On the night of Sunday, September 20, people using Meta's new Muse agent to buy something on Amazon started hitting a wall. TechCrunch reported the message they saw: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." Muse had launched on September 8 and gone straight to the top of Apple's free app chart. It lasted 12 days on Amazon.
Amazon's explanation, given to Payments Dive, is worth reading slowly: third-party applications that buy on a customer's behalf "should operate openly and respect service provider decisions about whether or not to participate." Amazon says it asked Meta to exclude Amazon voluntarily first and Meta had not sought authorization. Meta did not respond to requests for comment.
Everyone read this as Amazon versus Meta. I read it as the one door policy in big retail that got written down. So I went and checked the others.
Amazon's block is not the exception. It is the published version of what most large retailers already do at the network edge, where nothing is written and an agent cannot find out the rules.
Two doors, opened the same day
Muse launched on a Monday, and by that evening the two biggest names in online retail had answered it in opposite ways. Shopify added Meta to its Agentic Storefronts program the same day, September 8. Merchant catalogs are shared with Muse by default; a seller who wants out has to opt out. Muse pays through Link by Stripe, which brings its own purchase protections along.
Amazon went the other way, and it had been here before. It sued Perplexity late last year over the Comet agent, and a US appeals court overturned an injunction against Perplexity's shopping tools in August. The Muse block is the same argument with a bigger opponent. Amazon also told PaymentsJournal it believes Muse "appears to capture and store customer credentials," a security framing that sits alongside the commercial one.
Don Apgar of Javelin Strategy & Research gave the commercial one its plainest form: "The last thing they want is to be bot-shopped and reduced to a low-cost fulfillment house." Ben Thompson's Stratechery take, visible in his summary line, is that Amazon "predictably" blocked Muse but that there is room for a deal, because Amazon's physical-world investments are an AI moat. I think he is right about the deal and that it will be about who holds the customer, which is the same fight the shortlist piece described from the discovery end.
Here is the part that interests me more than the fight. Amazon's position was already public before Muse existed.
Amazon had written it down
On September 20, the day of the block, I ran a read-only scan of the largest US retailers. Six plain requests per site: the robots.txt file, a few well-known files that agents look for, and the homepage, all sent under a user agent that says who is asking and links to my research page. No logins, no carts, nothing a browser would not do on the first visit. Sample: the National Retail Federation's Top 100 list, 92 of them with a single consumer storefront to scan.
Amazon's robots.txt names 12 AI crawlers and agents and disallows every one of them, including Meta's own crawler by name. From a data-center address, its homepage answers an unknown, self-identified agent with a bot challenge rather than a page. Amazon did not change its mind this week. It enforced a policy anyone could have read.
That is what "operate openly" looks like from the merchant side. You publish the rule, then you enforce it.
Most retailers never wrote a rule
Now the rest of the list. 29 of the 92 would not show my scanner their robots.txt at all: 23 refused outright and six never answered. That file exists for one reason, to tell automated visitors what they may do. A third of the biggest retailers in the country keep it behind the bouncer.
Of the 63 that did show it, 16 name any AI crawler or agent. Five block a training crawler outright. Two block a user-triggered agent, the kind that acts for a person in real time, and Amazon is one of the two. Published trackers put GPTBot blocking near 25 percent across the top 1,000 websites, a sample dominated by publishers. Retail is different. Retail mostly has not said anything.
The homepage tells the same story from the front. Only 50 of the 92 gave a non-browser agent a readable page. 28 refused or challenged it. Seven returned a shell with nothing in it, a script challenge or a storefront that only fills in once JavaScript runs. Five never answered. I ran the scan from two independent US data-center addresses and they agreed on 88 of 92 sites; a UK home connection saw more refusals, which is geography and not agents.
Sixteen retailers out of 63 have a written AI policy. Forty-two out of 92 will not show an agent the homepage. The gap between those two numbers is the door policy nobody published.
A detail from the week makes the point better than the numbers. On September 22, JD Sports announced Algolia as the "governing intelligence layer" for its agentic commerce strategy. jdsports.com refused my scanner from all three vantage points and would not show its robots.txt. An agent strategy announced through the press while the front door stays locked to agents is not a contradiction. It is the industry's current position, stated honestly.
Why the door is locked
The merchant's problem is that it cannot tell a customer's agent from a scraper. Both arrive from a data center, both fetch pages a human would not, both ignore the ad units. The bot-management vendor at the edge scores the request and refuses it, and the refusal is not a policy. It is a default. That is the bot problem I wrote about two weeks ago, seen from the front door.
The agent's problem is the mirror image. An agent that wants to behave well has nowhere to read the rules. The Ninth Circuit decided this month that the shopping agent is legally the user. The merchant still cannot see the user; it sees a request from a cloud address with no name attached. In the MM Trust Layer Model this is the authorization layer sitting empty: discovery works, settlement works, and the merchant has no way to know whether the thing at the door was sent by a customer.
Amazon's phrase "operate openly" is a reasonable ask of Meta. The scan shows how little an open agent would find to read at most of Amazon's competitors.
The exceptions
Some retailers have decided the door policy should be readable. Three of the 92 publish a live Universal Commerce Protocol profile at a standard address, declaring checkout, fulfillment and order capabilities that an agent can discover without asking. Sixteen publish an llms.txt, a plain-text guide written for AI systems. A handful write explicit allow rules for named AI agents in robots.txt, and one grocer opens its inventory and search endpoints to AI search crawlers by name.
Three protocol profiles out of 92 is not adoption. It is a signal that the alternative to the bouncer exists and a few large merchants are trying it. Whether that number moves is the thing to watch, and verifiable agent identity is what would move it: a way for the merchant to check who sent the agent, which is the layer Major Labs tracks across the standards bodies now working on it. Until it exists, Shopify's default-open and Amazon's default-closed are both guesses about the same unknown visitor.
I will run the scan weekly and report what changes. One run is a level. The series is the story.
Sources
- TechCrunch: Meta's AI agent has been blocked from using Amazon.com
- Payments Dive: Amazon blocks Meta's AI shopper
- PaymentsJournal: Amazon blocks Meta's AI shopping agent
- Practical Ecommerce: Shopify opens to Meta Muse; Amazon balks
- Stratechery: Amazon blocks Muse, Amazon's moat, aggregator v aggregator
- Digital Commerce 360: JD Sports deploys Algolia for agentic commerce strategy
- NRF: Top 100 Retailers 2026
- Presenc AI: State of robots.txt for AI 2026
- Major Labs: Agent Identity Tracker
If a merchant cannot tell a customer's agent from a scraper, is blocking both a policy or an admission?
Charlie Major is a Product Development Manager at Mastercard. The views and opinions expressed in Major Matters are his own and do not represent those of Mastercard.
