People attempting to use Muse to shop on Amazon began seeing a popup that reads: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." Amazon framed the move as a straightforward application of its terms: third-party applications that make purchases on behalf of customers should operate openly and respect a merchant's decision about participation.
Meta launched Muse as a personal agent that performs multi-step tasks across services such as email, calendar, payments, dining, and shopping. Muse runs on a secure virtual machine with its own browser and uses a monitoring agent called Sentinel to approve anything it sends to the internet. According to Meta, credentials a user shares go into secure storage so Muse can use them without exposing passwords or payment details to Meta.
- Identification and transparency: Amazon says Muse browses and interacts without identifying itself as an agent, which Amazon views as an undisclosed third party moving through customer accounts.
- Merchant consent: Amazon insists services that transact on users' behalf typically do so with the merchant's agreement and pointed to analogies like food delivery apps and online travel agencies that operate with vendor participation.
The companies are commercial partners in other areas: Amazon products have been purchasable inside Facebook and Instagram since 2023, and Meta signed a multibillion-dollar deal to run agentic AI workloads on Amazon's Graviton chips. Amazon also has its own agent initiatives, like Alexa for Shopping. The commercial stakes extend to Amazon's ad business, which depends on user browsing and sponsored product views.
The dispute centers on who controls customer accounts and the shopping relationship when AI agents act on behalf of users. If agents can operate like human assistants but without merchant consent or clear identification, merchants argue that creates security, privacy, and commercial problems. Meta's architecture for Muse attempts to limit exposure to sensitive data, but Amazon argues the practical effect is that an undisclosed software actor can access accounts and transaction history.