
What Meta's Muse Changes: Amazon's Block, Subscription Cancellations, and the Fight Over the Front Door
Introduction
Meta launched its AI agent Muse in the US on September 8, 2026, and within ten days it was the top free app on Apple's App Store. Muse does not just answer questions. It sends emails, books trips, buys things, and cancels the subscriptions you forgot about.
Key takeaways
- Muse brings an agent that acts rather than answers to a mainstream audience, backed by a company with billions of users
- Twelve days after launch, Amazon blocked Muse from shopping on its site. The dispute is about whether an agent may operate another company's website without identifying itself
- The same week, Shopify embraced Muse and its stock rose about 7%. The industry is starting to split between blockers and adopters
- Muse has no announced launch date in Japan, but businesses can already decide how they will treat agent traffic
The feature list is not the interesting part. When an agent sits between a customer and a store, someone has to own the customer relationship, and Muse is the first product to put that fight in public at scale. This article walks through the first three weeks and what they suggest.
What is Meta Muse?
Muse is a personal AI agent that takes a goal, makes a plan, and carries it out by browsing the web and filling in forms. According to Meta, it keeps working after you close the app and asks for approval before sensitive actions such as purchases.
It runs on Muse Spark, the language model that Meta Superintelligence Labs first announced in April 2026. Muse is available in the US on iOS, Android, the web (muse.ai), and WhatsApp. Most features are free, with paid plans for heavier use.
Adoption has moved quickly:
- Downloads: More than 2.5 million, according to Sensor Tower estimates cited by CNN
- Partners: At Meta Connect on September 23, Meta announced retail partners including Walmart, Sephora, and Best Buy, and payment partners including Stripe and PayPal. Developers submitted more than 1,500 connector applications in under a week
- Business model: Meta says it expects "over time" to profit "by taking a small fee from transactions." The details have not been decided
- Small businesses: On September 29, Meta launched Muse for Small Business, which connects to Shopify, Slack, QuickBooks, and other tools
Why did Amazon block Muse?
Amazon objected that Muse operated its store without notice, without identifying itself, and using customers' login credentials. On September 20, Muse users trying to shop on Amazon began seeing a message that the agent's access violated Amazon's Conditions of Use.
Reports describe three concerns:
- Meta gave Amazon no notice or choice about Muse using its store
- Muse does not identify itself as an agent when it browses
- Muse appears to capture and store customer login credentials
In a statement to CNN, Amazon said third-party apps that buy on behalf of customers "should operate openly and respect service provider decisions about whether or not to participate." Meta responded that Muse has no visibility into passwords or payment methods.
This is not the first such dispute. Amazon sued Perplexity in November 2025 over the shopping agent in its Comet browser. A preliminary injunction granted in March 2026 was vacated by the Ninth Circuit in August, which found Amazon unlikely to prove that Perplexity, rather than the user, was the one accessing its systems. The legal question of who is accessing a site is still open.
Block or embrace: how is the industry splitting?
In the same week Amazon shut Muse out, others chose to embrace it, and the market rewarded them very differently. The most visible was Shopify, which provides online storefronts and checkout.
On September 21, Shopify and Meta announced that Muse can browse Shopify-powered stores and complete purchases on a user's behalf through Shop Pay, Shopify's checkout. According to 24/7 Wall St., Shopify shares rose about 7%. Deutsche Bank analysts, quoted by Yahoo Finance, called the deal "strategically important" because "it provides another proof point that leading AI platforms are integrating with Shopify's commerce infrastructure."
Meta's own stock rose too. CNBC reported that on September 24, the day after Meta Connect, shares were around $773, up from below $600 a month earlier. Seoul Economic Daily reported a 27% gain for September, the largest monthly rise in nearly four years. As CNBC put it, "Amazon blocking Muse from its marketplace looks more like the exception than it does the rule."
