Amazon Blocks Meta's Muse Agent Twelve Days After Launch
Bloomberg first reported the block, and GeekWire, Axios, TechCrunch and SC Media covered it separately. Amazon prohibits other companies from deploying automated tools to shop its site and started blocking Muse on Sunday night, a spokesperson said. Shoppers using Muse see a series of pop-ups saying its use violates Amazon's terms of use. GeekWire first spotted the exact wording, and TechCrunch later repeated it: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed."
The block came after talks failed. Amazon blocked Meta's new AI agent from its retail site after Meta declined a request to remove the bot. On Sunday night, Amazon said it is in direct conversation with Meta about the issue. Asked whether it would consider taking legal action, the company declined to comment.
Muse is a popular product, so the block affects a lot of people. According to Axios, Meta shares closed up over 11% Monday as Muse rose to the No. 1 spot for free app downloads in Apple's and Google's app stores. The two companies also work together in other areas. GeekWire notes that Amazon products have been buyable inside Facebook and Instagram since 2023, and that Meta signed a multibillion-dollar deal in April to run agentic AI workloads on Amazon's Graviton chips.
Meta introduced Muse on September 8. Its own announcement calls it a personal agent that runs in a dedicated cloud virtual machine with its own browser, fills in forms and opens websites for the user, and keeps working after the app is closed. GeekWire lists it as free with paid subscription tiers, on iOS, Android, the muse.ai website and WhatsApp. Because muse.ai runs in a browser, Windows users can reach the agent without installing anything. The agent itself runs on Meta's cloud machine, not on the PC.
Amazon's Case Against Muse Rests on Identification, Consent and Account Access
Amazon has given three reasons, and each is more specific than a simple turf war.
The first is that Muse never announced itself as an agent. Amazon's key concern is that Muse did not identify itself as an agent during purchases, which it says breaks Amazon's terms of service, and those terms require agents to embed a text snippet in HTTP requests. Benzinga describes the same rule more broadly: Amazon's 2026 agent rules require automated systems to identify themselves and stop accessing its services when requested. In practice, an agent that doesn't identify itself looks to Amazon's servers like a person clicking through the site.
The second is that Amazon was never asked. Amazon says Meta never told it that Muse would visit the store and never got permission. The company's spokesperson summed up the principle in a statement given to several outlets: any third-party service offering to buy from another business should operate openly and respect the merchant's choice to take part or not, the same expectation that applies to food-delivery platforms and online travel agencies.
The third reason is the one security-minded readers should look at hardest. Amazon says Muse can reach account pages and order history if a customer prompts it to. Amazon also says the agent does not identify itself while browsing and appears to capture and keep customer credentials. In Amazon's view, that combination lets an undisclosed third party move through account pages, order history and checkout without the merchant knowing.
These are Amazon's claims. No outside party has published an analysis of Muse's network traffic or credential handling, and Amazon has not released the technical evidence behind its phrase "appears to capture and store".
Meta's Muse Security Claims: Secure VM, Sentinel and Hidden Credentials
Meta's side comes mainly from its September 8 launch material, since the company didn't respond to requests for comment from GeekWire or Axios over the weekend. Meta says each Muse instance runs inside a dedicated Secure VM, and that passwords and payment methods stay hidden from the agent in protected credential storage. Meta's announcement adds that a separate system component called Sentinel has to approve Muse's internet access. It also says the agent asks permission before purchases and other sensitive actions, and that users can review an audit trail and disconnect services.
GeekWire points to the part of the launch material that is now at the center of the dispute. If a service has a public API, Muse connects to it with credentials the user supplies. If there is no API, Meta says the agent "can use the service through a browser the way you would." Crowdfund Insider describes the same two routes: Muse connects to email, calendars, payments and shopping sites either through public APIs or by operating a browser the way a person would. Amazon is the second case. Muse was driving a browser session inside the user's account, not calling an approved interface.
The two companies' accounts can both be partly true. Meta says the model never sees the password in plain text. Amazon says credentials that let an undisclosed third party log in are being stored somewhere outside Amazon's control. Neither company has published enough detail for an outsider to settle it. SC Media reports that Meta is working to strengthen Muse's data protection guardrails, including an upcoming Muse Confidential VM, to prevent such access. No other outlet has confirmed that feature or given a date for it.
Meta is also building official commerce channels. Its launch materials say the agent can check out through Stripe's Link, with Shop Pay support planned. Shopify now lists Meta as an AI sales channel, and a partnership will let Muse users shop across Shopify stores and pay through Shop Pay. Those are the kind of integrations Amazon says it expects: the merchant agrees, and the agent works through a sanctioned route.
The Perplexity Comet Ruling Narrowed Amazon's Legal Options to Conditions of Use
Muse is not the first agent Amazon has pushed off its site. Amazon has spent the past year trying to keep outside agents off its site, suing Perplexity over its Comet browser and moving to block shopping agents from Google and OpenAI. Some coverage treats the Perplexity case as a ruling still to come, but the key appeal decision has already been made, and it explains the wording of the Muse pop-up.
