Amazon blocked Meta’s AI Agent Muse AI on its app last month. Elon Musk has sided with Amazon’s restriction saying that the online commerce platform may not be able to distinguish human buyers from AI agents if the AI operates through the user’s own IP address and cookies, bypassing detection methods. Musk was responding to a post by an X user who highlighted this as the start of a ‘digital knife fight’. “Amazon cuts off Muse. While I am bullish Meta and Muse, I think many people are overlooking the digital knife fight that’s about to occur,” the user wrote, adding “Nobody wants to get commoditized or layered here”.Elon Musk replied to the post writing “Amazon won’t be able to tell whether the buyer is a human or an AI acting on their behalf if access is via the user’s IP address & cookies”.
What Amazon said on blocking Meta’s Muse
GeekWire reported that Amazon said it never consented to the integration. It added that Meta launched the feature without advance notice, designed the agent to browse without identifying itself as automated software, and appears to harvest and retain customer credentials, a combination Amazon warns poses serious privacy and security hazards.By September 20, consumers attempting to use Muse for purchases on Amazon encountered an explicit roadblock message: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.”According to the report, an Amazon spokesperson emphasized that external platforms should adhere to basic commercial boundaries:“We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate.”
What Meta said
Meta has previously rejected allegations that its agent mishandles sensitive user information. The company noted that Muse operates without direct visibility into user passwords or banking details. It also stated that any log-in information entered by a consumer is placed into protected storage, enabling the model to utilise credentials without reading them directly, even when an individual types them straight into a browser session.