Category: VRM+CRM (Page 1 of 11)

UCP needs VRM

In Microsoft Advertising’s Agentic Playbook, Laurie Sullivan of MediaPost looks into Microsoft’s “agentic commerce blueprint to guide businesses, retailers, and developers when AI agents make purchases on behalf of humans.”

Meaning agents are out there shopping for customers already. Intentcasting anyone?

Laurie explains,

Microsoft’s “Agentic Playbook” focuses on three priorities:

  • Getting discovered by the agent (which many brands struggle with today).
  • Ensuring the purchase becomes seamless.
  • Having the tools to optimize performance of the intended purchase.

Part of the blueprint details a path for marketers to build a 90-day structure for agentic.

Microsoft’s agentic, that is. She goes on:

One Microsoft product marketing director on the call focusing on product feeds said she can already see a major change in consumer behavior — the way people shop….

Microsoft Copilot runs on the same Universal Commerce Protocol (UPC) that many of its larger partners run on, the company said.

The framework connects Copilot with retail, including giants like Target, Ulta Beauty, and Stripe.

UPC founding partners include Google and Shopify.

UPC is new to me. Wikipedia too. But it does have a website: UCP.dev. There it says, “Universal Commerce Protocol (is) the common language for platforms, agents, and businesses (and) provides building blocks for agentic commerce across industries—from discovery to checkout and beyond—allowing the ecosystem to operate through one standard, without custom builds.”

The page goes on to say UCP is “co-developed by industry leaders,” and “built by the industry, to enable seamless agentic experiences. It solves fragmented user journeys that lead to frustrated users and conversion drop off.”

Solves for the seller, that is. Not for the buyer. Yet.

In Under the Hood: Universal Commerce Protocol (UCP), Amit Handa, Google’s Director of Engineering, Google Commerce, and  Ashish Gupta,  VP/GM Merchant Shopping and Engineering Fellow at Google, write,

By establishing a common language and functional primitives, UCP enables seamless commerce journeys between consumer surfaces, businesses, and payment providers. It is built to work with existing retail infrastructure, and is compatible with Agent Payments Protocol (AP2) to provide secure agentic payments support. It also provides businesses flexible ways to integrate via APIs, Agent2Agent (A2A), and the Model Context Protocol (MCP).

UCP is developed by Google in collaboration with industry leaders including Shopify, Etsy, Wayfair, Target, and Walmart endorsed by over 20 global partners across the ecosystem like Adyen, American Express, Best Buy, Flipkart, Macy’s Inc, Mastercard, Stripe, The Home Depot, Visa, Zalando and many more.

Then,

UCP is built to benefit the entire commerce ecosystem

  • For businesses: UCP empowers you to showcase your unique product and service offerings at shopping touchpoints across consumer interfaces such as AI Mode in Google Search and Gemini app, and others in the future. With UCP, you own your business logic, and you remain the Merchant of Record. UCP is built for retailer flexibility, and provides an ’embedded option’ that allows you to maintain a fully customized checkout experience from day one.

  • For AI platforms: With UCP, you can enable agentic shopping for your audiences. You can simplify business onboarding using standardized APIs while giving them flexibility to use MCP, A2A and existing agent frameworks of their choice.

  • For developers: UCP is an evolving open-source standard designed to be community-driven. We invite you to build the next generation of digital commerce with us.

  • For payment providers: UCP’s open, modular payment handler design enables open interoperability and choice of payment methods. Through this design, UCP enables universal payments that are provable. Every authorization is backed by cryptographic proof of user consent.

  • For consumers: When your favorite brands adopt UCP, it removes friction from product discovery to decision, so you can shop the brands you love, with peace of mind, ensuring you get the best value inclusive of your member benefits.

The last bullet is bullshit, but ignore that. Look at it the consumer side as an empty space where independent customers operate with agents of their own. These agents will roam and engage in the open market. They won’t just be “members” trapped in coercive “loyalty” programs. (Although smart agents can take advantage of whatever privileges might appear in those places too.)

Personal agents are VRM tools. They are the first VRM tools with real power since we started this project two decades ago.

In AI shopping gets simpler with Universal Commerce Protocol updates, Ashish Gupta writes,

Thanks to our partners and community contributors, UCP now provides new optional capabilities including:

  • UCP can help make online shopping more intuitive and convenient, thanks to a new Cart option that will let agents save or add multiple items to a shopping cart at once from a single store — just as a shopper typically would.

  • UCP adopters will be able to access a new Catalog capability that lets agents retrieve select real-time product details from a retailer’s catalog where necessary — like variants, inventory and pricing.

  • Building on existing standards, UCP will also support Identity Linking. That allows shoppers on UCP-integrated platforms to receive the same loyalty or member benefits they would on a retailer’s site when they’re logged in — like pricing or free shipping — making shopping more connected across the web.

Good, but again still just for retailers. Nothing in there addresses a question my wife asked when she first encountered e-commerce in 1995: Why can’t I take my shopping cart from site to site?

Back to Laurie:

On Thursday, Microsoft officially began rolling out “AI Max,” its full suite of features for search advertising campaigns, to all accounts. It optimizes performance across Copilot Search and Bing.

The product provides search term matching that expands reach beyond keyword lists.

It uses keywords, ads, and landing pages, along with intent and contextual signals to find relevant searches campaign might not reach.

It also customizes text by using a campaign’s existing assets and website content to generate and test variations on messages.

The system then selects the most appropriate combinations at auction time.

URL expansion sends people to the page on a brand’s website that best matches their intent.

