In late September, a customer asked Meta’s Muse to buy something on Amazon and got a popup instead of a confirmation. The popup wasn’t addressed to Meta. It was addressed to the customer, telling them that letting an unauthorized AI agent act on their behalf violated the terms they agreed to when they opened the account.
Amazon apparently asked Meta to remove Amazon’s website from its agent, but Meta refused. Meta’s apparent workaround was to have Muse access Amazon without declaring itself as an agent. Muse also captures the customer’s Amazon login credentials and stores them without permission. Meta says Muse never sees passwords or payment details. Given Meta’s reputation, it’s hard to believe that they are being upfront about what Muse does. But from an Amazon perspective, the pattern is bigger than this one fight. Amazon has shut out shopping agents from Google, OpenAI, Perplexity and Anthropic over the past year. eBay barred third-party buying agents in February. Kohl’s has restricted them too.
The usual explanation is the $68 billion advertising business, which runs on people searching and scrolling on Amazon’s own pages and which an agent that shops elsewhere and arrives only to pay would hollow out. That seems the most logical and tactical response. Amazon also argues that an outside agent skips the personalization they spent two decades building, so you end up with recommendations that have nothing to do with you. Even that is self-serving, and still not wrong.
This wasn’t Amazon’s first rodeo. Amazon sued Perplexity over its Comet browser, won an order blocking it in March, and lost that order in August when the Ninth Circuit held that the federal anti-hacking law contemplates access by a person, that an AI assistant is a tool rather than a person, and that the customer is therefore the one accessing Amazon. The court declined to reconsider in September, and went out of its way to say it wasn’t writing new rules for agentic AI or touching anyone’s right to govern access through their own terms. So the question went back to private agreement and whatever a company can enforce technically, which lands it with whoever runs the experience layer.
Meanwhile, Shopify opened its merchants to Muse and wired in its own checkout; Walmart and Best Buy have been welcoming, and Google launched an open commerce standard in January with Shopify, Walmart, Target, Etsy and Wayfair. Shopify says AI-referred orders grew about thirteenfold year over year last quarter. Nobody in either camp is being visionary or reactionary. They’re reading their own revenue model, and a business that sells attention reads it differently than one that sells transactions.
Whichever way it lands, someone in CX has to implement it, and that popup is a brand moment delivered at the worst possible second, blaming the customer for a fight between two enormous companies.
But let’s focus on the substance of Amazon’s complaint. The agent wouldn’t say what it was, wouldn’t say who sent it, and may have been holding a customer’s credentials. Those are fair questions, if simply from a cybersecurity perspective.
IEEE 7012 (MyTerms) was written for this. It lets a person arrive with their own machine-readable terms, lets the business agree to them, and leaves a record both sides can point to later. Not a consent banner, which asks you to accept what someone else already decided, but an agreement between two parties. It answers Amazon’s questions directly. Who this is, who authorized it, and what it can do with what it learns.
The Ninth Circuit made that case for MyTerms without meaning to. If the customer is the one accessing it, the customer’s terms should govern the exchange. I’d like us to get there before more companies decide a wall is the only option.


