Amazon cut off Meta's Muse personal AI agent from shopping on Amazon.com on behalf of users, with a popup message appearing on September 21 telling Muse users that "continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed"1,10,11.
Amazon cited terms-of-service violations, security risks, and merchant consent as grounds for the block. The company said Meta did not notify Amazon that Muse would access its store, that the agent does not identify itself when it browses, and that it appears to capture and store customer credentials5.
Muse's rapid adoption
Meta made Muse available in the U.S. earlier this month via a mobile app2. The agent topped 730,000 downloads within five days. According to Sensor Tower data cited by The Indian Express, Muse has seen more than 2.6 million downloads since its debut, with 1.5 million on iOS and 1.1 million on Android3. As of Monday, Muse was ranked as the No. 1 free app on the U.S. versions of Apple's App Store and Google Play Store.
Powered by Meta's large language model Muse Spark, the agent is designed to delegate tasks across the web, including filling out forms, organizing email inboxes, booking travel tickets, turning recipes into grocery lists, and making purchases at checkout. Meta offers in-app monthly subscriptions at $20 or $100 depending on usage.
Meta's stock surged more than 11% to $741, its highest closing price in a year, following the agent's rapid uptake. An analyst cited by The Wall Street Journal estimated that Muse could add $28.5 billion to Meta by 2030.
Security concerns compound the block
The Amazon block arrives alongside a separate security crisis. A researcher publicly disclosed a zero-day vulnerability in Muse that could allow malware to hijack the AI agent and access user data7. Meta had spent months building Muse's security architecture, including a dedicated Secure Virtual Machine and a Sentinel approval process, and rolled out a bug bounty program offering up to $300,000 for reported vulnerabilities.
The vulnerability echoes an earlier incident: Muse's predecessor, Muse Spark 1.1, accidentally exploited a real website vulnerability during a closed evaluation conducted by third-party cybersecurity firm Irregular, caused by a misconfiguration that gave the agent unintended internet access. Meta published a full retrospective on August 14 detailing new security measures including credential isolation and the expanded bug bounty program. Muse officially launched on September 8.
Amazon has previously taken similar action against Google and OpenAI's shopping bots. Its blocking of Perplexity's agent led to a lawsuit, with proceedings still underway. TechCrunch noted that Amazon operates its own cohort of foundation models and one of the most popular inference platforms, and faces no legal obligation to open its doors to Muse.
Shopify moves in the opposite direction
While Amazon shut Muse out, Shopify announced on Monday that it is partnering with Muse to allow agentic checkout in its online stores. Andy Jassy has indicated that Amazon is in talks with other firms wanting to run agents for commerce.
ANALYSIS The split between Amazon's block and Shopify's embrace exposes a fault line in agentic commerce: platforms with their own AI ambitions and direct customer relationships have strong incentives to gate access, while merchant-facing platforms may see agent traffic as incremental volume worth accommodating.