Instead of always sending traffic to a static landing page, it can route people to the page that best matches what they seek.

With AI Max features turned on, advertisers importing existing search campaigns from Google, for example, will seamlessly carry over into the corresponding Microsoft campaign.

I boldfaced intent because that’s the main force customers bring to the market’s table.

Add intelligence to that. Big AI today has far more market intelligence for customers than it does for companies, because customers are free to roam the whole world’s marketplace, while retailers and their third parties are trapped inside the walls of their own self-interest, offerings, and situations. Also their old mentality: the one that assumes that the best customer is a surveilled and captive one.

We started ProjectVRM twenty years ago next month with a thesis to prove: that free customers are more valuable than captive ones—to themselves and the marketplace. Turns out we couldn’t prove that until AI came along.

AI puts customers at an extreme advantage.  Roger Dunn, Chief Commercial Officer of Thrad, talks about this in a recent  Microsoft Advertising blog post:

When someone asks ChatGPT, Copilot, or Gemini for a product recommendation, the AI assembles a shortlist, usually three to five options, and that shortlist becomes the only consideration set that matters…

The vast majority of consumers still verify AI recommendations before buying. They take that shortlist to Google, to Bing, to a brand website, to YouTube. The verification stage is a confirmation exercise, not an open-ended one. They’re searching for the specific brands the AI mentioned, not starting from scratch…

So trust now operates in two layers.

First, there’s machine trust. From a retailer’s perspective – can an AI agent find you, understand what you sell, and have confidence that your product data is accurate and current? That’s about structured data, reviews, fulfillment reliability, pricing consistency. It’s operational, not emotional.

Second, there’s human trust. When the consumer arrives to verify, does your brand have the credibility, the reputation, the experience to close the deal? That’s the brand equity layer, and it’s not going away.

The brands that win will be the ones who treat product data as a strategic asset while continuing to invest in the emotional signals that make humans want to buy. The mistake is thinking you have to choose.

Product truth comes first signal to matter most, and it’s non-negotiable. AI agents reason over structured attributes: dimensions, compatibility, features, use cases. If those attributes don’t exist as machine-readable data, you’re not even a candidate. In the old world, poor data meant lower conversion. In the agentic world, poor data means you never enter consideration. Consumers aren’t prompting “what’s a good shoe brand.” They’re saying “I’m running a 5K this weekend on mixed terrain and my feet run narrow.” If your catalogue can’t answer that level of specificity, the agent recommends someone who can.

Reviews and third-party signals come second. AI systems synthesise review sentiment to answer highly specific questions. One detailed review explaining how a product performed in a real scenario is worth dozens of generic five-star ratings. Third-party endorsements, expert mentions, and certifications act as trust multipliers that AI increasingly weights.

Fulfillment reliability is third and rising fast. As we move up the automation curve, especially when consumers start authorising agents to purchase within preset rules, delivery reliability becomes a make-or-break signal. If an agent places an order and the delivery fails, the agent learns. Your logistics will become your trust score.

Brand authority is fourth. Still vital, but its mechanism is shifting from emotional halo to verifiable digital identity. Your reputation is increasingly a technical credential that agents use to evaluate trustworthiness.

That’s today, when all customers have to work with are Big AI agents. What happens when people get truly personal AIs, in addition to what the giants give them? These will be AIs that give them knowledge and control over the whole corpus of their personal data, meaning everything in this image:

Prompt: A woman uses personal AI to know, get control of, and put to better use all available data about her property, health, finances, contacts, calendar, subscriptions, shopping, travel, and work

What you’re looking at in that image is a far more empowered and agentic customer than one who operates only inside the milieu Roger describes. Because personal AI is by the person, not just for the person. This completely changes the game—especially when the customer comes with her own terms of engagement and  her own identity, credentials, policies, and engagement mechanisms. Both will happen. As Joe Mandese put it in MediaPost last November, Imagine Consumers Delegating Their Relationships With Marketers To Agents.

Nothing in marketing as we’ve known it contemplates the implications of full and independent customer agency, because marketing still lives inside the business-as-usual box to which we addressed The Cluetrain Manifesto twenty-six years ago.  Cluetrain said a lot of stuff to that box, but here was the summary statement:

Chris Locke wrote that. Wish he was still around to see personal AI’s reach break corporate grasp.

From inside that old box, what Microsoft talks about looks like this:

retailer → machine-readable offers → agent → customer

The customer’s side looks like this:

customer → machine-readable intentions/terms/preferences → agent → market → company

The view from above is this:

customer → agent ←  market → agent ← company

Just three things happen in markets:

  • Transactions
  • Conversations
  • Relationships

In the industrial age, which is finally ending, business was focused almost entirely on transactions. Still is, for good reason: without transactions we wouldn’t have markets. It was strong there, but weak in the other two.

Conversations were kept to a minimum because they looked like overhead: costly in time and money. Service was pushed off to call centers, and now call center workers are being replaced by AI robots.

Relationships were about “loyalty” programs in which customers were held captive and milked.

In the agentic world, the opportunities for conversation and relationship are immense—and will drive many more transactions.

Customers and companies can collaborate on countless benefits for each other when imarket ntelligence flows both ways. Products, services, and experiences by customers and companies can all improve together. Guesswork is minimized. So are the operational and moral costs of surveillance.

Lots to work on here.

