Amazon vs Meta's AI Shopper: One Popup, $68 Billion at Stake
Amazon vs Meta's AI Shopper: One Popup, $68 Billion at Stake
Amazon didn't sue Meta. It didn't post anything, call a press conference, or write a blog explaining its position. It just started showing a popup. Sometime on Sunday night, anyone who pointed Meta's new Muse agent at Amazon.com and asked it to buy something got this instead of a purchase:
The entire enforcement mechanism: a popup that cites the customer's own account terms, not hacking law. Screenshot: GeekWire
That one sentence is the whole fight, and it's worth reading carefully, because it says something slightly different from what most coverage repeated. Amazon isn't blocking Meta. It's blocking an agent that, in Amazon's telling, never introduced itself.
So why is Amazon doing this? The arc is simple, even if the details aren't. Amazon published rules in August that require AI agents to identify themselves in every request, to stop when Amazon says stop, and to never pretend to be a human. It says Muse doesn't do the first one. Then there's the part Amazon doesn't put in statements: more than $68 billion of ad revenue a year depends on shoppers browsing its pages, and an agent that jumps straight to checkout never sees a sponsored placement. And the legal shortcut Amazon used against Perplexity last year died in the Ninth Circuit on August 4.
Eleven months, four walls. The rules came first, the block came second — and the courtroom door closed in between. Chart: my own, from court filings, Amazon's terms, and press reporting.
What actually happened, in order
Meta launched Muse on September 8 as a US-only personal agent that runs on Muse Spark inside a cloud VM with its own browser. It was free, with paid tiers at $20 and $100 a month, it could also be reached from WhatsApp, and within ten days it was the No. 1 free app on the US App Store, ahead of ChatGPT. I wrote about the model inside it when that shipped earlier this month, and what it proves is that Meta finally built something normal people wanted.
Then Amazon turned it off. According to GeekWire, which broke the story, Amazon had already asked Meta to remove Amazon from the Muse experience, and Meta declined. Amazon's spokesperson gave the company line on the record, and it's worth quoting in full because every outlet ran a slice of it:
"We think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate. This helps ensure a safe, secure, and reliable customer experience, and it is how others operate including food delivery apps and the restaurants they take orders for, delivery services apps and the stores they shop from, and online travel agencies and the airlines they book tickets with for customers. Agentic third-party applications such as Muse have the same obligations, and we've requested that Meta remove Amazon from the experience." Amazon spokesperson, to GeekWire / Retail Dive / Forbes
Amazon's stated problems are specific. It says it wasn't told in advance that Muse would touch its store, didn't authorize it, and that Muse doesn't identify itself while browsing — so from Amazon's servers it looks like an ordinary logged-in shopper. Amazon also says the agent appears to capture and store customer credentials and scrape account data, and that it can reach order history when a user asks it to. Meta declined to comment on the block, and pointed back to its launch materials: Muse "has no visibility into people's passwords or payment methods," with credentials held in a separate secure store that the model can use without seeing.
The Register tested the block with a mundane request — find the best-reviewed ergonomic office chair — and got a surprisingly candid answer from Muse:
"Hit a snag: Amazon is showing an anti-bot wall that blocks automated browsers outright – the browser couldn't even get to the search page, so no chair was found or added. I didn't push past it, since the notice says continuing would violate Amazon's terms." Muse, quoted by The Register
What the wall looks like from inside the agent's own browser, mid-task. Screenshot: The Register
A day later, Shopify did the opposite. CEO Tobi Lütke said every store on the platform would be open to Muse, with checkout going through Shop Pay — described as "an easy and delightful way to shop and check out with Muse." Shopify's stock jumped 7.3% that Monday and kept climbing the next day. Wall Street is rewarding the side that keeps the payment rails and gives up the storefront.
