2026-09-22 18:22 UTC
DANGMUAAI & Developer Tools, Decoded
BackAgents

Amazon Blocks Meta's Muse AI Agent From Shopping Amazon

Amazon cut off Meta's Muse agent over identification and credential concerns, after a judge sided with Perplexity in a similar fight in August.

DangMua EditorialSep 21, 20265 min read
Amazon Blocks Meta's Muse AI Agent From Shopping Amazon

Amazon has blocked Meta's Muse AI agent from buying on Amazon.com — the second AI shopping service it has moved to shut out since November.

Muse users started hitting an error message on Sunday night. As first reported by GeekWire and picked up by both The Verge and TechCrunch on September 21, the popup read: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed."

The practical effect is blunt. Anyone who was using Meta's assistant to place Amazon orders now has to complete the purchase somewhere else.

Amazon's stated objections are about identification, not capability

The reasons Amazon gave are worth reading closely, because they are procedural rather than technical. According to GeekWire's reporting, Meta did not notify Amazon that Muse would access its store. Amazon also raised privacy and security concerns over Muse failing to identify itself while browsing, and over the agent seemingly capturing customer credentials.

An unnamed Amazon spokesperson put the company's position this way in a statement to GeekWire: "We think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate."

Two requirements are buried in that sentence: operate openly, and honour the host's decision about participation. Neither is about whether the agent works well.

Meta's own claims about Muse point the other direction. When it launched the agent earlier this month, Meta said Muse cannot see secure login details or card payment information. The Verge reports that it used Muse during testing to successfully buy tank tops from Amazon while other products sat in the basket — so the flow demonstrably worked before the block. The Verge also notes that privacy concerns have surfaced since launch, including reports that Muse can see the contents of user messages despite not having the necessary access permission enabled.

The Perplexity case is the precedent everyone will cite

This is not Amazon's first move against an outside shopping agent, and the earlier one did not go its way. The Verge reports that Amazon sued Perplexity in November last year to keep its platform out of the AI search provider's Comet shopping experience, and that a judge sided with Perplexity in August.

That matters for how this block is likely to play out. A terms-of-use popup is a unilateral technical measure that needs no court's agreement, and Amazon reached for it a month after losing the litigated version of the same fight.

There is a quieter measure running alongside it. Amazon's order confirmation emails have looked notably sparse since July, according to The Verge, with specific item names and product images omitted — limiting what external AI services can mine from a user's inbox.

Why a retailer might not want agentic commerce yet

TechCrunch's Russell Brandom offers two readings, and flags both as interpretation rather than reporting. The first is competitive: he notes Amazon has its own cohort of foundation models and one of the most popular inference platforms on the internet, and asks why it would open the doors to Muse absent any legal obligation.

The second reading is operational, and more useful for anyone building in this space. As Brandom frames it, if Muse makes a bad order, Amazon is the party that cleans it up — handling both the angry customer and the angry vendor. He adds that while Muse has one of the lower hallucination rates as AI models go, it is still pretty far from zero, and suggests Amazon may want to wait a few more release cycles even if it does see an opportunity in agent-driven commerce.

That is a liability argument, not a technology argument. The error rate does not have to be high for the returns and chargebacks to land on the merchant rather than on the agent vendor.

What this changes if you are building a shopping agent

The following is analysis, not reporting from the sources above. But the shape of Amazon's objections suggests a few things worth planning around.

  • Treat the host platform as a counterparty, not a surface. The stated complaint led with notification and self-identification. An agent that announces itself and negotiates access is arguing from a different position than one discovered through a popup.
  • Assume credential handling will be audited. Amazon's concern about credential capture is the kind of claim that survives a vendor's own assurances. Build so that what the agent can see is demonstrable, not just stated.
  • Design for the block, not around it. Blocking is cheap, immediate, and needs no ruling. A checkout flow that degrades to handing the user a ready-to-confirm cart will survive a platform cutting you off; one that silently fails will not.
  • Read the permissions gap as the real reputational risk. The most damaging report against Muse is not the block — it is the claim that it saw message contents without the relevant permission enabled.

What to watch next

The Verge says it has reached out to Meta for comment. The open questions are whether Meta pursues the Perplexity route now that there is a favourable ruling on the books, whether other large retailers follow Amazon's popup, and whether any agent vendor accepts an identification standard in exchange for sanctioned access. The first retailer to say yes to a self-identifying agent will set the terms for everyone else.

More from DangMua