Bonus linkages:

How VRM+CRM Will Play Out

Nitin Badjatia has been laying out more and more reasons, and ways, that enterprises will adapt to customers, rather than the reverse. Read his work and you can start to see what the middle name of both VRM and CRM will mean in the agentic era that is upon us.  His latest three:

From the latest:

The reason the customer contribution matters most is straightforward. The customer is the only body in the relationship that experiences the full arc of it. The organization knows what it built and why. The product knows how it is being used. Only the customer knows what any of it actually means. What they were trying to accomplish, whether they succeeded, and what they wished the enterprise had asked them about before making the decisions it made. All of that is context, and it has never been available to the enterprise on terms either party could trust.

That is about to change. Customer-side agents, operating under a trust protocol like MyTerms, will make the customer’s own account of the relationship available to the enterprise as a first-class contribution to the context layer. MyTerms provides the missing piece the industry has been circling for years. A bilateral agreement, machine-readable and enforceable, that specifies what the customer is willing to share, what the enterprise is allowed to do with it, and what the customer expects in return. With that protocol in place, the customer’s agent will share context the enterprise has never had access to at any point in the history of customer experience.

What the enterprise will receive is not another data feed. It will be a structured account of the relationship from the customer’s own perspective. Why the product was purchased. What problem it was meant to solve. Whether that problem was solved. What has changed in the customer’s circumstances since. What competing options are being considered. What the enterprise could do to strengthen its standing over time. That is a completely different order of information from anything the enterprise’s own instruments have ever produced, because it is the customer’s own account rather than the enterprise’s interpretation of behavior. The customer will have latitude, through a MyTerms contract, in the depth and breadth of the information to share with both the enterprise and the product/service.

The context also compounds in ways the enterprise-side context cannot. The customer’s agent will remember every interaction with every vendor the customer engages with. It will compare experiences across the customer’s full commercial life and surface patterns the customer might never have articulated on their own. When it shares context with the enterprise, it is offering not just what the customer knows about this relationship, but what the agent has learned across many.

But it won’t happen without MyTerms. So let’s build that out.

The Original and the Eventual Intention Economy

The Intention Economy subtitle. It’s the whole thing, right there.

A recent post by Simon Taylor on X expresses something important about AI agents and markets: if an AI agent arrives in a market with a clear mandate—

Get me X. Budget Y. Constraints Z.

—it obsolesces business-as-usual for digital marketing.

See, all of martech and adtech starts with the assumption that human intent is fuzzy and manipulable—and that the best customers are captive and manipulated. Let’s look at this from three angles, which are also the three things that happen in markets:

  • transactions
  • conversations
  • relationships.

On the transaction side, companies invest heavily in tracking people, analyzing their behavior, targeting ads at them, and then (in many cases) rationalizing extremely wasteful results. Plus, of course, discounting or ignoring boundless negative externalities, such as the annoying people to new extremes and massively abusing personal privacy. (In fact, the system treats absent personal privacy as a base feature.) Anyway, the entire surveillance-based advertising fecosystem exists to guess what people want, or to influence what they might want.

On the relationship side, all we have so far is on the sell side: CRM, for Customer Relationship Management, and CX, for Customer Experience. We’ve been trying here to build (or to encourage building) systems for VRM, for Vendor Relationship Management, to give CRM customer hands to shake. But, in VRM’s absence, CRM is all we’ve got. One hand clapping. Or slapping. Or pushing prospects into a funnel.

What many of us, including Simon Taylor, suggest is facilitating conversation through AI agents. Simon’s case, specifically, is that an agent representing a person doesn’t need to be guessed at. It already knows the user’s intent. So there is no attention to capture and no desire to manufacture or manipulate. The demand signal is clear from the start. That’s why he says agents can collapse the attention economy.

The underlying shift in this direction has been visible for a long time. In The Intention Economy: When Customers Take Charge (Harvard Business Review Press, 2012), I argued that markets work best when customers drive them with clear signals of demand, rather than when sellers try to infer demand through surveillance and unwelcome persuasion. I also said markets can be far richer and more vital when customers and companies operate as equals, with relationships based on mutual interest rather than forms of coercion (such as “loyalty” programs that aren’t).

The work of Vendor Relationship Management (VRM) has been about correcting that imbalance.

Instead of companies managing relationships with customers through CRM (Customer Relationship Management) systems, we need customers able to manage relationships with vendors through VRM (Vendor Relationship Management) tools.

Note that relationship is the middle name of both CRM and VRM. Markets are not just about transactions. They are about relationships that continue over time.

That’s why a working intention economy will involve far more than simple buying transactions.

As Esteban Kolsky once put it, companies often focus almost entirely on the “buy cycle.” But customers live mostly in the “own cycle”—the long period of using, maintaining, fixing, improving, and learning from the products and services they already have:

In an intention economy, intelligence about that experience flows both ways between customers and companies. I wrote about this recently here:

Market intelligence that flows both ways.

VRM has long described one key mechanism for this: intentcasting, where customers signal their needs directly to the market rather than being targeted by guesses and ads.

Agents may make this far more feasible than it was when we first started talking about VRM nearly two decades ago.

But there’s an important point that often gets missed in current AI discussions.

The agency that matters most is the person’s, not the agent’s.

A personal AI agent is an instrument—like a phone, a computer, or a car. It acts on behalf of the individual, but the intention behind it must be the person’s own.

And that leads to another requirement:

The only truly personal agents will be owned and operated by individuals.

We don’t have that yet.

What we have instead are assistants that live inside corporate systems—helpful, sometimes impressive, but ultimately operating within feudal structures run by very large companies.

They are, at best, friendly suction cups on the tentacles of giants.

