On Sunday night, September 20, 2026, Muse users who tried to shop on Amazon were met with a series of pop-ups saying the agent violated the store's terms of use. Amazon had officially blocked Muse, the personal AI agent Meta launched just two weeks earlier, from its retail site. The trigger was simple: Amazon asked Meta to exclude Amazon from Muse's shopping feature, and Meta declined.
To some, this sounds like a quarrel between two American tech giants, far removed from business in Indonesia. It is not. What is being fought over is a question that will reach every online store sooner or later, including here: when the shopper is no longer a person but an AI agent acting on a person's behalf, who actually owns the customer relationship?
This article covers what happened, why Amazon took such a hard line, and what online store owners should start preparing now.
A short timeline: twelve busy days
Meta launched Muse on September 8 as a general-purpose agent that handles multi-step tasks for its users. Muse connects to email, calendars, payment methods, and shopping sites. The reception was enormous: by September 18, Muse was the number one free app on Apple's US App Store.

Two days later, Amazon shut its door. The day after that, a security researcher disclosed a zero-day in the Muse app for Mac: an unprivileged local process could redirect the app's traffic to an attacker's server and steal the token used to control the agent. Meta patched it about 16 hours after disclosure. A fast response, but the incident illustrated exactly the concern Amazon had raised: an agent holding access to accounts, payments, and personal data is a very valuable target.
Why Amazon is taking such a hard line
Muse is not the first agent Amazon has barred. Shopping agents from OpenAI, Google, and Perplexity were blocked before it, and against Perplexity Amazon went as far as a lawsuit. Amazon's stated reasons came down to three points. First, Meta did not tell Amazon that Muse would access its store. Second, the agent does not identify itself when it browses, so it looks like an ordinary visitor. Third, Muse reportedly captures and stores customer credentials, which Amazon says creates privacy and security risks. Meta disputes that last point, saying it has no visibility into users' passwords or payment methods.
Behind the security argument sits a business interest that is just as large. Amazon's advertising revenue topped US$68 billion last year, and much of it depends on shoppers browsing the storefront, seeing recommendations, and clicking sponsored products. An AI agent that goes straight to a product and completes the purchase skips that entire path. Amazon already runs its own shopping agents, Alexa for Shopping and Buy for Me. The difference is that Buy for Me identifies itself when it visits other brands' sites and gives them the option to opt out.
The size of the prize also explains why every side is holding firm.

McKinsey estimates AI agents could orchestrate up to US$1 trillion in US retail revenue by 2030, and US$3 to 5 trillion globally. Morgan Stanley is more conservative, projecting 10 to 20 percent of US online spending will run through agents in the same year. The gap between forecasts is wide because each firm defines "agentic" differently, but the direction is the same: the share of purchases made by machines on behalf of people will grow, and whoever controls those agents will control a large share of buying decisions.
The real lesson: the issue is not the agent, it is how it behaves
Read Amazon's statements closely and one detail stands out. Amazon is not rejecting shopping agents as a concept. Its spokesperson said third-party applications that offer to make purchases on behalf of customers should operate openly. The line Amazon is drawing is not between humans and machines, but between closed agents and open ones.

That distinction matters to online store owners everywhere. An agent that identifies itself can be treated deliberately: given clean data access, rate-limited, or refused outright if it is not wanted. An agent disguised as an ordinary visitor cannot be told apart from a scraper or a fraudster, so the store owner loses control over who is transacting on their premises.
There is a security side too. In the same week, BigCommerce notified a number of merchants that API credentials belonging to a third-party app called Ribon had been compromised between September 13 and 17. Attackers used that access to read shopper names, emails, phone numbers, and shipping addresses, and injected malicious JavaScript into some storefronts. The BigCommerce platform itself was not breached. What was breached was a single integration that held keys with too much reach. Expect to see this pattern more often as online stores connect to more outside parties, AI agents included.
Why this matters for businesses in Indonesia
Most online sales in Indonesia still run through marketplaces and social media. That means the decision about which AI agents may enter those storefronts will be made by platform owners, not by sellers. The Amazon case shows such a decision can be made overnight, with sellers having no say in it.
This is not a reason to panic, but it is a reason to lay the groundwork. Stores with their own channel and well-organized data will have options once AI agents become common here. Stores that depend entirely on someone else's storefront can only wait for someone else's decision.

Own your channel. A storefront of your own, with customer data kept in your own system, gives you leverage that sellers with only a marketplace listing do not have. Marketplaces still matter for reach, but the relationship with loyal customers should not be handed entirely to another platform.
Make product data machine-readable. AI agents do not see beautiful catalog photos. They read data: product name, price, stock, variants, specifications, shipping cost. Structured, consistent, always-accurate data makes your products easier for agents to find and choose, the same way SEO makes them easier for search engines to find. A price that differs between the product page and the cart, or stock that is not kept current, will send an agent straight to another store.
Audit every third-party integration. Every plugin, app, or service holding your store's API keys is a way in. Grant the least access each one needs, rotate keys on a schedule, and revoke access for apps you no longer use. The BigCommerce case shows that what gets breached is often not the core system, but a party given too much access.
Set rules for agents. This is the step most often skipped. Decide early which kinds of agents may transact in your store, how they are recognized, what transaction limits apply, and what must be logged. The rules do not need to be complicated, but they need to exist before agent traffic actually arrives, not be drafted after an incident.
What to watch next
The Amazon and Meta dispute is not over. Amazon's legal fight with Perplexity is still ongoing, and a US appeals court ruled against Amazon's position in August. The final outcome will shape how far platforms can go in refusing agents that act on behalf of their own customers. At the same time, the industry has started discussing standards for agent identification, a kind of ID card a store can check before allowing a transaction.
For businesses in Indonesia, the question is not whether AI agents will arrive, but whether your systems are ready when they do: clean data, secure integrations, and clear rules.
Closing
The Muse case shows that the next wave of online commerce will not be won only by whoever owns the most advanced AI, but also by the store owners whose infrastructure is most ready. Your own channel, machine-readable data, audited integrations, and clear rules of engagement are foundations that stay useful no matter how the giants' dispute ends.
XETUP helps businesses build and strengthen that foundation, from online stores and system integration to securing them. If you want to review how ready your online store is, see our E-Commerce Solutions service. We are open to an initial conversation.
