Amazon Blocks Meta's Muse Agent Where the Perplexity Ruling Stops

Amazon cut off Meta's Muse agent, which runs in a Meta-hosted cloud browser with stored logins. The Ninth Circuit's Perplexity ruling covered agents in the user's own browser and left this architecture open, so site terms and detection now decide.

By Rajesh Beri·September 21, 2026·12 min read
Share:
A computer monitor in a dim data-centre aisle showing an online store checkout page covered by a blank grey warning dialog box, with a cardboard delivery box sitting on the floor beside the server racks; no text or logos

Illustration generated using AI

If your AI agent logs into other companies' websites from a browser in the cloud, the August ruling that rescued Perplexity's shopping agent was not written for it. Amazon made that concrete on Sunday night when it cut off Meta's Muse, an agent that, by Meta's own description, runs on a Meta-hosted computer with its own browser. The Ninth Circuit protected an agent running in the customer's own browser and expressly left open what happens on different facts. What governs the rest is the site's terms and its bot detection — so where your agent's browser runs, whether it identifies itself, and who holds its login are now your exposure.

Why Amazon Could Block Muse After Losing to Perplexity

Amazon lost one argument in August — that an AI company "accesses" its servers when the agent works through the customer's browser — and kept every other lever it had. On Sunday it pulled the one the court pointed to.

Muse users trying to shop on Amazon.com began seeing a popup that read: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed," AI Weekly reported. Amazon gave three reasons: Meta never told Amazon that Muse would access the site, the agent does not identify itself, and it appears to capture and store customer login credentials. "Third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions," a spokesperson said. Amazon also says it tried to get Meta to voluntarily exclude Amazon from the Muse experience before blocking it. Meta launched Muse on September 8, which puts the block twelve days after launch.

Now the court. In Amazon.com Services v. Perplexity AI, decided August 4, Judge Milan D. Smith Jr. wrote for a panel that vacated the preliminary injunction the Northern District of California had granted Amazon in March. The reasoning turned on architecture. Comet "is a web browser that operates like Google Chrome, running locally on a user's machine," and "Perplexity itself does not directly communicate with Amazon's servers." So "it is the user who 'accesses' Amazon's computers," not Perplexity, under the Computer Fraud and Abuse Act (CFAA) and California's analogue. Amazon asked the full court to rehear the case; on September 10, not one judge requested a vote. The underlying lawsuit continues, and Amazon has said it remains "confident in our case".

The line that matters for Sunday is footnote 5: "This outcome does not impair Amazon's ability to regulate access to Amazon.com via private terms of service for its users." Read the popup again. It does not allege hacking. It invokes the Conditions of Use "to which our customers have agreed" — the contract the court left standing.

The Perplexity ruling covers agents whose traffic reaches the site from the user's own machine; by Meta's account, Muse's traffic does not. Meta says "Muse runs on its own dedicated computer in the cloud," on "Muse Secure VM, a dedicated secure computer with its own browser" (Meta's launch post). The browser that loads Amazon's pages sits in Meta's infrastructure. That is exactly the fact the panel found missing in Comet's case.

The court saw the question coming and declined to answer it: "We do not address whether, on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon's servers." It added: "We do not establish a new legal regime governing agentic AI." Jones Day's reading is that the court "expressly limited its holding to the current record." Cooley flags the same gap: scenarios where an agent exercises "greater control" or communicates server-to-server.

Nobody has sued over Muse, and nothing here predicts how a court would rule if someone did. The practical point is narrower and more useful. The architecture your vendor chose decides which body of law you are standing in. A local-browser agent has an appellate opinion behind it. A cloud-browser agent has an open question — and a site owner who can end the argument with a terms-of-service block before anyone files anything.

Meta Has Argued Amazon's Side of This Before

The precedent that best fits a server-side agent is one Meta won. In Facebook v. Power Ventures (9th Cir. 2016), Power.com aggregated users' social-network accounts with their permission and pushed promotional messages through Facebook. On December 1, 2008, Facebook sent a cease-and-desist letter and blocked Power's IP address; Power switched IP addresses and kept going. The court held that "the consent that Power had received from Facebook users was not sufficient to grant continuing authorization to access Facebook's computers after Facebook's express revocation of permission."

Two rules came out of that opinion, and both matter now. First: "Once permission has been revoked, technological gamesmanship or the enlisting of a third party to aid in access will not excuse liability." Second: "a violation of the terms of use of a website—without more—cannot be the basis for liability under the CFAA." A terms breach alone is a contract problem. A terms breach after an explicit, communicated revocation, followed by evasion, is how Power ended up liable.

