Meta’s promotional images show Muse comparing strollers and asking for approval before placing an order. (Meta Images)

Amazon blocked Meta’s new Muse personal AI agent from shopping on Amazon.com — citing security, privacy, and transparency concerns — after attempting unsuccessfully to get the Facebook parent company to exclude the e-commerce site from the experience.

As of Sunday night, people using Muse to shop on Amazon see the popup, “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.”

Amazon told GeekWire that it wasn’t made aware in advance that Muse would access its store, and didn’t authorize it. Amazon said Muse appears to capture and store customer credentials and scrape account data, and that the agent doesn’t identify itself when it browses.

“We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate,” an Amazon spokesperson said in a statement.

The message Amazon is showing people who use Meta’s Muse agent to shop on its site. (Amazon Image)

The sudden standoff between the tech giants is especially notable because the two companies are business partners: Amazon products have been purchasable inside Facebook and Instagram since 2023, and Meta signed a multibillion-dollar deal in April to run agentic AI workloads on Amazon’s cloud.

Meta did not immediately respond to a request for comment Sunday night.

The fight is part of a larger debate over who controls the online shopping experience and the customer relationship when AI agents buy items on behalf of consumers.

Amazon has spent the past year trying to keep outside agents off its site, suing Perplexity over its Comet browser and moving to block shopping agents from Google and OpenAI.

The company said it is in direct conversation with Meta about the issue. Asked whether it would take legal action in this situation, Amazon declined to comment.

The business stakes are high for Amazon. In addition to operating its flagship e-commerce site, Amazon generated more than $68 billion in ad revenue last year — a business that depends on people browsing its pages and seeing sponsored products.

Security implications: Muse can reach account pages and order history if a customer prompts it to do so, Amazon says. As the company sees it, that amounts to an undisclosed third party moving through customer accounts and processing transactions without the online retailer’s knowledge.

Amazon said operating openly keeps the customer experience safe and reliable. It pointed to food delivery apps and restaurants, delivery apps and stores, and online travel agencies and airlines as intermediaries that work with the businesses they transact with.

“Agentic third-party applications such as Muse have the same obligations, and we’ve requested that Meta remove Amazon from the experience,” Amazon’s spokesperson said in the statement.

Legal background: Amazon won a preliminary injunction against Perplexity in March, then lost it on Aug. 4, when the Ninth Circuit ruled that the user — not the AI company — was the one accessing Amazon’s computers under federal anti-hacking law.

The court denied Amazon’s petition for rehearing on Sept. 10.

However, the ruling left one avenue open for Amazon: claims built on contract and terms of service. The message Muse users are now seeing doesn’t accuse anyone of hacking but cites Amazon’s Conditions of Use.

How Muse works: Meta launched Muse on Sept. 8 as a U.S.-only personal agent that carries out multi-step tasks rather than answering one-off questions, connecting to services including email, calendar, payments, dining and shopping.

It runs on what Meta calls a secure virtual machine with its own browser. It’s free, with paid subscription tiers, and available on iOS, Android, muse.ai and WhatsApp.

The company’s launch materials describe the mechanism that’s now at the center of the dispute: If a service has a public API, Muse can connect to it using credentials the user provides. If it has no API at all, Meta says, the agent “can use the service through a browser the way you would.”

Muse has caught on fast. A week after launch, it became the No. 1 free app in Apple’s U.S. App Store, ahead of ChatGPT. Early users have described it switching an auto insurance policy, hunting down discount codes at checkout, and loading an online grocery cart.

Amazon’s own agentic shopping feature, Buy for Me, fetches items from external brands’ sites, but the company points out that Buy for Me identifies itself and lets brands opt out.

Job Listings on GeekWork

Find more jobs on GeekWork. Employers, post a job here.