Amazon's rulebook was already written — you can read it
This is the part I'd missed until I opened Amazon's Conditions of Use. The page was last updated on August 14, 2026, and it now contains a section literally titled "Agents," with a definition broad enough to cover anything that acts on your behalf:
"‘Agent’ means any software or service that takes autonomous or semi-autonomous action on behalf of, or at the instruction of, any person or entity. … No Agent may access, use, or interact with Amazon Services unless, at all times, it identifies itself." Amazon Conditions of Use, "Agents" section
The technical requirements are the interesting part, because they're written like an anti-bot-team spec rather than legal boilerplate. In all HTTP and HTTPS requests, an agent must identify itself in the user-agent string as Agent/[agent name] — the example given is Agent/AmazonAgent. It may not mimic human keystroke speed, may not solve or dodge CAPTCHAs, and must answer truthfully if asked whether it's a human or a computer. And it must stop the moment Amazon asks it to.
| What Amazon's terms require of any agent | What Amazon says happened with Muse |
|---|---|
Identify itself in every HTTP/HTTPS request as Agent/[agent name] | Reportedly browsed as an ordinary logged-in shopper, not as a declared agent |
| Never disguise the agent nature: no human-like keystroke patterns, no CAPTCHA workarounds | Amazon calls the access "unauthorized"; Muse's browser mode is built to operate "the way you would" |
| Answer truthfully when asked if the session is human or machine | Not addressed publicly by either side |
| Stop immediately on request — Amazon reserves the right to limit access "by technical measures" | Amazon asked Meta to remove it from the Muse experience; Meta declined, and the block followed |
The rules aren't only consumer-side. Amazon's seller agreement gained a formal "Agent Policy" in March 2026 with the same three obligations — identify yourself, comply at all times, and cut access on request — which sellers have taken to calling the kill-switch clause. And per seller notices out of Japan, an Agent Policy update lands there on October 28 with identical identification requirements. Read in that order, the Muse popup isn't a one-off: it's the first enforcement of a policy Amazon wrote, published, and waited nine months for a target big enough to use it on.
Meta's own pitch for Muse: it books, budgets, and buys. That last verb is the one that ran into a wall. Image: Meta
Meta's side: the agent that swears it can't see your password
Meta's security story is more serious than the discourse gives it credit for. Muse runs in a dedicated cloud VM with its own browser; a separate "Sentinel" agent sits between Muse and the network; credentials live in secure storage so the model can use them without reading them; and payments go through Stripe's Link with a one-time-use card, so the agent never holds your card number. This is a more careful design than "give the chatbot your Amazon login."
But Muse also has a credibility problem of its own making. Users reported it appearing to know about messages it hadn't been granted access to, and Meta's David Singleton ended up apologizing for the agent's own explanation of itself: "it was confused about how to explain the feature and gave an incorrect explanation. That's on us." When your agent can't accurately describe its own plumbing, a retailer saying "we couldn't tell what it was doing in there" lands differently.
It's also not a perfect wall. A commenter in r/artificial claimed Muse simply went around it: "Just went through and bought something easily through the web browser for me. I don't know how they are blocking it but muse blew right past it." Take that as one user's report, not a measurement — but the community read is blunt: "They can't actually stop a properly set up agent."
Muse walking through a purchase end to end — the exact flow Amazon says it couldn't audit. Screenshot: GeekWire
The $68 billion question
Now the part that isn't in any statement. Amazon pulled in more than $68 billion in advertising revenue in 2025 — roughly a tenth of the company's total revenue, and a business that exists because people browse pages and look at sponsored placements while they browse. An agent that reads listings, picks a match, and pays skips that. It still hands Amazon the order; it just never walks down the aisle.
Same checkout, different aisle. The order still lands; the ad impressions and the recommendation feed don't. Diagram: my own, using Amazon's reported 2025 ad revenue.
Analysts aren't being coy about it. Matthew Hassett, who sells on Amazon and runs an AI commerce startup, put it best when asked about Amazon's statement: "'Respect service provider decisions' is the polite version of 'not on our shelf.'" Chris Jones of PSE Consulting framed the deeper question for Axios: who owns the origination of a purchase and the customer relationship, versus who merely fulfills the transaction — "the answer is still very much up for grabs." Scot Wingo, who advises retailers on agentic AI, told Digiday last year what he thought Amazon would do about it: "They want to be the front door, and they're going to fight this for quite a while."
