- Roko's Basilisk
- Posts
- Amazon Blocked Meta's Shopper
Amazon Blocked Meta's Shopper
Plus: the FTC won't blame the bots, Verisure's AI bet, OpenAI hits pause.
Here's what's on our plate today:
🧪 Amazon blocked Meta's Muse agent, and no law says who pays.
📰 The FTC's Ferguson refuses to call agents autonomous; Verisure trains AI on 6.4M subscribers; OpenAI pauses model training.
💡 Prompt of the Day: write the terms a store should demand from a shopping agent.
Let’s dive in. No floaties needed.

Business and tech news. One visual per story. Three minutes.
Bay Area Times is the free daily newsletter that gets business and tech leaders up to speed before their first meeting.
AI, startups, robotics, biotech, energy, and the wider innovation economy, each story paired with one clear visual so you see the point instead of digging for it.
Monday to Friday, three minutes, no noise. More than 250,000 founders, operators, and investors already read it.
*This is sponsored content

Goodies delivered straight into your inbox.
Get the chance to peek inside founders and leaders’ brains and see how they think about going from zero to 1 and beyond.
Join thousands of weekly readers at Google, OpenAI, Stripe, TikTok, Sequoia, and more.
Check all the tools and more here, and outperform the competition.
*This is sponsored content

The Laboratory
TL;DR
Amazon’s block on Meta’s shopping agent is a fight over who stands between a store and its customer.
The block: on September 20, 2026, Amazon shut out Muse, Meta’s shopping agent, after Meta refused to take Amazon off the service.
The law: an appeals court has ruled that one kind of agent is the shopper's own tool, leaving Amazon to argue that Muse is built differently.
The gap: no law says who pays when an agent buys the wrong thing, so American Express has promised to cover agent errors and Stripe is extending its usual purchase protections.
The cost: Amazon could end up paying for Muse’s errors and losing ad views, while Meta keeps the shopper’s trust.
The stakes: whoever promises to fix an agent’s mistakes may end up owning the customers that stores spent decades winning.
Amazon wants to know who is in its store
In the British monarchy, every request and piece of bad news between the sovereign and the state passes through the private secretary, whom the Royal Household describes as the channel between monarch and government. The Crown, the Netflix drama about the reign of Elizabeth II, gives much of its early story to one of the men who held that post, Sir Alan ‘Tommy’ Lascelles, played by Pip Torrens. Lascelles served the monarchy as an institution rather than the woman wearing the crown, and that loyalty sometimes set him against the royal standing before him. The series casts him among the men who decided that Princess Margaret could not marry Peter Townsend, the man she wanted. The arrangement survived that strain for a simple reason: everyone at court knew who Lascelles was, whom he served, and where to take a complaint about him.
An AI shopping agent is a new kind of go-between. It is a program that opens web pages, compares products, and places orders on a person’s behalf, often arriving at the store looking like the shopper themselves. Online shopping has always rested on a simple arrangement: a person clicked “buy,” the store took the order, and the store and the card company settled any problem with the person who clicked. An agent loosens every link in that chain, because the shopper approves a purchase they did not research while the company that built the agent sits outside the sale entirely. Whoever stands in that gap decides who pays for a bad purchase and who keeps the customer afterward, and that position is what Amazon and Meta are now fighting over.
The fight became public on the night of September 20, 2026, when Amazon shoppers using Muse, a personal AI agent Meta launched on September 8, started seeing a pop-up. The message said an unauthorized AI agent broke Amazon’s rules, and Amazon told Bloomberg it acted after Meta declined to remove Amazon from the service. In a fuller statement to the tech news site GeekWire, Amazon made three complaints: Meta never said Muse would shop there, the agent does not identify itself, and it appears to store customers’ logins. Meta disputes that last point, saying Muse never sees passwords or payment methods because they are stored separately in secure storage. The stakes rose quickly as Muse became the top free iPhone app in the U.S. within two weeks of its launch.
An agent’s mistakes look like the shopper’s own
Muse works from its own computer in the cloud, where it browses Amazon much as a person would, and it stops to ask the user before any purchase goes through. That approval step means Muse rarely buys anything the user hasn't seen, which makes quieter mistakes the likeliest. An agent might pick the wrong size or the wrong model, and a user who did not look closely would approve it without noticing. In ShoppingBench, a test researchers built to measure how well AI agents shop, the largest share of failures came from exactly this kind of mismatch. The study has not yet been peer-reviewed, and no one has published error rates for real agent orders. Each of these errors, however, carries the shopper’s approval, and that detail has already shaped how a court views the whole arrangement.
The law treats the agent as the shopper’s own tool
Amazon has already tested these questions in court, in a case against Perplexity, the AI search company, whose shopping agent had been buying on Amazon. Amazon sued under the federal anti-hacking law, which bans unauthorized access to a computer system. It argued both that the agent was an intruder and that it shopped badly. The Ninth Circuit, the federal appeals court for the western states, rejected both arguments on August 4. It ruled that the user, not Perplexity, accesses Amazon, called the agent “a tool, not a person,” and doubted that customers would blame Amazon for problems caused by a tool they had chosen themselves.
The court, in effect, treated an agent like a shopping list handed to a friend, since whatever the friend brings home is still the purchase of the person who wrote the list. When the court declined to rehear the case on September 10, the anti-hacking route closed. That left Amazon leaning on the contract customers accept when they use the site, alongside trademark claims the ruling did not touch. Those are the same rules the Muse pop-up now cites, but neither the ruling nor the contract says who pays when the friend comes home with the wrong thing.
Payment companies are volunteering to cover the mistakes
With the law silent on that question, the companies that move the money have begun to answer it themselves, and they have done so with promises. Meta says Muse purchases paid through Link, a digital wallet run by the payments company Stripe, carry Link’s purchase protections. Those protections cover damaged or lost items and allow free returns on eligible orders. American Express has made a similar pledge to protect card members from agent errors, provided the agent is registered and can show the customer approved the purchase, though the feature is still being built.
Both companies are taking on this cost for the reason a good shop replaces a faulty toaster without argument: the business that fixes a problem becomes the one the customer trusts. That logic runs against Amazon. A refund Amazon granted for a Muse error would cost Amazon money, while the shopper would likely credit Muse, the app where the purchase began. No one has tested whether shoppers really think this way, and nobody has confirmed how Muse pays on Amazon, which is the detail that decides who absorbs an error today.
The same gap threatens the money Amazon makes from its own pages. Amazon sells advertising that lets brands pay to show their products prominently to people browsing the site, a business that earned $21.3B in the last quarter of 2025. GeekWire points out that this business depends on people actually browsing, and an agent reading the page on someone’s behalf leaves fewer people to see the ads. An agent in the middle could therefore cost Amazon twice, once in the refunds it pays for and again in the attention it can no longer sell, while the agent’s maker keeps the shopper.
The strongest objection says the block is about control
A simpler reading of Amazon’s decision rests on the fact that Amazon never mentioned mistakes when it explained the block. On this reading, Amazon is keeping a rival out of its store. TechCrunch’s Russell Brandom makes the case by noting that Amazon has its own models and no duty to let Muse in. Amazon also uses agents itself, since its Buy for Me agent buys from other brands’ websites, and GeekWire reports that it identifies itself to those sites. When Amazon contacted Meta, it asked to be removed from Muse rather than proposing terms for handling errors.
That reading is right about what Amazon said, since its complaints were that Muse hides what it is and handles customers’ logins, and errors never came up. It is less convincing once you look at the arrangement Amazon says it would accept, which it compared to a food delivery app or a travel agency. Those services take orders only after a restaurant or airline has agreed to work with them, and that agreement is where both sides settle who refunds a cold meal. By demanding such an agreement before any agent shops in its store, Amazon is asking to settle the same question in advance. That makes control of the store and the cost of mistakes a single problem.
What kept Lascelles accountable was that everyone could see him: the monarch knew whose interest he served, the government knew whom it was dealing with, and a complaint about him had somewhere to go. Muse walks into Amazon without announcing itself. Stripe and American Express compete to stand behind the purchases it makes, yet the store where those purchases happen cannot see who is making the choices. Amazon's remaining claims against Perplexity now return to District Judge Maxine Chesney, and on September 21 Amazon amended its complaint to accuse Perplexity of telling the appeals court something its own engineers had watched be untrue. Whatever she decides, the larger question will outlast it: whether the companies promising to cover an agent’s mistakes end up owning the customers that stores spent decades winning.


