Amazon’s block targets the browser-based method Muse uses to interact with websites not covered by its built-in connectors. When a user asks Muse to shop on Amazon, the agent drives a signed-in browser session — a behavior Amazon argues violates its updated terms. The company told GeekWire it asked Meta to voluntarily exclude the store, but Meta did not agree before the block was enforced.
A key flashpoint is the handling of user credentials. Meta states that Muse has no visibility into passwords or payment methods, with credentials stored securely in its Muse Secure VM. Amazon counters that the agent appears to capture and retain customer credentials. Both positions may be sincere, but Amazon cannot independently verify what software holds the password from an unannounced session.
Amazon’s legal footing was shaped by a recent Ninth Circuit ruling. In early August, the court vacated the preliminary injunction Amazon had won against Perplexity, holding that a user directing an assistant is the party accessing the computers — not the agent itself. That decision makes lawsuits a weaker tool for excluding agents, pushing companies to enforce restrictions in their own infrastructure. Amazon’s Conditions of Use, updated 14 August, now require agents to identify themselves and stop when asked.
The block is not universal. Shopify has integrated Muse directly, giving the agent access to its storefronts via a formal connector. The contrast highlights the broader challenge: personal agents like Muse, Grok Bot, and the open-source OpenClaw project all operate by driving signed-in browser sessions without identifying themselves. As the category proliferates, the industry faces a fundamental design tension between agent autonomy and site control.