An AI agent goes shopping
Meta wants to do your shopping. It has a new tool for the job. The tool is called Muse.
Meta calls Muse an AI agent, a term that suggests a futuristic helper straight from science fiction. The reality is more mundane. Muse is not a thinking machine. It is not alive. It is a computer programme, an intricate script designed to perform a specific set of tasks on behalf of a human user. Its purpose is automation. You give it an instruction, like 'buy a new kettle', and the software is meant to handle the entire process from search to purchase. It is an errand boy made of code. One that promises to save you from the tedious clicking and scrolling of online retail, freeing you from the digital equivalent of wandering down endless supermarket aisles looking for a single jar of marmalade.
The process begins with a simple command. A user tells the agent what they need. They might ask for toilet paper, lightbulbs and a specific brand of cat food. The Muse programme then takes over. It opens a web browser in the background, invisible to the user, and navigates to a shopping website like Amazon. It then simulates the actions of a person. The software reads the website's code to find the search bar, types in the product name, and then analyses the results to find the correct item. This is not intelligence. It is pattern recognition and execution. The agent is simply following a very complex flowchart designed by its engineers at Meta.
Muse does not feel. It does not want. It does not understand the difference between a paperback novel and a bag of cement beyond the data points that define them. All the talk of artificial intelligence obscures a simpler truth. This is a tool for remote control. The programme is a puppet and the user’s instruction pulls the strings, sending it out onto the internet to perform its routine. To work, it must behave exactly like a human, clicking the same buttons and filling the same forms. It has to pretend. If it announced itself as a bot, many websites would block it instantly. Its utility depends on its disguise.
To complete its task, the agent must guide the chosen products into a digital shopping basket and on to the checkout. Here is the bargain. For the convenience to work, the user must entrust the programme with their most sensitive information. Muse needs account logins. It needs passwords. It requires access to saved payment details to finalise any transaction on your behalf. This is an enormous grant of trust, handing over the keys not just to one online store but potentially to any site the agent is configured to visit. You trade your credentials for convenience. That is the deal. A deal Amazon now rejects.
Amazon slams the door shut
The block came without warning. It was absolute. For the fledgling users of Meta’s Muse, the automated shopping journey ended abruptly on Sunday, 20 September 2026. Instead of a confirmation page, they received a popup message. It was a digital stop sign from Amazon. The message stated that 'continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed'. The connection was severed. The agent was locked out.
Amazon’s public reasoning is built on a foundation of security and consent. The company does not trust Muse. In statements first published by the technology news website GeekWire, the retail giant expressed grave concerns. It cited privacy. It cited security. The core of its argument is that Meta’s agent does not announce itself as a bot while it browses the site, moving through the digital aisles in a cloak of invisibility. This is a problem. Amazon claims Muse appears to be 'seemingly capturing customer credentials', a process that sets alarm bells ringing inside any large online enterprise responsible for millions of accounts.
This is not a negotiation. It is an expulsion. Amazon is framing the issue as a simple breach of contract, the digital terms and conditions that every single customer agrees to when they create an account. The company asserts that Meta never provided any notification that its Muse agent would be accessing the Amazon store. It just showed up. From Amazon’s perspective, an unidentified third party programme began attempting to log into customer accounts and make purchases. This behaviour mirrors that of malicious software. It looked like a threat. So Amazon acted.
The move is a direct response to the agent’s core design. A bot that must pretend to be human is vulnerable the moment its disguise fails. Amazon’s systems detected the agent. The company then deployed its own simple code, a popup, to halt it. The message for Meta and any other developer is unambiguous. Third party applications cannot make purchases on a customer’s behalf. Amazon’s statement to GeekWire confirmed this position was 'fairly straightforward'. The rules are the rules. That is the official story. It is a neat and tidy explanation. It is almost certainly not the real one.
The real fight is over the customer
The security argument is convenient. It is not the whole truth. The real conflict has nothing to do with passwords and everything to do with profits. It is about control. Amazon’s immense power is derived from its absolute ownership of the customer journey, a carefully constructed digital pathway that it has spent more than two decades optimising. It does not want to lose it.
This journey is Amazon’s core asset. It is the entire process. It begins the moment a person types a search term, 'cordless drill' or 'yoga mat', into the white search bar at the top of the page. It continues through the sponsored product listings that appear first, the 'customers also bought' suggestions, the star ratings, the verified reviews and the expertly placed 'buy now' button. Amazon does not just sell you a product. It guides you. It influences your choice. It harvests your data at every single click, refining its algorithms to better predict, and shape, what you will purchase next. This is not just a shop. It is a finely tuned machine for influencing consumer behaviour on a global scale. This machine is worth billions.
