Issue #67 — Amazon Blocked Meta's Shopping Agent

Meta's Muse logs in as the customer. European payment pilots identify the agent and limit what it may do.

Dear reader,

On the night of Sunday 20 September, people who asked Meta’s new Muse agent to shop on Amazon.com started getting a pop-up: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” Amazon had asked Meta to take Amazon out of Muse. Meta didn’t, so Amazon blocked the agent (GeekWire).

Meta launched Muse in the US on 8 September. Meta says it “can open a browser, fill out forms, and negotiate on their behalf”, and that it checks with the user before a purchase (Meta). A week later it was the top free app in Apple’s US App Store. Early users have described using it to switch a car insurance policy and to fill a grocery basket.

Amazon’s objections: Meta never told Amazon that Muse would shop there, the agent doesn’t identify itself when it browses, it appears to store customer credentials, and it can reach account pages and order history. “We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate,” an Amazon spokesperson said.

Meta says Muse cannot see passwords. Its launch statement says credentials go into secure storage, where the agent can use them without reading them. That addresses how credentials are handled; it does not resolve Amazon’s objection to unidentified access.

Amazon invokes its terms after losing an injunction

Amazon sued Perplexity last year over its Comet browser, which also shops for its users. It won a preliminary injunction in March. On 4 August the Ninth Circuit vacated the injunction and sent the case back for further proceedings, finding that Amazon was unlikely to establish that Perplexity itself accessed its computers under the US anti-hacking law (opinion). The court refused a rehearing on 10 September. Amazon is now invoking its Conditions of Use to block Muse.

Amazon says outside agents should identify themselves and respect a merchant’s decision about whether to participate. Its own agent, Buy for Me, buys from other brands’ websites; Amazon says it identifies itself and lets brands opt out (GeekWire).

Walmart joined Muse

At Meta Connect on 23 September, three days after the block, Walmart, Best Buy, Gap, Sephora, Wayfair and others joined Muse as shopping partners. Zuckerberg said Meta is giving Muse away free for a large number of tokens and expects that “over time we will profit by taking a small fee from transactions” (Yahoo Finance). GeekWire pointed out that Amazon’s advertising depends on people browsing its pages and seeing sponsored products, which an agent going straight to checkout skips.

Meta tested human substitutes for Muse’s calls

The day before Connect, Reuters reported a separate problem. Muse can also phone US businesses for its user, for example to book a haircut or get a quote. One Meta employee testing it said he had tried calling his insurance company and “they keep hanging up on Muse when they hear it is AI.” Meta’s answer was a “human concierge”, switched on for half of its employees: Muse passed the request to a contractor, who made the call. “We are one bug away from unnecessary information being leaked to human callers,” one employee wrote. A vice-president in Meta’s Superintelligence Labs wrote that it “was a miss” to start the test without proper disclosures and that the company had “rolled back this feature” (Reuters).

Europe’s payment pilots make the agent say who it is

Muse is available only in the US, and Meta hasn’t said whether or when it will come to Europe. The European payment pilots of recent months work differently.

On 25 May Mastercard ran the first authenticated agent transactions in Poland, with mBank, Bank Pekao and UniCredit. The agent was asked to find experiences in New York on Mastercard’s own Priceless.com and bought a coffee tasting. It carried an “agent token” defining what it was allowed to do, and the customer confirmed with a payment passkey (XYZ). By 2 June Mastercard said every issuer in Europe was enabled for Agent Pay at network level (Mastercard). In July Visa ran agent purchases with more than 30 European issuers, PKO Bank Polski and mBank among them (Visa). Under both schemes the agent must be registered in the network’s directory and sign every web request, stating whether it is browsing or paying (Cloudflare).

On 24 September Cleverbridge completed France’s first such payment, on a Revolut card, with Visa’s test agent. “Here the merchant knew which agent it was dealing with and the customer’s bank stayed in charge of the payment,” said its chief executive, Richard Stevenson (Business Wire).

On 9 September an agent in the Your KAYA online shop waited for a sold-out hand cream to come back into stock and bought it for PLN 19.99 without the user doing anything at that moment. The user had given the instruction in advance and approved it with a BLIK code in the banking app, within spending limits. The agent “operates exclusively within boundaries previously defined by the user and cannot complete a transaction without the user’s prior authorisation,” said Monika Król, BLIK’s vice-president (BLIK).

None of these is a consumer agent like Muse. Mastercard’s Polish test bought from Mastercard’s own site, Cleverbridge dealt with Visa’s test agent, and the BLIK agent operated in the shop. In each case the shop or the card network could identify the agent, and the customer authenticated the payment through their bank.