These two companies are partners everywhere else, by the way. You've been able to buy Amazon products inside Facebook and Instagram since 2023, and in April Meta signed a multibillion-dollar deal to run agentic AI workloads on Amazon's Graviton chips. This isn't a feud. It's a boundary dispute inside a working relationship.
Why now: the courtroom door closed in August
The timing isn't an accident. Amazon's first move against an agent that shopped on its site was legal, not technical: it sued Perplexity in November 2025, arguing that Comet browsing Amazon accounts for users amounted to unauthorized computer access. In March 2026 it won a preliminary injunction — the judge drew a commercially useful line, saying Comet acted "with the Amazon user's permission, but without authorization by Amazon."
On August 4, the Ninth Circuit vacated it. The panel's reasoning is the single most important sentence in this whole story: under federal anti-hacking law, the party accessing Amazon's computers is the user, not the AI company, with Comet acting as a tool executing the user's instructions. Amazon asked for a rehearing; on September 10 the court said no.
Which means the most powerful legal weapon Amazon had against shopping agents is gone, and what's left is the contract — the terms every Amazon customer already agreed to. Notice that the popup doesn't accuse anyone of hacking. It cites the Conditions of Use. That's not a downgrade in intent; it's a deliberate switch to the instrument that still works.
So where does your agent actually get blocked?
This is the practical question, and the answer is: it depends entirely on who owns the checkout. Here's the state of play as of this week.
| Platform | Stance on shopping agents | What it means for you |
|---|---|---|
| Amazon | Blocks on record. Muse is the confirmed case; crawler rules cut off several OpenAI bots in November 2025, and press reports say agents from Google and OpenAI are being restricted too | Your agent can plan an Amazon purchase and can't complete it. It typically hits a bot wall before the search page loads |
| eBay | Banned in the user agreement from February 20, 2026 — third-party agents and "any end-to-end flow that attempts to place orders without human review," unless authorized | Agent can research, you click buy. eBay has hinted at an approved-agent route later |
| Shopify | Open. Every store on the platform, checkout via Shop Pay, announced days after Amazon's block | This is where agents work today, and where most of the "it just ordered itself" stories come from |
| Walmart, Target | Partnering. Walmart is feeding product data to Google and OpenAI agents while building its own agent; Target says external AI platforms now send it 3.5x the traffic of a year ago | Discovery works; check who is allowed to finish the purchase |
| Google, OpenAI | Both pushing open plumbing: Google's Universal Commerce Protocol (January 2026, with Walmart, Target, Shopify and 20+ partners) and OpenAI's Agentic Commerce Protocol with Stripe | The long tail of merchants is becoming agent-ready faster than the big marketplaces are |
One clarification I'd flag, because it's easy to get wrong: Amazon has never published a list of blocked agents. The Muse block is confirmed by Amazon itself. The restrictions on Google's and OpenAI's agents are reported — by GeekWire, Business Insider, TechSpot, Forbes and others — and what's actually verifiable is Amazon's robots.txt, which cut off several OpenAI crawlers last November and blocks crawlers tied to Meta, Google and Perplexity. Treat "Amazon is blocking everyone" as reporting with a strong paper trail, not as a company announcement.
The adoption gap is the whole commercial puzzle. Plenty of us will ask an AI what to buy; almost none of us will yet let it pay. Chart: my own, from NIQ and Coveo surveys.
That gap is why this fight is happening now instead of in three years. Surveys put AI-assisted shopping research at 42% of consumers, comfort with letting an AI actually complete a purchase at 16%, and fully autonomous ordering at 5%. Amazon is spending political and technical capital today to set the terms before autonomous buying becomes normal — which is exactly what a platform does when it believes the volume is coming and would rather write the rule than negotiate it later.
Isn't Amazon doing the same thing with its own agent?
Yes, and this is the fairest criticism going around. Amazon's own Buy for Me feature shops other retailers' websites on customers' behalf, using their stored name, address and payment details. When it launched, Amazon added brands proactively — the opt-out was an email. More than 180 sellers complained about exactly that in January, and Amazon confirmed to Retail Dive that sellers still have to email to get out.
