Field report · · AgentConn Team
Who Owns the Transaction? The Agentic-Commerce Land Grab
Amazon blocked Meta's Muse. Shopify welcomed it. The real battle isn't who builds the best agent — it's who controls the checkout rails.
Who Owns the Transaction? The Agentic-Commerce Land Grab
On Sunday night, September 20, Amazon flipped a switch. Anyone trying to complete a purchase through Meta’s two-week-old Muse AI agent hit a wall: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use.” Amazon didn’t just block Muse — it drew a line that defines the next decade of commerce. The question is no longer which company builds the best shopping agent. The question is who owns the rails the transaction runs on.
This isn’t Amazon’s first eviction. Perplexity’s Comet browser got a court order in March. ChatGPT’s shopping features were blocked during the 2025 holiday season. Amazon has now blocked three major AI agents from its storefront in under a year. And while Meta protests that Muse runs in a sandboxed VM where it “cannot see a user’s passwords or payment details,” that misses the real game. This fight isn’t about security. It’s about a $68 billion advertising business that evaporates the moment shoppers stop scrolling Amazon’s pages.
Nikita Bier’s viral post — imagining an agent that auto-negotiates refunds on every past Amazon purchase — captures the existential threat in 30 words. If agents can shop, they can also un-shop. And they’ll do it at machine speed, across every order in your history.
The $68 Billion Threat Model
Amazon’s objections to Muse are technical on the surface — unauthorized access, failure to disclose agent identity, account security risks. But Forbes laid bare the real calculus: Amazon pulled in more than $68 billion in advertising revenue last year. That revenue depends on human eyeballs scrolling through sponsored listings, encountering display ads, and clicking through recommendation carousels.
When an AI agent handles search, comparison, and checkout autonomously, none of those touchpoints exist. The agent doesn’t see sponsored listings. It doesn’t click display ads. It doesn’t get nudged by “customers also bought” panels. For Amazon, an AI agent that completes purchases is an ad-blocker for commerce — except this one doesn’t just hide ads, it removes the entire surface they run on.
This is why Amazon’s “security” framing deserves scrutiny. As TechTimes pointed out, Amazon applies standards to Meta’s Muse that it conveniently ignores for its own shopping agent, Rufus. Amazon’s AI can navigate its own storefront, access customer data, and recommend products — all the behaviors it cites as disqualifying for Muse. The double standard is the strategy: keep third-party agents out, let your own in.
The pattern: Amazon blocked Perplexity’s Comet (Nov 2025, court order March 2026). Blocked ChatGPT shopping (holiday 2025). Blocked Meta’s Muse (Sept 2026). Three major agents in under a year. This isn’t security policy — it’s a moat strategy.
View discussion on Hacker News →
Shopify’s Counter-Move: Build the Open Rails
While Amazon locks the gates, Shopify opened them. Within days of Amazon’s Muse block, Shopify announced a partnership to let Muse browse Shopify-powered stores and complete purchases through Shop Pay. As Motley Fool noted: Amazon blocked Meta’s AI shopping agent. Shopify welcomed it — and gets paid on every checkout.
This isn’t opportunism. It’s the culmination of a strategy Shopify has been building since January, when it co-launched the Universal Commerce Protocol (UCP) with Google at NRF. UCP is an open standard that lets AI agents discover products, negotiate merchant capabilities, and complete purchases without the buyer leaving the conversation. More than 20 global partners — including Visa, Mastercard, Stripe, Adyen, Etsy, Wayfair, Target, and Walmart — have endorsed it.
The numbers tell the story. In Q1 2026, AI-driven traffic to Shopify stores grew 8x year-over-year. Orders from AI-powered searches increased nearly 13x. By mid-2026, Shopify merchants are discoverable across ChatGPT, Microsoft Copilot, Google AI Mode, and Gemini — all without additional configuration. Shopify activated UCP and native MCP servers by default for all merchants in its Winter 2026 Edition.
