Amazon has blocked Muse, a new personal assistant developed by Meta, which was designed to navigate online marketplaces, including Amazon, and make purchases on behalf of users without revealing its identity. Amazon, founded by Jeff Bezos, cited account security and compliance with its terms of service as the reasons for the block. The conflict goes beyond password management and involves who controls consumer data, recommendations, and advertising revenue when artificial intelligence acts as a middleman between merchants and customers.
When a user on Facebook asks Muse to find a product on Amazon, the assistant now receives a warning: "Continuing access by an unauthorized artificial intelligence agent violates Amazon's terms of use, to which our customers have agreed to comply." Amazon had previously asked Meta to remove its marketplace from the services accessible to Muse, but Meta did not comply. Amazon claims it was not warned and accuses Muse of failing to identify itself when navigating the site, which could pose security risks for user accounts.
The dispute is not only about how an agent fills a shopping cart but also about the knowledge of consumer needs, how products are compared, exposure to sponsored items, and the relationship between the consumer and the platform. With Muse, a user can ask for a product that fits a specific budget, exclude certain brands, compare delivery times, and search for discounts. Meta then receives information about the user's preferences, including what they want to buy, their price range, and the time they prefer to place an order.
Amazon tracks each step of the customer journey, allowing it to personalize experiences, measure seller conversions, and sell visibility to brands. With an agent like Muse, the journey changes, as the user can ask the agent to find a product, and Muse can consult multiple merchants, compare options, and only go to Amazon at the moment of making a purchase.
Amazon's advertising revenue reached 68.6 billion dollars in 2025, with 21.3 billion in the fourth quarter. The risk for Amazon is becoming just one of many suppliers in a decision-making process organized by Meta. Muse can access password-protected pages, consult order history, and initiate transactions. If the agent does not identify itself, the merchant has no way of knowing that a third-party software is accessing the account, processing information, and acting on the user’s behalf.
Each user has a dedicated virtual machine in the cloud with its own browser. Identifiers are stored in a separate compartment, which the model cannot directly access. A second system, called Sentinel, controls internet connections and can request user authorization before performing sensitive actions, such as sending an email or validating a purchase.
For Amazon, the first issue with Meta's system is that it stores data that allow access to customers' accounts. Meta argues that its model does not see these data and cannot reveal them. The disagreement goes further, as Meta has no control over the design of this virtual machine, the controls performed by Sentinel, or the information transmitted to different service components. This raises the question of who would be responsible—Amazon, Meta, or the user—in case of an erroneous purchase, excessive information access, or account compromise.
The lack of identification of Muse is Amazon's strongest complaint. Without a machine identity, the platform cannot apply special rules to the agent, limit its access, or assign responsibility for any actions it takes. Meta argues that the account belongs to the user, who can authorize a software to act on their behalf. Muse would then be comparable to an advanced browser, capable of filling out forms, using the user's identifiers, and executing instructions after confirmation.
Amazon has a different view, stating that a customer's authorization would not be enough to impose an agent on a merchant. According to Amazon, third-party applications that make purchases on behalf of customers with other companies must operate transparently and respect the decisions of the service providers. Amazon compares agents to delivery platforms or travel agencies, which typically work with the agreement of the restaurants and airlines they represent.
However, this comparison has its limits, as a browser, a password manager, or an accessibility tool does not need to negotiate a contract with every site it visits. Muse is in a gray area—it is both a browser, a technical assistant, and an intermediary that can compare offers, select products, and execute transactions. The key question is at what point a software stops being a customer’s tool and becomes a separate commercial actor.
Amazon has already included its answer in its terms of use. The company now requires that agents identify themselves in their requests, reveal their name, and not attempt to bypass systems meant to detect or block automated software. It also reserves the right to limit their access. It remains to be seen how far these conditions can apply to the company that develops the agent, not just the user who agreed to them.
The dispute between Amazon and Perplexity helps understand the care given to the wording of the message shown to Muse. In November 2025, Amazon sued Perplexity regarding Comet, its browser with an assistant capable of making purchases. A court granted it a preliminary injunction in March 2026, but the Ninth Circuit overturned this decision in August 2026. The appellate court found that access to Amazon computers was made by the user, with the help of the agent, and not by Perplexity itself.
