Executive Summary

From Sunday night, September 20, 2026, anyone who asked Meta's AI assistant Muse to buy something on Amazon got an error window instead of an order. The line in the window read: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." Log in to the same account yourself, buy the same thing, and nothing happens. All that changed is who presses the order button: a person, or a program standing in for that person. This article reads the block not as a contest between two companies but as a question about data access rights.

Amazon gave three reasons. Meta sent no advance notice, the agent browsed without saying what it was, and it appeared to be capturing and keeping customer credentials. Meta counters that Muse has no visibility into people's passwords or payment methods. What deserves a second look is the kind of ground Amazon stood on. It reached not for the federal statute on computer intrusion but for terms its customers had already clicked to accept. A month and a half earlier, an appeals court had vacated an injunction, holding that when an agent moves on a user's instruction the party doing the accessing is the user; ten days before the block, that court refused to hear the case again.

Sections 1 through 4 follow what sits in the reporting and the public record. Section 5, which reads the episode as a question about whose catalog and order data a company opens and on what credential, is this article's interpretation.

Key Figures

Sources: TechCrunch and GeekWire reporting, Stripe's announcement, Amazon's Conditions of Use (last updated 2026-08-14), and the IETF's public document list (counted 2026-08).

12 days

From launch to block

Muse launched on September 8; Amazon blocked it on the night of September 20. The door took less time to shut than the new agent took to reach a major marketplace

1M+

Merchants where Muse can pay outright

The count of merchants that accept Stripe's Link. Where Link is absent, a single-use virtual card covers the purchase. The payment plumbing is already laid

0

Agent identity specs adopted by a standards body

All nine related documents at the IETF were still individual submissions as of August 2026. Large operators run on those drafts anyway

10 months

How long Amazon has been shutting other agents out

From the November 2025 suit against Perplexity to this block. Not a single incident but a continuing policy

1

On a Sunday Night, Amazon Shut Out Meta's Shopping Assistant

Muse is the personal AI agent Meta released on September 8. Tell it what you want in a chat and it sorts your mail, fills in forms, looks up travel, orders things. A week after launch it became the number one free app in Apple's U.S. App Store, ahead of ChatGPT. Payment runs through Stripe's Link. At the million-plus merchants that accept Link it charges a stored payment method directly; at other shops it issues a single-use virtual card good only for the approved amount. Either way the user taps to approve the total in the chat window.

App icon and logo for Muse, Meta's personal AI agent
▲ Muse, Meta's personal AI agent | Source: Meta AI

On the night of Sunday, September 20, that flow stopped at Amazon. Ask Muse to buy something on Amazon and a warning came back instead of an order. An Amazon spokesperson gave three grounds: Meta had not told Amazon in advance that Muse would reach its store, the agent moved through the site without identifying itself as an agent, and it appeared to capture and store customer credentials, which the company said could create privacy and security risks. Amazon added that Muse can reach a customer's account pages and order history and complete transactions, none of which Amazon knew about or consented to.

The block was not the opening move. Amazon had first asked Meta to remove Amazon from the list of services Muse handles, and shut the door when that went nowhere. Even on the day of the block Amazon said it was in direct conversation with Meta, and declined to say whether it would go to court. These are not two companies that fell out, either. Amazon products have been purchasable inside Facebook and Instagram since 2023, and in April 2026 Meta signed a multibillion-dollar deal to run agentic AI workloads on Amazon's Graviton chips. Inside a working relationship, this one item alone was singled out and stopped.

The line on the screen was this. "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." The subject of the sentence is the agent; the party that agreed is the customer. A consent a person clicked became the ground for shutting out a program standing in for that person.

