Agentic shopping has its first head-on collision between two of the largest companies in technology. As of Sunday night, 20 September 2026, anyone trying to use Meta’s new Muse assistant to buy something on Amazon.com hits a popup instead: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.”

Amazon says it asked Meta to exclude the site from Muse’s agentic shopping reach voluntarily, and was refused. Its stated objections are specific: Meta never told Amazon that Muse would be browsing its store, the agent does not identify itself while it does so, and it appears to capture and store customer credentials. Meta’s launch materials say the opposite about credentials — that Muse “has no visibility into people’s passwords or payment methods.”

The dispute is not really about Muse. It is about who controls the customer relationship when software does the buying, and it arrives six weeks after a federal appeals court took away Amazon’s strongest legal weapon for stopping it. This article covers what each side has said, the legal history that shapes the wording of that popup, why the two companies are business partners in the middle of this, and what it signals for anyone building on top of a retailer’s website.

What Amazon Actually Said About Agentic Shopping

agentic shopping amazon bars meta muse ai b culvert pipe section lying on its side

The statements are worth reading closely, because they set out a policy rather than a complaint about one product.

The agentic shopping openness argument

An Amazon spokesperson framed it as a general principle: “We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate.” The two conditions in that sentence — disclose yourself, and accept a refusal — are the whole policy.

The analogy Amazon chose

The company compared agentic shopping intermediaries to food delivery apps and the restaurants they take orders for, and to online travel agencies and the airlines whose tickets they sell. In both cases the intermediary has an agreement with the supplier. “Agentic third-party applications such as Muse have the same obligations, and we’ve requested that Meta remove Amazon from the experience.”

The agentic shopping security framing

Amazon says Muse can reach account pages and order history if a customer asks it to. Because the agent does not identify itself, Amazon characterises that as an undisclosed third party moving through customer accounts, processing transactions and handling sensitive data without the site’s knowledge or consent.

What Meta has said about agentic shopping

Meta’s position comes from the Muse launch materials rather than a response to Amazon. Credentials a user shares “go into secure storage, so Muse can use them without seeing them, including passwords a person types into the browser themselves.” Meta did not immediately respond to requests for comment on Sunday night. Amazon said it is in direct conversation with Meta, and declined to say whether it would consider legal action.

How Muse Does Agentic Shopping in the First Place

agentic shopping amazon bars meta muse ai c holdall bag with a closed loop top handle

Understanding the agentic shopping mechanism explains why this was always going to end in an argument.

What Meta launched on 8 September

Muse is a personal agent that carries out multi-step tasks rather than answering one-off questions, connecting to email, calendar, payments, dining and shopping. It is free with paid subscription tiers, and available on iOS, Android, the web at muse.ai and inside WhatsApp. Meta describes it as “a secure, private personal AI agent that proactively helps with people’s goals and suggests ideas.”

The agentic shopping architecture Meta describes

The agent runs on a secure virtual machine with its own browser. It checks with the user before sensitive actions such as sending an email or making a purchase. A separate monitoring agent called Sentinel has to approve anything Muse sends to the internet. Purchases use a single-use card generated through Link by Stripe.

The clause at the centre of the dispute

Meta’s own launch materials describe the mechanism Amazon objects to. If a service has a public API, Muse connects to it using credentials the user provides. If it has no API at all, the agent “can use the service through a browser the way you would.” Amazon has no public purchasing API for third-party agents. So Muse does the second thing.

Agentic shopping went mainstream in a week

A week after launch it was the number one free app in Apple’s US App Store, ahead of ChatGPT. Early users describe it switching an auto insurance policy, hunting discount codes at checkout and loading an online grocery cart. That adoption curve is why this became urgent rather than theoretical. We covered the Muse launch and what Meta claimed for it when it was announced.

agentic shopping amazon bars meta muse ai d tuckbox chest with a hinged lid and a raised front clasp

The most revealing detail in this agentic shopping story is what Amazon’s message does not say.

Amazon sued Perplexity in November 2025

The precedent case is Comet, Perplexity’s browser with a built-in agent that shops Amazon for its users. Amazon sued, and in March 2026 won a preliminary injunction barring the agent from the password-protected parts of its site. For a few months, that looked like the template for controlling agentic shopping outright.

The Ninth Circuit took it away on 4 August 2026

The appeals court reversed, ruling that under federal anti-hacking law the user — not the AI company — is the one accessing Amazon’s computers. The court denied Amazon’s petition for rehearing on 10 September 2026. The Computer Fraud and Abuse Act route is, for now, closed.

What the ruling left open

Claims built on contracts and terms of service. Which is precisely why the Muse popup cites Amazon’s Conditions of Use and accuses nobody of hacking. The wording is a legal position, drafted by people who lost on one theory and are testing another.

