Amazon blocks Muse: Meta launches an agent that shops on your behalf, Amazon says "no" within hours
🔎 The first duel between an AI agent and an e-commerce giant
A few hours. That's all the career of Muse on Amazon.com lasted. A few hours between the moment Meta activated the shopping feature of its personal agent and the moment Amazon cut off access — no public negotiation, no grace period.
The scene is unprecedented. For the first time, a mainstream AI agent, deployed to hundreds of millions of users via WhatsApp, found itself facing the largest e-commerce merchant on the planet. And the merchant said no.
Behind this block, far more than a technical dispute is at stake: who has the right to act on your account when it's an AI doing the clicking? Who bears responsibility for a purchase decided by an agent? And above all, who owns the interface between you and the merchant? Amazon's answer is clear: itself. Meta's answer too: Muse. In the middle, your credentials and your credit card.
The essentials
- The lightning-fast block: Amazon cut off Muse's access to Amazon.com just hours after the rollout of its shopping feature, reports GeekWire.
- The reason: Muse browsed and made purchases on behalf of users without identifying itself as an agent or notifying Amazon — a violation of the terms of service, according to the platform.
- The gray area: Amazon raises the question of credential capture. Meta denies it and assures that Muse only acts with the user's explicit authorization.
- The precedent: this is the second confrontation of its kind, following Amazon's cease-and-desist against Perplexity in November 2025.
- The paradox: Meta is one of the biggest customers of AWS, Amazon's cloud division, for its agentic workloads.
- The stakes: agentic commerce, a market everyone wants to control — and that no one wants to see captured by a rival.
Recommended Tools
| Tool | Main use | Price (January 2026) | Ideal for |
|---|---|---|---|
| Muse (Meta) | Personal agent, shopping via WhatsApp | Free (check meta.com) | General public, Meta ecosystem |
| ChatGPT Work (OpenAI) | Long-running agent, complex tasks | From $20/month (check openai.com) | Pros, monitoring, comparison shopping |
| OpenClaw | Self-hosted open source agent | Free (open source) | Developers, full control |
| Perplexity Comet | Agentic browser | Included in Perplexity Pro (check perplexity.ai) | Browsing + assisted shopping |
| Hostinger | VPS to host your agent | From ~€5/month (check hostinger.com) | Self-hosting OpenClaw/Ollama |
What happened: a lightning-fast block
Amazon cut off Muse's access to Amazon.com within hours, after detecting that Meta's agent was making automated purchases on behalf of real users. The standoff began the moment the feature was activated.
The timeline, reconstructed by GeekWire, unfolds in three acts. First, Meta rolls out Muse's shopping feature: the agent browses Amazon.com, compares products, fills the cart, and completes the purchase with the payment methods configured by the user. Next, the first posts from satisfied users start flying across social media. Finally, Amazon detects the browsing pattern, isolates it, and blocks it.
The sore point: Muse wasn't identifying itself. No identification as an agent, no advance notice, no going through a partner API. In Amazon's eyes, this traffic behaved like a human while not being one.
According to AI Weekly, the block covers browsing and purchases on Amazon.com, with Meta having received no formal warning before the cutoff. A blunt response, befitting what Amazon considers a head-on violation of its terms of service.
On Meta's side, they deny it. The company claims that Muse only acts with the user's explicit authorization, that credentials are neither captured nor stored on its servers, and that the feature is designed to respect e-commerce platforms. Translation: "we are your users, not your bots." Amazon doesn't see it that way.
Why Amazon Fired Without Warning
Because Muse crossed three red lines at once: prohibited automated traffic, manipulation of user credentials, and disintermediation of the merchant relationship. Any one of them would suffice on its own. All three together explain the speed of the response.
Red Line #1: The Contract
Amazon's terms of service prohibit automated access to the platform without written authorization. This isn't a legal subtlety: it's the foundation that has protected Amazon against scraping, price comparison engines, and shopping bots for twenty years. Muse never asked for permission.
Red Line #2: The Credentials
To buy on your behalf, Muse has to use your Amazon session — and therefore handle your credentials. Amazon has no way to verify where those credentials travel, whether they're stored, or what happens in the event of a leak. According to GeekWire, it's precisely the question of credential capture that's troubling Amazon's legal teams. Meta disputes this interpretation, but the objection stands: Amazon cannot audit what it cannot see.
Red Line #3: The Business
This is the most important one. If the agent does the searching, compares the prices, and makes the choice, Amazon loses control of its own storefront: no more recommendations seen, no more upsell, no more sponsored ads — a $56 billion-a-year revenue machine for Amazon (fiscal year 2024). The agent becomes the interface. And an interface can be monetized. Or blocked.
The context makes Amazon all the more nervous: according to the 2025 Imperva Bad Bot Report, automated traffic surpassed human traffic on the web in 2024, at 51%. Retail sites are the number one target. If Amazon tolerates Muse, it loses the argument it uses against all the other bots. Muse, with millions of potential users, isn't just another bot: it's an army.
Muse, the mass-market agent born from OpenClaw
Muse is not a lab project: it's the first AI agent distributed at WhatsApp scale. And that's exactly what terrifies Amazon — not what Muse does, but how fast it can do it.