What Amazon asked for in public was procedure. Third-party applications that offer to buy on behalf of another business's customers "should operate openly and respect service provider decisions about whether or not to participate." Meta issued no statement of its own, but has said before that Muse "has no visibility into people's passwords or payment methods." Credentials a user shares go into secure storage and get used without the agent seeing them. The two companies describe one fact in two ways. Amazon objects to credentials sitting in the hands of a program outside the store; Meta answers that not even that program can read them. Amazon also argued that its demand was nothing new. Services that buy on someone else's behalf normally do so with the seller's agreement, it said, pointing to food delivery apps and the restaurants they take orders for, and online travel agencies and the airlines they book tickets with.

Commentary noted that Amazon has little reason to open its doors to somebody else's agent. The company has its own foundation models in Nova and one of the most used inference platforms in Bedrock, so helping a rival's shopping agent walk its aisles buys it nothing. There is also the question of cleanup: when an agent places a bad order, it is Amazon's customer service organization that handles the angry customer and the angry vendor.

The money at stake is more concrete still. Amazon generated more than $68 billion in ad revenue last year, and that business depends on people paging through product listings and meeting sponsored items along the way. An agent that skips the search results and simply places the order shrinks that foothold. On the other side, Mark Zuckerberg has said Muse could take "a very small cut of whatever the transaction is." The cut would potentially be paid by the businesses users buy from. One transaction, two ways to find a margin: advertising on one side, commission on the other.

2

From Hacking Law to House Rules

Read this block as a standalone event and you miss the point. Amazon has been taking on other people's shopping agents for ten months, and along the way it swapped weapons once.

In November 2025, Amazon sued Perplexity. The complaint said Comet, Perplexity's browser agent, passed itself off as an ordinary Chrome browser, gave no identification, entered customer accounts and bought on their behalf. The law it invoked was the Computer Fraud and Abuse Act, the federal anti-hacking statute. In March 2026 a federal court sided with Amazon and issued a preliminary injunction ordering Comet to stop reaching Amazon's systems as an AI agent and to destroy the data it had already taken.

On August 4 the Ninth Circuit vacated that order. The reasoning was short and hard to get around. If the agent runs on the user's machine at the user's instruction, then the party "accessing" the computer under that statute is the user, not the company that built the agent. Going into your own account is not unauthorized access. That closed the anti-hacking route in practice. The court did not, however, foreclose claims built on contracts and terms of service.

Main entrance of the James R. Browning U.S. Court of Appeals Building, home of the Ninth Circuit
▲ The James R. Browning U.S. Court of Appeals Building in San Francisco, seat of the Ninth Circuit | Source: Wikimedia Commons (Library of Congress)

Amazon asked the court to look again and was denied a rehearing on September 10. The anti-hacking argument was finished for good ten days before the block. The customer terms were updated within that window as well. The Conditions of Use that Amazon.com serves today carries a last-updated date of August 14, ten days after the appeal was decided.

Where the basis moved 2025.11 Perplexity sued Basis: anti-hacking law 2026.03 Injunction issued Amazon wins 2026.08.04 Vacated on appeal The user is the one accessing 2026.09.10 Rehearing denied Hacking route shuts 2026.09.20 Muse blocked Basis: Conditions of Use A fight argued under anti-hacking law relocates into contract
▲ Original Pebblous diagram. The five points confirmed in reporting and court records, in order; the gaps between marks are not proportional to elapsed time

A month and a half later, the error message in front of Muse pointed at exactly the route the court had left open. What it named was neither intrusion nor hacking but the Conditions of Use. One claim closed in court and the same purpose came through another. The second is not something a judge grants; it is a document the platform writes and rewrites itself.

Muse was not the only place that open route got used. The day after the block, Amazon added a claim to the Perplexity case: that Perplexity caused customers to break their agreement with Amazon, and the agreement in question is the same Conditions of Use the error message named. Within two days, the one door a ruling left standing was used against two different opponents.

3

The Same Account Lets in Two Different Guests

Look at what actually divides here. Before the block and after it the technology is identical: same account, same password, same cart, same card. What changed is the standing the store grants whoever comes through with that account. A person is a customer; a program standing in for a person is a third party who needs permission. Had this been a technical matter, the block would have turned into a contest of detection and evasion. What happened instead was a contest of documents.

