Amazon blocked Meta’s new shopping agent, Muse, late on Sunday, 20 September, serving its users a popup that reads: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” That wording puts the violation inside the customer’s own agreement rather than inside a statute, and it is no accident. It traces back to a Ninth Circuit opinion, filed seven weeks earlier, that stripped Amazon of a statutory injunction against a different AI agent and named, in a footnote, the door still open.
What did Amazon do to Meta’s Muse agent?
On the night of 20 September, Amazon started showing Muse users a popup citing its Conditions of Use rather than any unauthorized-access statute. An Amazon spokesperson said third-party apps that offer to make purchases from other businesses on a customer’s behalf “should operate openly and respect service provider decisions about whether or not to participate.” Amazon’s complaints, in the order it raised them: Meta never disclosed that Muse would touch the Amazon store, the agent does not identify itself while it browses, and it appears to capture and retain customer credentials.
GeekWire broke the story on 21 September, with The Verge and Engadget following. According to that reporting, Amazon had first asked Meta to voluntarily exclude Amazon.com from Muse, blocking only once that failed. The Verge’s report on the block says it had tested Muse buying tank tops on Amazon before the popup appeared, and that Amazon has omitted specific item names and product images from its confirmation emails since July to limit what outside AI services can mine.
From a Computer-Fraud Statute to a Customer’s Contract
Amazon had tried the statutory route before: in November 2025 it sued Perplexity AI, accusing its Comet browser agent of violating the Computer Fraud and Abuse Act and California’s Comprehensive Computer Data Access and Fraud Act, and won a preliminary injunction in March 2026, after a tentative ruling indicating that it was a close call. On 4 August, the Ninth Circuit vacated that injunction and sent the case back. The panel concluded that Perplexity had not used a tool to access Amazon’s computers within the meaning of either statute: the accessing party was the user, working through the agent. Footnote 5 spelled out what survived: “This outcome does not impair Amazon’s ability to regulate access to Amazon.com via private terms of service for its users. On the facts before us, Amazon is simply unlikely to succeed in its attempt to regulate access by invoking the CFAA and the CDAFA.” Seven weeks later, against a far larger opponent, Amazon walked through that exact door with a Conditions of Use popup.
The Grievance That Repeats
The Comet dispute turned on a technical absence: Perplexity’s decision not to send a “user-agent string,” a mechanism “that would communicate that the user has activated an AI agent” and that, per the court’s background, would have let Amazon block the Assistant’s access to its store. Amazon’s second grievance about Muse is the same complaint restated: the agent does not identify itself when it browses. Two companies, two agents, ten months apart, same objection.
Meta has not addressed this week’s block. Its public statement on credentials predates the block, made at Muse’s 8 September launch: “Muse has no visibility into people’s passwords or payment methods. Any credentials a person shares go into secure storage, so Muse can use them without seeing them, including passwords a person types into the browser themselves.” That answers a design question, not Amazon’s disclosure question.
What This Means Past the Courtroom
The detail worth sitting with is operational, not legal. Amazon runs one of the largest storefronts on the internet, and one of its three stated objections is that the agent will not say what it is while it browses. Nothing Amazon has published describes how it separates an agent’s session from a human one; what it has published is a popup and a clause. Undeclared agent traffic doesn’t announce itself inside an analytics property: it sits in the same session counts, conversion paths and channel groupings as ordinary visits, and nobody here, Amazon included, has published a figure for it.
What a marketer can still fix sits downstream of the browsing layer: campaign tags on a link you own resolve the same way no matter who, or what, drives the browser. They don’t detect, identify or filter an agent like Muse, but they survive the click regardless, which is why building them consistently with elsop’s campaign URL builder still pays off. The bigger shift sits further upstream: platforms dictating the terms on which an AI assistant reaches their commerce data, the same dynamic already shaping how retailers structure product feeds for ChatGPT Shopping. This week, Amazon drew that line against Meta in a clause, not a courtroom.