Meta gave Muse your authority. Amazon says that authority doesn’t travel.

The strangest thing about Meta’s Muse isn’t how much of your private information it can see.

It’s what happens when Muse leaves your accounts.

Meta can tell Muse: this person authorized you to act for them.

Amazon can answer: we never authorized you.

That is the fight that just started.

Meta designed Muse to send emails, make purchases, book travel, fill out forms and perform tasks on a user’s behalf. It runs inside a dedicated virtual machine containing the agent and the user’s data. Meta calls it a personal agent because it is supposed to act with the user’s authority rather than simply answer questions.

Then Muse hit Amazon.

Amazon blocked it.

Amazon says Meta never told it Muse would access Amazon, the agent did not identify itself while browsing, and Muse appeared to capture and store customer credentials. Amazon’s warning to users was blunt: continued access by an unauthorized AI agent violated its terms.

That creates a problem nobody had with ordinary software.

When you open Amazon yourself, Amazon knows who you are.

When a browser extension acts for you, there is still a recognizable software boundary.

When an autonomous agent does it, the website has a stranger sitting at the keyboard with your permissions.

And the stranger may be able to buy something.

That’s a completely different trust relationship.

Muse can be perfectly authorized by you and still be unauthorized by Amazon.

That distinction is going to become one of the nastiest problems in agentic computing.

Amazon has already been fighting this battle with other AI companies. It has restricted Perplexity’s Comet and added restrictions affecting Google’s agents, while Amazon’s own site increasingly decides which automated systems are allowed to crawl or interact with it.

This is also why the old internet rule of “the user clicked it” starts falling apart.

For 30 years, websites were largely built around a simple chain:

person → browser → website

Now the chain becomes:

person → Muse → browser → website

And every step creates another question.

Who actually gave the instruction?

What exactly did the person authorize?

Can the agent make a different decision halfway through?

Who is responsible when the agent buys the wrong product?

Can the website revoke the agent without revoking the customer’s account?

Can the agent prove to the website that the person authorized this particular transaction?

A research review published this month identified exactly this problem: AI-agent authorization still lacks reliable end-to-end ways to prove that an action is traceable to a human, limited to what that human actually delegated, and auditable afterward.

That sounds like boring security paperwork.

It isn’t.

It determines whether agents can actually take over the internet.

Because Amazon doesn’t merely sell products.

It controls the doorway through which those products are bought.

If every website gets to decide that Meta’s agent is an unauthorized third party, Meta cannot simply build a smarter agent and declare victory.

It needs the rest of the internet to recognize the agent’s authority.

And that means the next battle in AI may not be about which model is smartest.

It may be about whose permission counts.

There is already another warning buried in Muse’s first few weeks.

Meta launched a phone-calling capability that lets Muse call businesses on the user’s behalf. Then Reuters reported that Meta was testing human contractors to handle some calls behind the scenes. Some Meta employees raised concerns that sensitive information could reach those contractors.

That is revealing for a different reason.

The machine was supposed to represent the user.

Instead, the system sometimes needed another human to represent the machine.

So now there are three parties in the transaction:

the user, Meta’s agent and the business.

And potentially a fourth:

the human contractor sitting behind the agent.

The privacy problem is therefore bigger than “Meta might see your data.”

Meta says Muse uses a dedicated virtual machine and has separate protections for sensitive information. It also says certain interaction data can be used to train future models unless users opt out.

The deeper problem is that authority is moving around faster than the rules governing it.

We have spent years building permission systems around people and applications.

Now we’re handing applications the ability to behave like people.

Amazon is effectively saying:

Your customer may have authorized this agent. That does not mean we have to treat the agent as your customer.

That’s the sentence to watch.

Because if Meta wins that argument, Muse can become a passport for its users across the internet.

If Amazon and other platforms win it, every agent will need separate permission, identity and authorization agreements with every place it wants to operate.

That would make the “personal agent that can do anything for you” vision much harder to build.

And there is a reason this fight is happening now.

Meta isn’t asking Muse merely to know you.

It’s asking Muse to be you online.

Those are two very different things.

Not financial advice.

Got a news tip or correction? Let us know

If you got something out of this, please chip in to keep this site running, or subscribe to go ad-free.

1 view