Amazon had already put the distinction on paper. The seller side came first, not the customer terms. The revised seller agreement that took effect on March 4, 2026 created an "Agent" heading and gathered under that name the automated software and AI systems that reach Amazon's systems on a seller's behalf. It asks three things of such an agent: declare that it is automated, keep following policy, and stop accessing when Amazon asks it to. The recommended route is spelled out too. Use the official Selling Partner API rather than driving a browser the way a person would.

The seller agreement and the customer Conditions of Use are separate documents, and the one that caught Muse is the second. So the second is worth opening as well. The Conditions of Use now serving on Amazon.com, last updated August 14, carries its own section on agents. The definition is broad from the start: "'Agent' means any software or service that takes autonomous or semi-autonomous action on behalf of, or at the instruction of, any person or entity."

The section asks four things of an agent. Identify in every HTTP and HTTPS request that the request comes from an agent, and name it, by putting "Agent/[agent name]" in the user agent string. Do not conceal the fact, whether by mimicking human keystroke speed and page navigation or by completing or circumventing CAPTCHAs. Respond truthfully to any question asking whether the interaction comes from a human or a computer. Do not circumvent measures intended to block or limit agents. The clauses above those are shorter and sharper. No agent may access Amazon Services "if we have requested that the Agent refrain from accessing," and whether and how any agent gets in is set "at our sole discretion."

That single clause connects the request Meta received to the popup Muse users saw. From the moment the request went out, the next access became a breach of the terms. And the account section puts responsibility for all activities occurring under an account or password on the account holder. The party standing in breach is not the company that built the agent but the person who handed it a login. The claim added against Perplexity has precisely that shape.

What happens when the same measure is held up to Amazon? Its own shopping agent, Buy for Me, goes to other brands' sites and orders on a customer's behalf. Asked about doing the thing it wants stopped, the company gave two answers. Buy for Me identifies itself, and brands can opt out. If that answer holds, what Amazon is asking for is not that agents stay out but that they announce themselves on the way in.

Once that distinction settles, the questions that follow change character. "Can this request be served?" is a question a system answers. "Is the sender of this request entitled to it?" is a question a company answers. Reading a catalog, checking stock, placing an order are all acts of reaching data, and who may reach that data, holding what credential, is set by policy rather than by code. The larger the agent economy grows, the further a single line of that policy reaches.

4

Identity Now Has a Spec; Permission Still Lives in the Terms

The first item on Amazon's list was that the agent failed to identify itself. Yet the means for an agent to prove who it is already exists and already runs. It goes by Web Bot Auth: every request carries a signature that proves cryptographically who sent it. Cloudflare leads the work, engineers from Google co-wrote the architecture document filed at the IETF, and Amazon Web Services' own firewall product has recognized these signatures since November 2025. Amazon's agentic browser service can attach that signature to outbound requests.

Muse took a different path, and Meta's launch materials say so plainly. Where a service has a public API, Muse connects using credentials the user provides; where a service has no API at all, the agent "can use the service through a browser the way you would." That second sentence sits at the center of this dispute. With no sanctioned passage available, what an agent falls back on is looking like a person. On top of that, the identification Amazon's terms require is not a cryptographic signature but a line the agent writes into its own request header, which means it goes unwritten if the agent decides not to write it. Elon Musk put his finger on the same spot: Amazon "won't be able to tell whether the buyer is a human or an AI acting on their behalf if access is via the user's IP address & cookies."

Elon Musk
▲ Elon Musk — argued that an IP address and cookies alone can't tell Amazon whether the buyer is a human or an agent | Source: Wikimedia Commons (Gage Skidmore)

The state of the specification is a little odd. Nine related documents sit at the IETF, and as of August 2026 a working group had formally adopted none of them. Large infrastructure companies are running those drafts in production ahead of any settled standard. With spec names and version numbers shifting and everyone implementing early, two parties can use the same name and still disagree about how far it carries.