Individuals may well rent or borrow AI models from those giants. But the agents that represent us should operate inside our own environments, in our exclusive interest, rather than inside corporate systems whose interests may diverge from ours.

In other words, our agents should live in our own castles, not inside someone else’s kingdom.

When that happens—when individuals can show up in markets through tools they control—then the deeper shift becomes possible: from guesswork based on surveillance of captive customers to servicing self-qualified leads from free customers in the open marketplace.

Markets then begin to work the way markets are supposed to work: with demand and supply meeting in the open, in relationships that can last far beyond a single transaction.

This is also where work like MyTerms and the emerging ecosystem around personal AI becomes important. If individuals are to operate in markets through their own agents, those agents need ways to assert the person’s terms, preferences, and boundaries in forms that other systems can recognize and respect.

That is the direction VRM has been pointing for nearly twenty years: toward a world where individuals can arrive in markets with their own tools, their own data, and their own terms—and where markets can finally listen.

When that happens, markets will stop guessing what customers want—and start hearing them.

[Later… I actually wrote this post about a month ago, and put off publishing it while I worked on other things. Meanwhile, Adrian Gropper posted A Fork in the Road, which is required reading. I thank him for reminding me in the comments below, and for being a founding participant in ProjectVRM—going back to our earliest meetings almost 20 years ago.]

Finally Fixing Health Care

Source: ChatGPT

Interesting how old posts get new traffic. The heaviest traffic this morning is to Health Care Relationship Management, which ran almost nineteen years ago. That post concerned a Steve Lohr story in the NY Times titled Google and Microsoft Look to Change Health Care.  The gist:

The Google and Microsoft initiatives would give much more control to individuals, a trend many health experts see as inevitable. “Patients will ultimately be the stewards of their own information,” said John D. Halamka, a doctor and the chief information officer of the Harvard Medical School.

The initiatives were Google Health  and Microsoft Healthvault. Never mind why they died. Those links will tell you. What matters more is what I said way back then: The key, as with all VRM projects, is that the solution needs to be anchored on the customer side — in this case the patient side — of the relationship.

As it happens, Adrian Gropper, techie and MD, was on this case long before Google and Microsoft showed up to waste $billions failing to solve a problem they could only compound. And he’s still at it, with HIE of One and related efforts. Here is his Substack. These subjects will be on the floor at VRM Day and IIW later this month. VRM for healthcare will save the world $billions, in addition to countless lives.

Here’s Adrian’s latest.

Shooting for the World

There is no organisation on Earth with a more audacious purpose than this one:

From Customer Commons’ current index page.

This isn’t shooting for the Moon. It’s shooting for the whole world of business.

What Customer Commons wants to restore isn’t just what was lost when the Internet got real. (For example, privacy.) Customer Commons also wants to restore personal agency that was lost when Industry won the Industrial Revolution. That’s when jobs replaced work, labour replaced teams, and customers became consumers.

That last shift, Jerry Michalski explains, was from human beings to “gullets with wallets and eyeballs.” After that shift, freedom of contract in marketplaces was enjoyed only by businesses. Not by gullets.

Customer Commons was created to change that. It was spun out of ProjectVRM as a 501(c)3 nonprofit in 2013, shortly after Harvard Business Review Press published  The Intention Economy: When Customers Take Charge. That book specifically gave Customer Commons the job of doing for personal privacy terms what Creative Commons did for personal copyright.  And to do it by making privacy a contract between customers and businesses, rather than a “consent” to whatever the hell businesses wanted to shove down our gullets. (For example, with interruptive cookie “choices” that really aren’t and leave no audit trail.)

Work on that began in 2017, when the IEEE approached Customer Commons with an offer to host development of a standard for machine-readable personal privacy terms. That standard, officially called IEEE 7012-2025, and nicknamed MyTerms, was published this past January, concluding nine years of work.

Now what?

MyTerms is a great start toward completing Customer Commons’ audacious mission. Here are some goals we will achieve when that mission is accomplished:

  1. VRM will be a business category, welcomed and engaged by CRM and CX functions on the sell sides of markets.
  2. We will have proof that free customers are worth more than captive ones—to companies they engage, to whole markets, and to themselves. This was ProjectVRM’s original mission in 2006.
  3. The intention economy will materialize when voluntary signaling from customers to companies outperforms and obsolesces surveillance as the primary means for companies to obtain data about customers.

MyTerms is required for all three, because a contract is the only way for companies to commit to respecting personal privacy, and MyTerms is the standard for doing that.

So the first challenge is to make Customer Commons viable as the first mover in establishing MyTerms in the world.

The second challenge is to make Customer Commons substantial enough to lead work toward all three of the challenges listed above. Customer Commons won’t be the only entity working on those. In the U.S., Consumer Reports has already stepped forward as a natural ally.  MyData Global is partnering with Customer Commons in standing up the MyTerms Alliance, which is HQ’d in Europe. There are many other potential partners, such as Mozilla and the EFF.

There is development work on MyTerms already. You can learn more about those at VRM Day, IIW, and AIW, which run M-F through the last week of this month (April 27 to May 1) at the Computer History Museum in Silicon Valley.

