AI AgentIndustry & CompetitionGovernance & Compliance

Can Amazon Block the AI That Shops for You?

Muse Couldn’t Even Reach the Search Page

This May, in Google Shut Down Project Mariner, Anthropic and OpenAI Didn’t Really Make It Work Either, I wrote about how standalone browser assistants repeatedly hit walls when facing website anti-scraping mechanisms, leading the industry to shift its focus back to users’ own everyday browsers. Four months later, a notable new development emerged on this battlefield. In September 2026, Meta launched Muse, a cloud assistant designed to run errands for users—browsing the web, handling to-dos, and shopping on e-commerce sites. Yet on the core capability of shopping, it hit a brick wall right out of the gate.

According to test records by a reporter at The Register, the tester asked Muse to go to Amazon, find the highest-rated ergonomic office chair, add it to the cart, and proceed to the final checkout page. The process stalled before it even got off the ground. Muse neither found the chair nor added it to the cart, instead confessing in the dialog box: the browser couldn’t even reach the search page, so it didn’t find the chair or add it to the cart. The report also included a screenshot of Amazon’s blocking page.

This is not to say that Muse has never successfully purchased anything on Amazon. Reporting by a journalist at The Verge noted that they had previously used Muse to buy a vest on Amazon successfully. In other words, past success offers no guarantee of ongoing access; Amazon subsequently slammed the door shut.

Regarding this block, GeekWire obtained the on-screen warning and statement displayed by Amazon. In the pop-up notice, Amazon stated that an unauthorized AI program was repeatedly accessing its site in violation of the terms of service that users had previously agreed to. According to Amazon, it had already asked Meta to exclude Amazon from its automated errand-running. Amazon also accused Muse of failing to identify itself during visits, claiming it appeared to be collecting and storing user credentials and might even retrieve order histories upon user commands.

In response to questions regarding credential security, Meta had already detailed its system architecture in its official security documentation on September 8, before the block occurred: passwords entered by users go directly into an isolated secure storage enclave, meaning the primary model responsible for inference never sees plaintext passwords; only when a webpage genuinely requires authentication does the system inject the password into the browser window. The two sides were talking past each other completely. Meta was explaining how passwords are isolated and encrypted within its own systems—answering whether credentials would leak; Amazon was demanding to know what right an unauthorized external program had to enter its store and run errands in the first place. Keeping credentials technically secure addresses only data leakage; it does nothing to address whether the platform is willing to open its doors to errand-running software.

This raises a pivotal question: if servers deployed in vendor clouds are easily recognized and blocked by e-commerce platforms, what happens if the browser is moved back onto the user’s own computer? If a locally running browser carries authentic login states while an AI assists operations in the background, can websites still shut the door so easily?

Both Are AI Clicks, but the Website Sees Something Different

When it comes to picking an office chair and placing it in a shopping cart, the most immediate difference lies in whose computer is actually opening Amazon. Under the cloud errand model, you enter your request in a chat box, but the machine opening the storefront is a server located in a vendor’s datacenter. According to Meta’s official security documentation, Muse allocates a cloud PC and a remote browser in a datacenter for each user; all page navigation, clicks, and inputs take place entirely inside the datacenter.

For an e-commerce platform, this pattern is glaringly obvious. Enormous volumes of shopping requests originate from vendor datacenters rather than decentralized residential broadband connections across millions of households. If the platform identifies the server egress points behind these connections, it can block requests originating from those egress IPs in bulk. While datacenter servers may not exclusively own entire subnets and bulk egress blocking risks collateral damage to other tenants sharing the network, datacenter egress remains a concentrated, actionable fingerprint compared to dispersed residential connections.

Move to the user’s own computer, and the picture shifts entirely. You sit at your desk and launch your everyday browser. According to reverse engineering of desktop AI assistants by an independent security firm, while cloud models handle reasoning and planning, concrete operational commands are sent down to a local browser extension. Every click and navigation unfolds right on your screen, and the resulting network traffic originates from your home broadband.

What does the receiving e-commerce website see in this case? It sees an everyday device with regular hardware and software parameters, carrying your accumulated cookies and authentic login session, connecting from a normal residential network. The bulk blocking tactics the platform previously used against datacenter egress fail completely here. That said, having an existing logged-in session on a device does not mean automated operations have received legal or contractual authorization.

