On Sunday night, September 20, people who asked Meta’s Muse to shop Amazon.com started hitting a wall. “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed,” the popup read, per GeekWire. Amazon had cut off the number one free app in the United States, twelve days after it launched.
The timeline is the story. Meta introduced Muse on September 8 as a personal agent that handles multi-step tasks across email, calendar, payments, dining and shopping, available free on iOS, Android, muse.ai and WhatsApp. By September 18 it had overtaken ChatGPT as the top free iPhone app. By September 20, the largest store on the internet had locked its front door against it.
Consumer adoption is outrunning every institutional framework built to govern it. That is not a metaphor. It is a calendar.
What Amazon Alleges, and What Meta Answered
Amazon’s complaint has three parts, all laid out by the spokesperson GeekWire quoted. Meta never told Amazon that Muse would access its store. The agent does not identify itself when it browses. And it “appears to capture and store customer credentials,” including access to account pages and order history, which Amazon describes as an undisclosed third party moving through customer accounts and handling sensitive data without the merchant’s knowledge or consent.
“We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate,” Amazon’s spokesperson said.
Meta’s launch materials answer the security charge directly. Muse runs on Muse Secure VM, a dedicated cloud computer that houses the agent and the user’s connected data. A separate Sentinel agent runs on the same machine, isolated at the system level, and “nothing Muse does reaches the internet unless the Sentinel approves it.” Most pointedly: “Muse has no visibility into people’s passwords or payment methods. Any credentials a person shares go into secure storage, so Muse can use them without seeing them, including passwords a person types into the browser themselves.”
As for access mechanics, Meta describes two lanes. If a service has a public API, Muse connects with user-provided credentials. If it has no API, the agent “can use the service through a browser the way you would.” That second sentence, buried in launch documentation, is the entire conflict. A browser-using agent on a logged-in session is functionally a customer, at machine speed, on someone else’s storefront. Amazon considers that a trespass. The Ninth Circuit, so far, does not.
From Hacking Claims to Contract Claims
The legal choreography here matters more than the press statements, because Amazon has already run the other theory and lost. In March, Amazon won a preliminary injunction blocking Perplexity’s Comet browser from shopping its site. On August 4, the Ninth Circuit reversed, holding that the user, not the AI company, was the one accessing Amazon’s computers under the federal anti-hacking statute. The court denied Amazon’s rehearing petition on September 10.
Read the Muse popup again with that sequence in mind. It does not accuse anyone of hacking. It cites Conditions of Use. The ruling Amazon lost explicitly left open claims built on contracts and terms of service, and Amazon has now pivoted to exactly that runway. When the law stops treating your customer’s agent as an intruder, you renegotiate the meaning of “customer.”
The awkwardness is that Amazon’s own analogies cut both ways. The company likens agent operators to food delivery apps working with restaurants and travel agencies booking with airlines, relationships built on merchant agreement. But Amazon’s own agentic shopping feature, Buy for Me, buys from external brands’ sites while identifying itself and letting brands opt out, and the company unified Alexa and Rufus into Alexa for Shopping in May. Amazon asks for the courtesy it extends, which is a defensible principle. It also happens to preserve a $68 billion interest.
The $68 Billion Reason
GeekWire notes the business stake plainly: Amazon generated more than $68 billion in advertising revenue last year, a business that depends on people browsing its pages and seeing sponsored products. An agent that loads the cart without rendering the shelf does not see the sponsored placements. It does not see the retail media. It compresses an ad-funded browsing session into an API-shaped transaction.
The demand side makes the threat concrete. PYMNTS Intelligence counts roughly 132 million US adults who have bought a retail product with AI’s help, and 59 percent of those AI-assisted purchases land on Amazon. When the majority of a channel’s AI-mediated volume flows through your store, you either own the agent or you become inventory behind someone else’s interface. Amazon has chosen to own the agent. Blocking Muse, Google’s shopping agents, OpenAI’s shopping agent and suing Perplexity are not separate decisions. They are one strategy: no one intermediates Amazon’s customer except Amazon.
There is even a partnership layer that makes the blockade stranger. Amazon products have been purchasable inside Facebook and Instagram since 2023, and Meta signed a multibillion-dollar deal in April to run agentic AI workloads on Amazon’s Graviton chips. Meta trains its agents on Amazon’s silicon; its agents cannot shop Amazon’s store. Commerce makes strange bedfellows and stranger fences.
What Consumers Actually Fear Is Not Access
While the giants litigate access, the consumer data published the same week says the binding constraint is something else entirely. The French E-commerce Federation and KPMG released their agentic commerce study on September 18, and the numbers draw the frontier precisely:
- 31 percent of online shoppers already use AI in their shopping journeys, and the heaviest users reach for it on 73 percent of planned purchases.
