Skip to content
Agentsstrong signalpartially confirmed

Amazon has cut Meta's Muse agent off from shopping on its store

Amazon says it has blocked Meta's Muse from buying on its site for customers, after asking Meta to leave the store out of the product and getting nowhere. Shoppers who send Muse to the site are shown a notice calling it an unauthorized agent and citing Amazon's terms. The objection is not automation: it is that the agent arrived unannounced and does not say who it is while it browses. For anyone building an agent that acts on someone else's site, this is the first clear case fought over terms of service rather than over the federal anti-hacking law.

By Redakcija WebAiRadarPublished 3 min readwritten by a model
Image: Meta

Amazon has stopped Meta's Muse agent from shopping on its site on behalf of users. GeekWire reported the block on September 20, 2026, after Amazon said it had asked Meta to leave the store out of the agent and had not got it. People who send Muse to the site are shown a notice saying that continued access by an unauthorized AI agent violates Amazon's Conditions of Use.

What Amazon says the problem is

Amazon's complaint is not that an agent shopped, but that this one turned up unannounced. Meta did not tell Amazon that Muse would reach its store, the agent does not identify itself while it browses, and Amazon says it appears to capture and store customer credentials. A spokesperson put it as a rule of conduct between businesses: third-party applications that buy on a customer's behalf should operate openly and respect a service provider's decision about whether to take part.

Amazon also says Muse can reach account pages and order history when a customer asks it to. Because the agent does not announce itself, the company describes that as an undisclosed third party moving through customer accounts, processing transactions and handling sensitive data without its knowledge. It sets that against its own Buy for Me feature, which it says identifies itself and lets brands opt out.

  • Meta gave Amazon no notice that Muse would shop in its store.
  • The agent does not identify itself the way a food delivery app or an online travel agency does.
  • Amazon says Muse appears to capture and store customer credentials.
  • Amazon says it is talking to Meta directly, and it declined to say whether it will sue.

What Meta published about credentials

Meta's launch post of September 8, 2026 claims the opposite about the same mechanism. Muse runs on a dedicated virtual machine in the cloud with its own browser, and that is where the data and the credentials for every connected service are kept. Meta writes that Muse has no visibility into people's passwords or payment methods, and that anything a person shares goes into secure storage, so the agent can use a login without seeing it.

The same post describes a second agent, Sentinel, which runs on that machine but is kept apart from Muse at the system level. Nothing Muse does reaches the internet unless Sentinel approves it. Meta has not answered the specific complaint about credentials. It did not reply to GeekWire's request for comment, so the two public descriptions of what Muse holds remain unreconciled.

Why the notice cites terms and not the anti-hacking law

Amazon has spent the past year trying to keep other people's agents off its pages, and the wording of this notice follows a loss in court. On August 4, 2026 the Ninth Circuit ruled in the case against Perplexity that under the federal anti-hacking law it is the user, not the company that builds the agent, who accesses Amazon's computers. On September 10, 2026 the court refused to hear the case again, which closes that route and leaves the one built on contract.

This suggests the next disputes of this kind will be argued over terms of service rather than over intrusion. The notice that Muse users see accuses nobody of breaking in. It says the customer agreed to conditions and that continued access by an unauthorized agent breaks them. If you build an agent that works inside someone else's site, the governing document is that site's terms, and identification is the question that decides whether the agent is welcome.

The standoff is awkward for both companies. Amazon products have been purchasable inside Facebook and Instagram since 2023, and during 2026 Meta signed a deal worth several billion dollars to run agentic workloads on Amazon's cloud. Amazon also takes more than 68 billion dollars a year in advertising revenue, a business that depends on customers browsing its pages themselves.

„Continued access by an unauthorized AI agent violates Amazon's Conditions of Use“
Amazon's notice to Muse users

Sources

Related

Customize Claude Code with mods in TypeScript | Claude by Anthropic
Agentsstrong signal

Claude Code mods are not sandboxed, and version 2.1.289 fixes a deny rule they could override

Anthropic introduced mods for Claude Code on October 1, 2026. They are TypeScript functions, shipped inside plugins, that can rewrite prompts, change tool calls, and redraw parts of the interface. The documentation says mods are not sandboxed and run with your permissions, which covers your files, environment variables, and API keys. On Team and Enterprise plans a built-in mod named sec-default loads first and restricts the mods that users install. Versions 2.1.288 and 2.1.289 fix several cases where permission rules did not hold.

Anthropicverified

Agentsmedium signal

GitHub Copilot retires four models and makes Balanced its default code review effort

GitHub deprecated four models across all Copilot experiences on October 2, 2026: Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7. On the same day it made Copilot code review available through the REST and GraphQL APIs. Balanced is now the default review effort level, a change that took effect on September 28, 2026. According to GitHub's documentation, a Balanced review consumes more AI credits than a Lite one.

GitHub Changelogverified

Apple's illustration for its notice on Full Disk Access: a white disk drive symbol on a gray rounded square, set on a light gray background.
Agentsmedium signal

Apple will add controls to Full Disk Access on macOS, citing risks from AI agents

Apple said on October 2, 2026, that it will add controls to Full Disk Access, the macOS permission that lets an app read nearly everything on a Mac. The company says some developers use the permission in ways that expose files, mail, messages, and browsing history without users fully understanding it. Apple expects the risk to grow as AI agents become more capable and autonomous. The post gives no date, no macOS version, and no description of the new controls.

Appleverified