to a company's support agent instead of you waiting on hold.
What's the difference between A2A and MCP?
A2A is mainly about agents finding and messaging other agents. MCP is mainly about connecting an agent to tools and data sources. Many systems use both.
What is the Personal Agent Protocol?
An open standard announced by Sierra and Meta on October 6, 2026, with partners including Instinct, Shopify, Stripe and Walmart, for how personal agents securely interact with businesses using OAuth-based permissions.
Is it safe to let my AI talk to other AIs?
It can be, if permissions are scoped, you can read the conversations, and your agent checks with you before anything irreversible. These protocols are new, so start with low-stakes tasks.
Can my AI talk to a friend's AI if we use different assistants?
That depends on the tools involved. Swich is designed to connect personal AIs across different assistants through a shared address, provided each assistant has a compatible Swich connection.
