Story
September 22, 2026

Amazon Blocks Meta’s Muse, Turning AI Shopping Into a Control Fight

Amazon sees Meta’s shopping agent as an unauthorized and potentially risky intermediary, while Meta is pitching Muse as a smoother route from discovery to checkout. Beneath the security dispute lies a harder commercial question: whether AI agents will empower shoppers to range freely or leave major retailers guarding the gate.

Meta launched Muse on September 8 as a general-purpose assistant designed to handle multistep tasks, including shopping. Within a week it had reached the top of Apple’s US free-app chart, an early sign of enthusiasm for an agent that could act rather than merely answer questions.

Meta’s public pitch was expansion, not confinement. Mark Zuckerberg said Muse was teaming up with Shopify to make “shopping and checkout easier,” promising that shoppers would find more and merchants would sell more. That partnership underscored the model Meta appears to want: an agent moving consumers across stores and through purchases.

Amazon drew a hard line less than two weeks after Muse’s launch. Users attempting to shop through the assistant began seeing a warning that continued access by an “unauthorized AI agent” violated Amazon’s conditions of use. Amazon said it had not been told Muse would access its marketplace and had not authorized it to enter customer accounts, scrape data or process transactions.

The retailer’s stated case is about transparency and safety. “Third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate,” an Amazon spokesperson said, arguing that agents such as Muse carry the same obligations as delivery and travel-booking apps. Amazon also warned that the agent did not identify itself, could capture or store credentials, and might bypass the personalization of Amazon’s own shopping experience.

The clash arrived alongside a more damaging security challenge. Researcher Patrick Wardle disclosed a zero-day he said could let local apps or terminal commands seize control of a Muse account. “We can manipulate the agent and leverage its privileges to do whatever we want,” he said. Meta did not respond to requests for comment in the reports, though it has said Muse cannot view passwords or payment details.

Amazon’s move may also be commercial self-defense. Independent agents threaten to own product discovery and the customer relationship while retailers are left to fulfill orders — even as Amazon builds Alexa-based shopping tools of its own. And the practical risk remains: if Muse makes a bad order, Amazon may still face the customer and vendor fallout.