Personal AI Agents Meet The Walled Garden

Back in July, I wrote about Senator Mark Warner’s proposed AI AGENT Act, which envisioned consumers delegating authority to personal AI agents that could interact with large online platforms and make purchases on their behalf.

At the time, that future still felt somewhat speculative. Two months later, Meta’s Muse is doing exactly that. And Amazon has blocked it.

Amazon Closes the Gate

Users attempting to shop through Muse began seeing a message saying that access by an unauthorized AI agent violated Amazon’s Conditions of Use. Amazon says Meta never asked permission to operate Muse on Amazon, that Muse does not adequately identify itself as an agent, and that third-party applications must operate transparently and respect a service provider’s decision about whether to participate.

Amazon has been here before. It previously fought Perplexity over whether its Comet agent could shop Amazon on behalf of users. The litigation continues, but the commercial question is already clear. If I authorize an AI agent to act for me, does Amazon get to decide that my agent is not allowed through the door?

The Walled Garden Problem

This is one of the central issues in our research on agentic commerce. Instead of visiting Amazon, Walmart, Target and dozens of individual retailer websites, a consumer may increasingly tell a personal agent what she wants and let it search across all of them.

That changes who controls discovery, the customer relationship, advertising, recommendations and product placement. Large commerce platforms therefore have powerful incentives to decide which agents they will allow into their ecosystems.

Amazon has legitimate security, privacy, fraud and support concerns about unknown software operating inside customer accounts. But if every major platform can simply prohibit outside agents, consumers may discover that their personal agents work only where platform owners permit them. That is the competitive problem the AI AGENT Act attempts to address.

Warner’s Proposed Answer

When I first wrote about Warner’s proposal, it was still a discussion draft. It has since been formally introduced as S. 5051. The bill calls these personal representatives Custodial User Agents, or CUAs. A CUA is software expressly authorized by a user to interact with a large online platform on that user’s behalf in a way that is transparent, documented, limited in scope and revocable. Muse looks very much like the kind of agent the definition contemplates.

Under the legislation, large platforms would have to maintain interfaces through which consumers could delegate authority to these agents. Access would have to be offered on fair, reasonable and nondiscriminatory terms. Platforms could impose reasonable privacy and security requirements and block agents engaged in fraudulent or malicious activity. Amazon could set conditions for outside agents, but it could not rely on a blanket policy that keeps them out.

The current bill also requires a CUA provider to register with the Federal Trade Commission before its agents receive these access rights. For Muse, Meta would presumably register as the provider rather than registering every individual Muse instance. Registration could use standardized terms and self-attestation, with the FTC or a recognized independent certification body later evaluating compliance.

In practice, the bill envisions a system in which Meta registers as a CUA provider, Muse identifies itself to Amazon, and Amazon verifies that the consumer delegated limited and revocable authority to it. Payment authorization through a service such as Stripe Link remains a separate layer. Link can give Muse a consumer-approved payment credential, but it does not establish Muse’s right to act inside an Amazon account.

Registration or Open Standards

When I first examined the draft legislation, I wondered whether trust could be established primarily through open technical standards for agent identity, authentication, delegated authority, auditability and revocation.

The AI AGENT Act – S. 5051 – goes quite far in that direction. It directs NIST to identify open protocols, or develop model technical standards where necessary, covering precisely those functions. But the bill adds another layer. A third-party agent’s right to access a large platform is still conditioned on registration of its provider with the FTC.

The Amazon-Meta Muse dispute makes the rationale for both layers easier to understand. Amazon wants to know that a consumer authorized the agent, who operates it and whether that operator can be held accountable. Open standards can provide technical proof of identity, delegation and revocation. Registration provides an institutional identity behind the agent.

The remaining question is whether we need both. Could verifiable agent identity, consumer delegation and independent certification provide enough trust without requiring every provider to register with a federal agency? Or will registration prove necessary once personal agents routinely enter other companies’ walled gardens?

Only a few months ago, these sounded like architecture questions for a future agentic economy. Amazon and Muse have turned them into current events.



Categories: Articles