An agent like Muse breaks the machine. It shatters it. Meta’s AI does not meander through the digital aisles, susceptible to carefully placed promotions or impulse buys. It is a heat seeking missile. The user gives it a direct instruction, 'find me the cheapest 10kg bag of cat food with over four stars', and the agent executes it with cold efficiency. Muse bypasses the adverts. It ignores the upsell to a larger size. It feels no temptation to add a pack of chewing gum at the checkout. It reduces Amazon to a mere catalogue and a logistics network, a dumb warehouse to be plundered for goods by a rival’s intelligent software.
This is the existential threat. This is the real war. It is a fight for who gets to be the trusted adviser sitting between a customer and their wallet. Amazon has spent a fortune to become that adviser, and it will not cede that incredibly lucrative position to an automated agent from Meta, or from Google, or from anyone else. The popup message blocking Muse is not a security precaution. It is a declaration of sovereignty. It is Amazon defending its territory from an invading force that threatens to turn its entire business model upside down. The company is not protecting your account. It is protecting its own.
A new war for the internet begins
This is not about Meta. It is not even just about Amazon. This is the first battle in a new war for the internet itself. A war of agents. The popup that appeared on Sunday for Muse users was a shot fired in Seattle, but it was heard across Silicon Valley. Google is building these agents. Apple is building them too. Every major technology company understands that the next great platform will not be a phone or a speaker but an artificial assistant that lives everywhere. The fight is over who will own that assistant and, by extension, who will control the flow of commerce through it. What Amazon did was erect a wall. A very big wall.
Now every website faces a choice. The same choice. From global airlines to the local bookshop, every company with a '.co.uk' address must decide on its agent policy. It is a brutal decision with no good outcome. To block the agents, following Amazon's lead from 20 September 2026, risks becoming invisible to the next generation of online shopping, where a user might simply ask their phone to buy something without ever visiting a website at all. To allow them in, however, is to surrender. It means giving up control of the user experience, abandoning carefully constructed marketing, and letting a rival's software scrape your site for the data it wants. Your website becomes a dumb pipe. A database to be queried.
Amazon can afford to be defiant. It is a fortress. It has spent decades building its own ecosystem and can survive, even thrive, by pulling up the drawbridge and refusing entry to uninvited bots. Many other businesses cannot. They do not have that power. Consider an online travel agent. If a future Google agent can find and book the cheapest flight to Malaga, any airline that blocks that agent may simply lose the sale to a competitor that does not. The same applies to hotels, to insurance, to banking. This creates a powerful incentive to cooperate, even if it means being reduced to a supplier for a bigger company's intelligent service. It is a digital protection racket. The choice is to pay up or be left out.
The conflict between Amazon, based in Seattle, and Meta, with its headquarters in Menlo Park, is just the preliminary round. Their fight was crude. Meta's Muse agent, according to Amazon, failed to properly identify itself and tried to capture customer credentials without permission, making it relatively easy to spot and block. A future agent from Google will likely be far more sophisticated, built by the company that has spent a quarter of a century perfecting the art of crawling and indexing the entire public web. Many websites exist only because they appear in Google's search results. They depend utterly on its goodwill. The decision to block a future Google shopping assistant would be an act of commercial self harm for most of them. This is about power. This is about who sets the rules for the next version of the internet. The robots are coming. Now everyone has to pick a side.
What is the next move?
So what happens now? This is not the end. It is the beginning of a long war. Meta has two paths. It can retreat, conceding that Amazon's walls are too high and its moat too wide, or it can build a better spy. The second option is more likely. Its next agent will be stealthier. It will mimic human browsing more closely, with randomised delays and plausible mouse movements, all designed to slip past Amazon’s guards. This will trigger a quiet, expensive arms race fought in server rooms between two of the world’s richest companies. A contest between the bot and the bot detector. Between the agent and the gatekeeper. The prize is the future of shopping.
A stalemate is unlikely. The money is too big. This technical fight will almost certainly become a legal one. Regulators are watching. They have been for years. In London, the Competition and Markets Authority is already deep into multiple investigations concerning the market power of big technology companies, specifically examining their control over digital ecosystems. An argument that a dominant retailer like Amazon can deny access to a rival’s service, effectively acting as a private legislator for a huge swathe of the internet, will attract intense scrutiny. Amazon will claim it is protecting its customers and its terms of service. Meta will argue this is anticompetitive behaviour, a monopolist pulling up the drawbridge to protect its profits from an innovative challenger.
This is a familiar battleground. Regulators could force Amazon’s hand. They could demand that its website, a piece of critical digital infrastructure for millions, offer fair, reasonable and non discriminatory access to third party services. This would be a profound change. It would turn Amazon into something more like a public utility. A platform that must serve all comers. Amazon will fight this ferociously. It wants to own the customer. It does not want to become a warehouse for another company's front end. The lines are drawn. The lawyers are waiting. The next move will not be on a website. It will be in a courtroom.
Sources. The Register: Amazon shows Meta's Muse AI shopping agent the door. The Verge: Amazon doesn’t trust Meta’s Muse AI agent.
Analysis. Drafted with AI assistance from the sources listed above and reviewed by an editor before publication. Jnews links to the organisations it writes about.

