Amazon’s Muse Block Makes AI Shopping a Contract Fight
Amazon’s block on Meta’s Muse exposes a contract fight over AI shopping, merchant consent, user agency, account security and control of online commerce.
Written by AI. Dev Kapoor

Amazon blocked Meta’s Muse agent from shopping on Amazon.com less than two weeks after Meta launched the service in the United States on September 8.
Users who tried to send Muse shopping received a popup: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” GeekWire, which first reported the block, obtained Amazon’s explanation. The retailer said Meta had given it no advance notice, Muse did not identify itself while browsing, and the agent appeared to capture and store customer credentials and scrape account data.
The popup’s contractual language places the dispute on contested ground. A customer has asked an agent to shop using that customer’s account, while the merchant says the software company operating the agent lacks permission to enter. The practical question is who gets to delegate access: the account holder, the merchant, or both.
That question will follow shopping agents well beyond this week’s popup. It affects developers deciding whether browser automation is sufficient, merchants deciding what software may reach checkout, and users deciding whether an agent can exercise the access they already possess.
What Muse is Doing Inside the Browser
Muse carries out multi-step jobs across services including email, calendars, payments, dining and shopping. Meta says it runs inside a secure virtual machine with its own browser. Where a public API exists, Muse can connect through credentials supplied by the user. Without an API, Meta says the agent can use a browser as the user would.
That last mechanism is where a product feature becomes a governance fight. APIs give service providers a controlled doorway, with authentication rules, rate limits and the ability to withdraw access. Browser agents can work around the absence of that doorway by operating the interface built for humans. To a user, that can look like delegation. To a merchant, it can look like an undisclosed company inserting itself into an account and transaction.
Amazon’s strongest argument concerns accountability. The company told GeekWire that third-party purchasing applications should operate openly and respect a service provider’s decision about participating. It compared agents with food-delivery apps and online travel agencies, intermediaries that transact through relationships with restaurants, stores or airlines.
Meta’s disclosed security design addresses a different part of the risk. Gizmodo reported that Meta says Muse cannot see passwords or payment methods, keeps supplied credentials in secure storage and asks for approval before consequential actions such as purchases. Those protections may reduce the chance that the model itself exposes a password or buys without confirmation. They do not answer Amazon’s complaint that the agent fails to disclose its identity to the merchant.
Public reporting does not establish whether Muse’s safeguards failed, whether customer data was exposed, or whether an unauthorized purchase occurred. Amazon has framed possible access to account pages and order history as a security and privacy concern, but the available accounts describe a dispute over design and permission rather than a documented breach.
The Route from Anti-Hacking Law to Contract Terms
Amazon arrived here after a bruising round with another agent maker. In 2025, it sued Perplexity over the Comet browser, alleging that its access to Amazon accounts violated the federal Computer Fraud and Abuse Act. A federal judge granted Amazon a preliminary injunction in March 2026.
The Ninth Circuit vacated that order on August 4. The appellate panel concluded that Amazon was unlikely to show Perplexity itself accessed its computers. The judges viewed the customer as the accessing party, with Comet acting as the customer’s tool. The court denied Amazon’s rehearing petition on September 10, while leaving contract and terms-of-service claims available.
Muse launched two days before that rehearing denial. When Amazon blocked it, the notice cited the Conditions of Use and made no hacking accusation.
The sequence supports a cautious inference: contract enforcement now offers Amazon a more promising route than the anti-hacking theory rejected at the preliminary-injunction stage. It does not prove the appellate ruling caused Amazon to choose the popup’s wording. Amazon has not disclosed its internal legal strategy, and it declined to say whether it would sue Meta. Still, the wording tracks the legal avenue that remained open with impressive neatness. Lawyers do enjoy a labeled drawer.
The Perplexity comparison has limits. Comet and Muse are different products operated by different companies, and the Muse dispute has not produced a reported lawsuit. A preliminary-injunction ruling also does not settle every claim on the merits. What the precedent supplies is a working model of agency: when a person instructs software to use an account, a court may treat the person as the accessing party. Amazon’s contract position asks a second question, whether the customer agreed not to delegate that access to an agent the merchant has rejected.