As we recounted in Meta Muse: OpenClaw becomes a mass-market product — Meta's personal agent lands on WhatsApp, Muse is the culmination of Meta's agentic strategy: a personal agent that lives in a messaging app used by nearly 3 billion people (Meta, 2025), capable of comparing, booking, buying, and tracking orders.
The engine has changed in nature. Since the launch of Muse Spark 1.1, detailed in Meta Muse Spark 1.1: Meta launches its first paid model and enters the agentic coding battle, Meta controls its stack end to end. And in the process, it buried its open source legacy, as seen in Meta Muse Spark: why Meta betrayed open source — the first closed model of the.
This vertical integration — messaging, model, agent — sets Muse apart from all previous agents. OpenAI Operator remained confined to a $200/month subscription (January 2025, verify on openai.com). Muse is free and already installed.
That's also what explains the ferocity of Amazon's reaction. An experimental agent, you tolerate. A mass-market agent that enters the merchant's home through the messaging window, you block before it moves in.
Who has the right to act on your account?
Legally, almost no one — and that's precisely the gap Muse has just illustrated. Neither the terms of service, nor criminal law, nor civil law anticipated the agent that buys on your behalf.
The contract binds the human, not the agent
Let's start with contract law. Amazon's terms of service bind you, the human account holder. They provide nothing for your agent. When Muse violates the terms, it's not Meta that gets sanctioned: it's your account that risks suspension. The user bears the risk of a tool they don't technically control. That's the heart of the imbalance.
Criminal law is more nuanced than you might think
American case law has narrowed the scope of the Computer Fraud and Abuse Act: the Van Buren v. United States ruling (Supreme Court, 2021) severely constrained the notion of unauthorized access. And in Meta Platforms v. Bright Data (January 2024), a federal court in California ruled that scraping public data does not constitute hacking. But be careful: browsing public pages and logging into a private account with credentials are not the same thing. The latter remains a minefield.
The void of the agentic mandate
The real debate lies elsewhere: that of the mandate. An agent that buys on your behalf acts as a mandatary — a legal figure as old as commerce itself. But the platforms contracted with humans, not with software. What's missing is a standard for the "agentic mandate": an OAuth equivalent for commerce, where you would grant an agent a limited, revocable, and auditable permission — rather than your credentials.
My view is simple: Amazon is right on the substance — credential harvesting is a ticking time bomb — and wrong on the method. Blocking without offering a protocol-level alternative means protecting its storefront, not the user. And Amazon is hardly a neutral party when it comes to self-preferencing: the European Commission already fined it €798 million in 2021 for favoring its own offers. The solution is not prohibition, it's regulated delegation.
The AWS paradox: Amazon blocks Muse... which partly runs on AWS
Yes, Meta runs part of its agentic workloads on AWS — the same AWS that Amazon just armed against Muse. The commercial conflict and the infrastructure contract coexist, and that's what makes the situation genuinely dizzying.
The fact is rarely highlighted, yet it is central. Meta is one of AWS's very largest customers, with cloud spending commitments measured in billions of dollars (Meta regulatory filings, expanded partnership announced back in 2021). According to GeekWire, part of the infrastructure running Meta's agents — Muse included — relies on Amazon's cloud.
For Amazon, the financial stakes are considerable: AWS generated $107.6 billion in revenue in 2024 (Amazon annual report), and the bulk of the group's operating income. Amazon is obviously not going to cut the power on Meta — these contracts are worth hundreds of millions of dollars a year, and such a decision would be legally untenable.
But every future negotiation between the two groups will now unfold with this backdrop: "You want GPU capacity? Let's talk about Muse first." That is the true nature of this conflict: two giants fighting with one hand and invoicing each other with the other. The customer and the competitor are the same company.
Under these conditions, the blocking also serves as a message. Amazon is showing Meta — and every agent publisher — who holds the door to the world's largest merchant catalog. And it's doing so without spending an extra dollar on lawyers.
Agentic commerce, the new battleground
The blocking of Muse is no accident, it's a doctrine: Amazon wants the agent for itself. The market at stake exceeds $1.1 trillion in annual sales in the United States alone (Census Bureau, 2024) — nobody will leave the interface to this market to a rival.
The Perplexity precedent
The tone was set back in November 2025: Amazon sent a cease-and-desist letter to Perplexity to prevent its agentic browser Comet from buying on Amazon. Perplexity publicly refused. The difference with Muse is scale: Perplexity is a challenger. Meta is a behemoth with 3 billion users.
Amazon plays a two-speed game
Meanwhile, Amazon is building its own agentic empire. Rufus, its shopping assistant, has been rolling out since 2024. And since April 2025, the "Buy For Me" feature lets Amazon make purchases on your behalf... on third-party brands' websites. The symmetry is perfect: Amazon's agent on other people's turf is an innovation, Meta's agent on Amazon is a violation.
