Amazon has blocked Meta's personal agent Muse and prevented it from purchasing on Amazon.com on behalf of users. Users attempting this were met with a notification that the unauthorised AI was violating Amazon's Terms of Use, while Amazon states that users have agreed to these terms.
The company outlines three complaints. Muse does not identify itself when browsing, captures and stores user credentials, and navigates through user accounts without the knowledge or consent of the merchant. Meta counters that the agent never sees passwords or payment details, as these go to secure storage, and claims that it seeks user confirmation before sensitive actions, such as sending email or making a purchase.
Meanwhile, products are purchased on Facebook and Instagram from 2023, and in April Meta signed a multi-billion dollar contract to have its agent services run in Amazon's cloud. Muse became the most downloaded free app on the US App Store a week after its launch, ahead of ChatGPT.
Amazon is suing Perplexity, having received a temporary restraining order in November 2025 and March 2026. The US Ninth Circuit Court of Appeals overturned it on 4 August 2026, concluding that Amazon's computers are accessed by the user, not Perplexity, and the request for rehearing was denied on 10 September. Amazon does not claim that this is hacking, but rather that the use of the agent violates the Terms of Use.
Perplexity refused to place a label that would allow Amazon to identify and block its agent. Amazon states that the browsers Brave and Microsoft Edge have the same technical capabilities, but in response to a user's explicit request, they do not perform such access for security reasons. Cloudflare accused Perplexity in August 2025 of stealthily collecting, modifying browser labels and IP addresses to bypass blocks, while in October 2025, Reddit filed a federal lawsuit claiming that Perplexity's crawlers were accessing content via Google's search results, while licensed partners such as OpenAI pay for access.
From 15 September 2026, every domain on the Cloudflare network classifies incoming crawlers into three categories: search, training, and agent. Training and agent are blocked by default as soon as the page displays ads, and the Pay Per Crawl model has evolved into Pay Per Use, where the publisher pays only when their content appears in an AI response. OpenAI and Stripe have published the Agentic Commerce Protocol, while Google is developing AP2 with mandates signed as verifiable credentials, and Mastercard's Agent Pay ties the token to a specific agent, merchant, and consent.
The context is huge: Amazon made over $68 billion in revenue last year from ads alone. The robots.txt file was merely a request telling bots where they were allowed to go and where not, and the protocol is advisory in nature, not legally or technically binding. More and more platforms are checking entry, charging fees, and conditioning access on the agent identifying itself. Rules are set by the owners of the websites and network infrastructure, not by those accessing them, while a part of the agents, as the case of Perplexity shows, attempt to bypass blocks by changing browser labels and IP addresses.