Here are other ideas that have been floated in the past for Customer Commons:

  1. Customers Union. Being for customers what the AARP is for retired people. Only bigger, because it would include everybody who is a customer of anything. This isn’t far from Consumers Union, which begat Consumer Reports, and is now its advocacy group.
  2. CustomerCon. A trade show with company booths run by customers, to which companies are invited as guests. Key feature: no complaining. Guest companies are treated only to positive and constructive ideas. HT to Tim Hwang for helping come up with that one.
  3. Omie. A tablet with apps free of Google and Apple. HT to Iain Henderson.
  4. The ByWay, a new path for local e-commerce.
  5. The Free Customer Award. This would be given to companies that value free customers and do nothing to entrap them. The canonical example described in The Intention Economy is Trader Joe’s. But there are others. In-N-Out Burger, for example.

I share those only to give you an idea of how big and influential Customer Commons might be, and how it’s possible to have fun making a new and better economy happen.

We’re not at Square One. Customer Commons is an extant nonprofit, has an energetic board, and a huge accomplishment by getting MyTerms finished. What it needs now is to build out a working organisation. How can we do that?

Let’s look at how Creative Commons got rolling in 2002 and kept moving after that. Here is what I’ve found in diggings so far—

  • The History of Creative Commons in Wired (December 2011) says, “An hour after the court’s decision was announced, the William and Flora Hewlett Foundation presented Creative Commons with $1,000,000 to launch the movement.” The case was Eldred v. Ashcroft.
  • In 2008, there was a successful funding challenge from Hewlett: “The 5×5 challenge, issued in honor of Creative Commons’ fifth birthday, called for the organization to find five funders to each promise five years of support at $500,000 per year. In addition to the Hewlett Foundation, Creative Commons received pledges of $500,000 in yearly support for five years from Omidyar Network, as well as from an anonymous European trust. Google has pledged $300,000 in support renewable for five years, while Mozilla and Red Hat have each pledged to contribute $100,000 annually for five years. The final block of support comes from the board of Creative Commons, which has promised to personally raise or contribute $500,000 to the organization annually for five years.”(Source: Creative Commons Newsletter No.5, February 2008)
  • A Creative Commons  announcement in April 2008 said, “We’re thrilled about a major new grant of $4 million from the William and Flora Hewlett Foundation, consisting of $2.5 million to provide general support to Creative Commons over five years, as well as $1.5 million to support ccLearn.”
  • A MacArthur grant search reports a total of $3,225,000 provided between 2002 and 2022:
    • $750,000 in 2005 to support general operations for three years
    • $500,000 in 2007 to support Science Commons for two years
    • $700,000 in2008 to support general operations and an endowment campaign for three years
    • $25,000 in 2015 to provide travel and other support for attendees of the Creative Commons Global Summit in South Korea, for two months. The meeting was also funded in part by the Institute for Museu m and Library Services and th e Gates Foundation, and by the Korean Ministry of Culture, Sports and Tourism ($25,000), Mozilla ($10,000), and the Wikimedia Foundation ($10,000).
    • $50,000 in 2022 to support dedicated programming on open journalism issues at the 2023 Global Summit, “which is an annual event that brings together educators, artists, technologists, legal experts, and activists to promote the power of open licensing and global access.”

So, by inference, the phases were roughly this:

  • Launch (2001–2002) $1M of initial funding
  • Early build-out (2002–2004) +$1–3M with  additional foundation support
  • Continuous operations (2005 onward) at ~$1–3M/year

That gives us an idea of what we need to raise. (Given inflation, multiply those numbers by 1.5x.)

I’ll tell you more when I find out more. Meanwhile, watch this space. Better yet, jump in and help out.

 

 

 

Without Privacy, VRM Can’t Happen

Nor can CRM. Not really. The middle name of both is Relationship, and those require respect for each other’s boundaries. We don’t have that yet online, and can’t without working standards (hello MyTerms), tech, and norms. In fact, the opposite prevails: extreme exploitation of absent personal privacy.

Helen Nissenbaum has been teaching us that for decades, and working on solutions. One is Adnauseum, which may be on your browser already.  It works (says that last link) “by automating ad clicks universally and blindly on behalf of its users. Built atop uBlock Origin, AdNauseam quietly clicks on every blocked ad, registering a visit on ad networks’ databases. As the collected data gathered shows an omnivorous click-stream, user tracking, targeting and surveillance become futile.” In another word, obfuscation.

And that’s what Helen will unpack when she speaks in our salon series here at Indiana University next Tuesday at 4 pm Eastern, and on Zoom. Her title is Why Obfuscation is (still) Needed (more than ever). Here’s the flyer, with the registration and Zoom links:

And in case you don’t click on that, here it is again.

See you there.

The Only Way to Get Privacy Online

No regulation to make organizations respect personal privacy will work.

We’ve had cookie laws since the ’00s, the GDPR since the ’10s, and the CCPA since 2020. None of them has worked.

All those regulations are aimed at reducing the power of organizations to violate personal privacy. None is to empower people. That’s why, under those regulations, all we can do is agree to the terms organizations provide. We have no independent agency.  All we have is what they promise, and their promises aren’t worth the pixels they’re printed on.

The only way we will get privacy is with contracts, which are laws that two parties make for themselves.

And the only way to make contracts work, at scale, is if we are the ones proffering those terms as first parties, and organizations agree to them as second parties. This flips the script on business-as-usual online.

By the old script, privacy is a grace of corporate obedience to selections in cookie notices, many of which provide no choice at all. There is “Accept,” and that’s it. In that case, all you’re accepting is a corporate privacy policy, which is typically just a fig leaf over the company’s hard-on for personal data.

Regardless of what you do with a cookie notice, chances are the company still tracks you like a marked animal.  See here and here. You also have no easy of auditing compliance, because you keep no record of your “choices.” And we have that system because the incentives are worse than misaligned: they are completely broken.

