AI agents face website blocks as old bot defenses clash with new automation
Personal AI agents like Meta’s Muse are being blocked by major retailers and airlines, prompting industry leaders to develop a new open standard for agent-to-agent commerce.
Personal AI agents are hitting a wall of digital resistance as they attempt to perform tasks on behalf of users. Major platforms including Amazon, Delta, and Yelp are blocking or restricting access for agents like Meta’s Muse and ChatGPT’s Dots, causing friction for consumers who expect seamless automation. This conflict has accelerated efforts by tech giants and retailers to create a unified protocol for distinguishing helpful agents from malicious bots.
What happened
The rise of consumer-facing AI agents has introduced a new category of web traffic that existing infrastructure struggles to categorize. These agents do not just retrieve information; they execute actions such as booking flights, ordering groceries, and making reservations. However, users are increasingly reporting that these agents fail to complete transactions because websites block them. Amazon, for instance, actively blocks Meta’s Muse from browsing its catalog or making purchases. While some blocks are intentional policy decisions, others appear to be collateral damage from traditional anti-bot security measures.
The confusion is compounded by inconsistent responses from major retailers. Walmart, which announced a partnership with Muse at Meta’s Connect conference in September, claims it wants to support agent experiences. Yet, customers frequently encounter human verification checks that interrupt the agent’s workflow, causing the session to fail. A Walmart spokesperson stated these blocks were not intentional, attributing them to security checks that flag automated behavior. In contrast, Delta Air Lines explicitly stated it does not currently allow third-party agents to book flights, citing security and customer experience concerns. United Airlines points to terms of use that prohibit unauthorized automatic devices, though it did not confirm if it specifically targets personal AI agents.
Other major brands have also restricted access. Yelp requires non-human traffic to pay for data licensing, effectively blocking free agent usage for tasks like waitlist additions. eBay restricts unauthorized agents and scraping, leading to account suspensions for some users. Cloudflare, a major content delivery network, updated its crawler defaults on September 15 to allow site owners to block AI training while permitting other bots. This change may inadvertently block agents on pages with ads, though Cloudflare states it has no specific data on Muse traffic disruptions. The lack of clarity leaves users frustrated, unsure if the fault lies with the agent provider or the website owner.
How it works
Current web security relies heavily on distinguishing humans from bots using challenges like CAPTCHAs or behavioral analysis. These systems are designed to stop spam, scraping, and malicious automation. Personal AI agents, however, operate as automated scripts that mimic user interactions to complete tasks. When an agent encounters a security check requiring a human click or interaction, it often fails because it cannot pass the verification step intended for biological users. This creates a false positive where legitimate user intent is blocked by security protocols designed for threat prevention.
To resolve this, industry partners including Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE, and Decagon are developing an open standard for agent-to-agent communication. This protocol aims to create a verified channel for commerce-related interactions, allowing businesses to distinguish between "good" bots acting on behalf of users and "bad" bots engaging in scraping or attacks. By establishing clear norms and technical standards, the goal is to give businesses predictable control over agent access while ensuring users can rely on their agents to complete transactions without arbitrary blocks.
Key details
- Amazon actively blocks Meta’s Muse AI agent from browsing and purchasing on its retail site.
- Walmart partners with Muse but users still face blocks due to human verification checks interrupting agent workflows.
- Delta Air Lines explicitly prohibits third-party AI agents from booking flights on its digital platforms.
- Yelp blocks non-human traffic unless the agent pays for data licensing through its official program.
- Cloudflare updated crawler defaults on September 15, potentially affecting agent access on ad-supported pages.
- Meta and partners are building an open standard to differentiate legitimate commercial agents from malicious bots.
Why it matters
For software engineers and product builders, this friction highlights a critical gap in current web infrastructure. As AI agents become more prevalent, relying on legacy bot detection methods will lead to increased false positives and degraded user experiences. Developers building agent-enabled features must now consider how their tools interact with diverse security policies across the web. The lack of a universal standard means that every integration may require custom handling or risk being blocked, increasing development complexity and maintenance overhead.
The move toward an open standard signals a shift in how web access will be managed. Instead of treating all automation as a threat, the industry is moving toward a model of verified identity and intent. For technical founders and IT leads, this suggests that future-proofing applications will involve adopting these emerging protocols. Ignoring this shift could result in lost customers, as users abandon services that do not support the agent-mediated experiences they increasingly expect. The ability to distinguish between beneficial and harmful automation will become a core competency for web platform security.
What you can do
- Monitor your application logs for increased blocked requests from known AI agent user agents.
- Review your current bot detection rules to ensure they do not inadvertently block legitimate agent traffic.
- Stay informed about the developing open standard for agent-to-agent communication led by Meta and partners.
- Consider implementing explicit allow-lists for partnered AI agents if your business supports such integrations.
- Test your checkout and conversion flows with popular AI agents to identify potential friction points.
- Prepare to update your terms of service to clarify policies regarding authorized and unauthorized automated access.



