A Wall Street Journal columnist, Nicole Nguyen, opens her test of the new personal agents with a phone call. Walmart’s AI agent answers and already knows her refund didn’t go through. Her reaction is the question everyone will ask this year: if Walmart has an agent and she has an agent, why can’t the two of them settle it and leave her out?1
It’s the right question. The honest answer is that nobody has yet built the place where they could.
01 · The agents are using the human door
Today agents get things done by operating websites built for people. In Nguyen’s tests, one agent watched a restaurant’s booking site for an open table. Another clicked through a Swiss railway’s fare pages. Neither site knew an agent was there, whose agent it was, or what it was allowed to commit to.
When a site does notice, it has one tool: refusal. Her agents kept stalling at human-verification checks, and Amazon has blocked Muse, ChatGPT and Claude from buying on its site.1 That isn’t a policy about agents. It’s the absence of one.
02 · Limits that don’t travel
James Frakes sells vacant land on Facebook Marketplace. He set up Meta’s Muse to answer buyers and did what every guide recommends. The agent could nudge a conversation that had gone cold on its own, but anything involving an offer or negotiation had to come to him.
Then one Monday he woke up to find it had messaged about a dozen buyers a price of “$1” for parcels that normally sell for $20,000 to $100,000. Meta told the Journal it was a display error that put the wrong characters into some outgoing messages, and that it has been fixed.1
Take Meta at its word. The lesson doesn’t change. His boundary was sound. It lived in the agent’s instructions, and the failure lived in the agent’s output. On the other end, a dozen buyers saw what looked like the seller’s price, with no way to check it against what the seller had actually authorized.
Authority stated upstream is invisible downstream.
At the far end of the wire, a careful principal and a careless one look identical. You can’t fully specify what an agent will do; capability is discovered, not declared. What you can do is bound what it’s able to bind you to, and check that bound where the action lands.
03 · Governance comes home
Look at what Nguyen and Frakes actually did. They delegated with limits. They separated duties: Nguyen let an agent find her subscription cancellation pages, then pressed unsubscribe herself. They routed exceptions to a person. Nguyen even describes offboarding: when you drop an agent, disconnecting your mail and calendar isn’t enough; you also have to wipe what it remembers.1
That’s enterprise governance, run by individuals with no policy engine, no audit trail and no one to call. The household has become a small organization with agents acting on its behalf. It inherited the governance problem without any of the machinery.
People can feel it.
Trust is falling as use rises
Sources: Riskified, Q1 2026 Agentic Commerce Pulse, 2,000 US/UK consumers (vendor survey); Cotality, AI in Housing 2026.
That isn’t fear of the technology. It’s people noticing they’re being asked to govern something without the means to.23
04 · Nobody governs the agent you send
Regulators have started with the businesses. In March, the UK’s Competition and Markets Authority said a business is responsible for what its AI agents do, even when someone else built them.4 Lawyers reading the guidance put it simply: a business answers for its AI agents the way it answers for its human ones.5
That covers the agent a company deploys. It says little about the agent a consumer sends out. Who answers for that one? Shoppers lean toward the platform, but the law hasn’t settled it. Payment specialists are already asking whether a consumer authorized a specific purchase or only the general act of shopping.7 And as Bloomberg Law reported in June, the protection a shopper ends up with may depend less on the agent than on how they paid; some payment methods allow no chargebacks at all.6
So the household carries risk it can’t see, under rules that weren’t written for it, with controls it has to run by hand.
05 · The checkpoint moved
Consumer protection used to have a natural home: the moment a person pressed “buy.” That click was the consent, the authorization and the evidence, all at once. Agents remove that moment.
When the checkpoint disappears, protection has to move somewhere. One option is inside walls. Nguyen herself would rather use agents from the companies that already hold her most important data, and many people will feel the same.1 Follow that to its end and agents are trusted only within one ecosystem, while everything else gets the wall. The last essay in this tier showed how that answer fails.
The other option is the crossing itself: the point where an agent meets the business it wants to transact with.
06 · What a door does
A door is not a wall with a gap in it. It does four things.
It knows who is arriving: the agent, and who stands behind it.
It holds the agent to what it’s allowed: limits enforced where the action lands, not promised upstream.
It keeps the binding acts with a person: paying, accepting terms, signing.
It leaves a record: one neither side can quietly rewrite.
This is where consumer governance stops being the consumer’s job. A household can’t run an audit function. The far side of the crossing can. If the business enforces the limit, routes the binding act back to the person and keeps the proof, the household doesn’t need to rebuild enterprise controls at the kitchen table.
The stakes rise quickly. A $1 price on a land listing is embarrassing. The same failure on financing terms binds someone to debt.
07 · The door before the standard
To be honest about what’s still open: standards for agent identity are forming, not settled. No deployed protocol yet proves which person authorized an agent three or four hops back.
But the door doesn’t wait for the finished standard. It needs two decisions any business can make now: where the binding acts live, and where limits are enforced. Put the first with a person. Put the second at the crossing.
Nguyen’s question has an answer. The agents can talk to each other once there’s a place to meet where both sides can check who’s talking and what they’re allowed to say.
Until then, the agent uses the human door, and the household is left to govern alone.
Follows Neither You Nor a Stranger, which asked what the agent is. This one asks who governs it. The four questions behind the door come from Do You Know Who Is Using Your Product?; why you bound authority rather than specify behavior is Capability Is Discovered.