DateEventEffect on agentic shopping
November 2025Amazon sues Perplexity over the Comet browser agentFirst major test case filed
March 2026Amazon wins a preliminary injunctionComet barred from password-protected areas
May 2026Amazon launches Alexa for ShoppingAmazon’s own research-and-recommend agent
4 August 2026Ninth Circuit reverses: the user is the one accessingAnti-hacking law route closed
8 September 2026Meta launches MuseA top-of-the-charts agent starts browsing retail
10 September 2026Rehearing petition deniedContract and ToS claims left as the open path
20 September 2026Amazon blocks Muse, citing Conditions of UseThe contract theory goes live

Perplexity was not the only agentic shopping target

Amazon has spent the past year keeping outside agents off its site, and has moved to block shopping agents from Google and OpenAI as well. Meta is the largest name to date, not the first.

Why the Business Relationship Makes This Strange

agentic shopping amazon bars meta muse ai e corkscrew with a helical shaft and a round top cap

Two companies in an escalating agentic shopping standoff would be unremarkable. These two are commercial partners on both sides of the fight.

They already sell to each other’s users

Amazon products have been purchasable inside Facebook and Instagram since 2023. That arrangement is the exact model Amazon says it wants: a negotiated integration where both sides agreed to participate.

Meta runs AI workloads on Amazon silicon

In April 2026 Meta signed a multibillion-dollar deal to run agentic AI workloads on Amazon’s Graviton chips. The compute behind Muse-class products is, in part, rented from the company now blocking Muse.

What is actually at stake for Amazon

More than $68 billion in advertising revenue last year, a business that depends on people browsing Amazon’s pages and seeing sponsored products. An agent that goes straight to a product and buys it sees no ads at all. Agentic shopping does not just disintermediate the retailer’s recommendations; it disintermediates the highest-margin part of the business.

What an agent bypasses: Amazon’s reported 2025 advertising revenue against the scale of the dispute
Amazon advertising revenue, last year — more than $68bn
Muse age at the time of the block — 12 days
Days from Muse launch to No. 1 free US App Store — 7
Days from the rehearing denial to the block — 10

Amazon's Own Agentic Shopping Products

agentic shopping amazon bars meta muse ai f weir wall with three wide descending steps

The charge of hypocrisy over agentic shopping is the obvious one, and Amazon has a prepared answer.

Amazon’s own agentic shopping features

Amazon launched Alexa for Shopping in May 2026, an AI agent that researches products and makes recommendations. Its agentic feature, Buy for Me, goes further: it finds items on external brands’ sites and purchases them on the customer’s behalf.

The difference Amazon points to

Buy for Me identifies itself, and brands can opt out. Those are exactly the two conditions in the company’s public statement. Whether that constitutes a principled distinction or a convenient one depends on how easy the opt-out actually is — but as a stated policy it is at least internally consistent.

PropertyMeta MuseAmazon Buy for Me
Identifies itself to the merchantNo, per AmazonYes, per Amazon
Merchant can opt outNot offeredYes
Access methodPublic API, or a browser if none existsExternal brand sites
PaymentSingle-use card via Link by StripeAmazon account payment
Oversight layerSentinel monitoring agent approves outbound actionsAmazon’s own systems
User confirmation before purchaseYes, per MetaYes

The unresolved factual dispute

One item in that table is contested rather than unclear. Amazon says Muse “appears to capture and store customer credentials”; Meta says credentials go into secure storage that Muse itself cannot read. Both cannot be describing the same thing accurately, and neither has published evidence.

The Credential Question at the Heart of Agentic Shopping

The factual dispute is narrow and it is the one thing in this story that could be settled with evidence rather than argument.

What “secure storage” probably means

Meta’s phrasing — credentials go into secure storage “so Muse can use them without seeing them, including passwords a person types into the browser themselves” — describes a vault the model does not read from, with the browser automation layer retrieving the secret at the point of use. That is a recognisable design, and it is a meaningfully better one than putting a password in a prompt.

What Amazon is objecting to

Amazon’s phrasing is “appears to capture and store customer credentials”. Both statements can be simultaneously true. A credential that never enters the model’s context window is still a credential captured and stored by Meta’s infrastructure rather than held by the customer’s own browser, and from the site’s perspective that is a third party holding keys to an account.

Why the distinction matters for agentic shopping generally

Every agent that operates on a site without an API faces the same problem: it needs to authenticate as the user, because the site offers no way to authenticate as an agent acting for the user. Delegated credentials with scoped permissions are the standard answer elsewhere in software, and their absence here is a gap in the retail web rather than a flaw unique to Muse.

