IA · 22 September 2026 · 4 min read

Amazon slams the door on Meta's Muse: agentic shopping hits a wall

In brief: Amazon has blocked Meta's newly released Muse AI assistant from completing purchases on its marketplace on behalf of consumers. The e-commerce giant argued that unauthorized autonomous agents violate its terms of use, flagging risks around credential handling and dispute resolution for flawed orders. The clash coincides with the disclosure of a major zero-day vulnerability in the desktop version of Muse, intensifying security scrutiny on autonomous commerce agents.

by Team Mocchi's

Amazon slams the door on Meta's Muse: agentic shopping hits a wall

The sudden block: "Unauthorized agent"

Over the weekend, consumers using Meta's Muse assistant to buy items on Amazon were met with an unexpected barrier. The retail platform began serving a direct error message stating that continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which shoppers have agreed.

As reported by The Verge, Meta neither consulted Amazon nor sought permission before dispatching its agent to act on behalf of customers inside the store. Amazon raised explicit privacy and security concerns regarding Muse's failure to identify itself during automated browsing sessions and its potential capture of user login credentials. An Amazon spokesperson stressed that third-party applications attempting to purchase goods on behalf of users must operate openly and respect service providers' choices on whether to participate.

Defending the walled garden and customer ownership

Beyond legal formalities, the clash signals an escalating battle over the mechanics of agentic commerce. As noted by TechCrunch, Amazon has no strategic interest in letting third-party AI assistants wedge themselves between consumers and its marketplace, reducing the world's largest online retailer to a silent backend fulfilment pipeline.

There is also a very practical operational risk. While modern language models are increasingly competent, their error and hallucination rates remain well above zero. If an agent places an incorrect order—picking the wrong sizing, incorrect variants, or outdated shipping addresses—the financial and logistical headache of processing returns, refunds, and support claims falls squarely on Amazon and its marketplace sellers. The retailer previously took legal steps against Perplexity's Comet shopping assistant and recently stripped product images and descriptive metadata from confirmation emails precisely to hinder scraping by autonomous web agents.

Zero-day vulnerability raises the stakes for Meta

Adding to Meta's hurdles, independent security research revealed serious systemic vulnerabilities in the desktop architecture of Muse. According to reporting from Ars Technica, macOS security researcher Patrick Wardle uncovered a zero-day flaw that allows unprivileged local processes to seize control of the assistant.

To perform its advertised duties—such as booking reservations, handling forms, and interacting with local files—Muse holds deep operating system permissions that bypass standard sandbox limitations. However, Wardle discovered that undocumented settings can be manipulated by local code to divert the assistant's transcription endpoint to an attacker-controlled server. This exposes the master authentication token for the user's Muse account, effectively converting the assistant into an unintended malware execution pipeline. The discovery hands marketplace operators like Amazon a compelling rationale for shutting out privileged desktop agents that lack robust verification controls.

Mocchi's take

For digital agencies and European enterprises developing software solutions, this clash marks the end of the illusion that AI agents can simply scrape and interact with web applications pretending to be human shoppers. Big tech ecosystems will fiercely defend customer touchpoints and data boundaries, especially when autonomous hallucinations threaten to inflate customer service and return costs. The future of agentic commerce will not belong to unauthorized web-crawling bots, but to certified transactional APIs, verified identity protocols, and clear legal frameworks establishing who bears liability when an autonomous agent makes a mistake.

Further reading

All articles on the Mocchi's blog