Join OTP the operating platform for people and AI agents
Back to Blog
Founder Notes 2026-10-02 · David Steel

Block the agent that says who it is, and you are left with the ones that don't.

Amazon gave three reasons for blocking Meta's Muse shopping agent. Meta never told Amazon the agent would shop there. The agent did not identify itself while browsing. And Amazon said it appeared to capture and store customer account data without Amazon's knowledge.

The second reason is the important one, and it points at a trap.

"Third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate."

Amazon, as quoted by Yahoo Finance

Amazon is right that agents should operate openly. The trouble is what a block does to that goal.

A block only works on the honest

A website can only block a visitor it can recognize. An agent that announces itself, with a name in its request and a published list of addresses, is easy to recognize and easy to stop.

An agent that does not announce itself looks like a person. It may be running inside the customer's own browser, logged in as the customer, clicking the same buttons. A block cannot tell it apart from the human it works for.

So every rule that stops announced agents does two things at once. It stops the honest ones. And it tells every agent builder that the way to reach your customers is to stop announcing.

The banks learned this in 2015. When they cut off budgeting apps that logged in with customers' passwords, the apps did not vanish. As one report put it, it is "hard to distinguish these robo logins from hackers." The fix that eventually worked was not a better wall. It was a proper, identified connection where the bank could see who was asking and the customer could see what was shared.

You also lose the evidence

Here is the quieter cost. Traffic you block is traffic you cannot count.

The open question in agent shopping right now is demand. Only 3% of US adults say they would trust an agent to complete a purchase, per payments firm NMI. A third of active AI users told marketing firm VML they would never let an agent buy or even reorder for them. Amazon's own CEO said last year the customer experience "is not good."

Those numbers might mean agent shopping is years away. They might also be early numbers that move fast, the way ride sharing did. The only way a company finds out for its own customers is to see the traffic.

QVC is a good example of how hard that is even when you are open. Its head of product and technology strategy told the Journal the company cannot confirm whether agents have completed any purchases without extensive traffic analysis, and that older security systems built to stop bad actors may be blocking some agents without anyone deciding to.

If an open company cannot see its agent traffic, a closed one sees less. It is deciding blind and calling it caution.

What to ask for instead of a block

The demand behind Amazon's complaint is the right one: agents should say who they are, act only with the customer's permission and handle data openly. A company can require that without shutting the door.

  1. Identification. Agents that name themselves get in. Agents that do not get treated like any other unknown visitor.
  2. Customer permission. Meta says Muse asks the user's permission before buying anything. Make that a condition, not a hope.
  3. Limited payment. Meta also says Muse generates a one-time card number for each transaction. A purchase that cannot be reused for a second one is a smaller fraud risk.
  4. Browse first, buy later. Tapestry lets agents browse its brands' sites but not check out, and is building checkout so it is ready if that changes. That is a stage, not a wall.
  5. Measure it. Count agent visits, agent carts and agent orders as their own line. You cannot decide about a channel you cannot see.

What to do this week

  1. Ask your web or security lead one question: "Can we tell how many visits last month came from AI agents?" If the answer is no, that is the first fix.
  2. Check your bot settings in your CDN or firewall. Many have an AI or bot switch that was turned on by default.
  3. Run a free scan at agentready.sneeze.it. The Reach score shows whether agents can get in at all. Our own agency site scored zero on Reach the first time we scanned it, because our bot protection was blocking every agent, good and bad.

Frequently asked questions

Why did Amazon block Meta's Muse?

Amazon said Meta did not tell it Muse would shop on Amazon, that Muse did not identify itself as AI while browsing, and that it appeared to capture and store customer account data without Amazon's knowledge.

Can websites detect AI shopping agents?

Websites can detect agents that identify themselves by name or by published network addresses. Agents that run inside a customer's own browser, or that do not announce themselves, are much harder to tell apart from people.

Is it safer to block AI agents or allow them with rules?

Blocking stops only the agents that identify themselves. Allowing identified agents with conditions, such as customer permission, limited one-time payment and measurement, keeps the traffic visible and rewards agents for operating openly.

Sources

Put the decision on your agenda

OTP is readable from any MCP client, as an identified agent connection rather than a scraped page. In Claude Desktop, Cursor or any MCP client, add this block:

"otp": {
  "command": "npx",
  "args": ["-y", "@orgtp/mcp-server"]
}

Restart the client. Then ask: "Use OTP to show me Sneeze It's chart. Who owns each seat, and what number is each one measured on?"

Start free at orgtp.com. Every seat is free, for people and agents. You pay only for the AI you use.

The series

  1. Amazon blocked the AI shopping agents. History says the block is the risky part.
  2. Orlando's airport kept Uber out for years. The riders got picked up anyway.
  3. Block the agent that says who it is, and you are left with the ones that don't.
  4. Open, closed or ready: decide your company's AI agent policy on purpose.

All four on one page: When brands block the AI shopping agents.

Series: When brands block the AI shopping agents. Part 3 of 4. Read this post as markdown: /blog/block-the-honest-agent-keep-the-disguised-one.md.

DS
David Steel

Founder of OTP. Runs an AI agent army at a digital agency. Building OTP because nobody else seems to be building it. Notes from inside the build, not from the conference circuit.

More about David →

More posts on the blog index.

All posts