Amazon has blocked Meta’s new Muse personal AI agent from shopping on Amazon.com, turning what was supposed to be a new era of automated online shopping into an early confrontation over privacy, security, customer accounts and who controls the digital storefront.
Image Courtesy : Samuel Boivin/NurPhoto
The move came only days after Meta launched Muse as a general-purpose personal AI agent capable of carrying out tasks for users rather than simply answering questions. Amazon says Meta did not obtain permission for Muse to access its marketplace, that the agent does not identify itself while browsing Amazon, and that its handling of customer credentials creates potential security and privacy risks.
Users attempting to shop on Amazon through Muse began seeing a warning saying that continued access by an unauthorized AI agent violated Amazon's Conditions of Use. Amazon said it had previously asked Meta to exclude Amazon from Muse's shopping capabilities but that the companies did not reach an agreement.
The confrontation highlights a much bigger question emerging across the technology industry: what happens when an AI agent begins navigating the internet on behalf of a person?
For decades, websites were designed around the assumption that a human would visit, search for products, compare options, log into an account and ultimately click the button that completes a transaction.
AI agents change that model.
Instead of opening Amazon and searching for a product manually, a customer can tell an agent what they want and allow the software to navigate websites, compare products, fill out forms and potentially complete a purchase.
Meta's Muse was specifically designed around this idea.
When Meta introduced Muse on September 8, the company described it as a personal AI agent capable of taking action across the services people use every day. Rather than functioning solely as a chatbot, Muse can open a browser, fill out forms, work on longer-running tasks and return to the user when it needs approval for sensitive actions such as sending an email or making a purchase.
Meta says Muse runs inside a dedicated virtual machine with its own browser and security controls. A separate system called Sentinel monitors what the agent attempts to send to the internet, and Meta says Muse requires user approval before sensitive activities.
The company also says credentials provided by users are stored securely and that Muse itself does not have visibility into users' passwords or payment information. For purchases, Meta has integrated Stripe's Link system, which can generate a one-time-use card so that a user's actual payment-card details remain hidden from the agent.
Those safeguards are central to Meta's argument that Muse is designed to operate securely.
Amazon, however, is looking at the situation from a different perspective.
From Amazon's standpoint, the issue is not simply whether Meta has built security protections inside Muse. The issue is whether Meta has the right to send an automated agent onto Amazon's website, interact with customer accounts and conduct transactions without Amazon agreeing to that arrangement.
Amazon says it did not authorize Muse to do so.
The distinction could become one of the defining legal and technological questions of the agentic-AI era.
Traditional software integrations generally operate through APIs or other mechanisms established by the service provider. A company that wants to let another platform access its data can create authentication systems, usage restrictions, rate limits and other controls.
Muse introduces another possibility.
Meta says that when a service has a public API, Muse can connect through that interface using credentials supplied by the user. But when a service does not offer an API, Meta says Muse can interact with it through a browser in much the same way a person would.
That browser-based approach is precisely what makes the Amazon dispute so significant.
If an AI agent can operate a website through a browser without a formal integration, retailers could suddenly find themselves dealing with software users they did not explicitly authorize.
Amazon argues that such agents should operate transparently and respect the decisions of service providers.
The company has compared the situation with established third-party services such as food-delivery companies and travel agencies. Those businesses generally operate through commercial relationships or other arrangements with the companies whose services they facilitate. Amazon's position is that AI shopping agents should similarly obtain permission rather than independently accessing a retailer's website.
Meta has not publicly agreed with that interpretation.
The company had not immediately responded to requests for comment when the Amazon blocking was first reported, leaving the exact nature of the companies' discussions unclear. Amazon said it remained in direct conversation with Meta about the issue.
The credential question adds another layer to the dispute.
Amazon says Muse appears to capture and store customer credentials as it operates on the site. Meta has disputed the characterization, saying Muse does not have visibility into users' passwords or payment methods and that credentials supplied by users are placed into secure storage.
The disagreement illustrates why AI agents create a different security problem from conventional websites and applications.
A traditional application might store a password and use it in the background. An AI agent, by contrast, may actively navigate websites, interpret pages, make decisions and interact with accounts based on a user's instructions.
That means the security boundary is no longer simply between a person and an application.
It potentially extends across the person, the AI company, the agent's virtual environment, the retailer, payment providers and every other service the agent encounters.
If any part of that chain behaves unexpectedly, responsibility can become difficult to establish.
The Amazon dispute also comes at a particularly important moment for the retail industry.
Amazon itself has been developing its own AI-powered shopping tools. The company launched Alexa for Shopping in May, while its Buy for Me feature can find products on external brand websites and facilitate purchases. Amazon says Buy for Me identifies itself and allows brands to opt out.
That means Amazon is not rejecting the concept of agentic shopping altogether.
Instead, the company appears to be drawing a distinction between AI agents operating with retailer participation and outside agents that arrive without an established relationship.
That distinction could become commercially significant.
If consumers increasingly rely on AI agents to find and purchase products, the traditional shopping journey could change dramatically.
Today, Amazon controls much of the experience from search results through product pages, recommendations, advertising, checkout and post-purchase interactions.
