Abstract:
Amazon recently blocked the shopping function of Meta’s AI intelligent agent Muse on the Amazon website, prohibiting Muse from browsing products and placing orders on behalf of users. This conflict once again highlights a rapidly rising issue: when AI agents begin to visit e-commerce websites, select products and complete purchases on behalf of consumers, who should control the shopping process, and whether e-commerce platforms have the right to deny third-party AI agents access to their services.

GeekWire reported that Amazon had previously asked Meta to proactively exclude Amazon from Muse’s shopping experience, but the two parties failed to reach an agreement. Subsequently, Amazon directly took technical measures to prevent Muse from continuing to access its shopping platform. As of the evening of September 20, local time, users who use Muse to try to shop on Amazon will see a prompt message saying that unauthorized AI agents continue to access Amazon, violating Amazon's terms of use that users have previously agreed to.
Amazon stated that Meta had not previously notified Amazon that Muse would access its e-commerce platform. What’s more, Muse does not explicitly identify itself as an AI agent when browsing Amazon’s website, leading Amazon to believe that a third-party program that has not been authorized by the platform is browsing accounts, processing transactions, and accessing sensitive information on behalf of users.
Amazon also raised privacy and security concerns about the way Muse handles user login credentials. Amazon believes that if a third-party AI agent is able to perform operations in a user account without clearly identifying itself to the service provider, then the platform cannot actually fully determine who is accessing user data, nor can it manage such access in accordance with normal third-party service cooperation mechanisms.
Amazon stated that any third-party application that can purchase goods from other businesses on behalf of consumers should operate in an open and transparent manner, while respecting the decision of the relevant service provider whether they are willing to participate. Amazon believes that AI agents like Muse are no different in principle from traditional third-party purchasing services, so they should also be recognized by merchants.
Meta did not immediately respond to Amazon’s latest blockade as of the time of publication. However, when Muse was officially launched, Meta made it clear that Muse could not directly see users’ passwords or payment information. Meta explained that the login credentials that users actively provide to Muse will be stored in a secure environment so that the agent can perform tasks, and Muse itself will not directly read these credentials, including passwords that users manually enter in the browser.
Muse was officially launched on September 8 and is positioned by Meta as a personal AI agent that can truly complete multi-step tasks on behalf of the user, rather than just a chatbot that answers questions. It can connect services such as email, calendaring, payments, dining and shopping, and perform a series of continuous operations based on user requirements.
For example, users can ask Muse to find products, compare prices, process shopping carts, and even complete purchases after receiving user confirmation. Meta said Muse runs in a secure virtual machine environment and has its own browser. For sensitive actions, such as sending an email or completing a purchase, the system will ask the user for confirmation before execution. In addition, Meta also designed an independent monitoring agent called Sentinel to audit the operations that Muse is preparing to send to the Internet.
The way Muse is able to access third-party services is also one of the keys to this dispute. Meta previously introduced that if a service provides a public API, Muse can use the credentials provided by the user to connect through the API; if a service does not have an API, Muse can directly access the website through a browser, similar to how a human user opens a web page to operate.
Amazon believes that the latter model is particularly prone to platform control and security issues. Because in this case, the AI agent can actually browse the website like a human, but may not identify itself to the website in the same way as traditional third-party partners.
Amazon pointed out that if users allow Muse to access their account pages and order history, Muse may enter an area containing a large amount of personal information. In Amazon's view, since Muse does not explicitly identify itself as an AI agent, this is equivalent to a third party not authorized by Amazon performing operations in user accounts.
This is also part of Amazon’s recent continued restrictions on external AI shopping agents. Over the past year, Amazon has been taking steps to prevent outside AI agents from directly entering its website. The company has previously sued Perplexity over similar issues, trying to prevent its Comet browser from shopping on Amazon on behalf of users, and has also taken steps to restrict shopping agents from companies such as Google and OpenAI.
The legal dispute between Amazon and Perplexity is particularly noteworthy. Amazon obtained a preliminary injunction against Perplexity in March this year, but the U.S. Ninth Circuit Court of Appeals overturned the decision on August 4. The court held that regarding the application of relevant federal anti-hacking laws, it was the user himself, not the AI company, who actually accessed Amazon's computer systems.
On September 10, the court rejected Amazon’s request to reopen the case. However, the relevant judgment still leaves a legal avenue for Amazon to make claims based on contractual relationships and website terms of service. After Muse was blocked this time, the prompt displayed to users by Amazon also did not accuse Meta of hacking, but directly quoted Amazon's terms of use.
This means that the conflict between Amazon and Meta may further become a case of how to draw the boundaries of authority between AI agents and Internet platforms. As AI agents gradually develop from "telling users what to buy" to "complete purchases for users," the originally implicit access rules between the platform and the AI company are becoming more important.
This incident is particularly sensitive for Amazon, because the e-commerce website itself not only bears the function of commodity trading, but is also an important foundation for Amazon’s advertising business. Amazon’s advertising revenue exceeded $68 billion last year, and its advertising business relies heavily on consumers to directly browse product pages, see recommended products, and interact with the platform. If consumers no longer directly open Amazon in the future, but let an AI agent search, compare and purchase for them in the background, then the direct relationship between Amazon and consumers and product display opportunities may change.
At the same time, Amazon itself has not given up on the AI agent shopping model. Amazon launched Alexa for Shopping in May this year, allowing AI to help consumers research products and provide purchasing recommendations. Amazon’s own “Buy for Me” feature can even find items on external brand websites and complete purchases.
However, Amazon emphasized that Buy for Me will clearly identify itself and allow relevant brands to opt out. This is significantly different from Muse's direct access to Amazon through the browser.
Therefore, this dispute is not just a product compatibility issue between Amazon and Meta, but a direct overlap in the roles of the two companies in the future "agency business" model. Amazon not only hopes to become the core entrance for consumers to use AI to shop, but also hopes to know which third-party AI can enter its e-commerce platform; while Meta hopes to make Muse a universal agent for users to handle real-life tasks such as shopping.
Muse has grown very quickly since its launch. Only about a week after its official release, it ranked first in the free application rankings of the US Apple App Store, surpassing ChatGPT. Early users have started using Muse to handle tasks such as changing car insurance policies, finding checkout discount codes, and setting up online grocery shopping carts.
This means that AI agents are rapidly moving from experimental chat tools to software capable of actually operating Internet services. For consumers, this model can reduce the process of repeatedly searching and filling in information between different websites; but for the platform, an AI agent that can independently browse pages, read information and complete transactions also means that the traditional website access model is changing.
After Amazon blocked Muse this time, negotiations between Meta and Amazon are still continuing. Amazon said the two sides were in direct communication but had no comment when asked about possible further legal action.
It is worth noting that the two companies are not purely competitive. Amazon products have been available for purchase through Facebook and Instagram since 2023, and in April this year, Meta also signed a multi-billion dollar agreement with Amazon to use Amazon cloud computing resources to run its agent-based AI workloads. Therefore, on the one hand, the two companies have commercial cooperation, and on the other hand, they are directly competing in the emerging field of AI agent shopping.
As more and more consumers begin to let AI agents search for products, compare prices, manage shopping carts, and even directly complete payments on their behalf, the future Internet business model may gradually shift from "users visit websites" to "AI agents visit websites on behalf of users." Under this model, issues such as user authorization, account credentials, platform terms, advertising display, and transaction control will become new issues that must be resolved between AI companies and Internet platforms. Amazon’s blockade of Muse is the latest case in which this round of agency-based e-commerce competition has entered the stage of actual conflict.
Comments