Yet this does not mean local operations leave no footprint. Even with the browser running locally, the execution process still leaves distinct fingerprints. Beyond checking request origins and login states, e-commerce platforms can evaluate interaction patterns and client telemetry for bot detection and risk scoring. If an automated script pages through product listings too rapidly or switches between tabs with unnatural timing, these behavioral patterns can still trigger fraud and risk alarms.

For platforms, however, relying solely on behavioral patterns to block local devices carries the cost of false positives. Automated behavior overlaps with human habits: a savvy human shopper comparing prices during a flash sale or browsing discounts will also refresh pages quickly and click through multiple comparison links in rapid succession. If a platform tunes its detection thresholds too aggressively, it risks locking out real buyers as bots. Disrupting genuine shoppers degrades customer experience and leads to lost orders—a commercial cost the platform has to absorb on its own.

Whether the browser runs on the user’s machine or in the vendor’s cloud alters the origin of traffic visible to the website.

Whether a browser sits locally or in the cloud is not merely an engineering architecture choice; it has become the focal point of actual litigation. As noted in my article from May, Amazon sued Perplexity’s Comet browser, alleging that its unauthorized automated access to the marketplace violated the Computer Fraud and Abuse Act (CFAA), the federal anti-hacking statute governing unauthorized computer access. At the time, the district court issued a preliminary injunction against Perplexity, which Perplexity promptly appealed, leaving readers at the latest milestone of awaiting the May 15 hearing.

The Comet browser happened to test both local and cloud architectures. On the desktop, reverse engineering by an independent security firm showed that Comet took the local route: cloud models planned operational steps, while a local browser extension executed navigation and clicks within the user’s browser window.

On iOS mobile, however, early testing of Comet took a different path. MacStories wrote at the time: Comet for iOS’s agent does not browse the web on your behalf inside the iOS app, but rather spins up a virtual browser in the cloud for you. To grant this remote virtual browser an authenticated identity, the app uploaded temporary session cookies to the cloud after prompting the user.

This litigation reached a pivotal turning point on August 4, 2026. The U.S. Court of Appeals for the Ninth Circuit issued a significant 21-page opinion: vacating the preliminary injunction entered against Perplexity and remanding for further proceedings.

Reading through the Ninth Circuit’s opinion, it becomes clear that the judges focused primarily on a single question: in the legal sense, who is actually initiating access to Amazon’s computers?

Based on the record before it, the appellate court noted that while Perplexity’s cloud system transmitted operational commands locally, the party actually issuing access requests was still the consumer seated at the computer using an assistive tool to carry out specific actions. On page 15 of the opinion, the judge wrote: the party accessing Amazon’s computers is the user himself, who performs specific actions on Amazon.com with the aid of assistive tools. In other words, on that factual record, it was the consumer accessing Amazon’s computers with the help of a tool, and the court did not find Perplexity to be the accessor in the legal sense.

It must be stressed, however, that vacating the preliminary injunction is not the same as Perplexity winning the entire lawsuit, nor does it grant local tools unfettered legal passage. The appellate judges made strict reservations in the footnotes. Footnote 5 on page 21 of the opinion stated explicitly: this disposition does not foreclose Amazon from regulating access to Amazon.com through its private user-facing terms of service. The ruling in no way undermines Amazon’s ability to enforce its terms against its own users. The court neither ruled that all locally run assistive tools are lawful nor stripped the platform of its authority to govern its marketplace via private contracts, and it reached no final conclusions on other legal elements such as economic damages.

The plaintiff’s offensive quickly shifted focus. On September 21, 2026, Amazon formally filed an amended complaint with the court. In this new pleading, Amazon recalibrated its litigation strategy. Alongside its original anti-hacking claims, Amazon added a common-law tort claim: Tortious Interference with Contractual Relations. Amazon accused Perplexity of intentionally inducing and assisting users to circumvent and breach the terms of use they had agreed to with the site.

At the same time, Amazon turned its spotlight onto Comet’s practices on mobile. Targeting the iOS cloud-hosted virtual browser documented by MacStories, Amazon contended that direct connections initiated by cloud servers to its marketplace constituted unauthorized access. Furthermore, the complaint alleged that Perplexity deliberately updated its software to bypass defenses after two rounds of technical blocks in 2025. These new allegations have yet to be tested in court.