The Perplexity panel distinguished Power Ventures on exactly this axis, noting that Power "caused a message to be transmitted" inside Facebook's system and that the earlier opinion "implied that Power accessed Facebook's servers." Whether Amazon's request to Meta plus Sunday's popup amounts to the "express revocation" Power Ventures required is a question no court has decided for an AI agent. It is the question a Muse lawsuit would turn on — and Facebook, now Meta, was the plaintiff who established that rule.

The Strongest Case for Meta

Meta's position is not weak, and Amazon's is not disinterested. Meta says Muse "has no visibility into people's passwords or payment methods," that shared credentials go "into secure storage, so Muse can use them without seeing them," that a separate Sentinel agent runs on the same machine "kept apart from Muse at the system level," and that Muse "checks with the person before sensitive actions like sending an email or making a purchase" (Meta).

The Ninth Circuit was also unpersuaded by Amazon's security framing last time. "Amazon's cyber-risk harm argument is also weak," the panel wrote, noting Perplexity's point that Amazon's own expert could not fully replicate the claimed risks. It added that an injunction "would impair consumer choice and needlessly limit development of a nascent technology."

And Amazon runs agents on other merchants' storefronts itself. Its Buy for Me feature, launched in April 2025, sends an AI agent to purchase from brands' own websites; merchants complained their products were listed without permission, and the opt-out was an email to Amazon. Amazon's answer is that Buy for Me identifies itself and lets brands opt out. Note the standard: opt-out after the fact, not the advance notice Amazon says Meta owed it.

Look closely at the credential dispute, though, because both sides are right about different things. Meta disputes that Muse can see the password. Amazon objects that Meta holds it. Meta's rebuttal concedes the storage. For a site operator, custody is the whole issue: a third party with a vault full of your customers' logins is a third party you never chose to trust.


Your Computer-Use Agents Look Like Muse From the Site's Side

The computer-use agents that enterprise platforms now ship can run the way Muse does: a cloud-hosted browser holding a stored login. A computer-use agent is an AI model that operates a browser or desktop the way a person does — reading the screen, clicking and typing — rather than calling an API. Microsoft's Copilot Studio documentation says "if a person can use an app or website, computer use can too"; its hosted browser, still in preview, "runs in a Microsoft-managed environment"; and when "a sign-in prompt appears, computer use securely uses any credentials you defined" for that site. By default, the same page notes, "computer use can operate on any website or application."

So an agent your operations team built on a hosted browser to pull invoices from a supplier portal, check claim status on a carrier site or file forms on a state benefits portal looks, from the portal's side, like Muse: a cloud browser, a stored password, and a site owner who was never told. Our look at Copilot Studio's computer-use launch covered the cost case; this is the other column of the ledger.

There is one difference, and it cuts against you. In the Perplexity case, the user and the agent's maker were different companies, which is why placing the access on the user cleared Perplexity. When your company builds the agent and owns the account, you are both. Amazon's popup invoked the terms "to which our customers have agreed." For your portal agents, that customer is you, and the account at risk is yours.

The tooling offers both paths, sometimes in the same console. Browserbase, a hosted-browser platform for agents, documents options to "route browser traffic through residential or datacenter proxies" and "solve supported CAPTCHA challenges" — and, on the same page, participation in Cloudflare's Signed Agents program "to let your agent cryptographically prove that an authorized user operates it." Web Bot Auth, the protocol behind that program, is a draft IETF standard in which an agent signs each HTTP request with a published key so a site can verify who operates it. Cloudflare's case for it is that a user-agent header "is easily spoofable". Cloudflare's signed-agents list includes OpenAI's ChatGPT agent and Browserbase. On AWS, Amazon Bedrock AgentCore Browser supports signing in preview, but the feature "is disabled by default and must be explicitly enabled". Meta itself publishes a crawler identity, Meta-ExternalFetcher, whose stated job includes "helping AI navigate websites to complete tasks for users"; Amazon's complaint is that Muse did not identify itself on Amazon.com.

Under Power Ventures, which switch your team flips after a site says stop is the difference between a contract dispute and something worse.

Banks Already Ran This Fight Over Screen Scraping

The last industry to fight over third parties logging in with customers' passwords was banking, and it ended in declared, metered access. Aggregators used to obtain consumers' bank credentials, log in as the user and copy the data, which drew bank complaints and class actions, American Banker recounts. In October 2018, Chase and Plaid agreed to move to a token-based API that let customers authorize Plaid to pull their data without Plaid storing their usernames and passwords. In September 2025, JPMorgan reached a deal to charge Plaid "fractions of a cent per data pull"; by then, Plaid said, 80% of its data aggregation was on or migrating to APIs rather than screen scraping, per the same report.