See, if you are a typical website, you get paid for allowing third parties to harvest visitors’ personal data and use it to aim personalized advertising at their eyeballs. This is morally wrong on its face, but easily rationalized because it pays.

In the natural world, a store would never plant tracking beacons on every shopper, or require those shoppers to “choose” privacy protections by stripping naked and then selecting the purposes to which their personal tracking beacons will be put. Shoppers would avoid that store like the plague,

However, on the Net and the Web, we haven’t yet invented privacy, just as we hadn’t in the natural world before we invented clothing and shelter. So, on the Net and the Web, we are still naked as fish. As a result, a plague of near-ubiquitous surveillance has been raging online for decades. It is nearly impossible to avoid getting infected.

Most of that surveillance is for the $742 Billion surveillance-fed fecosystem* called adtech. And the only way we can obsolesce it is with a business ecosystem that works for everyone: customers and companies alike, and together.

We can do that now, with MyTerms.

MyTerms is the nickname for IEEE P7012 Standard for Machine Readable Personal Privacy Terms, which will be published next week after eight years in the works. (I chair the working group.)

It describes a protocol in the diplomatic sense: a way to reach and record agreements. Here is a diagram that shows how it works:

It is also the ultimate product of ProjectVRM, which began in 2006 with a mission: to prove that free customers are more valuable than captive ones—to companies, to markets, and to themselves. It was to ProjectVRM’s nonprofit spinoff, Customer Commons, that the IEEE came in 2017 with the challenge to create the MyTerms standard.

Of course, every agreement needs to be good for both sides. Right now we have five draft agreements for that. SD-BASE says “Service Delivery only.” This one requires that the site or service provide the visitor only what the visitor came for, and not to share personal data with third parties. This will make the site or service more inviting. (Customer Commons also plans to offer a trustmark to sites and services that sign MyTerms Agreements.) Lots of other mutually respectful agreements can also be built on top of SD-BASE: agreements that respect personal agency as well as privacy.

Other initial MyTerms agreements cover data portability, intentcasting, data-for-good, and AI training.

MyTerms will foster businesses and business methods that the surveillance fecosystem prevents. We describe how that will work, and some of the businesses MyTerms will create and improve, in The Cluetrain Will Run from Customers to Companies.

Of course, we need to develop tools and services for making that cluetrain run.  Please tell us what you’ve got or plan.

The place to list those is in a new section of our Developments page. We also need to re-write and condense our privacy manifesto, and welcome help with both.

We also need to thank our many teams over the past two decades for jobs well done, even if many of those jobs didn’t go anywhere, mostly because they were too early.

Now is the time, because the world is fed up with surveillance—and it is easier than ever to develop tools and services using AI.

MyTerms will be announced on 28 January at this event in the Imperial Business School and online. Please come.


*The word fecosystem is apropos, kinda like Cory Doctorow’s ensittification. Spread both words.

When Branding Means Relating

What is your best friend’s personal brand? How about your spouse’s?

Those questions came to mind as I read through The Death of Merchandising in an Online World, by  Dana Blankenhorn, who is reliably wise. In that post, Dana correctly observes that brand value is declining as merchandising shifts from stores to online services, and to influencers who are also stores.

I think there’s also something else going on at the same time: the shift in media from real advertising to the online equivalent of junk mail, which is what you see with nearly every ad you encounter on your browsers and apps. To marketers, browsers and apps are boxes for junk mail, which at its most ideal is personalized by surveillance.  As I put it in Separating Advertising’s Wheat and Chaff, ” Madison Avenue fell asleep, direct response marketing ate its brain, and it woke up as an alien replica of itself.”

I wrote that a decade ago. With AI today, that alien replica is the real thing. Madison Avenue is now AM radio, with a whip antenna and tail fins.

Brand advertising worked best when “the media” were mostly print and broadcast. Sources of both were so few that they all fit on a newsstand and the dials of radios and TVs. To operate a source of either, you needed a printing plant or transmitting towers. Publishers and broadcasters are still around, but now their goods are mostly distributed over the Internet and consumed through glowing rectangles. And they’re competing in a world where the abundance of other sources of content is incalculably vast. In that world, the only places you can still reliably create and maintain brands is by sponsoring live events. Especially sports. That’s why I know fifteen minutes will save me fifteen percent with Geico, even though Geico stopped saying that years ago. I also know that you only pay for what you need with Liberty Mutual. And I’ll never get the Shaefer Beer jingle out of my mind.

On the whole, however, branding has finished running the same course as the broadcasting it paid for.

It helps to remember that the words brand and branding were borrowed from ranching. They applied especially well when people had few choices of media, and few if any ways to avoid ads meant to burn the names of companies and products onto mental hides.

What we really (or at least should) mean by brand today is reputation. How a business obtains that in our still-new Digital Age (now with AI!) is an open question.

I believe the answer will come from the natural world, where markets have been working far longer than we’ve had digital media, broadcasting, or print. It was in the natural world that two very different people—one an athiest and the other a pastor—separately explained to me, not long after The Cluetrain Manifesto came out, that markets are not just about transactions and (as Cluetrain insisted) conversations. They are about relationships.

Marketing prevents those. Or shortcuts them. Especially as it continues to devolve into funnels at the bottom end of which are transactions alone, or entrapment in a company’s “loyalty” system.

The Internet and the Web were both designed to support maximum agency and independence for every entity using them. We can have far better markets and marketing if demand and supply both work with maximized agency, and scale in ways that are good for both. That’s the idea behind market intelligence that flows both ways.

