AI agents hit firewalls: Amazon blocks, Walmart tries to fix

The promise of personal AI agents — Meta's Muse, ChatGPT's Dots, Instinct and others — was to move us from the chat era to the execution era: booking flights, buying groceries, reserving restaurant tables, all without the user lifting a finger. In practice, the new wave has run into a first, unexpected barrier: the websites themselves. Amazon recently blocked Muse from its product catalog, preventing the agent from making purchases on the user's behalf. This is not an isolated glitch; online reports point to a broader pattern of agents being repeatedly blocked when they try to complete tasks.
Walmart illustrates the more complicated side of the problem. The company announced a partnership with Muse at Meta's Connect conference in September, saying it wanted to meet customers "where they are," including through agent-driven experiences. Yet customers who tried to use the integration ran into a human-verification loop — a button that requires a click to prove you are not a bot. When the agent attempts to pass that step, the check fails and it is ejected. A Walmart spokesperson characterized the issue as an unintentional bug, but for the end user there is no visible difference between a deliberate block and a flaw in the existing anti-bot infrastructure.
The Walmart episode shows how ill-suited current defense mechanisms — CAPTCHAs, JavaScript challenges, behavioral analysis — are for an era in which "good bots" act on behalf of legitimate users. Those tools were built to stop spam and attacks, not to distinguish a malicious script from an agent ordering groceries with full permission. When the experience breaks, the user is left frustrated with no clear target for blame: the retailer, the agent provider, or the protocol in between.
To untangle the knot, a coalition that includes Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE and Decagon has begun work on an open standard for agent-to-agent communication in e-commerce. According to a Meta blog post, the protocol will define how agents identify themselves to merchants and how to separate authorized bots from those operating without permission. The effort is still in early stages, and confusion in the field is only growing.
The airline sector shows how far adoption has to go. Delta said it is taking steps to guard against "unauthorized automated activity," and that any future opening to agents would be done with "security and customer experience" as the top priority. Heena Chavda, Delta's global communications director, said the company continues to evaluate the technology but has no integration today that allows a third-party agent to book flights. United was less direct, pointing to terms-of-service clauses that prohibit automated access. For users, the upshot is simple: the agent promises to book a ticket, and in practice hits a locked door.