Amazon sued Perplexity in November 2025 and won a preliminary injunction in March 2026. On August 4, 2026, the U.S. Court of Appeals for the Ninth Circuit vacated that injunction and sent the case back to the lower court. GeekWire summarizes the holding: the user, not the AI company, was the one accessing Amazon's computers under federal anti-hacking law. The court was looking at a preliminary injunction on the record in front of it. It found Amazon unlikely to show that Perplexity, rather than the user running the assistant as a tool, accessed Amazon's systems under the Computer Fraud and Abuse Act and California's equivalent law. The Ninth Circuit denied Amazon's petition for rehearing en banc on September 10.
The ruling has clear limits. It doesn't say Amazon must allow third-party agents, it doesn't apply to Muse directly, and it doesn't stop Amazon from blocking traffic it doesn't want. As GeekWire notes, it left Amazon one avenue: claims based on contracts and terms of service. The Muse pop-up doesn't accuse anyone of hacking. It cites the Conditions of Use and reminds the customer that they agreed to them.
Put simply, the Ninth Circuit said the user is the one doing the accessing. Amazon's reply is that the user also agreed to the rules. That is why the account holder is now in the middle of this dispute.
Alexa for Shopping and Buy for Me Show the Kind of Agent Amazon Accepts
Amazon isn't against shopping automation as such. It runs its own. According to Amazon, its Rufus assistant was renamed Alexa for Shopping on May 13, 2026. Amazon describes it as available to U.S. customers in its app and on its website, with product research, price history, deal-finding and automated cart-building or routine purchases. Its Buy for Me feature buys selected items from participating outside brand sites when Amazon doesn't sell them. The customer confirms the order through Amazon's checkout, and the brand handles delivery, returns and service.
GeekWire reports that Amazon points to one difference: Buy for Me identifies itself and lets brands opt out. That is the standard Amazon says Muse fails to meet. Critics can fairly note the asymmetry. Amazon's own agents are fine, and an outside agent that lets the customer pick the software counts as a terms violation.
The commercial stakes are real, even though no company has said they drove this decision. Amazon made more than $68 billion in ad revenue last year, a business that depends on people browsing its pages and seeing sponsored products. An agent that reads a product page and picks the best match won't look at sponsored placements the way a person does. That link is an inference, not a reason Amazon has given. Axios also notes that Amazon seems to care more, for now, about the long-term implications of allowing external agents on its platform than about the revenue it might lose in the short term.
Not every retailer is taking Amazon's line. Axios reports that Walmart is working with Google and OpenAI to make its products discoverable in their agentic shopping tools while building its own agent, Sparky. Target's CEO recently pointed to a 3.5x year-over-year increase in traffic from external AI platforms. Based on what has been reported so far, you shouldn't assume every large retailer will block agents the way Amazon does.
What the Muse Block Means for Anyone Delegating Logins to an AI Agent
The decision is about delegation. If you use Muse or a similar agent, keep it for sites and services that have chosen to integrate with it, and handle Amazon purchases yourself or through Amazon's own tools. On Amazon.com, Muse's shopping flow now stops at the pop-up. Anything you assumed the agent finished there should be checked.
Account enforcement is still an open question, not something that has happened. Amazon hasn't announced that it will suspend accounts for agent use, and no suspensions over Muse have been reported. Still, the pop-up ties the violation to the customer's own agreement, and if an agent misorders on your account, you are the one dealing with the retailer, since Amazon has no relationship with the agent.
For IT administrators, the same logic applies at work, as an inference from this dispute rather than anything Amazon or Meta has said about business use. A cloud-hosted agent holding saved credentials is a third party acting inside an authenticated session. When the agent doesn't identify itself, the service on the other end can't tell it apart from the user. That matters for any policy on employees connecting consumer agents to work email, calendars or procurement accounts.
- Check any order an agent claims to have placed directly in your Amazon account or the retailer's confirmation message, not in the agent's own summary.
- Keep purchase approval turned on in Muse. Meta says the agent asks before buying, and that approval step is your last check before money moves.
- Review Muse's audit trail and disconnect any services you no longer want it to reach. Meta says both controls exist.
- Assume an agent signed into your account can see what you can see. Amazon's complaint says Muse can reach order history and account pages when prompted.
- Don't read the Ninth Circuit's Perplexity decision as permission to use agents. It addressed anti-hacking claims at the preliminary stage, and Amazon's Conditions of Use argument is untouched.
- Prefer agents that connect through official APIs or merchant partnerships, like Muse's Shopify and Stripe Link checkout paths, over ones that drive a browser session on a site that hasn't agreed.
Amazon has made its position clear: an agent that doesn't identify itself and wasn't invited is breaking terms the customer accepted. Nothing in the Ninth Circuit's decision stops Amazon from enforcing that at its own front door. The next concrete developments will come from the Perplexity case now back in the district court, where Amazon's contract-based claims remain, and from whether Meta and Amazon reach an arrangement through the talks Amazon says are under way. Until then, Muse can't shop Amazon.com, and users who connect agents to their accounts carry the risk, not the companies that built them.