Making and maintaining those kinds of relationships will be VRM+CRM, What those together will make are wholes that exceed the sum of either part.

How CMPs Can Make Hay With Real VRM

By now you’ve seen one of these:

Never mind that you’re not running an ad blocker, but merely blocking tracking. Instead, note the small print in the lower right: “VRM by Admiral.”

By “VRM,” Admiral means this:

What we’re looking at here is the $.5 billion Consent Management Platform business, currently dominated worldwide by OneTrust, with a 40% market share. In the US, Admiral is the leading provider to publishers, giving it a high profile there. In Europe, the leaders are OneTrust, Usercentrics, and CookieYes.

So here is a challenge for Admiral , OneTrust, and the rest of them: make VRM  mean Vendor Relationship Management (like it says in Wikipedia).

Our case: real relationships are based on mutual trust, which can only happen if personal privacy is fully respected as a starting point. Consent management by cookie notice can’t cut it.  For real trust, we need people to bring their own terms to every website’s table, and have agreements to those. This is why we, the ProjectVRM community, through Customer Commons (our nonprofit spinoff) and the IEEE P7012 (aka MyTerms) working group, created the draft standard (on track to become official early next year) for machine-readable personal privacy terms. Three years ago, I called MyTerms The Most Important Standard in Development Today. The CMP business can help make it so, by getting on the Cluetrain.

Here are some opportunities:

  1. CMPs can provide sites & services with easy ways to respond to MyTerms choices brought to the table by visitors. Let’s call this a Terms Matching Engine.The current roster of terms we’re working with at Customer Commons (abbreviated CuCo, hence the cuco.org shortcut) starts with  CC-BASE, which is “service provision only.” It says to a website, “just give me your service, and nothing more.” In other words, no tracking. Yet. Negotiation toward additional provisions comes after that. Those can be anything, but they should be in the spirit of We’re starting with personal privacy here, and the visitor sets the terms for that.
  2. There is a whole new business (which, like the VPN, grammar-help, and password management businesses, people would pay for) in helping people present, manage, remember, and monitor compliance with their terms, and what additional agreements have been arrived at. This can involve browser add-ons such as the one pictured  on the ProjectVRM r-button page. CMP companies can make money there too, adding a C2B business to their B2B ones.
  3. Go beyond #2 to provide real VRM. Back in the last millennium, Iain Henderson pointed out that B2B relationships tend to have hundreds or thousands of variables over which both parties need to agree. Nitin Badjatia, another CRM veteran (and a Customer Commons board member like Iain and myself), has also pointed out that companies like Oracle have long provided AI-assisted ways for B2B relationships to arrive at contractual agreements. The same can work for C2B, once the base privacy agreement is established. There can be a business here that expands on what gets started with that first agreement.
  4. Verticals. There can be strong value-adds for regulated industries or companies wanting to acquire and signal accountability, or look for firmer ways to establish a privacy regime better than the called consent, which doesn’t work (except as thin ass-covering for companies fearing the GDPR and the CCPA). For example: banks, insurers, publishers, health care providers.
  5. For people (not just corporate clients), CMPs could offer browser plugins or apps (mobile and/or computer) that help people choose and present their privacy terms, track who honors them, notify them of violations, and have r-buttons mean something. Or multiple things.

Here is what a VRM-friendly person in the UK came up with as a prototypical first by a CMP away from cookie notices:

That was after this post went up.  (Which is great.)

Obviously, we want cookie notices (and other forms of friction) to go away, but we also want CMPs to have a nice way to participate in a customer-led world in which intention-based economies can grow.

And here is an example of r-buttons in a browser:

Real relationships, including records of agreements, can be unpacked when a person (not a mere “user”) clicks on either the ⊂ or the ⊃ symbols. There are golden opportunities here for both VRM and CRM vendors. And, of course, companies such as Admiral and OneTrust working both sides—and being truly trusted.

Give us more. (Like that cookie notice above.)

The Cluetrain Will Run from Customers to Companies

For the good of both.

Customers need privacy, respect, and the ability to provide good and helpful information to the companies they deal with. The good clues customers bring can include far more than what companies get today from their CRM systems and from surveillance of customer activities. For example, market intelligence that flows both ways can happen on a massive scale.

But only if customers set the terms.

Now they can, using a new standard from the IEEE called P7012, aka MyTerms. It governs machine readability of personal privacy terms. These are terms that customers proffer as first parties, and companies agree to as second parties. Lots of business can be built on top of those terms, which at the ground level start with service provision without surveillance or unwanted data sharing by the company with other parties. New agreements can be made on top of that, but MyTerms are where genuine and trusting (rather than today’s coerced and one-sided) relationships can be built.

When companies are open to MyTerms agreements, they don’t need cookie notices. Nor do they need 10,000-word terms and conditions or privacy policies because they’ll have contractual agreements with customers that work for both sides.

On top of that foundation, real relationships can be built by VRM systems on the customers’ side and CRM systems on the corporate side. Both can also use AI agents: personal AI for customers and corporate AI for companies. Massive businesses can grow to supply tools and services on both sides of those new relationships. These are businesses that can only grow atop agreements that customers bring to the table, and at scale across all the companies they engage.

