The Authorization Gap

What the Muse Block Confirmed

On September 21, 2026, Amazon blocked Meta's Muse from its retail site, six weeks after a federal appeals court had vacated Amazon's own injunction against a rival agent for the opposite reason. Both events turn on the same missing layer: a platform can detect and block traffic, but nothing yet lets it authorize, scope, and audit what an agent is allowed to do once inside. This paper names that layer, argues the commerce fight now unfolding in public is the clearest evidence yet that Detection-era tools cannot settle a Determination-era question, and closes by showing how Essence's own architecture, not litigation, is built to answer it.

Ken Granville CEO & Co-Founder, MindAptiv White Paper 80 The Governed Machine September 2026
Abstract

On September 21, 2026, Amazon blocked Meta's Muse shopping agent from its retail site after Meta declined a request to withdraw it, showing Muse users pop-ups citing a terms-of-use violation. The block landed roughly six weeks after the opposite result in a related case: on August 6, 2026, the Ninth Circuit Court of Appeals vacated a preliminary injunction that had barred Perplexity's Comet browser from shopping on Amazon on users' behalf, finding that when a user directs an AI assistant to act on a site, it is the user, not the AI company, who is accessing that site's systems. Both rulings, and the Muse block that followed them, turn on the same undecided question: not whether an agent can reach a platform, but who gets to define what it is authorized to do once it is inside. This paper argues that question will not be settled by blocking rules or litigation alone, because both are Detection-era mechanisms applied to a Determination-era gap, and names the axis underlying it: Access ≠ Authority.

Section 01The Muse Block

Meta introduced Muse earlier in September 2026 as an assistant designed to carry out common online tasks, shopping among them. Amazon began blocking it from its retail site on the night of September 20 into 21, after Meta declined Amazon's request to remove the bot; shoppers attempting to use Muse on Amazon's site were shown pop-ups stating that its use violated Amazon's terms of service. Amazon's stated position is that it prohibits other companies from deploying automated tools to shop its site, and CEO Andy Jassy had already voiced skepticism earlier in the year about the maturity of agentic shopping, citing agents that mishandled pricing and other data.

Muse is not the first agent Amazon has moved against. Amazon has also blocked shopping agents from Google and OpenAI, and has litigated directly against Perplexity's Comet browser since November 2025, while continuing to operate its own agents, Alexa for Shopping and Buy for Me, the latter of which identifies itself to other retailers and allows them to opt out.

The Asymmetry
Amazon's own cross-site agent discloses itself and lets the destination site refuse it. The agents Amazon blocks from its own site are the ones it says do not. Every party involved agrees an agent should identify itself and be subject to a site's own terms. The dispute is about who builds the mechanism that enforces that, and who it answers to.

Section 02The Distinction the Courts Keep Flipping On

The legal history behind the Muse block is more instructive than the block itself. Amazon sued Perplexity in November 2025, alleging that Comet concealed its automated shopping agent and accessed customer accounts, including password-protected areas, without Amazon's authorization. On March 10, 2026, U.S. District Judge Maxine Chesney granted Amazon a preliminary injunction, finding Amazon had presented strong evidence that Comet accessed Amazon's site without permission, after Amazon documented the cost of building detection tooling to identify and block the agent. The injunction barred Comet from Amazon's password-protected areas and required Perplexity to destroy previously collected data.

That ruling did not survive review. On August 6, 2026, the Ninth Circuit vacated the injunction, holding that Amazon was unlikely to prevail on its Computer Fraud and Abuse Act claim: when a user directs an AI assistant to complete a task on a site, the panel reasoned, it is the user who is accessing that site's computers, with the assistant's help, not the AI company acting independently. The court found the balance of harms and the public interest favored Perplexity, not Amazon, and remanded the underlying dispute for further proceedings.

Same underlying question, two opposite rulings
March 2026 Injunction (Chesney, N.D. Cal.)August 2026 Vacatur (Ninth Circuit)
Comet accessed Amazon's systems without Amazon's authorization: a user's permission to the agent does not by itself confer the site's authorization to the agent.The user, not the agent's operator, is the one accessing Amazon's systems; the agent is a tool acting at the user's direction, not an independent unauthorized party.
Turns on whether a platform's own terms and technical controls define authorized access.Turns on whether a statute written for unauthorized computer intrusion fits a user knowingly directing their own assistant.
Result: agent blocked, data ordered destroyed, pending appeal.Result: block lifted, case remanded, the question of what happens next left open.

Two federal courts, five months apart, reached opposite conclusions from closely related facts, in part because the statute they were applying was never built to answer this question. The Computer Fraud and Abuse Act asks whether access was authorized. It has no mechanism for a platform to define, in a machine-checkable way, what an agent may do once granted access, at what scope, on whose behalf, and with what audit trail left behind. Courts are left inferring authorization from terms-of-service language and after-the-fact evidence of intent, the same Detection-era pattern this series has named at the security layer, the model layer, and the architecture layer, now surfacing at the layer of commerce itself.

Section 03Why Detection Cannot Settle This

Amazon's response to both Comet and Muse is a Detection-era response: identify automated traffic after the fact, build tooling to distinguish it from human browsing, and block it at the edge. That is a real engineering effort, documented in court filings, not a bluff. But it treats the problem as identification rather than authorization, and identification does not resolve the harder question underneath it, which is what happens once an agent is let in.

See also: Paper 46, "The Liability Backstop," on liability as a Detection-era mechanism that fires only after harm is proven, using an Australia AI-booking-agent incident as its case study; and Paper 76, "The Governability Axis," naming Computable ≠ Governable as the axis underlying this series' recurring Detection ≠ Determination distinction.

The commercial stakes explain why blocking, not licensing, has been the default response. Amazon's advertising business generated roughly $68.6 billion in 2025 and is estimated at $19.8 billion for the second quarter of 2026 alone, revenue that depends on shoppers seeing sponsored listings an agent may simply skip. Amazon's own Rufus assistant reportedly drove nearly $12 billion in incremental annualized sales in 2025, evidence that Amazon is not opposed to agentic shopping as a category, only to a version of it that it does not build, cannot see inside, and cannot bill against. That is a business incentive, not a security argument, and treating it as a security argument is precisely the move a Determination layer would make harder to sustain, because it would force platform, agent, and user to state, in advance and in a checkable form, what scope of action was actually agreed to.

Section 04Access ≠ Authority

This series has named a family of Detection-era confusions under a shared pattern: Detection ≠ Determination at the doctrine's core, Correlation ≠ Coordinate at the model layer, Code ≠ Intent at the architecture layer, Compiled ≠ Resolved across ecosystems, and Captured ≠ Governed across signal verticals. The Muse block and the Comet litigation name a further member of that family, specific to agentic commerce: Access ≠ Authority.

A robots.txt entry, a terms-of-service clause, or a CFAA claim can each say whether an agent is present on a site without permission. None of them can say, in a form a machine can check before the agent acts, what that agent is authorized to do once present: which categories it may browse, whether it may complete a purchase, at what price ceiling, using which stored payment method, with what record left behind for the retailer, the user, and the agent's own operator to each independently audit. That is not a gap litigation is well positioned to close, because litigation evaluates conduct that has already happened. It is a gap only a Determination layer, evaluated before the agent acts, can close.

Access ≠ Authority
Reaching a site is not the same as being authorized to act on it.
A rule that blocks or permits an agent's presence, evaluated after the fact by a court or a detection system, is Access. A fixed, checkable scope of what that agent may do, established before it acts and auditable by every party it affects, is Authority. Agentic commerce currently has extensive tooling for the first and none for the second.

Section 05The Precedent Nobody Wants to Set

Coverage of the Comet ruling framed it as an early test of whether platforms can keep third-party AI agents from standing between themselves and their customers, and the Muse block is Amazon acting on that framing in public, weeks after losing a closely related argument in court. Neither outcome, taken alone, resolves anything. A platform that wins the right to block agents at will still has no way to admit a legitimate one on defined terms. A platform that loses that right still has no way to prevent an agent from acting outside the scope its user actually intended.

What both rulings share, and what the Muse block confirms in public view, is that the industry is litigating a scope-and-authority problem using tools built for a presence-and-access problem, and arriving at different answers each time because the tools were never built to answer it.

The Authorization Gap
Detection ≠ Determination.
Two federal rulings, five months apart, reached opposite conclusions about closely related conduct because neither had a fixed, checkable reference for what an agent was authorized to do. That reference is what this series has argued, from its earliest papers, needs to exist before the dispute reaches a courtroom at all. Essence is designed to be that reference.

The Governed Machine, The Common Substrate, and The Governed Signal are the only series naming a solution to this convergence across the security, model, architecture, and now commerce layers, rather than only tracking it.

Section 06How Essence Closes It

Every mechanism this dispute is missing is one Essence® treats as a starting requirement rather than a feature to add later. The distinction the courts kept flipping on (what an agent is permitted to do, as opposed to whether it reached the site) is exactly the distinction Essence's architecture is built to make explicit, checkable, and fixed before any action executes.

In Essence, an external agent does not act directly. It proposes intent. Synergy®, the platform's governance layer, captures that intent and maps it to Meaning Coordinates, a fixed, structured representation of what is being asked, not a statistical guess at it. Grok Units then interpret those Meaning Coordinates and convert them into real-time output through a three-step sequence: interpret intent, validate with Synergy, generate output via Morpheus®. If the interpretation is ambiguous, a Grok Unit asks a clarifying question through Synergy rather than inferring the answer. Nothing about this sequence resembles the presence-and-access test a court applies after the fact. It is a determination made before the agent's request ever reaches execution.

The Structural Difference
Amazon's blocking tools ask, after detecting traffic, whether an agent should have been there at all. Essence asks, before any action executes, exactly what that agent is authorized to do, at what scope, on whose behalf; and answers it from a fixed reference both sides can check, not from litigation over what should have happened.

Scope and authority in Essence are not blanket settled at the platform level, the way a robots.txt file or a terms-of-service clause tries and fails to do. They are customer-configurable: a retailer, or any platform integrating Essence, sets what an Aptiv operating on its behalf may do, within a set of principles that apply to every Aptiv regardless of configuration. That is the missing piece in the Amazon dispute made concrete: a retailer does not have to choose between blocking every outside agent and admitting all of them on unknown terms. It can define, and Essence enforces, exactly what an agent may do inside its systems, category by category, transaction by transaction.

The enforcement is architectural, not procedural. Aptivs do not attempt to expand their own capability, authority, or outcomes beyond what has been authorized: there is no code path for unauthorized action, not a policy an agent could be instructed to disregard. This is the same design principle stated elsewhere in the platform's own documentation: AI systems interfacing with Essence propose intent only and do not execute directly, which is precisely the authorization step that was absent from both the Comet injunction and the Muse block, and that no CFAA claim can supply after the fact.

See also: Composite Job Designs, on how Meaning Coordinates feed generation of the composite job designs an authorized Aptiv is permitted to execute; and this series' central doctrine, Detection ≠ Determination, of which this section is a direct application at the commerce layer.

None of this requires a court to decide, months after the fact, whose evidence was stronger. It requires the platform and the agent to agree, before the agent acts, on a fixed and auditable answer to the only question either ruling was actually reaching for: not access, but authority.

The Governed Machine: Paper 80
Two courts asked who could enter.
Essence asks what they're authorized to do.
Amazon's block of Meta's Muse and the Ninth Circuit's vacatur of Amazon's own injunction against Perplexity's Comet are not contradictory rulings on identical facts. They are two Detection-era answers to a question neither court had the tools to settle. Essence answers it structurally: intent proposed, mapped to Meaning Coordinates, validated against a fixed and customer-configurable scope, before any Aptiv ever acts.
Request Access Read Paper 79

White Paper Series · The Governed Machine

1The Civilizational Fault Line 2We Are Building the Wrong Machine 3The Ornithopter Mistake 4The Convergence 5The Four Horsemen of the Knowledge Apocalypse 6What the Insiders Confirmed 7The Metaphor Trap 8The Recall Standard 9The $1 Trillion Governance Gap 10The Litigation Layer 11The Scale of Intent 12The Intent Economy 13The Session Illusion 14The Necessary Sequence 15The Wrong Race 16The Ledger That Is Intent-Driven 17The Agency Illusion 18The Substrate 19The End of the Mean 20Era 3: The Architecture of the Next Civilization 21The Missing Substrate 22The Context Fatigue Ceiling 23The Iceberg Stays Frozen 24The Dependency Tax 25The Record That Was Never Kept 26Composable by Default 27Do No Harm 28The Stack Replacement Thesis 29The Moat Is the Code 30The Last Platform War 31Beyond the Agent: Intent-Native Execution 32The Hardware Imagination 33The Architecture Tax 34The Tokenization Ceiling 35The Payment Moment 36The Oracle Problem 37The Reviewer Problem 38The Provenance Fallacy 39Role Without Determination 40Known and Funded Anyway 41The Style Confusion Proof 42The Verification Tax 43The Pause Reflex 44The Human Margin 45The Balance of Power Fallacy 46The Liability Backstop 47One Substrate, Every Signal 48The Attribution Problem 49The Consciousness Ceiling 50The Detection Patch 51The Consumptive Machine 52The Agent That Isn't 53The Legibility Gap 54The Semiotic Machine 55The Transpilation Ceiling 56The Provisioning Ceiling 57The Reservation Ceiling 58The Circularity Ceiling 59The Coexistence Ceiling 60The Conformance Ceiling 61The Preservation Ceiling 62The Parity Clause 63The Governed Boundary 64The Transcript Problem 65The Unpaired System 66The Memory Ceiling 67The Admission Gap 68The Wrong Ask 69The Best Case 70The Last Chokepoint 71The Fourth Step 72The Adoption Standard 73The Same Weekend 74Sixty to One 75Coordinates, Not Correlations 76The Governability Axis 77Era 3, Confirmed 78The Eleventh Rule 79The Seventh Admission 80The Authorization Gap ← this paper 81The Authorship Fallacy 82The Camera and the Vault 83Cleared to Proceed 84A Class, Not a Product 85The Inherited Playbook