From the August appellate decision and the September amended complaint, we can clearly see how legal exposure branches along architectural lines: under a local execution architecture where the local browser performs the actions, vendors face substantially reduced pressure under CFAA claims of unauthorized computer access. Courts currently lean toward viewing this as a consumer accessing the service using a tool rather than an external rogue program intruding directly. But this hardly eliminates legal liability: breach-of-contract liability for users violating platform terms, alongside tortious interference claims against vendors for inducing those breaches, remains an active, looming risk.

If systems revert to a cloud direct-connect architecture—where a vendor’s datacenter servers or cloud-hosted virtual browsers access the storefront directly—platforms can immediately seize upon that unauthorized datacenter connection to mount a renewed CFAA attack. What the industry’s shift from the cloud back to the user client really changed in legal terms, and what liabilities it left unaddressed, is answered plainly by these two legal documents.

Ads Are Sold to Human Eyes

Beyond courtroom battles and contractual disputes, platforms run their own economic calculations. Many assume that e-commerce sites block errand-running software out of fear that external programs will siphon away orders. From a transactional perspective, however, when an assistant places an order on behalf of a shopper, the sale still happens, and the platform still captures the merchandise spread or seller commission. Transactional losses are minimal.

Where platforms suffer real financial damage is in the advertising revenue generated during search and browsing. Merchants spend money on e-commerce platforms for sponsored search rankings and featured display slots to capture living human attention. Looking at Amazon’s 2025 Annual Report, the filing specifies that advertising revenue is recognized based on clicks or impressions. Advertisers pay because ads attract real people, influence their purchasing choices, and drive clicks.

AI assistants browse in an entirely different manner. If you instruct one to evaluate twenty product pages, it will open dozens of pages in seconds without being influenced by ads. Logically, automated programs parsing page markup can distinguish between sponsored placements and organic search results. (To be clear, whether an agent filters sponsored listings is an analytical deduction rather than official data published by Amazon.) Confronted with these pages, an AI extracts only product pricing, specifications, and buyer reviews, bypassing paid promotional content entirely.

This creates a headache for platforms: pages that previously displayed ads to humans and generated click revenue have their underlying foundation—human attention—stripped away by agent browsing. Under this dynamic, external assistants consume storefront pages for free while the promotional value of those pages goes unrealized. This is the core economic motive driving platforms to block external traffic at the browsing layer.

Still, evaluating this loss requires perspective on scale. Amazon’s 2025 Annual Report shows that total net sales reached roughly $717 billion, with advertising services contributing approximately $68.6 billion—accounting for less than 10%. While advertising is growing rapidly, it is not the platform’s primary revenue driver. AI browsing disrupts the advertising layer layered atop product listings, not the entire business model.

Platforms want to safeguard the advertising value of their storefronts without closing the door on the broader AI wave. This tangled economic calculus explains why major tech giants defend their perimeters fiercely with technical blocks while simultaneously taking seats at the same negotiating table.

On the same product page, humans are influenced by ads, while machines extract only parameters.

Why Block on One Hand and Cooperate on the Other?

Looking solely at storefront technical blocks and courtroom battles, the tech giants appear locked in irreconcilable conflict. Yet inside the rooms where commercial standards are crafted, a very different picture emerges.

On April 24, 2026, participating parties announced that Amazon, Meta, Microsoft, Salesforce, and Stripe joined the Universal Commerce Protocol (UCP) Technical Council. Under UCP, an open protocol, these stakeholders gathered to establish shared standards for product discovery, cart management, and checkout workflows. Earlier in January, Google had partnered with retail heavyweights including Shopify, Target, and Walmart to advance UCP adoption, making clear within the protocol framework that retailers retain their status as merchant of record, preserving control over transactions and customer relationships.

Drafting industry standards together in April did not stop Amazon from blocking Meta’s Muse on its storefront in September. This stark contrast illustrates that collaborating on interface protocols is entirely separate from whether a company welcomes external bots into its own store. Protocols govern connectivity formats; they do not confer access permission. Participating in standard-setting does not automatically throw open storefront gates. Platforms continue to guard their workflows, and the contractual enforceability and legal issues remain unsettled.

