Amazon. com Inc. has blocked Meta Platforms Inc.'s Muse artificial intelligence agent from accessing its e-commerce marketplace, notifying users of the move late Sunday. The ban lands days after Muse topped 730,000 downloads in five days and overtook ChatGPT as the most popular free app on the App Store. For businesses watching agentic commerce, the dispute sets the first hard boundary between a retail platform and an agent that shops on a customer's behalf.
What happened on the first day of trading
Meta released Muse in the U. S. earlier this month through a mobile app, offering a free version alongside two paid editions with higher rate limits. The agent reached 730,000 downloads within five days, ahead of both ChatGPT and Claude, and by last Friday it had passed OpenAI Group PBC's chatbot as the most popular free app on the App Store. Investors reacted as well: Meta shares closed more than 11% higher, while Intel Corp., Advanced Micro Devices Inc. and Arm Holdings plc each posted double-digit gains. Those three companies are major suppliers of central processing units, which AI agents use heavily to run their tools. The rally indicates that Wall Street does not expect Amazon's ban to slow Muse's popularity.
Amazon's objection is procedural as much as commercial. The company told GeekWire that third-party applications offering to make purchases on behalf of customers from other businesses should operate openly and respect a service provider's decision about whether to participate. Its terms of service require agents to identify themselves by embedding a text snippet in HTTP requests, and according to Amazon, Muse does not do so when it makes purchases. The retailer also took issue with the agent's access to customer data: it says Muse can view a user's Amazon account pages and purchase history if the user prompts it to do so. GeekWire reported that Amazon views such activity as an undisclosed third party moving through customer accounts.
What this means for companies deploying AI agents
For companies that put agents in front of customers, the practical consequence is that access to marketplaces is now a negotiated condition, not a default. An agent that can browse, compare and buy removes work from a procurement or office manager, but only while the retailer tolerates it. The requirement Amazon enforces is narrow and technical — a self-identifying marker in the request — yet it decides whether the agent works at all. A small company buying through a single marketplace will feel the block immediately, because it has no alternative channel. A larger organization with several suppliers and its own purchasing systems can route the same task through other interfaces and treat the ban as a temporary constraint on one vendor.
Meta may try to lift the ban by addressing Amazon's concerns; the company has said it is working to expand Muse's data protection guardrails. Muse launched with a security mechanism called the Muse Secure VM, which places each instance in a virtual machine isolated from the rest of Meta's infrastructure. A second, cybersecurity-optimized agent named Sentinel reviews sensitive actions such as online purchases and prevents Muse from directly accessing credit card numbers and account credentials. Even so, Meta can theoretically reach data inside a consumer's Muse instance today. An enhanced version, the Muse Confidential VM, is designed to make that access impossible and is scheduled to roll out later this year; Meta is testing it with a limited number of users. Until then, the safeguards reduce exposure but do not remove it, and that gap is what a buyer should weigh before handing an agent payment credentials.
Amazon has blocked agents before. Last year it sued Perplexity AI Inc. over its Comet browser, which includes an AI agent that can shop on users' behalf. An appeals court dismissed the case in August, but the ruling did not bar Amazon from blocking agents that breach its terms of service. That precedent matters more than the lawsuit's outcome: platforms retain the right to refuse automated buyers, and the terms they publish become the operating rules for agent developers. The dispute also arrives while CPU suppliers rally on agent demand, a reminder that the infrastructure layer is being priced before the access rules between platforms and agents are settled.
What remains unclear is how quickly Meta can satisfy Amazon and whether other retailers will follow with their own restrictions. For a business evaluating an agent for purchasing, the questions to ask the vendor are concrete: does the agent identify itself to the sites it visits, what data from the account does it read, and what happens to an order if a retailer blocks it mid-transaction. The answers determine whether the tool can be used for routine buying or only for research. The Muse Confidential VM rollout later this year is the marker to watch: if Meta ships it and Amazon restores access, agentic shopping becomes a workable channel under published rules. If the block holds, businesses should plan for a fragmented landscape in which each marketplace sets its own terms for automated buyers.