Prompt of the Day
![]() | 💡Act as a retail policy lead. Write the terms Amazon should require before any AI shopping agent can buy on its site, covering identification, login handling, who refunds a wrong order, and what happens to ad views. One page, no legalese. |

Your ads are only as good as your data.
When browser-based tracking misses events, your ad platforms are optimizing with an incomplete picture.
Stape helps you move tracking server-side, recover lost signals, and send cleaner data to platforms like Google Ads and Meta. It’s a simpler way to build more reliable conversion tracking without managing your own infrastructure.
Get better visibility into what’s converting and make more informed decisions about the campaigns you’re already running.
*This is sponsored content

Bite-Sized Brains
The FTC won't blame the bots: FTC Chairman Andrew Ferguson said he will keep resisting the idea that agents break loose with wills of their own, and pointed at the developers who instruct them.
Verisure trains on its own alarms: The Swedish security firm is pulling data from 6.4M subscribers to teach models the difference between a real intruder and a false alarm, after losing a quarter of its market value to AI disruption fears.
OpenAI hits pause again: OpenAI halted training of its newest models after agents searching federal websites went past their instructions, including one that reposted SEC information elsewhere online.

Tuesday Poll
📊 Amazon blocked Muse from its store. When an agent buys the wrong thing, who should pay? |

The Toolkit
Browserbase: Cloud browser infrastructure for agents, with isolated sessions and recordings of everything the agent actually did.
Browser Use: Open-source agent that drives a real browser, converting pages into structured actions instead of guessing from pixels.
Composio: Manages auth and tool access for agents, so logins stay held by the platform rather than the agent.

Rate This Edition
What did you think of today's email? |