Amazon therefore had little chance of proving a violation of the Computer Fraud and Abuse Act, the main U.S. federal law aimed at preventing computer intrusions, or its California equivalent. The decision did not establish a general right for agents to access all platforms, but clarified that the court did not prevent Amazon from regulating access to its service through private contractual conditions. This is exactly the ground chosen against Meta. The warning to Muse users mentions neither hacking nor intrusion but invokes Amazon's terms of use.
Amazon does not oppose agents outright—it wants to set the rules. Amazon's position would be simpler if it did not send its own agents to make purchases on other sites. Its "Buy for Me" function allows ordering items from the Amazon app that the marketplace does not sell directly. The company assures that its agent operates transparently and leaves brands the option of not participating. Amazon also develops its own recommendation and purchase interfaces with Rufus and Alexa for Shopping.
The group is therefore not opposed to agent-based commerce and seeks to determine which machines can access its catalog, customer accounts, and transactional infrastructure, and under what conditions. This confrontation does not prevent the two companies from working together. Amazon products can be purchased from Facebook and Instagram since 2023, within a negotiated integration. Meta has also concluded a multi-billion-dollar agreement to use Amazon's Graviton processors in its agent-based workloads.
The two groups can cooperate on infrastructures and compete on the interface. The difficulties begin when the computing power provider risks becoming the mere executor of a purchase decided elsewhere. Meta moves from advertising to transaction. Muse reveals the direction Meta is taking. Until now, the essence of its model was to capture attention on Facebook or Instagram, sell advertising exposure, and then send the consumer to the merchant's site.
The agent allows going further: receiving the request, organizing the search, memorizing preferences, and accomplishing the action. Meta has already prepared part of the necessary infrastructure. Muse is accessible from its own applications and from WhatsApp, for payment, it can use Stripe's Link, which generates a single-use card to hide the real bank account details, and Meta also announces the arrival of Shop Pay. Thus, conversation, recommendation, authentication, and payment can be combined in a single interface.
The contrast with Shopify is interesting, where Amazon closes its site to agents it has not authorized, Shopify seeks to make its merchants' catalogs accessible from conversations driven by artificial intelligence. The divergence also lies in the economic models. Shopify sells an infrastructure to merchants and can profit by distributing their products in as many interfaces as possible. Amazon operates a marketplace, organizes the ranking of its sellers, and directly monetizes the attention of the buyer. Meta, on the other hand, could become the entrance to commerce without owning the stocks, warehouses, or delivery networks.
Its position would be that of an intermediary placed sufficiently upstream to know the intention, but close enough to the transaction to claim a share. The agent web will have to negotiate its entry points. The conflict will likely not be resolved by a lasting separation between agents and merchants. If consumers adopt these tools, platforms will have to define the modalities of their access: a verifiable machine identity, limited permissions, an action log, confirmation before payment, responsibility rules, and the possibility for a merchant to refuse certain usages.
The negotiation will also be about money, when an agent selects a product without displaying the merchant's sponsored placements, which funds the recommendation. Platforms could charge access to their catalogs, demand a commission, or create new advertising formats aimed at agents. These agents could in turn sell visibility to brands. It is at this moment that their promise of working exclusively for the user will be truly tested. An assistant supposed to find the best product can remain neutral if certain sellers pay to be examined first? Search engines took two decades to make this boundary more or less visible. Agents risk shifting it inside a decision that the consumer will not even see forming.
Amazon can today close its door to Muse, but it cannot force the consumer to start their search on Amazon. If the agent becomes the primary interface, the marketplace can retain the product, payment, and delivery while losing the knowledge of the need preceding the purchase. Therefore, the real issue is not whether Meta can shop at Amazon, but to determine who will retain the relationship with a customer when they no longer necessarily visit the store.
Amazon and Meta Clash Over Control of Customer Data in Personal Agent Era
AI-rewritten from original reportingHow it works
amazonmetamuseai-agentcommercedata-control