Amazon’s Own Agent Sharpens the Consent Question
Amazon does not oppose automated shopping across the board. Its Buy for Me feature retrieves products from external brands’ sites. Amazon says that agent identifies itself and allows brands to opt out.
That comparison reveals the permission structure Amazon wants: identification, merchant awareness and a veto. Under that model, user approval remains necessary but cannot authorize the agent by itself. Meta’s browser-based approach starts closer to the user’s side of the ledger, where the agent exercises credentials and instructions supplied by the account holder.
Neither model offers a neutral rule for the open web. Merchant control can protect account security, transaction reliability and infrastructure from opaque automation. It can also let dominant platforms decide which intermediaries may compare products, skip sponsored placements or sit between the platform and its customers. User delegation can expand competition and accessibility, while also creating hard questions about credential custody, liability and identifying the software making requests.
Amazon has a commercial interest in preserving the interface around each sale. The company generated more than $68 billion in advertising revenue last year, according to GeekWire. Shopping agents that move directly from request to purchase could reduce opportunities to show sponsored products, although the available reporting does not establish how much advertising exposure Muse actually bypassed or whether ad revenue motivated this block.
The two companies are collaborators elsewhere. Amazon products have been purchasable through Facebook and Instagram since 2023, and Meta signed a multibillion-dollar agreement in April to run agentic AI workloads on Amazon’s cloud. Cooperation in cloud infrastructure and social commerce plainly has not produced a standing invitation for Meta’s agent inside Amazon accounts.
Every Checkout May Need an Agent Policy
Amazon has also moved against shopping agents from Google and OpenAI. Palo Alto Networks CEO Nikesh Arora called the Muse episode a “bigger battle than anyone anticipates,” The Information reported. He predicted that Apple, Google and AI companies would eventually offer similar personal agents.
That forecast remains a prediction, but the current conflict gives developers and merchants immediate work. Agent builders need to decide whether a user’s authorization is enough, how agents identify themselves, what credentials they retain and what happens when a site explicitly refuses access. Merchants need terms and technical controls that say whether agents may browse, enter accounts and complete purchases. A buried prohibition paired with selective enforcement will create its own governance mess.
Users sit awkwardly between those policies. They supply the credentials, bear the consequences of a mistaken purchase and may reasonably expect software to perform an action they could perform themselves. Yet their accounts operate on infrastructure controlled by a merchant that also bears fraud, support and reliability costs.
The Muse block does not settle who should win that allocation of power. It shows where the argument is moving after the Ninth Circuit narrowed Amazon’s anti-hacking path: into contracts, disclosure protocols and platform rules that most customers will accept without reading. The next generation of shopping agents may be built in model labs, but their effective permissions could be written in the checkout terms.
More Like This
Meta Muse’s Download Boom Meets Platform Gatekeepers
Meta’s Muse raced up download charts, but Amazon’s block and Shopify’s welcome show why platform access, user trust and retention will decide its future.
Meta Muse Tests Privacy Limits for Personal AI Agents
Meta Muse shows why proactive AI agents need broad access, visible controls and clear audit trails before users trust them with messages and daily tasks.
The Agentic Commerce Protocol War, Explained
AI agents are about to start spending your money autonomously. Six protocol camps are fighting over who's liable when something goes wrong. Here's the map.
Why Shoppers Hesitate to Let AI Agents Complete the Checkout
Meta's Muse can email, book travel, and pay autonomously. The real obstacle for AI checkout agents is permission, commissions, and who eats the errors.
Stripe Wants to Run Your Entire Money Stack
Stripe's Will Gaybrick lays out a future of AI agents, disappearing checkouts, and stablecoins. What it means for businesses that write real checks.
Agentic Commerce Is Rewriting Who Controls the Sale
Stripe's agent commerce launch signals a fundamental power shift in e-commerce—from seller-controlled funnels to buyer-driven AI agents. Here's what's actually changing.
Cinematic iPhone Video on a Budget Runs on Apple's Terms
Connor Smith shows how to shoot cinematic iPhone video for under $100. But the best workflow depends on Apple's closed stack—and that's the real story.
Alberto Brandolini on Managing Software Model Complexity
EventStorming creator Alberto Brandolini argues at GOTO 2025 that bounded contexts and visual maps are the antidote to software's inevitable drift toward chaos.