Amazon has cut off Meta's Muse AI agent from shopping on Amazon.com, and shoppers started running into the block on Sunday night. Ask Muse to buy something there and you now get a popup saying the agent is unauthorized. The two companies are business partners, which makes the fight awkward for both. It is also the clearest test yet of a question that will shape online shopping: when an AI agent buys for you, who decides whether it may walk into the store?
Table of Contents
- What happened between Amazon and Meta
- Why Amazon is leaning on its terms of service
- What each company says
- What is at stake for both
- What to watch next
- Frequently Asked Questions
What happened between Amazon and Meta
GeekWire broke the story late on Sunday. Amazon told the outlet it had tried and failed to persuade Meta to leave Amazon.com out of Muse before it stepped in. The block is visible to users as a popup: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed."
Amazon gives three reasons. Meta never told it that Muse would use its store. The agent does not identify itself while browsing. And it appears to capture and store customer credentials.
Meta launched Muse on September 8 as a personal agent that carries out multi-step tasks across email, calendar, payments, dining and shopping. It is free, with paid tiers, and runs on iOS, Android, WhatsApp and muse.ai. GeekWire notes that a week after launch it became the top free app in Apple's US App Store, ahead of ChatGPT. Early users have described it switching an auto insurance policy, hunting down discount codes at checkout and loading an online grocery cart. Amazon says it is talking directly with Meta. Asked about legal action, it declined to comment, and Meta had not responded when GeekWire published.
Why Amazon is leaning on its terms of service
Amazon has been here before. It sued Perplexity over the Comet shopping browser and won a preliminary injunction in March. On August 4 the Ninth Circuit undid that win, ruling that under the federal anti-hacking law it was the user, not the AI company, who was accessing Amazon's computers. The court denied Amazon's request for a rehearing on September 10.
The ruling closed one route and left another open: claims built on contracts and terms of service. The Muse popup follows that path. It accuses nobody of hacking. It points at the Conditions of Use that Amazon's customers have already accepted.
There is a wrinkle that lawyers will notice. The D*AI*LY Brief argues that the Perplexity decision covered an agent running in the customer's own browser, while Muse runs on a Meta-hosted computer with its own browser. If that reading holds, the August ruling may help Meta less than it first appears. That is one analyst's view, and no court has tested it. Meta's own launch materials say that when a service has no API, Muse uses it through a browser the way a person would.
What each company says
Amazon's position is that anyone offering to buy from other businesses on a customer's behalf should operate openly and respect the merchant's choice about taking part. It points to food delivery apps and travel booking sites, which usually work with restaurants and airlines by agreement. In Amazon's words, third-party agents carry the same obligations as any other application, and it has asked Meta to take Amazon out of the Muse experience. On security, Amazon says Muse can reach account pages and order history when a user asks it to. Since the agent does not announce itself, Amazon sees an undisclosed third party moving through customer accounts and handling sensitive data.
Meta's earlier statements say Muse has no visibility into passwords or payment methods, and that credentials a user shares go into secure storage so the agent can use them without seeing them. According to Meta, the agent runs on a secure virtual machine, asks the user before sensitive steps such as sending an email or making a purchase, and needs a separate monitoring agent called Sentinel to approve anything it sends to the internet.
Amazon's own record complicates the picture a little. Its Buy for Me feature finds products on outside brands' sites. Amazon says the difference is that Buy for Me identifies itself and lets brands opt out.
What is at stake for both
For Amazon, the money sits in pages people browse. GeekWire reports that Amazon earned more than $68 billion in advertising last year, a business that depends on shoppers seeing sponsored products. An agent that goes straight from a request to checkout skips that step. Over the past year Amazon has sued Perplexity and moved to block shopping agents from Google and OpenAI, so the Muse block fits a pattern. Amazon also has agents of its own. It launched Alexa for Shopping in May to research products and make recommendations, which means it competes with tools like Muse while also controlling access to its site.
For Meta, Muse is pitched as the assistant that handles errands across many services. If large retailers keep saying no, that pitch gets smaller. Meta also depends on Amazon in other ways. Amazon products have been purchasable inside Facebook and Instagram since 2023, and in April Meta signed a multibillion-dollar deal to run agentic AI workloads on Amazon's cloud.
Our read: those ties make a negotiated settlement more likely than a long court fight, but that is a guess. Neither company has said it is close to a deal.
What to watch next
The next steps will show whether this stays a one-off dispute or becomes the template.
- Whether Meta agrees to remove Amazon from Muse, or to make the agent identify itself.
- Whether Amazon goes to court. It has not ruled that out.
- Whether other retailers copy the popup. The D*AI*LY Brief expects agentic shopping to be governed marketplace by marketplace, with disclosure and keeping out of customer credentials as the price of entry.
- Whether Meta publishes more detail on how Muse stores logins, which is the point where the two companies' accounts differ most.
The same trust question already shows up elsewhere in agent software. Our report on the Plugin4Shell flaw covers how coding agents run plugins with a developer's own permissions, and Google's push into autonomous agents, described in our piece on Gemini 3.8 Live, raises the same questions about who holds the keys.
For now, Muse users who ask it to shop on Amazon will see the popup, and everything else about the dispute is still open.
Frequently Asked Questions
Why did Amazon block Meta's Muse?
Amazon says Meta never told it Muse would shop on its site, the agent does not identify itself, and it appears to capture and store customer login credentials. Amazon cites its Conditions of Use and says it first asked Meta to remove Amazon from Muse voluntarily.
Can Muse still shop on other websites?
The reports so far describe a block on Amazon.com only. Meta says Muse connects to services through their APIs where they exist, and through a browser where they do not.
What happened in Amazon's case against Perplexity?
Amazon won a preliminary injunction in March, then lost it on August 4 when the Ninth Circuit ruled that the user, not the AI company, was accessing Amazon's computers under federal anti-hacking law. The court denied a rehearing on September 10, though contract and terms-of-service claims remain possible.
Does Muse see my passwords?
Meta says Muse has no visibility into passwords or payment methods and keeps shared credentials in secure storage. Amazon says the agent appears to capture and store customer credentials. The two accounts have not been reconciled.
