AI News

Amazon Blocked Meta’s Muse From Shopping. The Fight Is About Who Controls the Checkout

Amazon has blocked Meta’s Muse AI agent from shopping on Amazon.com, turning a routine product task into an early test of who gets to control AI-mediated commerce.

The Verge reported the block on September 21. Amazon says Meta did not ask permission, Muse does not identify itself while browsing, and the agent’s access to customer accounts creates privacy and security risks. Meta’s launch materials say Muse isolates each user in a secure virtual machine, keeps credentials hidden from the model, asks for approval before purchases and records an audit trail.

Both positions can be true at once. A user may want an agent to act for them, Meta may build meaningful safeguards around that delegation, and Amazon may still refuse an undisclosed automated system access to its store. The fight begins where those permissions collide.

The short version: Amazon’s security argument is credible, but security is only part of the story. An outside agent can also move product discovery, comparison and purchase decisions away from Amazon’s interface. That threatens Amazon’s control over recommendations, sponsored placements, customer data and the checkout relationship.

What Amazon blocked

Meta launched Muse in the United States on September 8 as a personal agent that can work across email, calendars, payments, travel and shopping. It runs in a dedicated cloud-based virtual machine with its own browser. If a service offers an API, Muse can connect through that route. If it does not, Meta says the agent can use the service through a browser in much the same way a person would.

That browser fallback is where the Amazon dispute starts. According to GeekWire’s report, Amazon asked Meta to remove Amazon from the Muse experience. When Meta did not do so, Amazon placed an anti-bot wall in Muse’s path. Users attempting the task saw a notice that access by an “unauthorized AI agent” violated Amazon’s Conditions of Use.

The Register independently tried the shopping flow and reported that Muse stopped at the block rather than pushing past it. Kingy.ai did not attempt to evade Amazon’s controls or complete a purchase through Muse.

Amazon told GeekWire that Muse had not disclosed its identity, could reach order history and account pages when directed by a user, and appeared to capture and store credentials. Meta disputes the credential framing. Its Muse launch documentation says passwords and payment methods go into secure storage and remain hidden from the Muse model, even when the agent uses them to sign in.

That distinction matters, but it does not settle Amazon’s concern. A credential can be protected from a model while still being used by a third-party system to enter a customer account. Amazon wants the agent, its operator and the scope of that access disclosed before the session begins.

Amazon’s case is about consent at two levels

Meta’s model begins with user consent. The customer connects an account, specifies a task and approves sensitive actions. Amazon’s model adds merchant consent. The customer’s instruction is necessary, but the destination service must also agree to receive an automated visitor.

Amazon has already written that position into some of its policies. Its Associates Program agent terms require agents to identify themselves in requests, avoid concealing automation, refrain from bypassing CAPTCHAs or blocking measures, and stop accessing content when Amazon asks. A March 2026 Business Solutions Agreement update similarly told sellers that agents must identify themselves, follow Amazon’s agent policy and cease access on request.

The security rationale is not invented. Shopping agents can read addresses, order histories, saved preferences and payment-adjacent data. They can also make costly mistakes, misunderstand a variant, choose the wrong seller or act on a malicious instruction embedded in a page. Meta itself acknowledged the risk by building a separate Sentinel agent to inspect outgoing actions and by requiring approval before purchases.

Independent reporting also shows why caution is warranted. Reuters reported internal Muse tests in which users encountered reliability problems and cases involving sensitive information. Meta said it delayed the product to improve safety and described its release threshold as a minimum across security, privacy and performance. Those reports do not prove that Muse mishandled an Amazon account, but they make unrestricted access hard to treat as a harmless browser feature.

The business conflict behind the security language

An AI shopping agent does more than automate clicking. It can decide which products make the shortlist, which attributes matter, what counts as a good review and whether a sponsored result deserves attention. If it completes those steps before the user reaches Amazon, much of Amazon’s influence over the purchase has already disappeared.

Amazon openly connects agentic shopping with advertising. In a June 2026 explainer, Amazon Ads described Alexa for Shopping as a system that can compare products, track price history, build carts and automate routine purchases. The same article tells advertisers that Amazon’s conversational shopping experience shortens the path from an ad impression to a purchase.

Muse changes who controls that path. A user can begin inside WhatsApp or the Muse app, let Meta’s agent form the shortlist and arrive at a retailer only when payment is due. Amazon may still get the sale, but it risks losing the search session, sponsored discovery, recommendation data and the chance to steer the basket.

The asymmetry is striking because Amazon operates an outside-shopping agent of its own. Buy for Me can purchase selected products from brand websites when those products are not sold in Amazon’s store. Amazon says its tool identifies itself and allows merchants to opt out. That disclosure is a meaningful difference, although it also reveals Amazon’s preferred rule: agents may cross storefront boundaries only when the storefront has been given a choice.

Amazon and Meta are partners elsewhere. Amazon products can be bought inside Facebook and Instagram, and the companies have a large cloud relationship. Those arrangements are negotiated. Muse’s browser model attempts to make a customer’s delegation sufficient even without a commercial integration, which is precisely the precedent Amazon does not want.

The legal line is still moving

Amazon has already fought a similar battle with Perplexity over the Comet browser. In March 2026, a federal district court granted Amazon a preliminary injunction based on federal and California computer-access laws. On August 4, the Ninth Circuit vacated that injunction.

The appellate court concluded that, on the record before it, the user accessed Amazon with help from Perplexity’s assistant. Perplexity itself had not “accessed” Amazon’s computers in the sense required by the Computer Fraud and Abuse Act. The court warned against turning ordinary computer-assisted behavior into hacking and said an injunction would unnecessarily limit consumer choice and a young technology.