The strategic logic is elegant: Amazon needs to keep agents out because its business model requires human attention. Shopify can welcome agents in because its business model charges on transactions, not attention. Every Muse checkout through Shop Pay is revenue for Shopify, regardless of whether a human or an agent pressed the button.
The Payment Networks Are Already Choosing Sides
The most consequential moves in agentic commerce aren’t happening at the storefront level — they’re happening in the payment infrastructure beneath it. And the payment networks are not waiting.
Mastercard launched Agent Pay in June, letting verified AI agents transact on a consumer’s behalf using Agentic Tokens — an extension of their tokenization infrastructure. No card numbers change hands. The agent gets a scoped credential, the issuer authorizes in real-time, and the transaction settles on existing rails. Then Mastercard went further with Agent Pay for Machines (AP4M), enabling agent-to-agent transactions where no human is in the loop at all.
Visa’s Intelligent Commerce takes a different approach, centered on the Trusted Agent Protocol and a partnership with OpenAI announced in June 2026. Visa’s system supports payments initiated through four major agent protocols simultaneously: Trusted Agent Protocol, Machine Payments Protocol, Agentic Commerce Protocol (Stripe/OpenAI), and UCP (Google/Shopify).
The agentic commerce protocol stack (mid-2026):
- UCP (Google + Shopify) — Open discovery-to-checkout standard. 20+ partners.
- ACP (Stripe + OpenAI) — Powers ChatGPT Shopping. Merchant redirect model.
- Agent Pay (Mastercard) — Tokenized agent credentials. Agent-to-agent capable.
- Trusted Agent Protocol (Visa + OpenAI) — Issuer-level authorization for agents.
- AP2 — Protocol envelope layer above Agent Pay.
Here is the insight the market is missing: whoever controls the payment protocol controls which agents can transact. Mastercard’s Agent Pay doesn’t just enable payments — it creates a registry of verified agents. Visa’s Trusted Agent Protocol doesn’t just authorize transactions — it decides which agents are trusted enough to transact. The payment networks are building the permitting system for agentic commerce, and that’s a far more durable moat than any storefront’s robots.txt.
The Legal Precedent Nobody Talks About
The Perplexity case set a legal precedent that undermines Amazon’s entire blocking strategy. In August, a three-judge panel of the Ninth Circuit reversed the lower court’s injunction against Perplexity’s Comet browser, ruling that an injunction “would impair consumer choice and needlessly limit development of a nascent technology.”
The key legal finding: the court held that Perplexity did not “access” Amazon’s site within the meaning of the Computer Fraud and Abuse Act. When a user authorizes an AI agent to shop on their behalf, the user is the one accessing Amazon’s servers — the agent is merely a tool, like a browser extension or a screen reader.
Amazon is pressing for an en banc rehearing, arguing the ruling “degraded website owners’ ability to set the terms on which powerful, fast-evolving, and potentially destructive AI agents may enter their secure systems.” But the Ninth Circuit’s reasoning — that an agent authorized by the account holder is not an unauthorized intruder — maps directly onto the Muse situation. Meta will almost certainly cite it if Amazon escalates.
What the Community Is Saying
The Hacker News thread on Amazon’s Muse block surfaced the tension that matters most: is this a security measure or an antitrust play?
The dominant sentiment is skepticism toward Amazon’s stated motives. Developers see the parallel to how Amazon blocked third-party price-tracking extensions years ago — “security” was the stated reason then too, and the real reason was protecting margin. The difference now is that the agents aren’t just reading prices. They’re completing transactions, which threatens a much larger revenue stream.
On the infrastructure side, Robonomics’ deep dive into the agentic commerce stack identifies a seven-layer architecture where Layer 3 (payments and identity) is the new battleground. The analysis argues that control of the payment layer gives far more leverage than control of the agent or the storefront — and that’s exactly what the Visa and Mastercard plays are targeting.
