Amazon blocked Meta’s Muse personal AI agent from accessing its e-commerce marketplace, preventing the browser-based agent from making purchases on users’ behalf. Amazon said Muse failed to identify itself as an automated purchasing agent in the HTTP-request text required under its terms, and alleged Meta did not notify Amazon before using the agent on the site.
Amazon also warned that an undisclosed agent operating inside customer accounts could expose sensitive data, including account pages, purchase histories, and stored login credentials. Muse, introduced by Meta as an autonomous browser agent for multi-step web tasks with approval required for sensitive actions, is reportedly being updated with stronger protections including a planned Muse Confidential VM. The block extends Amazon’s broader push to restrict third-party shopping agents, following disputes involving Perplexity’s Comet and reported limitations on Google and OpenAI agents.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Amazon blocked Meta's Muse agent from accessing its online store, preventing purchases through the agent. Amazon said Muse accessed the service without identifying itself as an automated agent and raised concerns about access to customer account data, purchase histories, and login credentials.
Meta introduced Muse as a personal AI agent that uses an integrated browser to perform multi-step tasks on websites, with user approval required for sensitive actions such as purchases.
Amazon previously asked Meta to remove Amazon's online store from Muse's operating scope, but Meta reportedly did not comply.
A court dismissed Amazon's lawsuit against Perplexity AI, while leaving Amazon able to block agents that violate its terms of service.
Amazon previously filed a lawsuit against Perplexity AI concerning its shopping agent.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.