Amazon is blocking Meta's Muse outright; even Walmart, a launch partner, is failing the 'are you human?' check. An open standard is now in the works.
Personal AI agents that shop, book, and buy on a user's behalf are running into a wall most readers have already seen: the "verify you are human" button. Amazon is blocking Meta's Muse agent from its retail site, according to TechCrunch, preventing the agent from browsing or completing purchases. Walmart says it isn't blocking the agent on purpose. Its own human-verification flow is doing that.
Muse was announced at Meta's September 2026 developer event. Weeks later, the agent still cannot reliably complete a Walmart checkout. Amazon never integrated Muse and now blocks the agent outright. Both failures trace to the same technology: the "are you human?" check, which cannot distinguish a malicious script from a session started by a logged-in customer's authorized agent. NBC News has reported similar Muse friction at Walmart and Wayfair, and users on social media describe the same pattern at large travel and booking sites. End users pay the cost: they tap a button, hand the task to an assistant, and watch the agent fail at the same step a malicious script would. The user hired help and got bounced anyway.
For the past two years, the consumer-AI story has been about model capability: bigger context windows, more reliable tool use, better reasoning. The next phase sits at a different layer: the door of every retail, travel, and booking site, and the script that decides whether a logged-in user's authorized agent gets through or gets bounced.
Sierra, a customer-experience AI company, announced on its blog that an industry coalition is drafting an open standard it calls the Personal Agent Protocol, with a v0.1 specification planned for later this month. The published list of named partners includes Meta, Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. TechCrunch's reporting on the same coalition adds NiCE and Decagon and notes that no single governing body has yet published a canonical partner list, so the roster should be read as provisional.
The proposed standard does one thing: it gives a website a way to verify that an incoming request really is from an authorized human's agent, signed by a party the site can check, separate from the human-verification flow that exists to stop scripted abuse. With that channel, a retailer can let an authorized agent through, keep the anti-bot layer doing its job, and stop bouncing legitimate traffic. Without it, every site faces the same choice Amazon has already made: refuse the agent and lose the sale, or let the agent in and accept the risk.
Anti-bot measures exist for a real reason, and the protocol does not replace them. Account abuse, credential stuffing, and inventory hoarding by automated buyers cost retailers measurable money, and any system that whitelists agents will have to assume some of them get spoofed. The protocol adds a parallel lane: a way for a site to verify that an agent is acting for a logged-in customer, separate from the script designed to catch scripted abuse. With that lane, the same check that protects a checkout can also recognize the assistant a customer just hired.
The v0.1 specification is the next milestone. Sierra says it lands later this month. The unresolved questions are who governs the standard, how the verification credential gets issued, and whether the largest retailers adopt it before or after their own anti-bot stacks keep failing their own launch partners in public.
Walmart, for the moment, is one of those launch partners. The company told TechCrunch the failures are not intentional blocks. Users still see them.