Amazon Blocks Meta's Muse as AI Agents Hit a Wave of Site Defenses
Amazon, Walmart, Delta, Yelp, and eBay are blocking or restricting personal AI agents such as Meta's Muse. Meta, Stripe, and Walmart are racing to ship an open standard.
Updated
Why it matters
- Amazon has blocked Meta's Muse AI agent from completing purchases on its retail website
- Cloudflare changed its crawler defaults on September 15, automatically shifting AI-agent blocks onto any page carrying ads
- Delta says no current integration lets third-party AI agents book Delta flights today
- Meta's agent-to-business protocol coalition includes Walmart, Stripe, Sierra, Genesys, Rocket, NiCE, and Decagon
- Walmart and Muse partnership was announced at Meta's Connect developer conference in September
Amazon began blocking Meta's Muse AI agent from completing purchases on its retail website, the latest sign that consumer AI agents are colliding with the defensive systems websites already use against scrapers and spam.
What is actually happening to users?
The blockade extends far past Amazon. Users have filed complaints across social media that AI agents such as Meta's Muse, OpenAI's Dots, and Instinct hit the same walls. The barriers fall into two camps.
Some are intentional — Amazon's fits this bucket. Others are unintended fallout from anti-bot defenses that were never built to tell a personal assistant from a malicious crawler.
End users cannot tell the difference. They see a checkout that fails, and they blame whoever sent them there, usually the AI provider.
Why Walmart's experience is the case study
Walmart offers the cleanest window into the mess. TechCrunch saw multiple social posts claiming Muse could not complete a purchase on walmart.com. NBC reported the same problem during Walmart's tests of the agent.
A Walmart spokesperson said the blocks were unintentional. The retailer partnered with Muse at Meta's Connect developer conference in September. Walmart said it wants to meet customers "where they are," and that now includes AI agent experiences.
The technical failure is plain. Walmart's site presents a human-verification button. When Muse interrupts that flow, the check fails and the agent gets bounced.
The episode exposes a structural gap. CAPTCHAs and bot filters were built to fight automated spam. They have no way to recognize an agent acting on behalf of an authenticated user who gave consent.
Who is drawing the line on agents
A growing roster of major brands have rejected personal AI agents or restricted them behind opaque policies. The pattern spans retail, travel, real estate, and food.
- Amazon: has blocked Meta's Muse from its retail catalog.
- Delta: no partnership lets third-party agents book flights today.
- United: Terms of Use bar "any robot, spider, other automatic device, or manual process" without prior written permission.
- Yelp: requires agents to pay for access through its data licensing program.
- eBay: restricts "unauthorized agents and actions, like automated scraping and model training." Some users report account suspensions over agent use.
- Google: kicked Instinct out while the agent was tidying a Gmail inbox.
- Adidas, Zillow, Pizza Hut: did not respond or declined to comment.
The list also captures various airlines. Flight booking is one of the use cases AI labs have marketed hardest.
What Delta and Yelp said on the record
Delta's response came from Heena Chavda, General Manager of Global Communications:
"While Delta does not currently have a partnership or integration that enables a third-party AI agent to shop for or book Delta flights on a customer's behalf on our digital platforms, we're continuing to evaluate how new technology, including external AI agents, could enhance the way customers engage with Delta."
United took a less direct line. A spokesperson pointed to the no-bots clause in its Terms of Use instead of confirming or denying specific blocks. United did not respond to a follow-up asking whether it was targeting agents like Muse.
Yelp drew a sharper boundary. The platform told TechCrunch it does not permit non-human traffic unless the agent holds a data licensing deal. A user asking an agent to fetch a restaurant quote, add a name to a waitlist, or book a table will hit a wall unless Yelp has a formal partner agreement.
Where Cloudflare fits
Cloudflare sits between most major websites and the agents trying to reach them. The company runs a marketplace that charges AI bots for data access. It recently started testing a browser built specifically for AI agents.
On September 15, Cloudflare changed its crawler defaults. Site owners can now block AI training while permitting other bot categories. Sites that had blocked AI bots for generic security reasons were automatically shifted to block AI agents on every page carrying ads.
That policy change fueled speculation that Cloudflare and similar CDNs now disrupt Muse traffic. Cloudflare told TechCrunch it has no specific data on the latest blocking reports. The company pointed to Cloudflare Radar, a free public dashboard. Radar shows total bot traffic is rising. It does not separate friendly agents from scrapers.
Cloudflare has commercial reason to police this carefully. Its bot marketplace depends on deciding which AI traffic counts as paid access.
Who is building the new protocol
A consortium has formed to draft an open standard for agent-to-business communication. The members: Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE, and Decagon.
Meta's blog post said the standard will focus narrowly on agent-to-agent communication for online commerce. The aim is to distinguish good bots acting for users from bad ones running scrapes and prompt injection.
Meta framed the work this way in its announcement:
"Turning away a personal agent means turning away the customer behind it. We'd rather work with businesses to address the underlying concerns than see them lose that customer."
The same statement said the protocol "starts with clear norms, gives businesses more predictable control, and evolves toward a more efficient way for agents to work together."
What users see in the meantime
Meta keeps a list of "connectors," its term for partners, inside the Muse app. The list continues to grow. Many names from the September announcement have not yet appeared there.
The clearest pattern: Meta's formal partnerships define which websites reliably accept a Muse request. Anything outside that list is a coin flip between working and bouncing off a CDN or a CAPTCHA.
For early adopters, that experience shapes the brand of agentic AI itself. A first run that fails at checkout often ends the experiment.
Where this goes from here
The regulatory vacuum around agentic commerce keeps moving the fight to private terms-of-service clauses and CDN policy switches. The losers are users who cannot tell whether the agent or the retailer is at fault.
Whoever ships the first credible agent-to-business standard will likely set the rules. Meta, Walmart, and Stripe hold seats at the table. Cloudflare holds the network layer.
The likely near-term timeline: a draft spec, a handful of live integrations, and a long tail of brands that still prefer to keep agents out. The open question is whether the protocol becomes the default or one of several competing standards that sites can ignore.
Original: bloomberg.com
More from Rebecca Stone
Show full bio
Correspondent covering consumer brands and retail at AI In Context.
237 articles