The invisible wall between agents and checkout
Personal AI agents like Meta's Muse, Instinct, and ChatGPT's Dots can do more than answer questions—they can book flights, add a user to a waitlist, or order groceries. But the sites they need to transact on are increasingly shutting them out. Amazon recently began blocking Muse from its retail catalog, and social-media threads name a long list of other brands: Yelp, eBay, Zillow, Pizza Hut, Adidas, and several airlines. Some blocks are deliberate, some are accidental. For a frustrated user, the two look identical: a purchase never happens, and blame lands on both the retailer and the agent.
Walmart is the clearest example of the accidental kind. Despite announcing a Muse partnership at Meta Connect in September, Walmart's site presents a human-verification button that must be clicked. If that flow is interrupted, the check fails and the agent gets kicked out. Walmart says it isn't blocking agents on purpose. But when an agent silently fails, the customer doesn't know that.
- Yelp requires paid data licensing for any non-human traffic, so unpartnered agents are likely to fail on waitlists and bookings.
- eBay says it restricts unauthorized agents, scraping, and model training—though some users report their accounts were suspended.
- Delta has no third-party AI agent integration and says it's protecting customers from unauthorized automated activity.
- United's terms of use ban robots, spiders, and other automatic devices without prior written permission.
- Zillow, Pizza Hut, and Adidas have all been named in complaints, though they declined or didn't respond.
A standard to separate good bots from bad ones
The friction has pushed an industry coalition to build an open standard. Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE, and Decagon are working on a protocol for agent-to-agent communication in online commerce. The purpose is to help websites recognize an agent acting on a user's behalf versus a malicious scraper. Meta's position is direct: "Turning away a personal agent means turning away the customer behind it." Cloudflare is also a key player. Its September 15 change to crawler defaults lets site owners block AI training while allowing other bots, which may explain why Muse traffic is disrupted on pages with ads. Cloudflare already runs a marketplace where AI bots pay for data access and is testing a new browser built specifically for AI agents.
Why early friction feels worse than it should
Muse's design makes it especially likely to trip anti-bot defenses. The agent runs inside a persistent cloud VM with its own browser, filesystem, and terminal, and it pays through Stripe Link's virtual single-use cards—exactly the profile that traditional bot filters are built to repel. Meta is even extending Muse to smart glasses, which means an agent endpoint on your face will inherit the same access problem. Until the open standard lands and more retailers opt in, agentic AI will remain a patchwork: brilliant where partnerships exist, and a dead end where they don't.