Read the arc as a forecast. Credential custody was the objection that moved banking from scraping to tokens, and seven years after the Chase–Plaid token deal the site owner was pricing the pipe. Amazon's three conditions are the 2018 step. It has already written them down for sellers' tools: an Agent Policy effective March 4 requires automated agents to identify themselves and stop accessing Amazon when asked. If your automation plan assumes free, anonymous, password-based access to other companies' portals, budget for the version where that access is declared, tokenized and billed. The commerce protocols for declared agent access are already being drafted.


What to Do Before a Portal Blocks Your Agent

Treat every agent that logs into a site you do not own as a third-party access arrangement, not a script.

This Week:

  1. Build the inventory. For each computer-use or browser agent, list the target domain, where the browser runs (employee device, vendor cloud, your own cloud PC), whose credentials it holds and where they are stored, and whether its requests are signed. Start with Copilot Studio stored-credential entries and any AgentCore or Browserbase configurations.
  2. Turn identification on where it exists. If you build on AgentCore Browser, enable Web Bot Auth when you create the browser tool. If your platform supports signed agents, use it for every external target.
  3. Find the evasion settings. Search agent configurations for residential proxies, fingerprint masking and CAPTCHA solving pointed at third-party sites. Any aimed at a site that has already blocked or objected to your agent come off today.

This Month:

  1. Read the terms of your top ten target portals for clauses on bots, automated access and credential sharing. Where they prohibit it, ask the operator for written permission or an API — the Chase–Plaid route, not the Power Ventures route.
  2. Write "blocked means stop" into the runbook. When a site returns a block page, a cease notice or an account warning, the agent halts, the run fails loudly and legal gets the ticket. No retries through new IP addresses. Our agent-authorization guide covers scoping the credentials themselves.
  3. If you run a logged-in site, adopt Amazon's three conditions as your agent-access policy — declare, identify, no third-party credential custody — and put them in your terms. Then enforce them technically: AWS WAF verifies Web Bot Auth signatures for CloudFront customers, and Cloudflare puts signed agents in their own category so enterprise customers can act on them as a group in security rules.

Before Your Next Agent-Platform Renewal:

  1. Put the architecture in the contract. Require the vendor to disclose where the browser runs, ship identification on by default, document credential custody (vault, rotation, deletion on termination) and notify you when a major target site blocks the product.
  2. Allocate the third-party-site risk. Ask who indemnifies you if a site operator sues over the agent's access. If the vendor's answer is "the user accessed it," remember that for your portal agents, the user is you.

The Bottom Line

Banking took seven years to get from the Chase–Plaid token deal to a priced API; the credential-custody argument got it to tokens, and the pricing came while the CFPB was rewriting its open-banking rule. Agentic commerce is at the 2018 step. The Perplexity ruling pushed the fight toward contracts and detection — venues where site owners write the rules — and Amazon just showed how little it needs to use them: a popup and a sentence from its own terms, no judge required.

The Ninth Circuit answered, on its record, who touches the server when the browser is yours. For every agent whose browser is not, the site's terms are the law that is left.

Continue Reading

Share:

Frequently Asked Questions

Why did Amazon block Meta's Muse agent?

Amazon says Meta never told it Muse would access Amazon.com, the agent does not identify itself, and it appears to capture and store customer login credentials. Users saw a popup saying continued access by an unauthorized AI agent violates Amazon's Conditions of Use. Meta says Muse cannot see passwords or payment methods and keeps shared credentials in secure storage.

Does the Ninth Circuit's Amazon v. Perplexity ruling protect cloud-hosted AI agents?

Not directly. The August 4, 2026 opinion held that the user, not Perplexity, accessed Amazon because Comet runs locally in the user's browser and Perplexity itself does not communicate with Amazon's servers. The court declined to address different facts where the AI company gains entry itself, and said Amazon can still regulate access through its terms of service.

What is Web Bot Auth?

Web Bot Auth is a draft IETF protocol in which an AI agent or bot cryptographically signs each HTTP request with a published key, so a website can verify who operates it instead of trusting a spoofable user-agent header. Cloudflare and AWS WAF verify it; Amazon Bedrock AgentCore Browser supports it in preview but ships with it disabled by default.

What should enterprises running computer-use agents do after Amazon blocked Muse?

Inventory every agent that logs into a site you do not own, recording where its browser runs, whose credentials it holds and whether it signs its requests. Turn on agent identification where supported, remove proxy and CAPTCHA-solving settings aimed at sites that have objected, and make 'blocked means stop' a hard rule in the runbook.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →