metir
metir
Docs
Download on App StoreGet it on Google PlayLoginSign Up
Back to Blog
Amazon
Meta
Agentic Commerce
AI Agents
Muse

Amazon Blocks Meta's Muse AI Agent: Inside the Standoff

Amazon cut off Meta's Muse AI shopping agent from Amazon.com after Meta refused to remove it, escalating the fight over who controls agentic commerce.

Metir AI TeamSeptember 26, 20269 min read
Amazon Blocks Meta's Muse AI Agent: Inside the Standoff

Amazon blocked Meta's Muse AI agent from shopping on Amazon.com on the night of September 20, 2026, after Meta declined Amazon's request to remove the retailer from the agent's experience. The move turns a months-long, largely legal skirmish over AI shopping bots into a direct, public standoff between two companies that, on paper, are commercial partners, and it puts a hard question in front of the entire agentic AI industry: when software shops on a person's behalf, who gets to decide whether it is welcome.

AWS logoAWS
Meta logoMeta
Perplexity logoPerplexity
Amazon has now moved to block AI shopping agents from three of the industry's largest companies, treating Meta's Muse the way it earlier treated Perplexity's Comet browser.

What Amazon says happened

Meta introduced Muse on September 8, 2026, an AI agent built to handle everyday online tasks such as shopping and booking appointments, available on iOS, Android, WhatsApp, and the web. Within about a week it reportedly became the top free app on the iPhone App Store, ahead of ChatGPT. Amazon says Meta never told it that Muse would access Amazon's store, that the agent does not identify itself as an automated system when it browses, and that it appears to capture and store customer credentials in a way Amazon considers a privacy and security risk. Shoppers who try to use Muse on Amazon.com now see pop-ups stating that the access violates Amazon's Conditions of Use, effectively an error message where a checkout used to be.

Amazon's own statement on the matter, given to Forbes, put the underlying principle plainly: "third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate." According to reporting, Amazon is not stopping at Meta either; it is reportedly working to extend the same block to shopping agents from Google and OpenAI, treating this as a policy position rather than a one-off dispute with a single company.

Sep 8, 2026Muse's public launch date
Sep 20, 2026Date Amazon began blocking it
Aug 4, 2026Ninth Circuit vacated Amazon's injunction against Perplexity
$68B+Amazon's reported 2025 ad revenue, ~10% of total
Apr 24, 2026Meta-Amazon Graviton chip deal signed

Meta's public defense centers on architecture, not policy. The company says each instance of Muse runs inside a dedicated Secure VM, a virtual machine isolated per session, and that passwords and payment methods are kept in protected credential storage that stays hidden from the agent itself, which only receives scoped, temporary access when a purchase is actually authorized. Meta has separately described Muse's monetization plan as taking a small fee from the transactions it completes, a detail that matters because it means Muse is not simply a convenience layer on top of retailers. It is designed to be a new toll booth between the shopper and every store it touches.

“

Amazon still gets the sale. What it loses is everything that used to happen around the sale.

On the retail-media stakes of agentic shopping

Why a retailer has a structural reason to say no

The dispute is easy to read as a security story, and Amazon's stated concerns, undisclosed access and credential handling, are genuine ones. But the economics underneath it are just as real. Amazon's advertising business generated more than $68 billion last year, on the order of 10% of the company's total revenue, and that business is built almost entirely on shoppers scrolling, comparing, and seeing sponsored listings before they buy. An agent that goes straight from a request to a completed purchase skips the browsing session where that revenue is made. It also skips the merchandising Amazon controls directly: the recommended add-ons, the "customers also bought" module, the placement decisions that steer which products win a sale. A retailer does not need to prove an agent is unsafe to have a rational reason to keep it out; losing the browsing session alone is a meaningful cost, independent of any security question.

Where value moves in an agent-mediated purchase

A simplified view of who sits between whom, and what each party gains or gives up, once a shopping agent stands in for direct browsing.

1

Shopper

Delegates a task ("find me running shoes") and approves the final purchase.

Captures:Time saved, one less form to fill in.
Gives up:Account credentials, browsing intent, purchase history.
2

Agent (e.g. Muse)

Plans the task, browses on the shopper’s behalf, and may take a fee on the transaction.

Captures:A transaction fee, a data trail across every retailer it touches, the primary relationship with the shopper.
Gives up:Its own credibility if it mishandles credentials or misrepresents itself to a site.
3

Retailer (e.g. Amazon)

Fulfills the order, but the agent stood between it and the shopper for the whole browsing session.

Captures:The sale itself, order fulfillment revenue.
Gives up:Ad impressions, cross-sell and upsell moments, first-party browsing data, direct brand contact with the shopper.

The retailer still gets the sale. What it loses is everything that used to happen around the sale: the ad impressions, the recommended add-ons, and the direct, identifiable relationship with the shopper.

The irony in this particular pairing is hard to miss. Amazon products have been purchasable directly inside Facebook and Instagram since 2023, and in April 2026 Meta signed a multibillion-dollar, multi-year deal to run its own agentic AI workloads on tens of millions of Amazon Graviton processor cores inside AWS data centers. The two companies are simultaneously commercial partners in cloud infrastructure and, now, publicly opposed on the storefront. That is not really a contradiction. It reflects how narrowly the conflict is scoped: Amazon is not objecting to Meta as a company or to AI agents as a category, it is objecting specifically to an agent standing between Amazon and its own customers at the point of purchase.

