Amazon has blocked Meta's personal AI agent, Muse, from shopping on Amazon.com. GeekWire reported the block based on its inquiry to Amazon. On the night of September 20, 2026 (US time), a warning was displayed saying that access by unauthorized AI agents violates Amazon's terms of use. Muse is designed to operate sites on a user's behalf and ask for approval before a purchase, but that alone doesn't make it acceptable to a retail site. The standoff shows the hard part of cross-service automation: on whose permission can an AI entrusted with shopping act?
Amazon wants agents to identify themselves
According to GeekWire's report, Amazon had earlier asked Meta to exclude its site from Muse's targets. Amazon says Meta never notified it of the access, and that Muse does not identify itself as an agent while browsing. Amazon also cited privacy and safety concerns, saying Muse appears to collect and store customer credentials and, depending on instructions, could access account information and order history.
This is Amazon pointing to a risk, not an announcement that information leaked from Muse. Meta did not immediately respond to GeekWire's inquiry as of the night of September 20, and Amazon said the two companies are talking directly.
Amazon's demand can be seen concretely in the "Agents" section of its published terms of use. An agent must identify itself by including Agent/[agent name] in the information that conveys the browser or client type in every HTTP/HTTPS request. The terms also prohibit continued use after Amazon has asked an agent to stop, and prohibit circumventing blocking measures. Another clause says Amazon may restrict access by technical means.
In other words, even when a user buys with their own account, Amazon takes the position that it may know which software is operating that account and decide whether to accept it. That said, the fact that the terms say so is separate from whether the legal validity of each clause has been settled in court.
Storing a password versus exposing it to the AI
Meta announced Muse on September 8 and launched it in the US on the app and the web. It is also available from WhatsApp. Beyond advice on choosing products, it uses a dedicated browser to operate sites and carry out tasks such as shopping. It runs not on the user's smartphone itself but in a dedicated virtual machine in the cloud, called the Muse Secure VM.
Reading Meta's technical explanation, Amazon's concern that Muse stores credentials and Meta's claim that Muse never sees passwords don't necessarily contradict each other.
When a user logs in through the browser, the username and password entered on a dedicated screen are sent directly to a service that handles credentials. They are stored in the same virtual machine but isolated from Muse's execution environment, and are entered into the browser only when needed. What is passed to the AI that operates the browser is information for reading on-screen elements, and the raw password value is not shown to it, according to Meta.
An independent monitor separate from Muse, called Sentinel, also sits in the path of external actions. Muse proposes an action, and Sentinel decides whether to allow it, deny it or ask the user. The user's approval is returned directly to Sentinel, so Muse cannot gain permission to execute merely by interpreting something in the conversation as "approved."
This design is meant to guard against attacks in which a malicious web page steers the AI into stealing secrets. But even a design that keeps secrets from the model leaves the fact that an AI operates the account after login. The third-party operation Amazon objects to and the exposure of secrets Meta is trying to prevent overlap, yet they are different risks.
The current version of the virtual machine also does not technically block all Meta access to data. Meta says it limits employee access through operational policy but that access needed for support, safety and similar purposes remains possible. A "Muse Confidential VM," which would use cryptography to make the data inaccessible even to Meta, is planned for later this year and should be distinguished from the current version.
Approving a purchase is not the same as permission to access the site
Stripe, which underpins Muse's payments, also says users approve the total for each purchase and that Muse is not shown the original payment details. According to Stripe's September 8 announcement, stores that support Link use the payment method saved in Link, while other stores get a single-use virtual card limited to the approved purchase. The same payment path is not used at every store.
Meta explains that even when a card is already registered with a store, Muse detects the checkout screen and asks the user to confirm the details each time. Newly issued single-use cards carry limits on store, amount and validity period. All of these are measures to curb mistaken purchases and misuse of payment information.
Muse's credential protections and pre-purchase approval do not substitute for the agent identification and stop-access compliance that Amazon demands. Sorting the published mechanisms and terms by what they protect and who grants permission shows where the conflict lies.
| Mechanism / condition | What it protects or approves | What it does not settle on its own |
|---|---|---|
| Meta's credential isolation | Separates the password from the AI's execution environment and enters it into the browser when needed | Whether a retail site accepts third-party operation |
| Muse's pre-purchase confirmation | The user approves specific purchase details | Whether the retail site permits that agent |
| Stripe Link payments | Uses a saved payment method at supporting stores, or a virtual card limited to the purchase | What can be viewed after login, or the site's access conditions |
| Amazon's Agent Terms | Agent identification, compliance with stop requests, adherence to restrictions | Muse's internal safety, or the legal validity of the terms |
The table sorts Meta's September 8 technical explanation (the "Browser" and "Purchases" sections), Stripe's announcement of the same date, and Amazon's "Agents" section as checked on September 22, by what each protects or approves. It is not an independent safety test, and it does not verify Muse's actual traffic or how Amazon carried out the block.
Even if card numbers are handled safely, an order can't be placed if the agent can't reach product pages or checkout. The better the payment plumbing gets, the more the conditions under which a retail site accepts the AI determine how far it can actually be used.
Why the Comet ruling doesn't simply apply to Muse
Courts have already weighed in on AI use of Amazon. On August 4, the US Court of Appeals for the Ninth Circuit vacated a preliminary injunction Amazon had obtained against Perplexity's AI browser, Comet, and remanded the case. But it is premature to read this as "any shopping AI may freely access Amazon."
What the court examined in the opinion was how Comet works when running on the user's PC. It is the user's browser that receives pages from Amazon, while Perplexity's servers receive screen information and return instructions for actions. On those facts, the court judged that the party accessing Amazon's computers is not Perplexity but the user, who is assisted by AI.
As a result, Amazon's claims under the federal Computer Fraud and Abuse Act (CFAA) and the corresponding California state law were found unlikely to succeed on the evidence at that stage. It was not a final ruling on the merits, and the court reserved judgment on cases with different facts.
Furthermore, footnote 5 at the end of the opinion states that the decision does not prevent Amazon from controlling access through its terms of use. The warning shown to Muse users this time also pointed to a violation of the terms of use, not an unauthorized-access law.
Muse runs its browser in a dedicated cloud virtual machine. That is not the same set of facts as Comet, which accesses from the user's PC, so the August ruling cannot be said to extend to Muse as is. Conversely, this difference in implementation alone does not decide that Muse is unlawful. Legal liability in court and a site's technical blocking of access need to be considered separately.
Amazon itself buys on external sites
Amazon also plays the role of buying products from sellers outside Amazon through its own "Buy for Me." According to the company's Shop Direct explanation, once a user confirms the order for an eligible product on Amazon, Amazon's AI completes the checkout on the external store. Orders can be tracked in Amazon's interface, while shipping, returns and customer service are handled by the seller.
To GeekWire, Amazon said Buy for Me discloses that it is an agent and that brands can decline to participate. The official Shop Direct page also links to ways to connect product information and to opt out. This does not, however, mean prior consent to participate has been obtained from every store.
Because Amazon is also advancing AI purchasing on customers' behalf, it is hard to explain this standoff purely as being for or against AI shopping. Whether a user starts shopping from Muse or looks for products at external stores from Amazon changes which company shows the product and steers the order. Competition over that entry point overlaps with the question of stores setting the conditions for access to their own sites.
For users, even an AI that confirms before purchase may find that the stores it can be trusted with change suddenly. Whether Amazon and Meta's talks produce agreement on how agents are identified and on the conditions for allowing access will be a concrete factor in how usable Muse is. Only when it is also clear which stores accept the agent and how responsibility is divided after a purchase can users comfortably hand a shopping request over to the end.