Three weeks after launch, responses fall into three groups:
| Response | Companies | Reason or condition |
|---|---|---|
| Block | Amazon | No prior notice, the agent does not identify itself, and it handles login credentials |
| Conditional | Resy (restaurant reservations) | Does not permit unapproved third-party bots or agents, while integrating with ChatGPT and Claude |
| Embrace | Shopify, Walmart, Sephora, Expedia, OpenTable, and others | Official integrations with Muse that capture agent-driven orders |
Embracing agents did not pay off for everyone. According to CNN, shares of Expedia, Airbnb, and Tripadvisor each fell about 5% the week Meta announced new Muse features, even though Expedia chose to allow agents because it wants "to show up wherever travelers are searching."
We think the difference comes down to whether a company is a path the agent must use or a window the agent replaces. Shopify runs the checkout and storefront infrastructure, so more agent shopping means more transactions. Travel sites have offered a window where people compare and choose; if the agent does the comparing, that window loses value. Amazon, as Bloomberg Intelligence's Mandeep Singh notes, grows by showing people other products while they look for the one they came for. An agent that buys directly removes that chance.
Our expectation is that neither blanket blocking nor unconditional acceptance will last. Businesses will converge on conditional access: agents that identify themselves and come through official entry points get in. Resy is an early example. A company that keeps blocking hands agent-driven orders to competitors who accept them, while once Meta starts charging a fee, adopters' margins get thinner. Either way, businesses need a way to recognize agents and set conditions.
Whose revenue does an agent that cancels for you cut into?
The first businesses to feel it are subscriptions that depend on customers forgetting to cancel. CNBC reported that users who gave Muse access to bank and card statements found unused subscriptions and cancelled them.
The money at stake is large:
- A Mastercard and FT Strategies report found that 44% of US consumers increased subscription spending in 2025, with average annual spending reaching $1,887, or about $157 a month
- Research by Stanford economist Neale Mahoney and colleagues found that people forced to decide are about four times more likely to cancel, and estimated that inertia and cancellation friction roughly double sellers' revenue
An agent that reads your statements and cancels for you weakens both effects. Apollo chief economist Torsten Slok has argued that if agents moved household cash from checking accounts paying 0.1% into accounts paying 3.3% to 5.0%, banks could lose much of the cheap deposit base they lend from.
Easy cancellation does not only shrink revenue, though. In the same Mastercard research, 74% of consumers said they are more likely to subscribe when cancelling is easy. Recurly reports that use of "pause before cancel" options rose 337%, and three in four customers who paused eventually returned. Businesses that rely on friction are exposed. Businesses that keep customers by showing value may come out ahead.
How far can Muse's security design be trusted?
Muse's design keeps the power to send data out of the agent's hands. According to Meta, each user's Muse runs in a dedicated virtual machine (Muse Secure VM), and a separate agent on that machine, Sentinel, reviews every outbound network request and third-party action. Muse can only propose; Sentinel decides whether to allow it, deny it, or ask the user.
There is a reason for this split. Developer Simon Willison describes the "lethal trifecta": an agent that can read private data, reads untrusted content, and can send data out can be tricked by injected instructions into leaking that data. By moving the third capability to Sentinel, Muse tries to break the combination.
Meta does not claim the problem is solved. In its write-up of Muse's safety design, Meta says that "no matter how strong the model is at the core, any agent like this will still make mistakes, and it will sometimes be attacked via the data it reads." Its bug bounty pays up to $300,000, including up to $130,000 for a prompt injection affecting one user.
Beyond technical defenses, users are reporting things they do not remember allowing. Inc. columnist Jason Aten wrote that Muse read his messages with a podcast co-host about new iPhones and, unprompted, offered to research it as a column idea. Aten says he explicitly chose not to give Muse access to his messages.
Meta disputes this. Spokesperson Andy Stone said the Messages integration in the Mac app is entirely opt-in: users must enable both Full Disk Access and the Messages connector, and Muse cannot read messages otherwise. The two accounts remain at odds.
Agent safety is not only about blocking data exfiltration. If users cannot see what they have actually permitted, even a correctly working system will be perceived as reading things without permission, and trust suffers. Users need a place to review what they have granted.
What should businesses decide now?
Even where Muse is not yet available, businesses can decide today how they will treat agents that arrive at their sites. Turn Amazon's three concerns around and they become three questions: who is this agent, on whose behalf is it acting, and how much has it been authorized to do?