The Meta entrance sign reading '1 Hacker Way' at Meta's Menlo Park, California headquarters
Meta's headquarters sign in Menlo Park, California. Meta built Muse and has defended its credential-handling design; the photo shows Meta's campus, not the Muse product itself.

The unresolved question: what makes an agent legitimate

Underneath the specific complaints sits a question the industry has not settled: what does it mean for a shopping agent to identify itself honestly, and who gets to set the rules for that. There is no shared standard yet. Emerging proposals, including agentic-commerce protocols that let a retailer expose structured checkout endpoints on purpose, and web-bot authentication schemes that would let an agent present verifiable, scoped credentials rather than a user's own login, point toward a negotiated answer. None of them are in wide enough use to have settled this dispute before it became public.

That gap has already played out in court, in a closely related case. Amazon sued Perplexity over its Comet shopping browser under the Computer Fraud and Abuse Act, won a preliminary injunction in March 2026, and lost it on appeal in August, when a unanimous Ninth Circuit panel ruled that it is the user, not the AI company, who "accesses" a retailer's computers under that law, so long as the agent operates through the user's own browser session under the user's own direction. The panel tied that holding narrowly to how Comet actually works and explicitly left room for a different answer with a more autonomous system, and it left Amazon free to sue over contract violations instead of unauthorized access. Reading the two disputes together, Amazon's shift from suing Perplexity to simply blocking Meta looks less like a change of principle and more like a change of tactic: a terms-of-service block does not require proving a federal hacking statute was violated, and Amazon controls its terms of service unilaterally.

That is also why Meta's Secure VM defense, however genuine, answers a different question than the one actually in dispute. A closed, credential-isolated sandbox is a real security property, and Amazon has not disputed Meta's specific technical claims about it. But it says nothing about disclosure or consent. Whether an agent is safely built and whether a retailer authorized it to act on its site are separate questions, and satisfying the first does not resolve the second. Elon Musk pointed at a related, unresolved edge of this on social media, arguing that if an agent operates through a user's own IP address and browser cookies, a retailer may have no reliable way to tell a human shopper from an AI acting on their behalf in the first place, whatever its rules say. Whether that turns out to be true at scale is itself untested, but it captures why "identify yourself" is a harder technical requirement to enforce than it is to write into a terms-of-use policy.

Where this goes: negotiated protocols or walled gardens

Two different futures are visible from here, and neither has won yet. One is a negotiated standard, where retailers expose sanctioned checkout endpoints to agents that authenticate properly, likely in exchange for some continued visibility into the shopping session, the way payment processors already broker agent checkout for merchants who opt in. The other is a walled-garden outcome, where major retailers treat undeclared agents as a security and business threat by default, block on sight, and let commerce agents work only where a retailer has explicitly agreed to participate, deal by deal. Amazon's own AWS Bedrock business and its stated openness to further agent partnerships, alongside retailers like Walmart, Best Buy, and Sephora that have chosen to integrate with Muse rather than block it, suggest the negotiated path is not closed off. But nothing in the public record commits Amazon to it, and its posture with Meta this month reads as the second path in practice, at least for now.

For builders working with AI agents, the practical lesson is not about who wins this particular standoff. It is that agent identity, authorization, and portability across the services an agent touches are still being figured out in public, case by case, rather than governed by a shared standard. Metir AI approaches that same problem from the model layer rather than the retail layer, staying model-agnostic so the choice of which AI does the work is never locked to a single vendor's infrastructure or its unilateral terms.

Sources:

  • Amazon Blocks Meta's Muse AI Agent From Its Retail Site | Bloomberg
  • Amazon blocks Meta's Muse AI assistant in new standoff over agentic shopping | GeekWire
  • Amazon's fight with Meta: Who owns the customer relationship when an agent does the buying? | GeekWire
  • Amazon's $68 Billion Reason To Block Meta's Muse | Forbes
  • Amazon Blocks Meta's Muse AI From Shopping: Elon Musk Says AMZN 'Won't Be Able to Tell' Humans From Agents | Benzinga
  • Meta's AI agent has been blocked from using Amazon.com | TechCrunch
  • Amazon is blocking Meta's shopping AI agent, and plans to block Google and OpenAI's too | TechSpot
  • Amazon asks Meta to remove it from the Muse AI agent experience | Yahoo Finance
  • Meta signs multibillion-dollar deal to use Amazon's Graviton chips for agentic AI | GeekWire
  • Ninth Circuit Vacates CFAA Injunction Against Perplexity's Comet AI Agent | Jones Day
  • AMAZON.COM SERVICES, LLC v. PERPLEXITY AI, INC., No. 26-1444 (9th Cir. 2026) | Justia

Image credits

Hero: "Amazon spheres W.jpg" by Sea Cow, licensed under CC BY-SA 4.0. Source: Wikimedia Commons. Shows the Amazon Spheres at Amazon's Seattle headquarters campus, a real and current part of Amazon's HQ, not any Muse-related product or event.

In-body figure: "Meta Headquarters Sign.jpg" by Nokia621, licensed under CC BY-SA 4.0. Source: Wikimedia Commons. Shows Meta's own entrance signage at its Menlo Park, California headquarters, not the Muse app or product itself.

Both images reviewed before publication.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of Service
  • Privacy Policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational