What the Muse Block Confirmed
On September 21, 2026, Amazon blocked Meta's Muse from its retail site, six weeks after a federal appeals court had vacated Amazon's own injunction against a rival agent for the opposite reason. Both events turn on the same missing layer: a platform can detect and block traffic, but nothing yet lets it authorize, scope, and audit what an agent is allowed to do once inside. This paper names that layer, argues the commerce fight now unfolding in public is the clearest evidence yet that Detection-era tools cannot settle a Determination-era question, and closes by showing how Essence's own architecture, not litigation, is built to answer it.
On September 21, 2026, Amazon blocked Meta's Muse shopping agent from its retail site after Meta declined a request to withdraw it, showing Muse users pop-ups citing a terms-of-use violation. The block landed roughly six weeks after the opposite result in a related case: on August 6, 2026, the Ninth Circuit Court of Appeals vacated a preliminary injunction that had barred Perplexity's Comet browser from shopping on Amazon on users' behalf, finding that when a user directs an AI assistant to act on a site, it is the user, not the AI company, who is accessing that site's systems. Both rulings, and the Muse block that followed them, turn on the same undecided question: not whether an agent can reach a platform, but who gets to define what it is authorized to do once it is inside. This paper argues that question will not be settled by blocking rules or litigation alone, because both are Detection-era mechanisms applied to a Determination-era gap, and names the axis underlying it: Access ≠ Authority.
Meta introduced Muse earlier in September 2026 as an assistant designed to carry out common online tasks, shopping among them. Amazon began blocking it from its retail site on the night of September 20 into 21, after Meta declined Amazon's request to remove the bot; shoppers attempting to use Muse on Amazon's site were shown pop-ups stating that its use violated Amazon's terms of service. Amazon's stated position is that it prohibits other companies from deploying automated tools to shop its site, and CEO Andy Jassy had already voiced skepticism earlier in the year about the maturity of agentic shopping, citing agents that mishandled pricing and other data.
Muse is not the first agent Amazon has moved against. Amazon has also blocked shopping agents from Google and OpenAI, and has litigated directly against Perplexity's Comet browser since November 2025, while continuing to operate its own agents, Alexa for Shopping and Buy for Me, the latter of which identifies itself to other retailers and allows them to opt out.
The legal history behind the Muse block is more instructive than the block itself. Amazon sued Perplexity in November 2025, alleging that Comet concealed its automated shopping agent and accessed customer accounts, including password-protected areas, without Amazon's authorization. On March 10, 2026, U.S. District Judge Maxine Chesney granted Amazon a preliminary injunction, finding Amazon had presented strong evidence that Comet accessed Amazon's site without permission, after Amazon documented the cost of building detection tooling to identify and block the agent. The injunction barred Comet from Amazon's password-protected areas and required Perplexity to destroy previously collected data.
That ruling did not survive review. On August 6, 2026, the Ninth Circuit vacated the injunction, holding that Amazon was unlikely to prevail on its Computer Fraud and Abuse Act claim: when a user directs an AI assistant to complete a task on a site, the panel reasoned, it is the user who is accessing that site's computers, with the assistant's help, not the AI company acting independently. The court found the balance of harms and the public interest favored Perplexity, not Amazon, and remanded the underlying dispute for further proceedings.
| March 2026 Injunction (Chesney, N.D. Cal.) | August 2026 Vacatur (Ninth Circuit) |
|---|---|
| Comet accessed Amazon's systems without Amazon's authorization: a user's permission to the agent does not by itself confer the site's authorization to the agent. | The user, not the agent's operator, is the one accessing Amazon's systems; the agent is a tool acting at the user's direction, not an independent unauthorized party. |
| Turns on whether a platform's own terms and technical controls define authorized access. | Turns on whether a statute written for unauthorized computer intrusion fits a user knowingly directing their own assistant. |
| Result: agent blocked, data ordered destroyed, pending appeal. | Result: block lifted, case remanded, the question of what happens next left open. |
Two federal courts, five months apart, reached opposite conclusions from closely related facts, in part because the statute they were applying was never built to answer this question. The Computer Fraud and Abuse Act asks whether access was authorized. It has no mechanism for a platform to define, in a machine-checkable way, what an agent may do once granted access, at what scope, on whose behalf, and with what audit trail left behind. Courts are left inferring authorization from terms-of-service language and after-the-fact evidence of intent, the same Detection-era pattern this series has named at the security layer, the model layer, and the architecture layer, now surfacing at the layer of commerce itself.
