Just 13 days after Meta's personal AI assistant went viral, Amazon pulled the plug on it.
On September 21, a pop-up window began appearing on the screens of users trying to shop on Amazon with Meta Muse: "Unauthorized AI Agent continued access will violate Amazon's Terms of Service."
It has only been 13 days since Muse was officially launched.
Meta's newly launched personal AI assistant Muse has gone viral recently | Image source: Meta
Meta released Muse on September 8, defining it as "the world's first personal AI Agent built for everyone". Unlike chatbots such as ChatGPT and Claude, Muse does not only answer questions. It can open browsers, log in to your email, fill out forms, book flight tickets, and even place orders for you directly to buy goods.
The effect is immediate. Data from Sensor Tower shows that Muse has accumulated more than 2.5 million downloads in 13 days after its launch, topping the free App Store chart in the United States on September 18, leaving ChatGPT, Gemini and Claude far behind.
Obviously, the traditional internet giants are not willing to indulge the wildly popular personal AI assistant.
01
The Agent That "Does Not Watch Ads"
In the letter rejecting Muse, Amazon's statement was politely worded but logically firm. Meta never notified in advance that Muse would access Amazon's store; the Agent did not identify itself as an AI when browsing; and it appeared to capture and store users' login credentials.
Amazon compared Muse to food delivery platforms and online travel agencies: "These third-party applications should operate openly and transparently when purchasing goods from other merchants on behalf of users, and respect the decision of service providers on whether to participate."
The wording is decent, but the real pain point is hidden in the financial report.
Amazon's advertising revenue last year exceeded 68 billion US dollars. The source of this money is very specific: users enter keywords in the search bar, scroll past sponsored products, are guided by recommendation algorithms, and finally click to make purchases. The premise of the entire chain is that people are browsing.
The AI Agent does not browse. It does not scroll pages, does not look at sponsored products, and will not be "inspired" by recommendation algorithms. It only does one thing: find what the user wants, and then check out.
In transactions initiated by Agent, advertising loses its meaning of existence.
This is not the first time Amazon has taken action against AI shopping Agents. In November 2025, Amazon sued Perplexity on the grounds that the AI Agent of its Comet browser pretended to be an ordinary user to log in to Amazon accounts and shop on behalf of users. In March 2026, a federal judge approved a preliminary injunction, blocking Comet's access to Amazon's password-protected areas.
AI will not "go shopping" | Image source: techspot
But the story took a turn in August.
The U.S. Court of Appeals for the Ninth Circuit overturned the injunction for a very interesting reason: according to the available evidence, it is the user accessing Amazon's system, not Perplexity. The judge's logic is that the Computer Fraud and Abuse Act is essentially an anti-hacking law, and the scenario where a user authorizes an Agent to operate on their behalf is not within its scope of crackdown.
After the legal weapon failed, Amazon turned to an older and more effective means — Terms of Service.
Since July, Amazon has quietly carried out a series of "reinforcement" actions, deleting specific product names from confirmation emails to make it more difficult for AI Agents to parse purchase records; expanding the robots.txt file to block 47 AI crawlers. When Muse actually came to visit, Amazon only needed to show a line of pop-up window to close the door.
On September 10, the court rejected Amazon's request for a retrial in the Perplexity case. But the judgment left an opening: litigation claims based on contracts and terms of service can still proceed.
In other words, the battle Amazon fought in court did not really end, it just changed the way of fighting.
02
Complementary Agent-Native Architecture
On the same day when Amazon pulled the switch, Shopify CEO Tobias Lütke announced the completely opposite news: Shopify will cooperate with Muse to support Agents to complete checkout directly in the stores of Shopify merchants.
In fact, Shopify's actions were even earlier.
On September 8, the day Muse was launched, Shopify added Meta to the AI channel of "Agentic Storefronts". This means that the product data of all eligible Shopify merchants is open to Muse by default, and no additional operations are required from merchants.
The technical base that supports all this is called Universal Commerce Protocol, referred to as UCP. This is an open standard jointly released by Shopify and Google in January 2026, which defines how AI Agents discover products, negotiate transaction terms, and complete payments. More than 20 retailers and payment networks including Etsy, Target, Walmart, Wayfair, as well as Visa, Mastercard, and Stripe endorsed it at the time of release.
Shopify actively supports access to the Muse application | Image source: Naughton&Bird
The design philosophy of UCP is in sharp contrast with Amazon's defensive posture. It regards Agent as a new distribution channel, not an intruder. Merchants declare which capabilities they support within the framework of the protocol, and Agents select the appropriate payment method to complete the transaction. Users do not need to leave the chat interface throughout the whole process. Merchants remain the main body of the transaction, retaining customer relationships, pricing power, and all transaction data.
The "one-click shopping" that Amazon is afraid of is defined as a new shopping experience in Shopify's framework.
