The next hurdle for AI agents: getting websites to let them in

Personal AI agents from companies like Meta, OpenAI and others are beginning to perform transactions on users’ behalf, but many websites are blocking those agents either deliberately or via conventional anti-bot defenses. Industry players including Meta, Walmart and Stripe are now working on an open standard for agent-to-business communication to let legitimate agents transact while keeping malicious automation out.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 1 minute agoUpdated 1 minute ago0 views
The next hurdle for AI agents: getting websites to let them in

Why It Matters

If websites and online services continue to block legitimate AI agents, consumers will face broken experiences and frustration even when merchants and agents intend to interoperate. A protocol that distinguishes authorized agent actions from malicious bots could enable commerce via agents while preserving site security and anti-abuse protections.

Key Facts

  • Examples of consumer AI agents: Meta’s Muse, Instinct, ChatGPT’s Dots (and others)
  • Notable blocking incident: Amazon blocked Meta’s Muse from browsing and purchasing on its retail site
  • Companies working on a standard: Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE, Decagon
  • Walmart relationship with Muse: Walmart announced a partnership with Meta’s Muse at Meta’s Connect developer conference in September
  • Airline responses: Delta says it has no third-party agent partnerships and is evaluating agents with security and UX in mind; United points to Terms of Use forbidding automated access without prior written permission

Personal AI assistants — such as Meta’s Muse, Instinct, and ChatGPT’s Dots — are being positioned to act on users’ behalf for tasks like booking flights, making reservations and shopping. While these agents can automate interactions that previously required manual input, users have reported frequent failures when agents try to interact with third-party websites. Some of those failures are deliberate blocks by sites, while others appear to stem from conventional anti-bot systems that cannot distinguish legitimate agent activity from malicious automation. High-profile examples have surfaced publicly: Amazon recently blocked Muse from accessing its retail catalog and completing purchases. Social-media complaints also described Muse failing to complete purchases on Walmart’s site, though Walmart says those issues are not intentional and that it is partnered with Muse. In many reported cases the failure follows an interrupted human-verification flow (a click or similar interaction), which causes the site’s bot-protection check to fail and eject the agent. Beyond retail, travel sites and airlines have been cited as places where agents run into resistance. Delta told reporters it does not currently support third-party AI agents booking flights on its platforms and is weighing any opening carefully with security and customer experience in mind. United’s published terms prohibit automated access without written permission. Other platforms such as Yelp require paid data-access agreements for non-human traffic, and eBay says it restricts unauthorized automated actions while not banning all shopping agents outright. To reduce user confusion and enable legitimate commerce via agents, a group of industry partners including Meta, Walmart, Stripe and others are developing an open protocol focused on agent-to-agent communication for online commerce. The stated goal is to create a way for businesses and agents to identify and authorize “good” agents acting for users while continuing to block abusive or data-scraping automation. Meanwhile, users remain caught between service providers and merchants when a site’s existing anti-bot tooling blocks agent activity, producing inconsistent experiences across different services.

Keep Reading