The first question is starting to get technical answers. In 2025 Cloudflare introduced Web Bot Auth, which lets agents sign their HTTP requests so sites can verify their identity, and created a separate category for signed agents acting on behalf of end users.
A signature alone does not answer the other two. Sites also need a way to verify the delegation itself: "this user authorized this agent to buy up to this amount." Think of a digital power of attorney that the user issues, the agent presents, and the store verifies. Verifiable Credentials (digitally signed statements whose issuer and integrity the recipient can check) are one technology suited to this.
In the meantime, what to decide depends on the type of business:
- Retailers and platforms that own the customer relationship: Decide in writing whether to block agents, as Amazon did, or allow them on conditions. The legal footing for blocking is still unsettled, as the Perplexity case shows
- Booking, comparison, and referral services: If you accept agents for reach, as Expedia did, plan how to keep a relationship with customers who no longer visit your site
- Small merchants on platforms like Shopify: You are on the side that gains exposure through agents, so making product information readable by agents pays off
- Subscription businesses: Rethink retention that depends on friction, and offer pause or downgrade options
We have covered how to make a site readable by agents before. You can measure how agents see your site with Cloudflare's Agent Readiness Score.
FAQ
Q. Is Meta Muse available outside the US?
A. As of October 2026, Muse is available only in the US on iOS, Android, the web (muse.ai), and WhatsApp. Meta has said it is coming to its AI glasses, and other regions have no announced dates.
Q. How is Muse different from chat assistants like ChatGPT?
A. Muse is built to carry out tasks rather than answer questions. It operates a browser inside its own virtual machine to book, buy, fill in forms, and cancel, and asks for approval only before sensitive actions.
Q. Should my site block AI agents?
A. There is no single answer. If the customer relationship itself is your revenue, consider blocking or conditional access; if you want reach, consider allowing agents. Either way, start by stating the policy in your terms of service and robots.txt.
Q. Is Muse's security good enough?
A. Keeping outbound access away from the agent and having a separate agent review traffic is a sound defense against prompt injection. Meta itself, however, acknowledges remaining weaknesses and is paying bounties to find them.
Summary
Muse has brought agents that shop and cancel on our behalf to ordinary consumers. The result is a public fight over who owns the customer relationship, visible in Amazon's block and Shopify's embrace, the dip in travel stocks, and the pressure on subscription businesses. The industry is splitting into blockers and adopters, but we expect it to settle on conditional access for agents that identify themselves and use official entry points.
The question for businesses is not simply whether to allow agents. It is whether they can verify who an agent is, whom it represents, and what it has been authorized to do, and then set a policy on that basis. At ZenChAIne, we keep making zench-aine.io easier for agents to read, and we will continue writing about how to verify agent identity and delegation.
References
- Introducing Muse: The World's First Personal AI Agent Built for Everyone - Meta
- Everything new coming to Meta's AI agent Muse - TechCrunch
- Meta is expanding its AI agent Muse to small businesses - TechCrunch
- AI agents promise to do everything for you. There may be a big wrinkle in that plan - CNN
- Meta's Muse agent is attacking one of the economy's most profitable weak spots - CNBC
- How We Built Safety Into Muse - Meta AI Research
- Meta disputes claim that Muse read a user's private messages without permission - TechCrunch
- Shopify Spikes 7%, Meta Eases as Muse Agent Gains Shop Pay Checkout - 24/7 Wall St.
- Shopify Stock Rallies on Checkout Partnership With Meta's New Muse AI Agent - Yahoo Finance
- Meta nears first new high in a year as Muse success showcases winning AI strategy - CNBC
- Meta Stock Jumps 27% in September on Muse Success - Seoul Economic Daily
- Amazon blocks Meta's Muse shopping agent - implicator.ai
- Meta Muse AI agent internal security flaws - implicator.ai
- Meta's New Muse AI Agent Read My Private Messages. I Never Asked It To - Inc.
- The lethal trifecta for AI agents - Simon Willison
- The age of agents: cryptographically recognizing agent traffic - Cloudflare
