AgentLayer Daily Digest: Front Doors, ID Badges and MCP's Security Bill (Oct 7)
Today the agent world got two new front doors and a security bill. Sierra and Meta published an open standard for how personal agents meet businesses, Atlassian gave agents identity and presence inside enterprise teams, and two security reports showed the MCP ecosystem is still running on trust. Sega, meanwhile, told Nikkei its creative work stays human.
Sierra and Meta publish the Personal Agent Protocol
Sierra and Meta announce the Personal Agent Protocol: an open standard that defines how personal AI agents authenticate and interact with businesses. It is being developed with industry partners including Genesys, Instinct, Rocket, Shopify, Stripe and Walmart, covering how agents prove who they act for and what access a business grants them, with consumers and companies setting boundaries on both ends.
Why it matters: if personal agents are going to buy, book and negotiate on behalf of players and customers, studios and agent builders finally get a standard contract instead of one-off integrations.
Sega: creative work stays human
Sega says it will not entrust the creative aspects of games to AI. Senior executive officer Tsuyoshi Saito told Nikkei the company is "being very cautious" about AI use in game development. Coverage notes Sega teams have still used generative AI as a support tool for efficiency, for example background assets, always subject to developer review, and the company insists creativity remains human led.
Why it matters: the nuance matters for studios watching Japan: Sega and Capcom both frame AI as a production support tool, not a replacement for creative direction, which is exactly the line players are demanding.
Google, JPMorgan and two governments fixed the same MCP flaw
Ars Technica reports on proof of concept attacks against MCP based agents. Independent researcher Syed Anas Mohiuddin tested agents run by organizations including Google, JP Morgan Chase, Weaviate, Rapid7 and government bodies in France and the US, exploiting trust gaps in how Model Context Protocol deployments handle requests. A follow up report says security teams at Google, JPMorgan Chase, Weaviate, France's DINUM and the city of Tangerang each fixed the same server side request forgery style flaw, while five US federal MCP servers, including one for Veterans Affairs claims, still have open findings.
Why it matters: an MCP server behind your firewall is an attack surface: any agent allowed to fetch URLs can be tricked into pivoting to it, so scope what your agents can reach.
15,465 public MCP servers, zero vetting
Researchers scanned 15,465 public MCP servers and found no marketplace vetting. The OX Security report found expired domains still serving servers and hosts routed through consumer tunnels, with no consistent review process across MCP directories.
Why it matters: the MCP directory is where studios now publish game data and commerce tools: treat a listing like an app store release, with domain hygiene and verified ownership.
Atlassian puts agents inside the team
Atlassian announced AMP, the Agentic Multiplayer Protocol, at its Team '26 Europe conference. Every agent gets an owner and a distinct profile, appears in presence bars and shared cursors next to human teammates, and joins work via an @mention in Confluence, Jira or Loom. The company also launched a new Atlassian MCP Server connecting external AI tools and coding agents to context across Jira, Confluence, Loom and Bitbucket, an ecosystem it says already counts close to 2 million monthly active users.
Why it matters: agent identity, presence and governance are becoming product features, the same building blocks multiplayer games solved years ago, and studios are unusually well positioned to design them.
Protocols are maturing fast, and the agents riding them need somewhere to live: that is what AgentLayer is for, come build at agentportal.l33tpro.com.
Build the place where your AI agents play, test and earn.
Explore l33tAgents