Top 5 in AI

Signals

Why Amazon Blocked Meta Muse — and Whether Muse Still Works on Amazon

By the Top5Apps editorial team · Published September 21, 2026 · Updated September 21, 2026 · 5 min read

Share

What happened: since Sunday night, September 20, anyone asking Meta's Muse agent to shop on Amazon hits a wall. Amazon confirmed to GeekWire that it cut Muse off, citing three things: Meta never told Amazon the agent would access its store, Muse doesn't identify itself when it browses, and it 'appears to capture and store customer credentials.' Amazon says it asked Meta to leave Amazon.com out of Muse voluntarily, and Meta declined. Does Muse still work on Amazon? No — not for shopping, and Meta hasn't said when or whether that changes. Everything else Muse does still works. Here's the rule Muse broke, why this was coming, and what it means for every agent that shops.

Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed. — the popup Muse users now see on Amazon.com

The rule Muse broke was written before Muse existed

This is the detail that reframes the story. On August 14 — twenty-five days before Muse launched — Amazon added a dedicated 'Agents' section to its Conditions of Use. It's specific: no agent may touch Amazon 'unless, at all times, it identifies itself'; every request must carry an 'Agent/[agent name]' user-agent string; agents may not mimic 'the speed or pattern of human keystrokes' or solve CAPTCHAs; and Amazon may block any agent 'at our sole discretion… including by technical measures.' Amazon's three complaints about Muse map one-to-one onto that text. Meta built an agent that browses as a human, in a cloud VM, with your stored credentials — and walked into a doctrine Amazon had already published.

Amazon's spokesperson statement is a permissions argument, not a competition one: 'third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate.' And Amazon has a consistency card to play — its own outbound agent, Buy for Me, identifies itself to other stores and lets brands opt out (though merchants have complained that the opt-out defaults the wrong way).

Meta's answer, and why both sides are technically right

Meta hasn't issued a fresh statement; what circulated Monday is its launch-day language: 'Muse has no visibility into people's passwords or payment methods. Any credentials a person shares go into secure storage, so Muse can use them without seeing them, including passwords a person types into the browser themselves.' Read that last clause against Amazon's complaint and you'll notice both companies are correct. Meta's help center confirms credentials 'are stored in a secure credentials store' — so Meta does store your Amazon login; the model just doesn't see it. Amazon objects to the storing. Meta defends the not-seeing. They're describing the same architecture from opposite sides.

The precedent cuts both ways

Amazon has done this before, and lost — sort of. It sued Perplexity in November 2025 over its Comet agent shopping on Amazon, won an injunction, then had it vacated by the Ninth Circuit on August 4 (opinion): 'It is the user who "accesses" Amazon's computers, with the help of the Assistant.' That sounds like a green light for Muse. It isn't, for two reasons. First, the court's footnote: the ruling 'does not impair Amazon's ability to regulate access to Amazon.com via private terms of service' — which is exactly the lever Amazon pulled this week, no lawsuit required. Second, the factual hinge: Comet ran in the user's own browser, so Perplexity's servers never touched Amazon's. Muse runs in a Meta-hosted cloud VM. No court has ruled on that configuration, and the opinion explicitly left it open.

The sides, honestly

Amazon's case is stronger than the 'digital knife fight' framing suggests: disclosure and consent are reasonable asks, its terms said so in advance, and an agent holding your credentials inside a third party's VM is a real security surface. The case against Amazon is also real: it blocked OpenAI's, Perplexity's, Anthropic's, and Google's crawlers before Muse ever existed, it's building its own shopping agents, and — per one retail-media analyst — it 'stands to lose its golden goose' if agents skip the sponsored placements behind a US ad business eMarketer projects at $56.7 billion this year. 'Identify yourself' is a fair rule; 'identify yourself so we can say no' is a moat. Both are happening.

The irony nobody's mentioned: there is already an open standard for agents that shop with merchant permission — the Agentic Commerce Protocol, 'created by Stripe, OpenAI, and Meta.' Meta co-authored the permission model, then shipped an agent that shops without asking. Amazon, for its part, participates in neither ACP nor Google's rival protocol. The two biggest players in agent commerce have each declined to join the system that would resolve this.

What Muse users can and can't do right now

  • Can't: have Muse browse, cart, or buy on Amazon.com from inside its own browser. The popup is a session-level block, and Amazon says it's deliberate.
  • Can: everything else — Link checkout on other merchants, bookings, email, calendar, calls. Nothing in the record says Meta has changed Muse's behavior; it's Amazon's door that's shut.
  • Unknown (nobody's reported it yet): whether search-only browsing still loads, whether the block differs on WhatsApp, web, or Mac, whether you can take over the session manually, and whether Meta will add the 'Agent/Muse' identifier Amazon's terms demand — which would also let Amazon block it cleanly.
  • Don't: paste your Amazon password into Muse to 'fix' it. Stored credentials are precisely the thing Amazon objected to, and Amazon's terms now prohibit agents from bypassing its blocks.

Our read: the retailer veto just became a feature of the category

Two days ago we published our personal AI agents ranking and a guide to what Muse can access, both built on one idea: the buying question for agents is permissions, not model quality. This is that idea arriving from the other direction. Users decide what an agent may touch; it turns out merchants get a vote too, and Amazon just cast the first big one. Expect it to spread — the mechanism is a terms-of-service clause and a popup, which any retailer can copy by Friday. OpenAI already learned the hard version: its Instant Checkout wound down in March after Walmart reported in-chat conversion running about three times lower than click-out, replaced by retailer-sanctioned apps inside ChatGPT. Sanctioned beats sneaked.

Bottom line: Muse's Amazon shopping is dead until Meta and Amazon talk, and this won't stay a Muse problem. The agents that win the next year will be the ones merchants can identify and choose to admit — the model Meta itself co-designed and then didn't use. For our ranking, this is a con on Muse's card, not a demotion: every unsanctioned agent faces the same door, and Muse's #1 rests on being the one most people can actually run. But 'can it shop where I shop?' just became a question to ask before you connect anything.