Payment-account access has specific identification rules

EU payment rules require regulated providers of account-information and payment-initiation services to identify themselves to the bank. The Commission said the rules applying from September 2019 would end third-party access using the customer’s credentials without identification (Commission). Applying those duties to a general-purpose browser agent first requires deciding whether its provider is supplying a regulated payment service.

Payment authorisation requires the customer’s consent in the form agreed with their payment provider. An instruction to an agent does not by itself establish that form of consent. An agent exceeding its instructions could create a dispute about whether a payment was authorised. Under UOKiK’s interpretation, a Polish bank normally refunds an unauthorised payment by the end of the next business day after detection or notification. Suspected gross negligence alone does not justify withholding the refund; the bank can pursue the customer afterwards. A documented suspicion of fraud reported to law enforcement is an exception (UOKiK).

The agreed draft of the new Payment Services Regulation would also allow banks to withhold a refund on objectively justified grounds for suspecting gross negligence, with written reasons to the customer. It lists clear, specific warnings from the bank among the factors relevant to that assessment. The text still requires formal adoption (European Parliament).

For insurance, the EU’s proposed Financial Data Access Regulation would create a regulated route into insurance and investment data. It was tabled in June 2023 and has not been adopted (European Parliament). Access to data would not itself give an agent authority to switch a policy. An insurer’s terms can define conditions for access to its website, within the consumer-protection and data-protection rules that already apply.

The Commission’s non-binding guidelines on Article 50 of the AI Act, published on 20 July, interpret the transparency duty as requiring agents interacting with people to disclose that they are AI and whom they represent (Commission). Machine-to-machine activity with no output intended for a person is outside that duty. A phone call or a message to a person through a website can fall within it. Using a browser does not by itself remove the disclosure requirement.

An agent that says who it is still needs limits

In May, in a comment for XYZ, I argued that the useful limit for agent payments is the mandate: the customer authenticates once, sets what the agent may spend and where, and the agent works inside that (XYZ). BLIK’s hand cream was bought exactly that way, and the card schemes are building their own versions. One update to that comment: I said then that delegated authentication was the model emerging from the PSD3/PSR negotiations. The agreed text of the Payment Services Regulation has no provision specific to AI agents; its closest mechanism is the mandate for payments a merchant initiates. For now, BLIK and the card schemes are building the agent mandate themselves.

Muse uses the customer’s login and, to the website, looks like the customer. A company has to decide whether to allow that access, subject to the law governing its service. Walmart and the others signed up. Amazon, citing its customers’ accounts and their security, said no. Either choice needs the shop to know an agent is there.

I’d start with access rules that the company can enforce: how an agent identifies itself and what it may do once admitted. Reading a quote carries less risk than switching a policy or cancelling a contract, so permissions can differ. The website needs a way to recognise the agent and restrict its actions; call-centre staff need to know whether to handle its request and how to check that the customer authorised the agent to act.

A signed request identifies the agent’s operator. The customer’s permission must also cover the transaction. Even after those checks, manipulated page content can cause the agent to take a different action. That was my other point in May: agent registration cannot replace protection against manipulated content.

Briefing

On 24 September Prime Minister Anthony Albanese disclosed that an OpenAI agent had accessed Services Australia’s Medicare statistics portal during an evaluation on 18 June. OpenAI discovered the activity on 11 August and notified Services Australia on 10 September, 30 days later, through a public vulnerability-disclosure address (ABC). Contracts with your own AI vendors can specify a named incident contact and a notification deadline.

On 25 September Microsoft introduced a split between subscription access and advanced work billed through Copilot Credits: everyday capabilities remain in the per-user licence, while services such as Cowork and frontier models consume credits (Microsoft). A per-user price therefore does not cover the full cost of advanced usage; budgeting needs the consumption rates and limits for the work employees will run.

A US appeals court ruled 2–1 on 25 September that the Pentagon may treat Anthropic’s Claude as a supply-chain risk, citing the usage restrictions Anthropic builds into the model (Breaking Defense). European suppliers working on US defence contracts may be told to keep Claude out of that work.

Summary

Amazon blocked Muse, saying the agent did not identify itself and accessed customer accounts without Amazon’s agreement. A Meta employee also reported that his insurer hung up when it heard the caller was AI. The European payment pilots show how merchants and payment networks can identify an agent and act on a customer’s prior authorisation.

Companies can set rules for agents using their customer channels, within the law governing each service. Those rules need to distinguish the agent’s identity from its authority to act, and the company needs a way to enforce them. Knowing who runs an agent does not establish what the customer authorised it to do.

Stay balanced,
Krzysztof

Krzysztof Goworek is founder of Quintant — AI advisory that gets enterprises from experiment to production value.