The single-use card is the clearer design

The payment side is less contentious. A single-use card generated through Link by Stripe limits the blast radius of a compromised session to one transaction, which is a stronger guarantee than a stored card on file. It also means the merchant cannot easily recognise a repeat customer — another quiet cost of agentic shopping that nobody has priced yet.

How Merchants Should Prepare for Agentic Shopping

Most retailers are not Amazon and will not get to set the terms. They still have decisions to make.

Work out whether an agent is a customer or a competitor

For a retailer whose margin comes from selling goods, an agent that brings a completed basket is a channel. For one whose margin comes from advertising, merchandising or upsell, it is a threat. Amazon is decisively in the second camp, which is why its response is the firmest in the industry.

Log what you can already see

Even without a formal agent policy, session telemetry usually distinguishes automated behaviour from human behaviour: navigation speed, absence of scroll and hover, straight-line paths to a product page. Knowing how much of your traffic is already agentic shopping is a prerequisite to having an opinion about it.

Decide the policy before the traffic arrives

Amazon’s position took a year, a lawsuit and an appeal to arrive at. A smaller merchant can reach a defensible version in an afternoon: publish whether agents are welcome, what identification you require, and what you will do about unidentified ones. Terms of service that say nothing about agents are the weakest position available.

Expect the ground to keep moving

The Ninth Circuit ruling changed the legal landscape in six weeks. A contract theory that works today may be tested next quarter, and the technical arms race between undeclared automation and detection has no obvious stopping point.

What Agentic Shopping Looks Like After This

The specifics will be settled by lawyers. The pattern is already visible.

Identification is becoming the price of agentic shopping

Both sides of this argument agree on one thing: an agent that announces itself is easier to allow than one that does not. Expect self-identification headers, signed agent credentials and merchant allowlists to arrive faster than any court ruling.

The browser is a loophole, not a channel

Meta’s “use the service through a browser the way you would” clause is the crux. It works technically and it is exactly what a retailer with no agent API cannot distinguish from a customer — until it can, at which point the block is a configuration change rather than a lawsuit.

The customer is the party nobody is representing

Both companies are arguing about consent, and neither is arguing about the customer’s. Amazon’s position is that its customers agreed to Conditions of Use that forbid this; Meta’s is that its users asked for an agent that shops for them. Those are both true, and the person who wants a working assistant and a working Amazon account is the one caught between them. Nothing in the current dispute produces a mechanism by which a customer could simply authorise an agent to act on their behalf and have both parties accept it.

Retailers will build the toll booth

A negotiated agent API, with terms and a revenue share, is the obvious equilibrium. Amazon’s food-delivery analogy is not accidental: those platforms ended up with commission agreements, and the company is signalling the shape of the deal it would accept.

Agentic shopping gives security teams a new category

An agent operating inside a logged-in session, on a virtual machine, with stored credentials, is a genuinely new thing to threat-model. The concerns Amazon raises about an unidentified party moving through customer accounts are the same ones that make AI security an engineering problem at every layer of the agent stack, whoever is right about Muse specifically. Teams deploying autonomous AI agents against third-party sites should assume the access they rely on today is revocable.

Frequently Asked Questions About the Amazon and Muse Dispute

Is Muse blocked from agentic shopping on Amazon entirely?

Users attempting agentic shopping on Amazon.com through Muse see the Conditions of Use popup. Amazon says it is in direct conversation with Meta, so the block’s scope and duration may change.

Did Amazon sue Meta?

No. Amazon declined to comment on whether it would consider legal action. The block is an enforcement of its Conditions of Use rather than a filed claim.

Why did the Perplexity ruling matter here?

Because it removed anti-hacking law as a tool. The Ninth Circuit held that the user, not the AI company, accesses the site. Contract and terms-of-service claims survived, which is the theory the Muse popup relies on.

Can users still buy from Amazon manually?

Yes. Nothing about this affects a person shopping on Amazon themselves. It affects software doing it on their behalf without identifying itself.

Does this apply to other agents?

Amazon has moved against Perplexity’s Comet and shopping agents from Google and OpenAI. The stated policy applies to any third-party application making purchases on a customer’s behalf.

What would make agentic shopping acceptable to Amazon?

Two things, on the company’s own account: the agent identifies itself to the merchant, and the merchant can decline to participate. Amazon says its own Buy for Me feature meets both conditions on the external sites it buys from.

Is Meta’s Sentinel agent relevant to the dispute?

Only indirectly. Sentinel approves what Muse sends to the internet, which is an internal safety control rather than a disclosure to the sites being visited. Amazon’s objection is about what the merchant can see, not about what Meta’s own stack checks.

References