Amazon has cut off the ability of Meta's personal assistant Muse to shop on users' behalf on Amazon.com. Anyone who now tries to place an order through Muse sees a pop-up instead:
"Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed."
Amazon lists three reasons: Meta never told Amazon that Muse would be accessing the site; the agent doesn't identify itself while browsing; and it "appears to scrape and store customer credentials," which Amazon says creates privacy and security risks. Amazon's position is that third-party apps placing orders on someone else's behalf "should operate transparently."
Meta's response focused on the credentials point: Muse "cannot see users' passwords or payment methods," Meta said. Credentials a user provides go into secure storage that Muse can call without ever touching the content itself.
Muse is this month's breakout hit
Meta launched Muse on September 8 as a personal AI agent that can send emails, book travel, shop, and track goals. A week after launch, it reached No. 1 on the U.S. App Store's free chart, ahead of ChatGPT. Installs climbed fast — and so did the friction.
The same week brought a separate security story. Researcher Patrick Wardle disclosed a zero-day in the macOS version of Muse: the app's voice-dictation feature sends audio to Meta's servers for transcription, and the shipped build still contained an undisclosed internal setting that specifies which server handles that transcription. Software running locally could change that setting, redirecting traffic to a server controlled by an attacker and, from there, obtaining an authentication token tied to the user's Muse account. Meta reportedly shipped a fix afterward; neither side has disclosed how many accounts were affected or whether the flaw was actually exploited, and Meta hasn't publicly addressed the disclosure process.
Amazon has blocked more than one agent
Amazon's friction with agentic products follows a pattern. It has previously sued Perplexity over its Comet browser agent, and it has restricted shopping agents from Google and OpenAI as well. In March 2026, Amazon won a preliminary injunction against Perplexity; in August, the Ninth Circuit overturned it, ruling that it was the user, not the AI company, who was accessing Amazon's computer systems.
That opinion shifted the question from "who is accessing" to "who can a platform's terms bind." The wording Amazon chose for the Muse pop-up lands squarely on the terms of use its customers have already agreed to.
What this means for teams in China
E-commerce agent teams building in China face the same three questions: does the agent identify itself while browsing, does it hold account credentials on a user's behalf, and do a platform's terms even allow a third party to place orders for someone else? The logic behind the U.S. case line — that it's the user accessing the platform, not the developer — has no public ruling to match it in China so far. Platform terms of use and anti-scraping rules remain the main constraint, and how far any given platform will tolerate this depends on its own developer agreement.
What can be gotten around technically isn't necessarily gettable-around in the terms. If an agent keeps refusing to identify itself, the cost of a platform detecting it gets passed on as stricter risk controls — and the people who end up paying that cost are the account holders: logins interrupted more often, extra verification at checkout. Both land on the user. What Muse's situation shows is a separate layer entirely: what an agent can do, and what it's allowed to do inside someone else's store, are decided by different people.
Sources: GeekWire, Ars Technica, CocoLoop, Gizmodo; reporting checked against the pop-up's original wording, Amazon's three stated reasons, and the timing of the Ninth Circuit ruling.