OpenAI bets on protocols
OpenAI chose the opposite path. With the Agentic Commerce Protocol, launched with Stripe in September 2025, and partners like Etsy and Shopify, the company is trying to establish rules of the game that merchants will accept. And with ChatGPT Work, the agent that works for hours without you, OpenAI is pushing a vision of the agent as a long-term collaborator — not as a bot that forces the door.
Technically, everything is ready. The latest generation of agentic models — OpenAI's GPT-5.5 (98.2 on agentic benchmarks), Anthropic's Claude Opus 4.7, Google's Gemini 3 Pro Deep Think — know how to browse, compare, and pay. What's blocking isn't the technology: it's politics.
| Player | Agentic approach | Access to purchases on Amazon |
|---|---|---|
| Amazon (Rufus, Buy For Me) | In-house agent, integrated into the platform | Native and encouraged |
| Meta (Muse) | Universal agent via WhatsApp | Blocked (2026) |
| OpenAI (ChatGPT Work, ACP) | Merchant protocol + partnerships | Absent (Etsy, Shopify instead) |
| Perplexity (Comet) | Agentic browser | Cease-and-desist (November 2025) |
My prediction: the walls will eventually give way to the protocols. No merchant can refuse for long a channel that brings in customers ready to pay. But in the meantime, it's the users who serve as the battleground.
And you, the user: taking back control without handing over your keys
If you don't want to choose between the Meta gatekeeper and the Amazon gatekeeper, the only way out is an agent you host yourself. It's more accessible than you might think — and more necessary after this conflict.
Never hand over your credentials
The lesson of this conflict is simple: an agent worthy of the name must act through delegation — limited sessions, virtual cards with tight spending caps, a reviewable action log — never by holding your passwords. If a service asks for your Amazon login in plain text, that's a red flag, not a convenience.
The local option has become credible
With Ollama, it's now possible to run full agents locally, as we detail in Open source AI agents with Ollama locally. The latest generation of self-hosted models — Kimi K2.6 from Moonshot AI or GLM-5 (Reasoning) from Z.AI — offer agentic capabilities close to those of cloud models, without sending your credentials to anyone.
On the infrastructure side, a VPS is enough to get started: Hostinger offers servers from just a few euros per month (January 2026, check hostinger.com) capable of running an open source agent 24/7. To take the plunge, our guide how to create an AI agent details the complete architecture, and our selection of the best LLMs for AI agents will help you choose the model that fits your budget.
Some honesty is in order
Self-hosting your agent doesn't exempt you from Amazon's terms of service. The blocking targets a behavior — undeclared automated purchasing — not a company. The difference is that, at home, at least, you know where your credentials live and what your agent is doing. That's already more than with any cloud agent.
❌ Common Mistakes
Mistake 1: Giving your Amazon credentials to an AI agent
What's wrong: handing your login and password to a cloud agent gives it unlimited, irrevocable access to your account, your history, and your payment methods. In the event of a leak or abuse, you have no audit trail and no clear recourse.
The solution: demand proper delegation — a dedicated session, a virtual card with a spending cap, an action log. If the agent insists on your password, find another agent.
Mistake 2: Believing that "it's my account, I can do what I want"
What's wrong: the terms of service bind your account, not your conscience. Using an agent that violates those terms can get you suspended — and you'd lose an Amazon account with years of history, orders, and a Prime subscription.
The solution: read the terms before connecting an agent, and favor official integrations and ACP-style protocols where they exist.
Mistake 3: Treating the Muse block as a technical problem
What's wrong: many users are hunting for workarounds — VPNs, alternative browsers, hijacked sessions. That misses the point: the block is political and commercial. It will be lifted through negotiation, not through a hack.
The solution: follow protocol developments (ACP, merchant partnerships) rather than tricks. Those are what will determine what you can do six months from now.
❓ Frequently Asked Questions
Can Muse still buy on Amazon today?
No. Amazon's blocking covers browsing and automated purchases on Amazon.com, according to AI Weekly. Muse remains functional on other e-commerce sites, but its access to the world's largest catalog is closed to it for now.
Is it illegal to use an AI agent to buy on Amazon?
Not illegal in the criminal sense in most cases, but it is a contractual violation of the Terms of Service, which exposes your account to suspension. Recent case law (Van Buren, 2021; Meta v. Bright Data, 2024) limits the scope of the CFAA without protecting automated logins to private accounts.
Does Amazon have its own shopping agent?
Yes, two of them. Rufus, the conversational assistant deployed since 2024, and "Buy For Me," launched in April 2025, which buys for you on third-party brand sites. Amazon wants the agent — but its own, inside its walls.
Can Meta strike back?
Few options. Amazon doesn't depend on any Meta channel to sell. Meta's only real lever is its weight as an AWS customer — billions of dollars in commitments — which gives weight to its negotiations without guaranteeing anything. The outcome will likely come through a protocol-level agreement.
Should you give up on shopping agents?
No, but change your approach. Favor official integrations, open protocols like ACP, and agents you control, ideally self-hosted. And never give a master password to a third-party cloud service.
✅ Conclusion
Amazon's blocking of Muse marks the end of agentic innovation without permission: from now on, any agent that wants to buy will have to go through the front door — or build it itself. To stay ahead of the curve, start with our comparison of the best autonomous AI agents.