Meanwhile, NLW’s analysis on the AI Daily Brief nailed the framing: “The moat fight isn’t the agent — it’s who controls the transaction. Whether normal people actually want agentic shopping is still unproven.” That last point deserves more attention than it’s getting.
Contrarian Corner: Most People Don’t Want AI Shopping
The uncomfortable data point: Fortune reported that most people don’t want AI touching their money. Muse has 2.5 million downloads, but that’s adoption of a free personal assistant — not evidence that consumers trust an AI to handle their credit card.
The industry is building infrastructure for a consumer behavior shift that hasn’t happened yet. According to Forrester’s mid-2026 assessment, most “agentic” experiences are still conversational — humans drive decisions and checkout in the vast majority of cases. McKinsey’s $3-5 trillion global projection for 2030 assumes a behavioral transformation that current data doesn’t support.
This matters for agent builders: the near-term opportunity in agentic commerce may not be the B2C “agent shops for you” narrative that gets all the press. It may be the B2B infrastructure play — agents handling procurement, supply chain optimization, and wholesale ordering where the trust threshold is lower and the efficiency gains are immediate. The consumer shopping agent might be the showcase, but enterprise procurement might be the business.
That said, the VC money is betting hard on the consumer vision. Brad Gerstner’s framing captures why investors keep writing checks despite the trust gap:
Read the full article on Fortune →
What Agent Builders Should Do Now
If you’re building agents that touch commerce, here’s what this week’s developments mean for your roadmap:
1. Integrate with the payment protocols, not the storefronts. Amazon can block you from its website. It cannot block you from Visa or Mastercard. Agents that integrate directly with Agent Pay or Trusted Agent Protocol operate on rails that the storefronts don’t control. Start with Shopify’s UCP documentation — it’s the most accessible on-ramp.
2. Identify your agent. The strongest technical argument Amazon has against Muse is that it doesn’t disclose its agent identity. Every request your agent makes should include agent identification headers. This isn’t just good citizenship — it’s legal insulation. The Ninth Circuit’s reasoning protects authorized tools, and a tool that identifies itself has a stronger case than one that masquerades as a human browser.
3. Assume the walled-garden/open-rail split is permanent. Amazon will not voluntarily open its storefront to third-party agents. Shopify, Google, and the payment networks will continue building open infrastructure. Design your agent architecture for a split world — Amazon-compatible through its own Rufus agent (if it ever opens an API), and open-protocol-compatible for everything else.
4. Watch the Ninth Circuit. If Amazon’s en banc petition succeeds, the legal landscape for agentic commerce shifts dramatically. If it fails, the “agent as user tool” precedent solidifies and Amazon’s ToS-based blocking strategy weakens. Either outcome reshapes what agents are legally allowed to do.
The builder’s thesis: The agent is the easy part. The checkout integration is the hard part. And the payment protocol your agent speaks determines which merchants it can reach. Pick your protocol stack now — UCP + Agent Pay is the broadest coverage as of September 2026.
The Transaction Layer Is the New Platform
Every platform war follows the same pattern: the visible product gets the attention, but the invisible infrastructure captures the value. In social media, it was the ad auction. In mobile, it was the app store’s 30% cut. In cloud, it was the API gateway. In agentic commerce, it’s the transaction layer.
Amazon understands this, which is why it’s blocking agents rather than welcoming them. Shopify understands it, which is why it’s building open rails that every agent can use. The payment networks understand it best of all, which is why Mastercard and Visa are building the agent permitting system that sits beneath every checkout.
For agent builders, the strategic implication is clear: stop optimizing your agent’s product recommendations and start optimizing its payment protocol integration. The agent that can transact on the most rails wins — not the one with the best taste in sneakers.
The land grab is on. And it’s not for the agent. It’s for the transaction.
For more on how agent infrastructure — not models — determines winners, see our coverage of the harness-as-moat thesis and agent web write access.