The more important point is that identity and permission are separate layers. A signature proves who I am; it says nothing about whether I may come in. An agent that declares itself honestly can still be turned away, or asked to pay. Cloudflare marks that gap itself: because one intermediary sends requests on behalf of a great many end users, trusting the intermediary and trusting every user behind it are not the same act. That is exactly where Amazon stood when, after the appeals court said the user is the one accessing, it invoked terms "to which our customers have agreed."

Payments, by contrast, are converging. The commerce protocol Google published with Shopify and other retailers arrived in January 2026, and a spec for proving an agent's delegated payment authority by signature is running with several financial institutions already on board. The checkout spec OpenAI built with Stripe survives, though the product that let people pay inside the chat window was retired in March. So the plumbing for "how much is paid, and how" is being tidied up quickly, while "who gets through the door, holding what credential" remains scattered across one company's terms and another's.

That blank is where the block happened. At the layer no standard answers yet, each platform's terms fill the space instead. So the speed of the agent economy hangs on how the other company reads its own terms, not on model performance. Muse did not get blocked because it got dumber overnight.

5

Why Pebblous Is Watching This Standoff

From here on, this is the episode read through the lens of our own work. It looks like a quarrel between Amazon and Meta, but the same question reaches much smaller meeting rooms before long. The day something other than a person starts showing up in your site's logs, is there an answer already decided about blocking or opening?

Talk about AI-Ready Data usually starts with the condition of the data itself. Is the format consistent, are the labels right, is the provenance still attached? What this episode shows is that there is another layer above all that. Amazon's catalog is among the best organized product data in the world, and that data is open to anyone even now. To Muse it might as well not exist. Saying data is ready and saying the credential for reaching it has been settled are two different statements.

5.1Companies That Set a Default, and Companies That Decide on the Spot

Most companies today sit in a state that is neither blocked nor open. The terms say nothing about agents, and no sentence separates a person's login from a delegated program's. In that state, when delegated access arrives the call lands on whoever is on duty that day, and it usually tips toward blocking. Set that against Amazon, which wrote a clause into its seller agreement. With a clause, going either way is a decision; without one, both ways are accidents.

Which way Amazon resolves this became visible three days after the block. On September 23 it released a plugin letting sellers check inventory, adjust prices and update listings from inside Anthropic's Claude or Amazon's own assistant. That is a door opened to an agent from outside, and Amazon still decides which platforms to support while sellers choose which types of data the plugin can reach and approve each action. A decision to block and a decision to open came within three days of each other. What separated them was not how capable the agent was but whether the passage had been agreed.

Three things are worth working through when setting the default. Can you separate the data open to people from the data you would open to a delegated program? Is there a channel for confirming that an incoming request belongs to a delegated program? And once confirmed, where do you write down the scope and the rate you will allow?

5.2What the Log Doesn't Record, You Can't Argue Later

Turn the appeals court's reasoning around and a practical implication falls out. A request that arrives through the user's device and session looks like the user's own. Unless the agent declares itself, the record keeps only a human visit. The means of retracing what happened then disappears. A record that cannot tell which order was a person's judgment and which was a delegated program's leaves nothing to say about accountability or about improvement.

So there is work that comes before deciding whether to allow agent access: recording who the accessing party was. Whether it was a person or a delegated program, which user it stood in for, and what credential brought it in. Write that into the record and you have grounds the next time policy changes. This is why Pebblous, in looking at data quality, asks for the path a value traveled to be kept alongside the value itself. Without the record, you have no standing to fix the policy.

Thank you for reading this far. The facts cited here can be checked in the reporting by TechCrunch and GeekWire, and the clauses in the text of Amazon's Conditions of Use (last updated August 14, 2026). Does your company's own agreement contain a sentence about programs that stand in for people? If not yet, we would be glad to talk about who ends up filling that blank.

R

References

News Reporting

Official Documents

Industry Standards