Digital Marketing & Advertising

Meta’s Muse Is Buying Things for People, and Amazon Just Shut the Door

Meta's Muse Is Buying Things for People, and Amazon Just Shut the Door
Email :2

The viral AI app is turning an abstract idea called agentic commerce into a very real platform fight

Meta’s new Muse app is doing more than answering questions. It can browse websites, fill forms, send messages, book travel and make purchases on a user’s behalf.

That has helped make it one of the hottest AI launches of September.

Reuters reported that Muse passed 2.5 million downloads within roughly two weeks of its September 8 U.S. launch, and the app climbed to the top of Apple’s U.S. free-app ranking.

Then something more interesting happened.

Amazon blocked Muse from shopping on Amazon.com.

Shopify went in the opposite direction and added Meta as an AI channel in its Agentic Storefronts system.

If that sounds like a niche tech fight, it probably will not stay one for long.

The bigger question is what happens when shoppers stop clicking around websites themselves and start sending AI agents to do the work.

What exactly is Muse doing?

Muse is what the industry calls an AI agent.

That means it is supposed to do more than generate an answer.

A normal chatbot might tell you which headphones look good for travel.

An agent can potentially check the products, compare prices, see what is in stock and complete more of the purchase process.

Meta says Muse can also perform tasks across email, calendars and websites and continue some work after the user closes the app.

That makes it convenient.

It also makes it much more powerful than a chatbot that simply talks back.

Why did Amazon block it?

Fortune reported that Amazon said Meta did not have authorization for Muse to access Amazon’s shopping environment in the way it was doing.

The Verge and TechCrunch also reported the block.

This is where the story gets bigger than one app.

If you tell an AI agent to buy something for you, the agent has your permission.

But does it also need the retailer’s permission?

Amazon’s answer, at least in this case, is yes.

The company has already been adding rules for automated agents in other parts of its ecosystem, including requirements around identifying themselves and following access restrictions.

That makes sense from a platform-control perspective.

Amazon does not want unknown software deciding how to interact with its systems just because a customer asked it to shop.

Shopify is basically saying, come on in

Shopify is building a very different model.

Its Agentic Storefronts system is designed to make products available through approved AI channels.

Meta is now one of those channels.

Shopify says merchants can share product information such as titles, descriptions, images, prices and availability with participating AI systems.

Merchants can also manage whether they participate in a channel. In some cases, they can turn off direct checkout and send the shopper back to their own online store.

That is important because it gives businesses choices.

They can use AI for discovery without necessarily handing over the entire customer journey.

Your next customer may never see your homepage

This may be the strangest part of agentic commerce.

A customer can buy from a business without personally browsing the business’s website.

They might tell an agent: find me a waterproof backpack under $150 that can arrive by Friday.

The agent may check multiple retailers, compare specifications and select one.

If that becomes common, the website still matters, but not only as a visual experience.

The underlying information matters too.

Is the price current?

Is the item actually in stock?

Are the dimensions clear?

Can the agent understand the return policy?

Is shipping information accurate?

For businesses, boring data cleanup may suddenly become a marketing advantage.

If the agent cannot understand your product, it cannot recommend it confidently.

This could change what online traffic means

Businesses also need to think about analytics.

For years, a website visit usually meant that a person opened a page.

AI agents can change that.

One customer request may trigger several automated visits while the agent checks products, prices and inventory.

That could make traffic numbers harder to read.

A website might get more visits without more people actually seeing the brand.

Businesses may eventually need to track which AI agent generated a sale, whether checkout happened on the merchant’s website and whether the company still received the customer’s information.

That sounds technical, but it affects a very basic question: is the AI channel bringing valuable customers or just more machine activity?

Muse is also getting attention for security and privacy

Because Muse can take actions, people are watching its security closely.

Meta says the agent runs inside a dedicated cloud virtual machine and keeps credentials separated from the main AI system. The company also says a Sentinel component helps control access and that users are asked to approve sensitive actions such as purchases.

Meta’s own documentation still says Muse can make mistakes and that prompt injection remains an open industry problem.

On September 22, The Verge reported that Meta patched a vulnerability in the Muse Mac app after researcher Patrick Wardle demonstrated a way to redirect part of the agent’s processing.

Meta said the attack required malicious software already running on the user’s computer, which makes it a more limited scenario than a simple remote takeover.

Still, the story is a reminder that action-taking AI carries different risks from ordinary chatbots.

A bad chatbot answer is annoying.

A bad agent action can become a purchase, booking or message.

There may even be humans behind some agent tasks

Reuters reported on September 22 that Meta is internally testing a human-concierge feature for some Muse phone calls.

Under the test, human contractors may step in when the agent cannot complete a call automatically.

Meta said this is an internal test and not a general public feature.

Even so, it raises an interesting question for businesses.

If you receive a call from an AI agent, are you talking to software, a human contractor or a system that can switch between the two?

That could matter for account verification, customer-service rules and privacy.

What is the privacy story?

Meta says Muse conversations and data inside its virtual machine are not shared directly with its advertising systems.

But that does not mean Muse activity is invisible outside the agent.

Meta says websites visited by Muse may still treat the activity as belonging to the user. That can affect what those websites do with the browsing behavior.

Meta also says sanitized interaction trajectories may be used to improve models unless the user opts out.

So the simple version is not that Muse is private or not private.

The details depend on what is connected, what the agent is allowed to do and what happens to the activity afterward.

What should businesses actually do?

Most businesses do not need a giant AI strategy meeting tomorrow.

They do need to start answering a few practical questions.

Can an AI agent accurately understand our products or services?

Which automated systems are allowed to access our site or booking tools?

Can an agent place an order or reservation?

Which actions should require a human approval step?

What customer information would be shared through an AI channel?

Can we tell machine traffic from human traffic?

After an AI-driven purchase, do we still have a direct relationship with the customer?

Those questions are becoming part of normal digital business.

What about Canada?

Meta currently describes Muse as rolling out in the United States, so Canadian businesses should not assume the same consumer adoption is already happening domestically.

However, the larger agentic-commerce trend is broader.

Shopify’s systems already include merchant contexts involving Canada, and other technology companies are developing AI agents that can browse, book and buy.

That means the issue is coming even if Muse itself is not the app Canadian consumers eventually use most.

Why this story matters beyond Meta and Amazon

Muse is getting attention because it is new, popular and attached to Meta.

Amazon’s block makes the story dramatic.

But the long-term trend is bigger than both companies.

AI is moving from answering questions to taking actions.

Once that happens, every retailer, service company and online platform has to decide how much access it wants to give these systems.

Some will block them.

Some will build special channels for them.

Some will probably do both, depending on the task.

The next phase of online shopping may not be about which website you visit.

It may be about which AI agent you trust to visit for you.

Sources: Meta, Reuters, Fortune, Shopify, The Verge and Amazon policy documentation. Publication date: September 23, 2026.

Comments are closed

Related Posts