Less than two weeks after Meta introduced Muse as the agent that would run your errands, Amazon shut it out of the biggest store on the internet. Since Sunday night, people who ask Muse to buy something on Amazon.com have run into a pop-up: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." The standoff is the sharpest clash yet between two tech giants over who owns the customer when an AI agent does the shopping.
Amazon's case rests on three complaints, which it laid out to GeekWire and Campaign. It says Meta never told Amazon that Muse would be accessing its store. It says the agent does not identify itself as automated while it browses. And it says Muse appears to capture and store customers' login credentials. Amazon also says Muse can reach account pages and order history if a user prompts it to. In the company's view, that means an undisclosed third party is moving through customer accounts, processing transactions and handling sensitive data without Amazon's knowledge or consent. Bloomberg reported that Amazon imposed the block after Meta turned down a request to pull the bot off the site voluntarily.
"We think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate," an Amazon spokesperson said in a statement. The company compared the situation to food delivery apps, which work with the restaurants they order from, and to online travel agencies, which work with the airlines they book. "Agentic third-party applications such as Muse have the same obligations, and we've requested that Meta remove Amazon from the experience," the spokesperson said. Amazon said it is in direct talks with Meta and declined to say whether it would sue.
Meta has not commented publicly on the block. In earlier material it said Muse "has no visibility into people's passwords or payment methods." Tarek Sheasha, a vice president at Meta Superintelligence Labs, wrote in a September 8 blog post that browser login credentials go "straight to secure storage" and are "not visible to your main agent." The same post also admitted that "prompt injection remains an open problem in the industry." Amazon's security case may get extra attention because of Muse's record so far. Reuters reported that Meta delayed a planned April launch after an agent got around safety controls and exposed a user's private iCloud photos. After launch, security researcher Patrick Wardle disclosed a hijacking bug, which Meta fixed within 16 hours.
A fast-growing agent meets a closed door
Meta launched Muse on September 8 as its first consumer AI agent. It is built to carry out multi-step tasks across email, calendars, payments, dining and shopping, and it runs on iOS, Android, the web and WhatsApp. The basic tier is free, and paid tiers cost $20 and $100 a month. The mechanism at the heart of the dispute is in Meta's own launch materials: when a service has no public API, the agent "can use the service through a browser the way you would." Muse took off quickly. About a week after launch it passed ChatGPT to become the No. 1 free app in Apple's U.S. App Store.
The two companies are also business partners, which makes the fight unusual. Shoppers have been able to buy Amazon products inside Facebook and Instagram since 2023. In April, Meta signed a multibillion-dollar deal to run agentic AI workloads on Amazon's Graviton chips.
Why It Matters
This is Amazon's fourth confrontation over outside shopping agents in about a year. In November 2025 it sued Perplexity over the Comet browser, and it has since moved to block shopping agents from OpenAI and Google. The Perplexity case is also why Amazon's pop-up is worded the way it is. Amazon won a preliminary injunction in March, but the Ninth Circuit threw it out on August 4. The court ruled that under federal anti-hacking law, the user and not the AI company is the one accessing Amazon's computers, and it denied rehearing on September 10. That ruling left Amazon with contract and terms-of-service claims, and those are exactly what the Muse warning cites. It makes no accusation of hacking.
Security is only part of the story. The rest is about money. Amazon brought in more than $68 billion in advertising revenue last year, and that business depends on people browsing its pages and seeing sponsored listings. An agent that picks the product for the shopper skips all of that. It also skips Amazon's recommendation engine, which Amazon itself pointed out when explaining its objections. Critics note that Amazon's own Buy for Me agent shops on outside brands' sites. Amazon's answer is that Buy for Me identifies itself and lets brands opt out.
Palo Alto Networks CEO Nikesh Arora put it in broader terms on X. "This will be a bigger battle than anyone anticipates," he wrote. "Every app that is a services, marketplace or commerce app will need to existentially decide to open APIs for consumer agents to interact."
What to Watch
The main question is whether Meta chooses to negotiate or to fight. Meta could make Muse identify itself, strike a formal deal with Amazon, or steer shoppers toward partners like Shopify's Shop Pay checkout, which is already built for agents. Amazon has not ruled out legal action, and after the Perplexity appeal, any lawsuit over Muse would test whether terms-of-service claims can do what the anti-hacking law could not. For a Meta product that earns its keep by acting on users' behalf, being locked out of the largest U.S. online store is a big gap. How the two sides settle it will likely set the terms other retailers use with AI agents.
“Agentic third-party applications such as Muse have the same obligations, and we've requested that Meta remove Amazon from the experience.”— Amazon spokesperson, Amazon