Amazon's own agent buys from brand sites that didn't invite it in — with, Amazon says, self-identification and an opt-out. Image: Amazon
Amazon's answer is that Buy for Me identifies itself and lets retailers opt out, so the difference is consent and visibility, not direction of travel. And the tell that this is about control rather than some blanket ban on autonomy: on Wednesday, Amazon quietly opened its seller platform to Anthropic's Claude through a plugin Amazon built itself — catalog, metrics, inventory, pricing suggestions, with sellers approving each action. Claude walks in through the front door, on Amazon's terms. "Claude, by contrast, enters through an Amazon-built connection," as Benzinga put it.
So the rule isn't "no agents." It's "agents we can see, that we can switch off, and that we've agreed to." You can call that a gate with a guest list, or you can call it a protection racket with good documentation. Which one it is probably depends on whether your agent ever gets an invitation.
Will Amazon ever let agents in?
Amazon's CEO has already hinted that it will. On an earnings call last year, Andy Jassy said the company was "having conversations" with third-party shopping agents and expected to "find ways to partner" over time — while complaining that many agents report inaccurate pricing, delivery and inventory data. "We have to find a way, though, that makes the customer experience good."
The incentive problem is real on both sides. If Amazon stays closed, the demand simply routes around it — one Microsoft AI engineer made the point on X that an agent that can buy from Instacart and not Amazon will send the order to Instacart, and Amazon will eventually have to choose between protecting the relationship and matching the offer. If Amazon opens up, it hands the top of its funnel to another company's agent. Palo Alto Networks CEO Nikesh Arora called it the fight nobody has priced in yet: "Every app that is a services, marketplace or commerce app will need to existentially decide to open APIs for consumer agents to interact."
And Meta's bet is precisely that this becomes a land grab. Zuckerberg told Meta Connect on Wednesday that Muse stays free and will eventually "take a small fee from transactions" it completes, alongside retail integrations with Walmart, Best Buy, Sephora, Expedia and Instacart, and a palm-sized Muse Charm device arriving in December. Download estimates already range from 2.3 million to 4.3 million since launch, depending on which analytics firm you believe, with Sensor Tower sitting in the middle at 3.4 million. Greg Isenberg's take on X is the one founders are repeating: "Being early could be as valuable as being early to the App Store in 2009. Every business will need an agent strategy, just like every business needed a mobile strategy."
The weird part of this story: Meta, of all companies, shipped the consumer AI app of the year. Photo illustration: Cheng Xin/Getty Images via Fortune
My take
I think that popup is the template for the next year, and I don't think it's mostly about security. Amazon's stated concerns are legitimate — an agent that won't say what it is, touching order history, on an account whose owner agreed to terms that require a name tag. But the same company auto-enrolled brands into its own agent and made them email to leave, so "consent" is doing a lot of work in that sentence. What Amazon is really enforcing is who gets to be the front door.
The good news for anyone who just wants their agent to buy things: the terms Amazon published are not impossible to satisfy. Identify yourself as Agent/[name], don't hide what you are, stop when asked. That's a compliance checklist, not a wall. Any serious agent company can meet it, and the ones that do will probably get an integration program with revenue terms attached — because the alternative is that the demand routes to Shopify merchants and never comes back. I'd expect an Amazon "agent partners" page within a year, priced like advertising.
What I'm watching: whether the reported Google and OpenAI restrictions ever get confirmed on the record, and whether Muse keeps growing outside Amazon, in the roughly 60% of US e-commerce spending that isn't Amazon's. I'll write a follow-up when Amazon either launches an agent program or confirms a second block — whichever lands first. If a store you shop at suddenly stops accepting your assistant, that's the same story arriving at your cart.
Sources: GeekWire (Amazon blocks Meta's Muse) · Amazon's Conditions of Use (Agents section, updated Aug 14, 2026) · Retail Dive · CNBC · Axios · The Register · The Verge · Business Insider · Fortune · TechSpot · Digiday / Modern Retail · TechCrunch · Benzinga · Meta's Muse announcement. Numbers I did not measure myself are quoted from the outlets above; the charts are my own renderings of those figures, and the survey results come from NIQ and Coveo, each on its own sample. Meta and Amazon were both asked for comment by the outlets listed; Meta declined to comment on the block, and Amazon's position is quoted above.
Comments
Post a Comment