Your shopping cart is empty!
Amazon blocked Meta's Muse agent — and robots.txt had nothing to say

- "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use" — the message Muse users, Meta's shopping agent, saw on September 20.
- Amazon's robots.txt lists 101 rules for specific bots, but there's no line for Muse: the agent isn't even in Meta's own documentation of five crawlers.
- An Amazon spokesperson gave three reasons for the block: Meta never said Muse would access the store, the agent doesn't identify itself, and it appears to capture and store customer credentials.
"Continued access by an unauthorized AI agent violates Amazon's Conditions of Use." That's the message Muse users saw on September 20 when trying to shop on Amazon through Meta's new agent. Todd Bishop broke the story for GeekWire, and Amazon confirmed to the outlet that the block was deliberate.
Why robots.txt couldn't block an agent that isn't on paper
Amazon's robots.txt lists 101 rules aimed at specific user agents, from classic search crawlers to newer AI bots. The problem is there's simply no name to write a rule against: Muse has no documented user-agent string. Meta's own crawler documentation lists five bots, and Muse isn't one of them. Without a name, Amazon couldn't target it with a specific rule, and robots.txt is only a request nobody can force an agent to follow anyway.
An Amazon spokesperson gave GeekWire three reasons for the block: Meta never told Amazon that Muse would access its store, the agent "doesn't identify itself when it browses," and, Amazon said, it "appears to capture and store customer credentials" — a security concern, not just a courtesy issue.
Meta describes Muse as running on "a real up-to-date Chromium based browser" that will "appear as your activity" to the site. Credentials, the company says, are stored in a virtual machine each user receives, not in centralized Meta infrastructure. Nobody has published independent verification of Amazon's credential concerns yet, so for now it's one company's word against another's.
We've written a guide on setting up robots.txt and sitemap.xml properly, though none of the classic tricks in it were built for agents with no name.
A court ruling already weakened the main tool for blocking these agents
There's a relevant precedent here. In August 2026, the Ninth Circuit denied Amazon a court order against Comet, Perplexity's shopping agent, ruling that the shopper is the one accessing the site, not the software vendor. That decision weakened the Computer Fraud and Abuse Act (CFAA) as a tool against this kind of blocking. Search Engine Journal has more on the mechanics.
In my view, what's most interesting here is that neither side has shown technical proof: Meta says its data isn't centralized, Amazon says it sees a risk to customers, and there's no way to check either claim from outside. Next time an agent shows up with no documented user-agent, sites will be back to guessing blind.


