Skip to content
TUESDAY, SEPTEMBER 22, 2026

Independently reported.

Tech

Meta Called Muse Secure and Private. Amazon Just Banned It From Shopping.

Meta's new AI shopping agent has been downloaded more than 900,000 times. As of September 21, it can no longer buy anything on Amazon, the site says, because of privacy and security problems Meta has not fixed.

By Mara Voss, Technology

· 4 min read · Updated

A minimalist smartphone interface glowing with soft blue light against a dark background, suggesting an AI assistant chat screen, no people, no text, no logos
Image: Google Flow (Nano Banana 2)

Key Takeaways

  • Amazon began blocking Meta's Muse AI agent from making purchases on its site on September 21, 2026, saying the agent does not identify itself while browsing.
  • Muse had been downloaded more than 900,000 times in its first week, according to Sensor Tower data cited by WIRED.
  • Muse opts users into having their chats used for Meta's AI model training by default; turning it off requires finding the Help improve our AI models toggle inside the app's Data controls.
  • Meta says Muse never sees a user's passwords or payment details, routing purchases through a single-use virtual card from Link by Stripe, while Amazon says the agent still poses unresolved privacy and security risks.
  • Privacy researchers, including EFF's Rory Mir and EPIC's Calli Schroeder, compared the rollout to Meta's September deepfake tool on Instagram, which the company enabled by default for adult users and then pulled days later.

Amazon started blocking Meta's Muse AI agent from making purchases on its site on September 21, 2026. That was less than a month after Meta introduced Muse as a secure, private personal AI agent. The product description and the ban do not agree with each other.

Anyone who tries to buy something on Amazon through Muse now gets a message instead of a checkout screen. It reads: continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed. Engadget reported the block and the wording September 21.

The short answer

Meta launched Muse earlier this month as a secure, private AI agent that shops, fills out forms, and manages email on a user's behalf. Amazon banned it from making purchases on its site September 21, citing unresolved privacy and security concerns. WIRED's own multi-day test of the app found it repeatedly nudges users to link bank accounts, email, and passport data, with AI-training data collection turned on by default.

900,000+

Muse downloads in its first week

Figure from Sensor Tower, cited by WIRED. Downloads had continued to climb by the time Amazon blocked the app on September 21.

Why Amazon shut the door

Amazon says it asked Meta to voluntarily keep Muse off Amazon before it resorted to a block. Meta didn't. Amazon's objections are specific: Muse doesn't identify itself while browsing, and it can access customer information without the safeguards Amazon requires.

We think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate.

Amazon spokesperson, in a statement to Engadget

Amazon compared the arrangement to food delivery apps and the restaurants they order from. Or travel agencies and the airlines they book. In Amazon's framing, Muse skipped that step and helped itself.

What several days with the app actually showed

WIRED senior writer Reece Rogers, who previously covered streaming for Business Insider, spent several days testing Muse. He documented the results September 20. He asked it to order breakfast from Kahnfections, a bakery popular with tourists in San Francisco.

Muse found the shop's site and added a biscuit sandwich to the cart. It picked cheddar cheese, because the site only allowed one choice, and selected no tip on his behalf. Rogers didn't let the order go through. He walked to the bakery and bought something himself.

The browsing itself was fast and accurate, he wrote, a real improvement over agents he'd tested a year earlier. What bothered him wasn't the shopping. It was everything else Muse kept asking for.

The gap between secure and what it asks for

Muse's ideas tab suggested, unprompted, that Rogers let it scan his full email inbox. It offered to photograph his meals to estimate calories, and asked when his passport and driver's license expire.

Users are opted in by default to having their conversations used for training Meta's AI models. Opting out takes work. The toggle is labeled Help improve our AI models. It's buried inside the app's Data controls menu, not a setting most users go looking for.

We think this is a good default. Every Muse user gets a better personal agent as we all collectively use the product and help the model understand the intricacies of human life.

Tarek Sheasha, vice president, Meta Superintelligence Labs, in a blog post announcing Muse

Meta's counter, and what's still unverified

Meta disputes that Muse is a security risk. Muse has no visibility into people's passwords or payment methods, the company said in its announcement. Credentials go into secure storage, and Muse never sees them.

Purchases route through a single-use virtual card from Link by Stripe, not a stored number. Two large companies are now making opposite factual claims about the same product. Neither has published data settling it.

Meta also told WIRED that training data is sanitized to strip identifying information before use, but the company did not explain how that process works. Call it unverified, not confirmed.

The pattern privacy researchers are pointing to

Rory Mir, director of open access at the Electronic Frontier Foundation, told WIRED that chat windows feel private. They aren't. He says they're really direct lines to Meta's servers. Calli Schroeder, senior counsel at the Electronic Privacy Information Center, drew a comparison to Meta's own recent history.

Earlier this year, Meta opted all adult Instagram users into an AI deepfake tool by default. It pulled the feature days later after backlash. She sees Muse's opt-out defaults as a repeat of the same pattern, not a one-off.

Neither researcher has audited Muse's code or its data flows firsthand. Their objections are about default settings and disclosure, not a confirmed breach, and Trestlewire found no evidence of one. Amazon's objection is narrower: an unidentified bot placing orders on a site it does not control.

Amazon has made its verdict on Muse a matter of site policy, not opinion. Whether Meta changes the app's defaults to get back in, or simply leaves Amazon off the list, is the next fact to watch for. It is not an assumption to make yet.

  • Meta
  • Muse AI
  • Amazon
  • AI agents
  • data privacy
  • Stripe

Sources

  1. 01Meta's Muse Is Better at Surveilling Than Helping Me, WIREDwired.com
  2. 02Amazon Bars Meta's Muse AI From Shopping On Its Site, Engadgetengadget.com

Corrections

No corrections have been made to this article.

About the reporter

Mara Voss

Technology Reporter, Trestlewire

I spent seven years as a product manager at a mid-size SaaS company before I ever wrote a sentence for pay, which means I have sat through more roadmap reviews than most people would tolerate in a lifetime. I watched a scheduling feature get rebranded three times before it shipped, and I watched a launch date slide past four straight quarters while the slide deck stayed exactly the same. That is where the question I still ask every day came from: does this actually ship, or is it a demo.

Read full bio and all stories →