
Amazon says it has cut off Meta’s new Muse personal AI agent from shopping on Amazon.com on behalf of customers, after attempting unsuccessfully to get the Facebook parent company to voluntarily exclude the e-commerce site from the experience.
The problem, Amazon says, is that it never agreed to any of it. Meta didn’t tell Amazon that Muse would access its store, the agent doesn’t identify itself when it browses, and it appears to capture and store customer credentials, which the company says could create privacy and security risks.
As of Sunday night, people trying to use Muse to shop on Amazon were seeing the popup, “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.”
“We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate,” an Amazon spokesperson said in a statement.

Meta did not immediately respond to a request for comment Sunday night.
The company said previously that Muse “has no visibility into people’s passwords or payment methods,” and that credentials a user shares “go into secure storage, so Muse can use them without seeing them, including passwords a person types into the browser themselves.”
Business partners: The standoff between the tech giants is especially notable because the two companies work together: Amazon products have been purchasable inside Facebook and Instagram since 2023, and Meta signed a multibillion-dollar deal in April to run agentic AI workloads on Amazon’s cloud.
It’s part of a larger debate over who controls the online shopping experience and the customer relationship when AI agents buy items on behalf of consumers.
Amazon has spent the past year trying to keep outside agents off its site, suing Perplexity over its Comet browser and moving to block shopping agents from Google and OpenAI.
On Sunday night, Amazon said it is in direct conversation with Meta about the issue. Asked whether it would consider taking legal action, the company declined to comment.
The business stakes are high for Amazon. In addition to operating its flagship e-commerce site, Amazon generated more than $68 billion in ad revenue last year — a business that depends on people browsing its pages and seeing sponsored products.
Security implications: Muse can reach account pages and order history if a customer prompts it to do so, Amazon says. Because the agent doesn’t identify itself, the company says, that amounts to an undisclosed third party moving through customer accounts, processing transactions and handling sensitive data without Amazon’s knowledge or consent.
Amazon said agents that operate openly help keep the customer experience safe and reliable, and that other services buying on a customer’s behalf typically do so with the merchant’s agreement. It cited food delivery apps and the restaurants they take orders for, and online travel agencies and the airlines they book tickets with.
“Agentic third-party applications such as Muse have the same obligations, and we’ve requested that Meta remove Amazon from the experience,” Amazon’s spokesperson said in the statement.
Legal maneuvering: Amazon won a preliminary injunction against Perplexity in March, then lost it on Aug. 4, when the Ninth Circuit ruled that the user — not the AI company — was the one accessing Amazon’s computers under federal anti-hacking law.
The court denied Amazon’s petition for rehearing on Sept. 10. However, the ruling left one avenue open for Amazon: claims built on contracts and terms of service. The message Muse users are now seeing doesn’t accuse anyone of hacking but cites Amazon’s Conditions of Use.
How Muse works: Meta launched Muse on Sept. 8 as a personal agent that carries out multi-step tasks rather than answering one-off questions, connecting to services including email, calendar, payments, dining and shopping.
It’s free, with paid subscription tiers, and available on iOS, Android, muse.ai and WhatsApp.
Meta says the agent runs on a secure virtual machine, with its own browser, and checks with the user before sensitive actions like sending an email or making a purchase. A separate monitoring agent called Sentinel has to approve anything Muse sends to the internet.
The Muse launch materials describe the mechanism now at the center of the dispute: If a service has a public API, Muse can connect to it using credentials the user provides. If it has no API at all, Meta says, the agent “can use the service through a browser the way you would.”
Muse has caught on fast. A week after launch, it became the No. 1 free app in Apple’s U.S. App Store, ahead of ChatGPT. Early users have described it switching an auto insurance policy, hunting down discount codes at checkout, and loading an online grocery cart.
Amazon launched Alexa for Shopping in May, an AI agent that researches products and makes recommendations. Its own agentic shopping feature, Buy for Me, finds items on external brands’ sites, but the company points out that Buy for Me identifies itself and lets brands opt out.