- Before purchase, 58 percent regularly use AI agents. Trust in those agents: 47 percent.
- At payment, usage drops to 27 percent and confidence to 30 percent.
- 57 percent of consumer refusals stem from doubts about the commercial neutrality of recommendations.
“Agentic commerce is shifting the centre of gravity in e-commerce,” François Xavier Leroux, a partner at KPMG in France, told FashionNetwork. “The aim is no longer simply to secure a click, but to be included in a recommendation generated by artificial intelligence, and retailers who can make their offerings clear, reliable and actionable by these new intermediaries will have a decisive competitive advantage in the years to come.”
Marc Lolivier, executive director of Fevad, called it a change in “how consumers make choices, how retailers reach their customers and how value is distributed among the various players.”
Notice what consumers are telling researchers, as opposed to what platforms are telling courts. The blocker is not “can the agent get into the store.” It is “can I believe the agent’s recommendation, given that somebody might be paying for it.” Amazon is fortifying the perimeter of a trust problem that lives inside the recommendation itself. A user blocked from Muse-on-Amazon does not become a browser again; they become a Muse-on-Shopify user.
The Route Around the Wall
Which is exactly what is happening. Muse scours Shopify catalogs using the Universal Commerce Protocol, co-developed by Google and Shopify, and checks out through Shop Pay across Shopify-powered stores, a partnership Shopify CEO Tobias Lütke announced at launch. Stripe’s Link wallet generates one-time-use cards for Muse purchases, and Link’s purchase protections, covering damaged items, price drops, no-fee returns and a return guarantee, extend to Muse as their first AI agent.
The payment and identity rails of agentic commerce are being assembled in the open, on protocols, by parties who want the traffic. The perimeter wars will decide who hosts the transaction. They will not decide whether agent commerce happens. Volume flows to surfaces that welcome it, and the open rails are already ahead of the walled ones.
But now ask the question the protocol stack cannot answer. When Muse shortlists five strollers from a Shopify catalog, what does it know about those products beyond the merchant-authored attributes? Ratings and review corpora still feed every ranking, and the contamination of those corpora is documented by the platforms themselves: Amazon reports blocking hundreds of millions of suspected fake reviews annually, and independent detection work keeps finding AI-generated text on front pages. An agent that cannot see a sponsored label on Amazon because Amazon blocked it also cannot see a purchased review on Shopify because nobody filters it. The walled garden and the open road have identical epistemics. Whatever the merchant says is what the agent knows.
The Layer That Does Not Belong to Either Side
Access disputes have venues: courts, contract law, protocol consortia. Product truth has no venue, which is the gap GoBuy occupies, deliberately and openly:
- Filter before scoring. Smart Score runs 0 to 100 on review quality computed after manipulated and low-information reviews are removed, so the substrate under any recommendation is clean before an agent reads it.
- Curation over firehose. Top seven verified products per category, not thousands of ranked listings, which means the shortlist an agent shows was not purchased, placed or sponsored into existence.
- Persistence as the test. The GoBuy Verified badge requires a filtered score of 80 or above sustained for 90 days. An advertising budget can buy a week of attention. It cannot easily buy a quarter of verified quality.
- Protocol-native delivery. Agents consult GoBuy over MCP at gobuy.ai/api/mcp, so the trust check happens inside the agent’s workflow regardless of which storefront, protocol or walled garden hosts the transaction. The Chrome extension puts the same panel on Amazon pages for the humans still browsing them.
The design principle underneath all four: verification that lives inside any single commerce platform inherits that platform’s incentives. Amazon’s referee problem in its sponsored auctions and Meta’s neutrality problem in its recommendations are the same structural fact wearing two logos. A trust layer has to sit outside the transaction to be believed about it.
What to Watch
Four signals over the next quarter. First, whether Amazon files a Conditions of Use action against Meta, which would make the contract theory the first real courtroom test of agent access since the CFAA theory died in August. Second, whether Meta adds agent self-identification and negotiates sanctioned API access, converging on the Buy for Me model Amazon demands of others. Third, whether Muse’s Shopify volume holds: if agent-mediated sales on welcoming rails keep growing while the blockade stands, the perimeter strategy starts looking like a tax on Amazon’s own future traffic. Fourth, and least covered: the first mainstream incident where an agent’s shortlist on open rails is shown to have been shaped by manipulated reviews, which will make the neutrality numbers in the Fevad study look like a leading indicator.
The access war has lawyers. The truth war has an opening.
Check what your agent is about to buy, before it buys it, at gobuy.ai, and if you build agents, wire them to independent product verification first at gobuy.ai/agent-docs.