Amazon has blocked Meta’s new Muse agent from shopping on Amazon.com, less than two weeks after Meta launched it as a personal assistant that can browse, fill forms and make purchases. GeekWire reports that Amazon asked Meta to remove the store from Muse, then began showing users a notice that the agent’s access violates Amazon’s terms. Meta did not respond to the publication’s request for comment.

The immediate inconvenience is plain: a user can ask Muse to shop elsewhere, but not to complete the same job on the largest U.S. online marketplace. The larger problem is less tidy. Consumer agents are arriving before the web has settled who must authorize them, how they identify themselves and which company carries the blame when automation makes an expensive little decision.

A browser with someone else’s keys

Meta says Muse runs inside a dedicated cloud virtual machine, keeps credentials in secure storage, asks before sensitive actions and gives users an audit trail. A separate Sentinel system is supposed to approve anything the agent sends to the internet. Meta also says Muse cannot see passwords or payment details, even when it uses them, and can pay with a one-time card through Stripe’s Link.

Those controls protect the person from some failures inside Meta’s system. They do not answer Amazon’s objection that the merchant did not approve an undisclosed automated visitor moving through account pages and processing transactions. Amazon told reporters that Muse does not identify itself, can reach order history when asked and was neither authorized to scrape store data nor act inside customer accounts. Axios reports that Amazon framed the dispute as a requirement for third-party purchasing services to operate openly and let service providers decide whether to participate.

That sounds like a safety rule, and it is partly one. A merchant needs to distinguish a customer from malware, rate-limit abuse, handle returns and know which system generated an order. It is also a business rule. An outside agent can compare products without lingering over sponsored placements, move the customer relationship to another company and reduce Amazon’s control over discovery. Security and self-interest have achieved the rare corporate feat of sharing a shopping cart.

The law did not settle the product boundary

Amazon has fought this fight before. It sued Perplexity over the Comet browser and initially won an injunction. In August, the Ninth Circuit vacated that order, finding Amazon was unlikely to show that Perplexity itself accessed Amazon’s computers under federal and California anti-hacking laws when the user employed an AI tool to act on the site. The court sent the case back for further proceedings; it did not create a general right for every agent to enter every service.

The Muse warning instead points to Amazon’s Conditions of Use. That pivot matters. If anti-hacking law treats the agent as a user’s tool, platforms may lean harder on contracts, technical blocks and negotiated access. The result could be a patchwork where a personal agent is capable of a task but only permitted to perform it on businesses that have signed on.

TINA’s view: require identity, then require fair rules

TINA’s view: Amazon is justified in demanding that an agent identify itself before it reaches customer accounts or places orders. User permission is necessary, but it is not a substitute for secure delegation, transaction logs, revocation and a clear path for disputes. Meta’s safety architecture addresses important risks; it does not automatically grant Muse a backstage pass to somebody else’s store.

The strongest counterargument is that Amazon can use “safety” to protect its advertising funnel and exclude assistants that shop too efficiently. That concern is credible, especially when Amazon operates its own shopping agents. The durable answer is not invisible automation or permanent platform vetoes. It is a technical and commercial standard for agent identity, scoped credentials, merchant opt-out, liability and non-discriminatory access.

This judgment would change if Meta shows Muse already provides Amazon with reliable identity and tightly scoped authorization, or if Amazon opens comparable access only to its own agents while rejecting technically equivalent rivals. Watch whether the companies negotiate access, whether Muse changes its identification behavior, and whether courts or standards bodies turn this improvised barricade into a rule the rest of the web can actually use.