Amazon Draws a Line Against Meta’s Shopping AI Agent

Amazon has blocked Meta’s Muse AI from shopping on its site, putting a clear limit on what personal AI agents can do inside one of the internet’s largest shopping platforms. Anyone using Muse to shop on Amazon now sees a message saying that continued access by an unauthorized AI agent violates Amazon’s Conditions of Use.
The popup appeared on Sunday for Muse users. Amazon’s message states: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” Meta did not notify Amazon that Muse would access its store, which adds another point of tension between the companies.
Meta launched Muse earlier this month as a secure, private personal AI agent designed to help people reach goals and suggest ideas. The agent can fill out forms, send emails, and shop with a generated single-use card from Link by Stripe. That turns Muse from a chatbot that offers advice into a tool that can take actions on a user’s behalf.
Why Amazon blocked Muse
Amazon says Muse does not identify itself while browsing the company’s website. The company has raised privacy and security concerns because the agent may access and retain customers’ information, while also capturing customer credentials during the shopping process.
Meta disputes the concern over sensitive payment and login details. The company says Muse cannot see secure login details or card payment information. Meta also said, “Muse has no visibility into people’s passwords or payment methods. Any credentials a person shares go into secure storage, so Muse can use them without seeing them, including passwords a person types into the browser themselves.”
The disagreement centers on how an AI agent should behave when it browses a website for someone. Amazon is focused on identification, access, and retention of information. Meta says the design of Muse keeps passwords and payment methods out of the agent’s view, even when Muse uses credentials stored securely.
There is also a separate question about what Muse can see inside a user’s messages. Reports indicate that the agent can view the contents of user messages even when the required access permission is not enabled. That concern sits alongside Amazon’s complaints about privacy and security, though the two issues involve different kinds of access.
Muse’s shopping test and Amazon’s wider dispute
Meta used Muse during testing to successfully purchase tank tops from Amazon while other products remained in the basket. The test shows why the agent’s ability to shop matters: Muse can move through a store, handle a purchase, and use a payment method created for a single transaction.
Amazon’s response also fits into an earlier dispute over AI-powered shopping. The company sued Perplexity in November last year to keep its platform out of the AI search provider’s Comet shopping experience. A judge sided with Perplexity in August.
That case and the Muse block point to the same basic disagreement over online shopping agents. Amazon controls the store and its Conditions of Use, while AI developers want their tools to browse websites and complete tasks for users. The companies have not reached the same view on whether an agent needs to identify itself before it shops.
Amazon’s handling of customer information adds another layer to the dispute. Confirmation emails from Amazon have started looking sparse since July, with item names and product images omitted. That change gives customers less detail in those messages, while Amazon is also objecting to an outside agent accessing information during the shopping process.
What the decision means for AI shopping
Muse’s blocked access shows that an AI agent’s ability to complete a task does not guarantee permission to use every website needed for that task. Muse may be able to fill out forms, send emails, and buy products, but Amazon can still treat its browsing as unauthorized under the company’s Conditions of Use.
The dispute also highlights the difference between what an AI agent can see and what it can use. Meta says Muse cannot view passwords or payment methods, while Amazon remains concerned about the agent’s failure to identify itself and its access to customer information. Those positions address different parts of the same shopping process, so the disagreement is not settled by the use of a single-use card alone.
For users, the immediate result is simple: anyone trying to shop on Amazon through Muse is greeted by Amazon’s warning instead of uninterrupted access. For Meta, the block challenges the promise of an agent that can act across the web on a person’s behalf. For Amazon, it reinforces control over how outside AI systems enter and use its shopping platform.
The conflict leaves a practical question for AI agents: should websites treat them like ordinary users, or require them to identify themselves as software? Amazon has made its position clear in the popup shown to Muse users. Meta, meanwhile, maintains that its handling of passwords and payment details keeps those credentials in secure storage rather than exposing them to the agent.
Based on