What's the difference? Amazon's business model is "ad-driven traffic monetization". Every search, every swipe, and every stay of users is the basis of advertising revenue. Agent skips all of this, while Shopify's business model is "charging commissions by providing infrastructure for merchants". Shopify does not care which channel the user comes from or how they find the product, it only cares whether the transaction takes place and whether it goes through its checkout system.
Therefore, Amazon blocks the door while Shopify opens the door. It's not because one is more enlightened than the other, but because their business models determine their attitudes towards Agents.
03
The "Same Wall" Faced by Personal AI
Almost in the same week when Muse was shut out by Amazon, a similar story was staged in China.
On September 16, the second-generation Doubao Phone (Nubia NaviX Ultra) was officially released for sale, starting at 5999 yuan, with an initial stock of 200,000 units, and the number of reservations on JD.com was nearly 400,000.
If you still remember the bustle last December, the AI assistant carried by the first-generation Doubao Phone could simulate clicks through GUI to operate almost all apps on the phone on behalf of users. 30,000 units of the 3499-yuan engineering machine were sold out on the same day, and the second-hand market once speculated the price to nearly 8000 yuan.
Then in less than 48 hours, super apps such as WeChat, Alipay, Meituan, and Taobao collectively pulled the switch. The risk control mechanism accurately intercepted the AI's simulated click behavior, and some bank apps even directly popped up warning windows. The Doubao team was forced to offline the operation permissions of financial payment scenarios, and the "fully automatic" function became "half-disabled".
The logic of super apps is exactly the same as that of Amazon. If users get used to letting AI complete operations directly, the apps will lose user duration, ad exposure and data sovereignty, and degenerate into undifferentiated background service providers.
Nubia's "Second-Generation Doubao Phone" | Image source: Nubia Official Website
The second-generation Doubao that came back after nine months has learned to be more tactful. Its technical route has changed from "breaking the window to enter the house" to "knocking on the door to visit", shifting from GUI simulated clicks to MCP and A2A protocol-driven operations. The Doubao team also specially released the SAEP Screen Automation Operation Declaration Protocol, giving apps a 30-day public notice period to decide whether to accept AI operations.
But what is the result? Real machine tests show that mainstream applications such as WeChat, Meituan, and Taobao still cannot achieve automation. At present, the applications that can be called smoothly are basically only ByteDance's own products. More notably, Tencent has cooperated with Huawei, Honor, Xiaomi, OPPO, and vivo to launch WeChat's A2A assistant capability, but ByteDance is not on this cooperation list.
What Doubao and Muse face is actually the same structural problem: AI Agents want to become the intermediate layer between users and services, but the platforms that control "user reach" have no reason to give up this position.
The difference between the two sides lies in the form of expression. In the United States, Amazon uses terms of service and court lawsuits, and the logic is "you are not qualified to operate on my platform on behalf of my users". In China, super apps use risk control interception and ecological alignment, and the logic is "you are not my friend, so you cannot knock on my door".
But the underlying contradiction is completely the same: Whoever controls users' attention and purchase decisions controls the distribution right of commercial value.
The emergence of AI Agents is threatening this distribution right.
04
Blocking Is Not the Endgame
If you only look at the present, the situation of AI Agents is indeed not optimistic. But looking at the bigger picture, blocking is not necessarily the endgame.
The UCP alliance led by Shopify and Google has covered more than 20 large retailers and payment networks. Visa, Mastercard and Stripe are all developing their own Agent payment protocols. If more and more merchants realize that Agents can bring incremental transactions instead of seizing existing traffic, opening up will be a more rational choice.
Amazon itself cannot always be a "countercurrent traveler". It has its own AI shopping tools Rufus and Alexa for Shopping, but these tools are carefully designed to be "ad-compatible", continuing to display sponsored content while recommending products. What Amazon has blocked is not AI shopping itself, but AI shopping that is not under its own control.
There is also a key variable on the consumer side.
A survey of 1,500 U.S. consumers by Oppenheimer shows that only 8% of people trust Meta to manage their passwords, and 58% are unwilling to give their passwords to any AI Agent.
Muse's 2.5 million downloads are impressive, but whether it can cross the trust threshold is the key to determining how far this road can go.
To some extent, the current conflict between Muse and Amazon is very similar to the scene when mobile payment first emerged in the early days. Banks and traditional financial institutions once tried their best to prevent third-party payment from entering their own territory. The final result is that the two sides found a way to coexist, although the balance of power has tilted permanently.
The game between AI Agents and super apps may not end with the complete victory of either side. The more likely outcome is: Agents learn to "knock on the door", platforms learn to "open the door", and the rules behind this door will take a long time to negotiate.
But before the rules are settled, every AI that tries to "do things" on behalf of users has to be blocked outside this door first.
This article is from the WeChat official account "GeekPark" (ID: geekpark), written by Wildcard, edited by Jing Yu, and published with authorization from 36Kr.