Amazon's response to both Comet and Muse is a Detection-era response: identify automated traffic after the fact, build tooling to distinguish it from human browsing, and block it at the edge. That is a real engineering effort, documented in court filings, not a bluff. But it treats the problem as identification rather than authorization, and identification does not resolve the harder question underneath it, which is what happens once an agent is let in.
The commercial stakes explain why blocking, not licensing, has been the default response. Amazon's advertising business generated roughly $68.6 billion in 2025 and is estimated at $19.8 billion for the second quarter of 2026 alone, revenue that depends on shoppers seeing sponsored listings an agent may simply skip. Amazon's own Rufus assistant reportedly drove nearly $12 billion in incremental annualized sales in 2025, evidence that Amazon is not opposed to agentic shopping as a category, only to a version of it that it does not build, cannot see inside, and cannot bill against. That is a business incentive, not a security argument, and treating it as a security argument is precisely the move a Determination layer would make harder to sustain, because it would force platform, agent, and user to state, in advance and in a checkable form, what scope of action was actually agreed to.
This series has named a family of Detection-era confusions under a shared pattern: Detection ≠ Determination at the doctrine's core, Correlation ≠ Coordinate at the model layer, Code ≠ Intent at the architecture layer, Compiled ≠ Resolved across ecosystems, and Captured ≠ Governed across signal verticals. The Muse block and the Comet litigation name a further member of that family, specific to agentic commerce: Access ≠ Authority.
A robots.txt entry, a terms-of-service clause, or a CFAA claim can each say whether an agent is present on a site without permission. None of them can say, in a form a machine can check before the agent acts, what that agent is authorized to do once present: which categories it may browse, whether it may complete a purchase, at what price ceiling, using which stored payment method, with what record left behind for the retailer, the user, and the agent's own operator to each independently audit. That is not a gap litigation is well positioned to close, because litigation evaluates conduct that has already happened. It is a gap only a Determination layer, evaluated before the agent acts, can close.
Coverage of the Comet ruling framed it as an early test of whether platforms can keep third-party AI agents from standing between themselves and their customers, and the Muse block is Amazon acting on that framing in public, weeks after losing a closely related argument in court. Neither outcome, taken alone, resolves anything. A platform that wins the right to block agents at will still has no way to admit a legitimate one on defined terms. A platform that loses that right still has no way to prevent an agent from acting outside the scope its user actually intended.
What both rulings share, and what the Muse block confirms in public view, is that the industry is litigating a scope-and-authority problem using tools built for a presence-and-access problem, and arriving at different answers each time because the tools were never built to answer it.
The Governed Machine, The Common Substrate, and The Governed Signal are the only series naming a solution to this convergence across the security, model, architecture, and now commerce layers, rather than only tracking it.
Every mechanism this dispute is missing is one Essence® treats as a starting requirement rather than a feature to add later. The distinction the courts kept flipping on (what an agent is permitted to do, as opposed to whether it reached the site) is exactly the distinction Essence's architecture is built to make explicit, checkable, and fixed before any action executes.
In Essence, an external agent does not act directly. It proposes intent. Synergy®, the platform's governance layer, captures that intent and maps it to Meaning Coordinates, a fixed, structured representation of what is being asked, not a statistical guess at it. Grok Units then interpret those Meaning Coordinates and convert them into real-time output through a three-step sequence: interpret intent, validate with Synergy, generate output via Morpheus®. If the interpretation is ambiguous, a Grok Unit asks a clarifying question through Synergy rather than inferring the answer. Nothing about this sequence resembles the presence-and-access test a court applies after the fact. It is a determination made before the agent's request ever reaches execution.
Scope and authority in Essence are not blanket settled at the platform level, the way a robots.txt file or a terms-of-service clause tries and fails to do. They are customer-configurable: a retailer, or any platform integrating Essence, sets what an Aptiv operating on its behalf may do, within a set of principles that apply to every Aptiv regardless of configuration. That is the missing piece in the Amazon dispute made concrete: a retailer does not have to choose between blocking every outside agent and admitting all of them on unknown terms. It can define, and Essence enforces, exactly what an agent may do inside its systems, category by category, transaction by transaction.
The enforcement is architectural, not procedural. Aptivs do not attempt to expand their own capability, authority, or outcomes beyond what has been authorized: there is no code path for unauthorized action, not a policy an agent could be instructed to disregard. This is the same design principle stated elsewhere in the platform's own documentation: AI systems interfacing with Essence propose intent only and do not execute directly, which is precisely the authorization step that was absent from both the Comet injunction and the Muse block, and that no CFAA claim can supply after the fact.
None of this requires a court to decide, months after the fact, whose evidence was stronger. It requires the platform and the agent to agree, before the agent acts, on a fixed and auditable answer to the only question either ruling was actually reaching for: not access, but authority.