That decision is important, but it is not a universal permission slip for shopping bots. The opinion repeatedly limits itself to the specific technology and evidence in the Perplexity case. Comet ran locally on the user’s machine and sent screenshots to Perplexity’s servers. Muse runs in a Meta-hosted secure virtual machine, so its architecture may present a different record. The Ninth Circuit also said its ruling did not prevent Amazon from regulating access through private terms of service.

Amazon’s current notice to Muse users cites its Conditions of Use rather than accusing Meta of hacking. That choice fits the legal opening the Ninth Circuit left in place. Contract claims, account restrictions, technical blocking and negotiated access can remain available even when an anti-hacking theory fails.

Is there a workaround?

There are useful workarounds for the shopping task. There is no responsible reason to disguise Muse as a human, defeat a CAPTCHA, rotate browser fingerprints or otherwise evade Amazon’s block. Amazon’s published agent terms expressly reject that conduct, and attempting it could put a customer account at risk.

Alternative What it preserves Trade-off
Research with Muse, buy manually Let the agent compare specifications, reviews, price ranges and alternatives from accessible sources. Open Amazon yourself for the final search and checkout. The handoff loses full automation, and the user must verify that the Amazon listing matches the researched product.
Use an agent-friendly retailer Muse can complete the workflow on merchants that permit browser agents or support its payment methods. Selection, price, delivery speed and return terms may differ from Amazon.
Use Alexa for Shopping Amazon’s own assistant can research and act inside the Amazon ecosystem with the platform’s approval. The customer accepts Amazon’s ranking, data environment and commercial incentives.
Build an approved integration Retailers and agent developers can use documented feeds, APIs or a negotiated connection with clear identity and permissions. A product-data or advertising integration does not automatically authorize consumer-account access or checkout. Approval and product scope matter.
Keep a human at the purchase gate The agent prepares a shortlist or cart elsewhere; the user reviews seller, variant, delivery date and total before paying. Less convenient, but safer for purchases with returns, subscriptions or meaningful cost.

The cleanest workaround today is research plus manual checkout. Ask the agent for an exact product specification, model number, acceptable substitutes, target price and warning signs. Then search Amazon directly and confirm the seller, variant, warranty, delivery date and return policy. This keeps the agent useful without asking it to cross a blocked boundary.

Developers should resist treating Amazon’s advertising MCP server or Product Advertising API as hidden checkout routes. Those products have defined scopes and contracts. An integration that can retrieve approved product information is not automatically authorized to enter a consumer account or place an order.

What is most interesting about the standoff

Agent identity is becoming internet infrastructure

Websites have long distinguished browsers, crawlers and malicious bots. Personal agents complicate that taxonomy because they act with a real customer’s instruction but run software controlled by another company. A useful standard will need to answer more than “bot or human?” It should identify the agent operator, the user’s delegated authority, requested permissions, payment method, audit trail and a way for the merchant to accept, limit or reject the task.

The fight over the interface is a fight over market power

The company that answers the shopping question can influence the sale before checkout. It chooses which sources to trust, how to rank options and whether to expose advertising. Retailers risk becoming fulfillment back ends for agents they do not control. Agent companies risk becoming dependent on whichever large platforms grant access.

Brands may need to sell to machines and people at the same time

Product photography and persuasive copy still matter to people. Agents care more about structured attributes, inventory, price, delivery, warranty and return rules they can parse reliably. Merchants that make those facts machine-readable may appear more often in agent recommendations, especially when a dominant marketplace is unavailable.

Payment protection may become the practical differentiator

Meta says Muse can check out with Stripe’s Link using a one-time card and purchase protections for eligible transactions. Amazon has its own guarantees, fraud systems and account history. As agents move from recommendations to purchases, consumers will care less about whether a demo can click “Buy” and more about who handles a wrong item, a price drop, a lost package or an unauthorized transaction.

A user’s right to delegate remains unresolved

The Ninth Circuit’s Perplexity ruling gives weight to the idea that software can act as a user’s tool. Amazon’s terms and technical controls give weight to a service provider’s right to decide how its systems are accessed. A durable settlement will probably require standardized disclosure and scoped permission rather than treating every agent as either an ordinary browser or an intruder.

What happens next

Amazon told GeekWire that it was in direct conversation with Meta. A negotiated integration could resolve the immediate block if Muse identifies itself, limits account access, follows Amazon’s rules and gives Amazon enough operational control. Meta could also remove Amazon from Muse’s supported shopping experience, leaving users with a manual handoff.

The wider dispute will continue regardless. Google, OpenAI, Perplexity, Meta and Amazon all want their assistants to become the place where users express intent. Retailers want access to those customers without surrendering ranking, advertising and transaction control. Consumers want an agent that can act across the web without rebuilding every task around commercial alliances.

For now, Amazon has the stronger practical position because it controls the storefront. Muse can respect the block, send the user elsewhere or negotiate access. Trying to sneak through would weaken Meta’s claim that personal agents deserve to be treated as trusted representatives.

Amazon’s block also exposes a limit in the promise of a universal personal agent. Intelligence is not enough. An agent needs permission, identity, payment protection and cooperation from the services it is meant to use. Until the industry builds those layers, the web’s most valuable storefronts can still close the door.

Kingy.ai’s AI agent adoption playbook explains how to set permissions, approval gates and audit trails before an agent touches real accounts. Our State of AI Agents 2026 report covers the broader shift from chat interfaces to systems that take action.

Reporting checked September 21, 2026 (Pacific time). This analysis draws on Meta’s product documentation, Amazon’s published agent terms and product materials, the Ninth Circuit’s Perplexity decision, and reporting from The Verge, GeekWire, Reuters and The Register. Kingy.ai did not test an Amazon purchase through Muse or attempt to bypass Amazon’s block. Featured artwork is an original AI-generated editorial illustration.