The Take — Give shopping agents a name, not a permission slip

Share
The Take — Give shopping agents a name, not a permission slip

Amazon cut Meta's Muse off from Amazon.com over the weekend, and by Monday the argument had settled into the usual shape: open web versus walled garden, scrappy agents versus the store that owns the shelf. I think that framing buries the only question worth arguing about. Amazon is right that an agent should have to say who it is. It is wrong that a merchant's consent should decide whether the person who owns that agent gets to buy something. Those are two different demands wearing one sentence, and the bundling is the story.

Here is what actually happened. As our brief on the block laid out, Amazon told users through a popup that continued access by an unauthorized AI agent violates its Conditions of Use. Per GeekWire, Meta never told Amazon that Muse would shop its store, the agent does not identify itself when it browses, and Amazon says it appeared to capture customer credentials. An Amazon spokesperson then stated the principle in a line worth reading twice: third-party applications that offer to make purchases on customers' behalf from other businesses "should operate openly and respect service provider decisions about whether or not to participate."

Two clauses, two very different claims. Operate openly is a disclosure demand, and it is reasonable on its face — a retailer is entitled to know that the thing hitting its servers is a machine, and on whose behalf. Respect service provider decisions about whether or not to participate is an authorization demand. It is a veto, and it is the half that does not survive contact with either the law or the market.

A customer making a contactless payment with a smartphone at a grocery store checkout counter.

Start with the law, because a court already drew this line. In August the Ninth Circuit vacated Amazon's anti-hacking injunction against Perplexity's Comet browser in Ninth Circuit: the user accessed Amazon, not Perplexity's agent, holding that the human user — not the company that built the assistant — "accessed" Amazon's computers, and that a user-directed assistant running in the user's own browser is "materially different from a service independently sending its own automated requests to a target's servers." That ruling did not hand platforms a permission regime. It told them the statute written for hackers is not the wall, and warned explicitly that the legal understanding of agentic AI will change. What Amazon is doing now is enforcing by product what it could not enforce by statute.

The commercial tell makes the consent language hard to take at face value. Amazon spent a year fencing its catalog off from outside agents — crawler blocks, the Perplexity suit, product feeds pulled from Google Shopping — while simultaneously buying its way into ChatGPT, which is not the posture of a company worried about who reads its listings. Access that runs through a paid door is a toll, not a consent regime. If a merchant admits only the agents that pay it, or only the assistant it ships itself, the veto was never about safety. It is about who gets to be the middleman — and the assistant wearing the store's own logo never has to apply for a pass.

The identity half of the demand, meanwhile, is already being built somewhere else. China's payment industry adopted a Know Your Agent rulebook for AI that spends money last month, and Visa, Mastercard and Ant have each started pushing toward a shared trust layer for agent transactions — because a payment rail that cannot name the agent behind a purchase cannot price its risk. That is the whole argument in miniature: naming agents is a solvable engineering problem with a commercial incentive attached, while merchant-by-merchant licensing is not a protocol. It is N contracts per user per task, which is not a gate, it is a queue.

On the credential claim, both sides are asserting architecture. Amazon says Muse appeared to capture customer credentials. Meta's launch materials say Muse cannot see login details or card payment information, that checkout runs through Link by Stripe, and that a separate monitoring agent is kept apart from Muse at the system level inside a sealed virtual machine. Neither claim has been demonstrated in public. If credential capture is the real harm — and it would be a real harm — the remedy is a security requirement applied to every agent that touches a checkout, not a per-merchant veto that never has to state its reason.

The strongest case for Amazon

Give the other side its best version, because it is better than "big retailer hates innovation."

A merchant carries the downside of agent traffic: account takeover, orders placed by something that cannot be held to a contract, disputes the store eats, support load, and a bot-mitigation stack that works only if the automated client lets itself be distinguished from a person. Terms of service exist for exactly that, and contract law has always let a shop refuse service to anyone, for any reason. Nobody has a right to a private marketplace. Add the context: Meta never told a company it has a multiyear chip deal with, and Amazon products have been purchasable inside Facebook and Instagram since 2023. A partner that behaves furtively about a launch has not earned the benefit of the doubt. And the Ninth Circuit ruled narrowly, on a single prong of a case still alive on remand — the panel said out loud that the rules will move.

A veto still binds the wrong party.

An agent that drives the user's own logged-in browser from a residential connection is, to any server, indistinguishable from the user. Every retailer that has tried to keep web agents out has learned the same lesson: the block lands on the agents that announce themselves and misses the ones that do not. So Amazon's enforcement landed on a publicly launched product from a named company with a chip contract, while credential stuffers that lie about their user agent browse on unaffected. A rule that punishes disclosure and cannot touch concealment is not a security control.

The unit of accountability is wrong too. The purchase is the user's purchase; the loss, if there is one, belongs to whoever caused it, per transaction. A per-merchant invite list replaces that with a permission economy in which the incumbent decides which rivals' agents reach its shelf, and publishes no reason. That is the arrangement the Ninth Circuit declined to create — not because agents are innocent, but because the wrong party was being asked to grant permission.

Names, then, not permits. If an agent presents verifiable identity, the human behind it, and the fact that it is automated, a site can apply the same rules it applies to people: rate limits, fraud checks, no credential handling, bans with a stated cause. That is enforceable per transaction, auditable after the fact, and it competes on detection rather than on disclosure. A registry of named agents is a protocol; a registry of approved agents is a licensing board, and nobody voted for one.

What would change my mind

Three things, all specific. First, a number: evidence that identified agents generate fraud and account-takeover losses measurably above the human baseline. Not an assertion — a figure, because retailers already have that data for human traffic. Second, a pattern: if an agent that discloses itself, carries no credentials and brings the customer's own payment method is still barred for being a rival's, I will stop calling this consent, and Amazon's defenders should want that distinction tested too. Third, the reverse test: if the identity layer ships and Meta's Muse still refuses to present a name, then Meta is the one refusing the reasonable half of Amazon's demand, and the block is defensible on the terms Amazon actually stated.

The party that will not identify itself forfeits the right to complain about the door. The party that owns the shelf does not get to own the customer's choice of how to walk in.

Should a merchant be able to refuse an agent that names itself and spends the customer's own money? Tell us in the comments.

Sources: GeekWire · The Verge · Ninth Circuit opinion, No. 26-1444 (PDF) · Meta — Introducing Muse · TechCrunch