This is the kind of thing that four guys (me included)† had in mind when they posted The Cluetrain Manifesto* on the Web in April 1999. A book version of the manifesto came out in early 2000 and became a business bestseller that still sells in nine languages. Above the manifesto’s 95 theses is this master clue**, written by Christopher Locke:

MyTerms is the only way we (who are not seats or eyeballs or end users or consumers) finally have reach that exceeds corporate grasp, so companies can finally deal with the kind of personal agency that the Internet promised in the first place.

The MyTerms standard requires that a roster of possible agreements be posted at a disinterested nonprofit.  The individual chooses one, the company agrees to it (or not). Both sides keep an identical record of the agreement.

The first roster will be at Customer Commons, which is ProjectVRM’s 501(c)3 nonprofit spinoff. It was created to do for personal privacy terms what Creative Commons does for personal copyright licenses. (It was Customer Commons, aka CuCo, that the IEEE approached with the idea of creating the MyTerms standard.)

Work on MyTerms started in 2017 and is in the final stages of IEEE approval process. While it is due to be published early next year, what it specifies is simple:

  • Individuals can choose a term posted at Customer Commons or the equivalent
  • Companies can agree to the individual’s choice or not
  • The decision can be recorded identically by both sides
  • Data about the decision can be recorded by both sides and kept for further reference, auditing, or dispute resolution
  • Both sides can know and display the state of agreement or absence of agreement (for example, the state of a relationship, should one come to exist)

MyTerms not a technical spec, so implementations are open to whatever. Development on any of those can start now. So can work in any of the six areas listed above.

The biggest thing MyTerms does for customers—and people just using free services—is getting rid of cookie notices, which are massively annoying and not worth the pixels they are printed on.  If a company really does care about personal privacy, it’ll respect personal privacy requirements. This is how things work in the natural world, where tracking people like marked animals has been morally wrong for millennia. In the digital world, however, agreements need to be explicit, so programming and services can be based on them. MyTerms does that.

For business, MyTerms has lots of advantages:

  • Reduced or eliminated compliance risk
  • Competitive differentiation
  • Lower customer churn
  • Grounds for real rather than coerced relationships (CRM+VRM)
  • Grounds for better signaling (clues!) going in both directions
  • Reduced or eliminated guesswork about what customers want, how they use products and services, and  how both might be improved

Lawyers get a new market for services on both the buy and sell sides of the marketplace. Companies in the CMP (consent management platform) business (e.g. Admiral and OneTrust) have something new and better to sell.

Lawmakers and Regulators can start looking at the Net and the Web as places where freedom of contract prevails, and contracts of adhesion (such as what you “agree” to with cookie notices) are obsolesced.

Developers can have a field day (or decade). Look for these categories to emerge

  • Agreement Management Platforms – Migrate from today’s much-hated consent management platforms (hello OneTrust, Admiral, and the rest).
  • Vendor Relationship Management (VRM) Tools and services – Fill the vacuum that’s been there since the Web got real in 1995.
  • Customer Relationship Management (CRM) – Make its middle name finally mean something.
  • Customer Data Return (CDR) – Give, sell back, or share with customers the data you’ve been gathering without their permission since forever. Talking here to car companies, TV makers, app makers, and every other technology product with spyware onboard for reporting personal activity to parties unknown.
  • Platform Relief –  Free customers from the walled gardens of Apple, Microsoft, Amazon, and every other maker of hardware and software that currently bears the full burden of providing personal privacy to customers and users. Those companies can also embrace and help implement MyTerms for both sides of the marketplace.
  • Personal AI (pAI)– Till and plant a vast new greenfield for countless companies, old and new. This includes Apple (which can make Apple Intelligence truly “AI for the rest of us” rather than Siri in AI drag), Mozilla (with its Business Accelerator for personal AI) , Kwaai (for open source personal AI), and everyone else who wants to jump on the train.
  • Big meshes of agents, such as what these developers are all working on.

In the marketplace, we can start to see all these things:

  • Predictions made by The Intention Economy: When Customers Take Charge finally come true.
  • New dances between customers and companies, demand and supply. (“The Dance” is a closing chapter of The Intention Economy.)
  • New commercial ecosystems can grow around a richer flow of clues in both directions, based on shared interest and trust between demand and supply.
  • Surveillance capitalism will be obsolesced — and replaced by an economy aligned with personal agency and respect from customers’ corporate partners.
  • A new distributed P2P fabric of personally secure and shared data processing and storage — See what KwaaiNet + Verida, for example, might do together.

All aboard!


†Speaking for myself in this post. I invite the other two surviving co-authors to weigh in if they like.

*At this writing, the Cluetrain website, along with many others at its host, is offline while being cured of an infection.  To be clear, however, it will be back on the Web. Meanwhile, I’m linking to a snapshot of the site in the Internet Archive—a service for which the world should be massively grateful.

**The thesis that did the most to popularize Cluetrain was “Markets are conversations,” which was at the top of Cluetrain’s ninety-five theses. Imagining that this thesis was just for them, marketers everywhere saw marketing, rather than markets, as “conversations.” Besides misunderstanding what Cluetrain meant by conversation (that customers and companies should both have equal and reciprocal agency, and engage in human ways), marketing gave us “conversational” versions of itself that were mostly annoying.  And now (thank you, marketing), every damn topic is now also a fucking “conversation”—the “climate conversation,” the “gender conversation,” the “conversation about data ownership.” I suspect that making “conversation” a synonym for “topic” was also a step toward making every piece of propaganda into a “narrative.” But I digress. Stop reading here and scroll back to read the case for MyTerms. And please, hope that it also doesn’t become woefully misunderstood.

« Older posts

© 2026 ProjectVRM

Theme by Anders NorenUp ↑