On Sunday night, shoppers who asked Meta's Muse agent to buy something on Amazon ran into a new kind of checkout error: a popup warning that continued access by an unauthorized AI agent violates Amazon's Conditions of Use. Amazon has confirmed it cut off Meta's personal AI agent from shopping on Amazon.com, escalating a year-long fight over who gets to do the clicking when software buys things on your behalf.

The block matters for reasons far beyond one app. Muse became the most-downloaded free iPhone app in the US within a week of its September 8 launch. Amazon, for its part, is where Americans actually spend money online, and the company made more than $68 billion in advertising revenue last year, almost all of it dependent on humans browsing its pages. Agents don't browse. They transact.

The Sunday-night block#

Amazon says it tried the diplomatic route first. Before any technical block, it asked Meta to voluntarily exclude Amazon.com from the Muse experience. According to Amazon, Meta never told the company the agent would access the store at all — Muse simply showed up, uninvited and unannounced. When the request went nowhere, the popup went live for Muse users attempting Amazon checkouts.

Amazon confirmed the cut-off to GeekWire on Sunday night and reiterated it in statements to other outlets on Monday. Meta did not respond to requests for comment that evening.

Amazon's three objections#

Amazon's case against the agent clusters around three complaints, all of which boil down to one idea: Muse arrived acting like a customer without ever identifying itself as a machine.

  • No permission, no notice. Amazon says Meta never asked for permission and never disclosed that Muse would browse or buy on its storefront. In the company's words, "third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate."
  • No identity. Muse does not declare itself as automated software when it browses. Amazon says that makes it an undisclosed third party moving through customer accounts, processing transactions and handling sensitive data without the retailer's knowledge or consent.
  • Credentials on file. Amazon says the agent appears to capture and store customer login credentials, giving it reach into account pages and order history — a privacy and security risk. Meta has previously said Muse has no visibility into passwords or payment methods and keeps shared credentials in secure storage the agent can use without seeing them.

There is also an economic complaint hiding inside the legal one: Amazon says agentic shopping bypasses the personalization and recommendations it builds into the shopping experience — the browsing flow that produces its ad and discovery revenue.

Meta's defense#

Meta's version, as stated at launch, is that the agent was architected for exactly this kind of task. Muse runs on a secure virtual machine with its own browser, checks with the user before sensitive actions like purchases, and a separate monitoring agent called Sentinel has to approve anything Muse sends to the internet. The credential-sharing flow — where the agent uses credentials it cannot see — was presented as a security feature, not a hack.

None of that satisfied Amazon. And the dispute is sharpened by the fact that the two companies are otherwise deep partners: Amazon products have been purchasable inside Facebook and Instagram since 2023, and Meta signed a multibillion-dollar AWS deal in April to run agentic AI workloads on Amazon's Graviton chips. One partner's agent is now being told the store is closed to it.

The wider war over checkout#

This is not Amazon's first fight with an agent — it is the opening of a second front. For the past year Amazon has tried to keep outside shopping agents off its site, including a 2025 lawsuit against Perplexity over its Comet browser, which Amazon accused of violating the federal Computer Fraud and Abuse Act. Amazon won a preliminary injunction in March, then lost it on August 4, when a Ninth Circuit panel ruled that the customer — not the AI company — was the party accessing Amazon's computers. The court denied Amazon's rehearing request on September 10.

That ruling is the tell. With the hacking theory weakened, Amazon has pivoted to contract law — the Muse popup doesn't accuse anyone of hacking; it cites Amazon's Conditions of Use. GeekWire also reports Amazon has moved to block shopping agents from Google and OpenAI. The message to every lab building a shopping agent is the same: negotiate first, or expect a popup.

Amazon is also drawing a line between outsiders and its own agents. It launched Alexa for Shopping in May, and its Buy for Me feature shops on outside brands' sites — but, Amazon points out, it identifies itself and lets brands opt out. In Amazon's framing, the problem isn't agentic commerce. It's agentic commerce that arrives uninvited and anonymous.

What to watch#

Amazon says it is in direct conversation with Meta about the dispute and declined to say whether legal action is on the table. Three things will decide how big this gets: whether Meta complies and pulls Amazon out of Muse, or holds its ground and dares Amazon to escalate; whether Amazon's terms-of-service approach succeeds where its hacking claims failed — a playbook every retailer will copy; and whether the industry finally agrees on agent identity standards, since the entire fight turns on one missing piece of information. The agent never says who it is.