The question
The timing on this one was pointed. Amazon just blocked Meta's "Muse" AI shopping agent from its own store, only twelve days after launch — accusing it of browsing without identifying itself, not disclosing that Meta never got permission to send it in, and appearing to capture and store customer login credentials. Meta disputes the credential claim.
What we told them
Yes, this is worth paying attention to now, before it becomes routine. AI shopping agents are a new class of traffic that looks almost identical to a normal browser session — same request patterns, no obvious bot signature — except there's no human actually making the click-by-click decisions, and often no clear way for your site to tell the difference.
The specific risk Amazon called out is the one that matters most for a smaller business: an agent that stores a customer's login and payment details in its own "secure" wallet is storing credentials somewhere outside your control and outside your visibility. If that wallet is ever compromised, or if the agent misfires and completes an order the customer didn't actually intend, there's no clean audit trail connecting the action back to a real human decision — which makes disputes, chargebacks, and fraud investigations much harder to resolve.
This isn't hypothetical or far off. Amazon has spent the past year walling off outside shopping agents one at a time — suing Perplexity over its Comet browser, blocking Google's and OpenAI's agents, and now Meta's. That's a sign the major platforms already consider this a live problem, not a future one.
Three things worth doing now: check your order and session logs for patterns that don't look human — unusually fast form completion, checkout behavior inconsistent with the browsing history that led to it, or orders with no prior product-page views; decide deliberately whether you want to allow AI-agent purchases at all, and if so, what disclosure or identification you'll require, rather than discovering the policy gap after a dispute; and if your storefront platform (Shopify, WooCommerce, or similar) offers any agent- or bot-traffic controls, review what's available and turn on what makes sense for your risk tolerance.
Agentic shopping traffic looks exactly like a human browsing your store, right up until something goes wrong and you have no way to tell who — or what — was actually behind the click.