Amazon blocks Meta's Muse AI agent from shopping on its store
Amazon says it first asked Meta to take its store out of Muse, without success. The dispute looks set to turn on terms of service rather than hacking law.

Key takeaways
- Amazon blocked Meta's Muse agent from Amazon.com after asking Meta to exclude the store.
- Amazon objects that Muse does not identify itself and stores customers' login details.
- Muse runs in Meta's cloud, so the Perplexity appeals ruling may not carry over.
Amazon has cut off Muse, Meta's two-week-old personal AI agent, from shopping on Amazon.com. GeekWire reported the block late on Sunday, September 20. Amazon says it acted after trying, without success, to get Meta to take the store out of Muse voluntarily.
People who send the agent to Amazon now meet a notice: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." Meta had not responded to GeekWire by Sunday night. Amazon says the two companies are in direct talks and declined to say whether it will sue.
What Amazon objects to
Amazon's complaint, as GeekWire reports it, has three parts. Meta never told Amazon that Muse would be operating on the store. The agent does not identify itself when it browses. And it captures and stores customers' login details, which Amazon calls a privacy and security risk. If a user asks, Muse can also reach account pages and order history.
A spokesperson put the principle this way:
"We think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate."
Meta's launch post of September 8 anticipates the point about credentials. "Muse has no visibility into people's passwords or payment methods," it says. "Any credentials a person shares go into secure storage, so Muse can use them without seeing them." A second agent called Sentinel must approve anything Muse sends to the internet, Muse asks the user before making a purchase, and checkout runs through Stripe's Link, which generates a one-time-use card. The post says nothing about whether Muse announces itself to the websites it visits. That is the heart of Amazon's objection.
Why the Perplexity ruling may not settle this one
Amazon has been here before. It sued Perplexity over the shopping assistant in the Comet browser and won a preliminary injunction in March. On August 4 the Ninth Circuit appeals court threw that injunction out, and on September 10 it declined to rehear the case. Courthouse News reported that not one judge asked for a vote.
So is the law now on the agents' side? Only partly, and here is the detail most coverage will skip. The appeals court reasoned that "it is the user who 'accesses' Amazon's computers," with the assistant's help, and found that "Perplexity itself does not directly communicate with Amazon's servers." It described Comet as a browser "running locally on a user's machine." Muse does not work that way. Meta's post says Muse "runs on its own dedicated computer in the cloud" and can open a browser there to fill out forms on a person's behalf.
Would a court treat a cloud computer operated by Meta the way the Ninth Circuit treated a browser on your laptop? Nobody has asked one yet. That is our reading of the two documents, not a position either company has taken.
The panel also limited itself. It ruled on two anti-hacking statutes, the federal Computer Fraud and Abuse Act and its California counterpart, and wrote that it did "not address whether in other contexts, including tort claims, Perplexity can avoid liability." GeekWire notes that claims based on contracts and terms of service were left open. Amazon's notice to Muse users is worded to match: it cites the Conditions of Use that customers accepted and makes no mention of hacking.
What Amazon is protecting
Follow the money. Amazon took in more than $68 billion from advertising in 2025, GeekWire reports, a business that depends on people browsing the store and seeing sponsored listings. An agent that goes straight to checkout does not linger over sponsored results. That, at least, is the obvious commercial worry.
Amazon also runs agents of its own: Alexa for Shopping, launched in May, and Buy for Me, which purchases from other brands' websites. Its answer to the charge of a double standard is that Buy for Me identifies itself and lets brands opt out. It has already moved to block shopping agents from Google and OpenAI.
The awkward part is that these two companies are partners. Amazon products have been on sale inside Facebook and Instagram since 2023, and in April Meta signed a multibillion-dollar deal to run AI agent workloads on Amazon's cloud, using Amazon's Graviton chips.
Who gains, who loses
Muse became the No. 1 free app on Apple's US App Store within a week of launch, ahead of ChatGPT, with early users reporting that it loaded grocery carts and hunted for discount codes. A shopping agent that cannot shop on Amazon is a lesser product, so Meta loses most in the short run. Users lose a convenience. Amazon keeps control of its storefront, at the price of looking like a gatekeeper while it promotes agents of its own.
Watch whether Amazon files a contract claim against Meta, or whether the two settle on terms, perhaps an agent that identifies itself and operates with Amazon's agreement. Either outcome will be studied by every other retailer deciding whether to let agents through the door.
- AI agents
- Amazon
- Meta
- Muse
- agentic commerce
- Perplexity
Sources
- Amazon blocks Meta's Muse AI assistant in new standoff over agentic shopping — GeekWire, Sep 20, 2026
- Introducing Muse: The World's First Personal AI Agent Built for Everyone — Meta, Sep 8, 2026
- Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (opinion) — US Court of Appeals for the Ninth Circuit, Aug 4, 2026
- No 9th Circuit rehearing in Amazon-Perplexity case — Courthouse News Service, Sep 10, 2026
Related stories

Microsoft opens Hyderabad cloud region, its fourth in India, for AI
India South Central is live, with Adani Group, Bajaj Finserv, HDFC Bank and PB Pay signed up. Microsoft has not said how much AI computing capacity the region holds.
3 min read

Subscribers sue Anthropic, OpenAI, Google, SpaceXAI over AI pacing
A proposed class action filed in San Francisco says the labs' public agreement to slow frontier AI is an illegal deal among rivals. The evidence is the executives' own words.
4 min read

OpenAI Publishes Framework for Disclosing Model Misalignment
OpenAI has set out how it will track and report cases of AI models behaving in unintended ways, and published six examples alongside the new framework.
3 min read
Comments
No comments yet. Start the conversation.