An AI agent could sit between the consumer and that experience.
The customer might never see Amazon's search results.
They might never scroll through sponsored listings.
They might never read Amazon's product recommendations.
They could simply tell Muse, another AI assistant or a future agent what they want and receive a recommendation generated somewhere else.
That possibility represents a potential threat to the economics of online retail.
Amazon generated more than $68 billion in advertising revenue last year, according to GeekWire's reporting, making product discovery and customer attention financially important parts of its business.
If AI agents increasingly become the interface between shoppers and retailers, the companies controlling those agents could gain influence over product discovery that has historically belonged to retailers and search engines.
That creates an entirely new layer of competition.
Amazon does not want an outside AI company determining which products its customers see.
Meta, meanwhile, wants Muse to become a general-purpose personal assistant capable of working across the internet.
The consumer sits between those interests.
From the user's perspective, the appeal is straightforward. Instead of spending 30 minutes searching for the right office chair, comparing prices and reading reviews, a person could ask an AI agent to find the best option and handle the process.
The agent could potentially compare multiple retailers at once.
That could make the internet feel less like a collection of individual websites and more like an underlying database of services that AI systems operate on behalf of consumers.
Retailers have obvious reasons to resist that transformation if they believe they are losing control of their customer relationships.
The same conflict is already appearing elsewhere in the technology industry.
Amazon has pursued legal action against Perplexity over its Comet browser, another AI-powered system capable of navigating websites. Amazon won a preliminary injunction earlier in 2026, although the Ninth Circuit later overturned that injunction in August. The court's ruling left potential contractual and terms-of-service arguments available to Amazon.
The Muse dispute therefore arrives in the middle of a broader struggle over automated access to websites.
The legal question is complicated because an AI agent may technically be acting on behalf of a legitimate customer.
That raises an important distinction: Is the customer accessing Amazon, or is Meta accessing Amazon through the customer's account?
The answer could have major implications for the future of AI agents.
If retailers can prohibit outside agents categorically, AI companies may need formal partnerships with individual websites before their agents can operate broadly.
If consumers have a stronger right to instruct software to interact with websites on their behalf, retailers may have less control over how those interactions occur.
The ultimate answer will likely involve a combination of contracts, technical standards, authentication systems and potentially future court decisions.
Security is another major concern.
Amazon says that an unidentified third-party agent navigating customer accounts creates risks because the retailer cannot easily determine what the software is doing or whether the user understands its actions.
Meta's approach attempts to solve the problem by putting controls inside the agent's environment. Muse runs in a dedicated virtual machine, maintains an audit trail and uses Sentinel to monitor internet access.
But Amazon's objection demonstrates that security cannot necessarily be defined only from the perspective of the AI developer.
A system can be secure inside its own environment while still violating the security policies of the website it is accessing.
That is a critical distinction as autonomous agents become more widespread.
Imagine an AI agent that is authorized by its user to shop, book travel, manage subscriptions, negotiate bills and interact with financial services.
Each individual website may have its own policies about automated access.
Without common standards, the agent could encounter a different set of rules everywhere it goes.
The industry may therefore need a new generation of authentication and permission standards designed specifically for AI agents.
Instead of simply asking whether a user is logged in, a website could determine whether an AI agent is acting with delegated authority.
The agent could identify itself, disclose the identity of its user without exposing unnecessary personal information, specify what action it intends to perform and receive permission from the website before continuing.
Such a system could provide retailers with more control while still allowing consumers to delegate tasks to AI.
The Amazon-Meta confrontation demonstrates why those standards may become necessary.
For now, the two companies are taking fundamentally different approaches.
Meta is attempting to make Muse capable of operating across the existing internet.
Amazon is attempting to maintain control over how automated software interacts with its platform.
Neither side has completely defined what the future of agentic commerce will look like.
The confrontation could eventually result in a negotiated integration between the companies. It could also lead to broader restrictions on third-party shopping agents, new commercial agreements or further legal disputes.
The fact that the dispute emerged so quickly after Muse's launch illustrates just how quickly agentic AI is moving from an experimental technology into a practical consumer product.
Muse was introduced on September 8. Less than two weeks later, Amazon had blocked it from shopping on one of the world's largest e-commerce platforms.
That timeline may be more important than the individual dispute.
AI agents are beginning to challenge an assumption that has existed throughout the modern internet: that websites control the interface through which their services are consumed.
In an agent-driven internet, users may increasingly interact with an AI layer instead.
The agent decides what websites to visit, what information to retrieve, what products to compare and potentially what transactions to complete.
That creates enormous convenience for consumers, but it also raises questions about privacy, accountability, advertising, authentication and commercial control.
Amazon's decision to block Muse is therefore about more than one shopping assistant.
It is an early confrontation over the architecture of the agentic internet.
The question is no longer simply whether AI can shop for people.
It is whether retailers will allow AI to become the customer-facing layer between their businesses and the people who buy from them—and, if they do, under whose rules those transactions will take place.
As Meta, Amazon, Google, OpenAI and other technology companies build competing agentic systems, that question is likely to become increasingly difficult to avoid.