Major AI vendors have also been feeling their way forward and adapting implementations. OpenAI previously attempted to keep transactions contained within the conversation, partnering with Stripe in September 2025 to launch Instant Checkout and the ACP protocol. Yet after nearly half a year of real-world operation, OpenAI made an adjustment on March 24, 2026. The company conceded that the original instant checkout lacked flexibility, choosing instead to allow merchants to use their own checkout workflows. As stated verbatim in the official announcement: We found that the initial version of Instant Checkout didn’t offer the flexibility we wanted to provide, so we are allowing merchants to use their own checkout experiences while we focus on product discovery.

According to Shopify’s official explanation, ChatGPT users who select a product are now routed through an in-app browser to the merchant’s site to finalize checkout. Merchants control the checkout process and the customer relationship, while the conversational assistant focuses on discovery and recommendations upstream. Google’s documentation similarly indicates that Gemini Spark can connect to a user’s local Chrome browser to leverage existing login states or operate inside a remote browser environment.

When it comes to identity attribution, technical mechanisms similarly do not equate to access authorization. In its documentation on cloud browsers, OpenAI explains that the system attaches a verifiable cryptographic signature to egress requests, enabling target sites to confirm traffic originates from ChatGPT. But identifying source traffic is not the same as being granted admission; whether to allow or block the request after verification remains entirely the website’s prerogative. Stating who you are is not a ticket through the turnstile.

Amazon’s own product strategy mirrors this control philosophy. For enterprise procurement, Amazon launched the Business Ordering API for organizational purchasing. But this API is restricted to vetted partners with rigorous onboarding and authorization requirements—a walled garden for institutional purchasing rather than an open door for generic automation.

When looking outward at third-party retailers, Amazon launched its own errand feature, Buy for Me, within its shopping app to purchase goods from other merchants on behalf of users. Amazon stated that its errand requests identify themselves and provided an opt-out mechanism allowing merchants to request exclusion via email. Yet offering a post-hoc opt-out is not the same as obtaining prior consent, and independent brands had previously protested when their products were featured in the service without prior notice.

Returning to the scenario of purchasing an ergonomic chair: technology can shift browsers from datacenters to local devices, minimizing visible network differences; algorithms can mimic human operational pacing with increasing fidelity; and industry protocols can standardize data interchange. But as long as transactions take place in someone else’s marketplace, platforms retain control over their workflows, traffic, and ad revenues, and questions of contractual validity and legal boundaries remain open. What determines whether a shopping assistant can complete a purchase is not simply how deftly software drives a browser, but whether the store on the other side is willing to unlock the door when an errand runner arrives.

Additional sources

The incident and statements from both sides - The Register: Amazon shows Meta’s Muse AI shopping agent the door (2026-09-21, journalist hands-on test and blocking page screenshot) - GeekWire: Amazon blocks Meta’s Muse AI assistant (2026-09-20, pop-up warning and Amazon statement) - The Verge: Amazon blocks Meta’s Muse AI agent shopping (2026-09-21, reporting on previous successful vest purchase) - Meta Muse Official Security Documentation (2026-09-08, credential isolation architecture, prior to the block)

Legal filings and independent analyses - U.S. Court of Appeals for the Ninth Circuit Opinion (2026-08-04, 21-page PDF) - Amazon v. Perplexity Docket, including amended complaint filed 2026-09-21 - MacStories: Hands-on review of Comet for iOS (2026-03-18, early iOS impressions) - Zenity Labs: Independent reverse engineering of Comet desktop

Financial reports and industry developments - Amazon 2025 Annual Report (advertising revenue recognized on clicks/impressions; 2025 advertising revenue approx. $68.6B) - UCP Technical Council Press Release (2026-04-24) and UCP Project Site - Google: Building agentic commerce with retailers (2026-01-11) and Gemini Spark Support Documentation - OpenAI: Instant Checkout adjustment announcement (2026-03-24) and ChatGPT Cloud Browser Documentation - Shopify: How agentic commerce works (2026-06-18) - Amazon Business Ordering API Documentation, Buy for Me Announcement, and Merchant Opt-out Page - Modern Retail: Brands object to Buy for Me featuring their products without communication (2026-01-06)

Previous articles on this site - Google Shut Down Project Mariner, Anthropic and OpenAI Didn’t Really Make It Work Either (2026-05-11)