Back to Blog
Insights

Amazon Blocked Muse. Shopify Let It Check Out. Neither Answered the Expensive Question.

Who may send an agent to checkout is settled. What the merchant can prove afterward is not.

Know Your Agent (KYA)September 28, 20264 min read

On the night of Sunday, September 20, people who asked Meta’s Muse to buy something on Amazon got a popup instead of an order: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” The next day, Shopify CEO Tobi Lütke announced that Muse could check out with Shop Pay across Shopify stores.

One agent, two platforms, opposite answers inside a day. The popular reading is that Amazon is protecting an ad moat and Shopify is chasing volume. That reading is mostly right, and it skips the part that costs merchants money.

Amazon’s reasons are real. So is its motive.

Amazon’s stated case is specific. Meta didn’t tell Amazon that Muse would shop there, the agent doesn’t identify itself when it browses, and it appears to capture and store customer credentials. “Third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate,” an Amazon spokesperson said. It’s the same line Amazon took against Perplexity’s Comet browser, which we covered in March.

Meta says Muse has no visibility into passwords or payment methods, and that shared credentials go into secure storage the agent uses without reading. Its own security write-up also concedes that the Muse Secure VM “does not prevent Meta from accessing data when necessary to support, secure or operate the service.” However good the vault is, the store sees an agent signed in as the customer and can’t tell the two apart. That’s the problem Amazon named, and it would be a problem with no ad business attached.

The motive is real too. Amazon’s advertising revenue reached $68.6 billion in 2025, up 22%. Much of it comes from sponsored listings that shoppers see while they browse, and an agent that goes straight to checkout doesn’t browse. (Prime Video ads are in that figure too, so not every dollar depends on someone scrolling a results page.) And Amazon’s own Buy for Me agent places orders on other brands’ sites. Amazon has said brands can opt out; some brands say they never agreed to be included.

/ Takeaway

Amazon’s principle is right and its application is self-serving. Both are true. Don’t let the ad number talk you out of the credential problem.

Shopify opened a different door

Shopify didn’t say yes to the thing Amazon said no to. Its path doesn’t depend on the agent holding a shopper’s store login. Muse finds products through Shopify Catalog, the purchase runs through a Shopify-powered direct checkout with Shop Pay, and the order is attributed to Meta. The agent arrives through a declared channel, which is roughly what Amazon asked Meta to do.

The cost sits in the defaults. For eligible stores selling to customers in the US, Canada, or Mexico, Meta direct checkout is on by default. A merchant who wants out goes to Sales channels → Agentic → Meta in the Shopify admin and switches direct checkout off. The merchant stays the merchant of record and keeps fulfillment, returns, and customer service.

Shopify charges no channel fee, and it doesn’t need one. Shop Pay orders run on Shopify Payments, so Shopify collects its processing fee on every Muse order. Shopify President Harley Finkelstein told investors in August that agentic transactions “carry the exact economics as an online store transaction,” as the Motley Fool noted.

/ Takeaway

Shopify gets paid on every checkout. The merchant of record handles everything that happens after it.

The question both answers skip

Blocking and welcoming settle one question: may this agent reach checkout? They don’t settle the one that decides who absorbs the loss: what did the customer actually authorize?

Meta says Muse asks the user to approve “the exact details of the purchase every time.” That’s the right design, and it makes the gap easier to see. Say a Muse user asks for running shoes under $150, the agent buys a $140 pair, and the customer later says, “I didn’t ask for that.” Maybe the agent overstepped, which is what we’ve called authorized agentic fraud. Maybe the customer approved it and changed their mind. The record that tells the two apart is the approval, and it sits with Meta.

The merchant has an order that Shopify attributes to Meta and shows in the admin like any other channel’s order. Shopify’s help page for the channel doesn’t say that the instruction, the budget, or the approval reaches the merchant. A valid credential doesn’t close that gap either, because authorization needs an outcome record.

Three checks if you’re in by default

  1. Separate the orders. Filter Meta-attributed orders in your admin and track their refund and dispute rates apart from everything else. You can’t price a channel you can’t see.
  2. Decide your evidence now. When a Muse customer disputes an order, what will you submit? If the answer is the order confirmation, decide whether that’s enough before the first dispute arrives.
  3. Make staying in a decision. Default-on was Shopify’s choice. Staying in should be yours.

Amazon and Shopify gave opposite answers to “should this agent be here?” Both answers were about access. The question that decides who pays when an agent order goes wrong is about evidence, and neither company has answered it yet.

KYA records agent verification decisions and transaction outcomes as source-attributed evidence. On Shopify, our checkout verification is advisory today: it records and recommends, and it doesn’t block an order. The product documentation covers what’s implemented.

Request a pilot