Consumer AI agents are moving from conversation to action, but the web they are supposed to operate is not consistently ready to receive them. TechCrunch reports that assistants such as Meta’s Muse, Instinct and ChatGPT’s Dots can attempt tasks including buying groceries, booking flights and making restaurant reservations. The problem is that the website on the other side may treat the agent as an unwanted bot rather than as a customer’s authorized representative.

The conflict is already visible in retail. Amazon recently began blocking Muse from browsing or purchasing through its store, according to TechCrunch. Users have also complained that Muse could not complete Walmart purchases, but Walmart said those failures were not intentional. Walmart is a Muse partner and told the publication that it wants to be available wherever its customers are, including through agent experiences.

A security checkpoint tries to distinguish an authorized AI agent from a malicious bot.
Existing human-verification systems can block a legitimate assistant even when the website wants the customer’s business.

In Walmart’s case, the apparent obstacle is a familiar human-verification step. If an interaction with the verification button is interrupted, TechCrunch reports, the check can fail and eject the agent. That distinction matters: an agent may be denied because a company objects to automated access, or because an anti-spam system cannot tell an authorized assistant from abusive automation. To the person whose purchase failed, both situations can look like the agent simply does not work.

A group of technology and commerce companies is now working on an open standard intended to separate agents acting for users from malicious bots. TechCrunch says the participants include Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE and Decagon. Meta described the planned protocol as focused on agent-to-agent communication for online commerce. The report does not yet establish the standard’s technical details, adoption timetable or whether companies outside the group will accept it.

Travel exposes the same problem with higher stakes. Delta told TechCrunch that it currently has no partnership or integration allowing a third-party agent to shop for or book flights on a customer’s behalf, while it evaluates how such technology could fit with security and customer experience. United did not say whether it blocks particular personal agents, but pointed to terms that prohibit robots, spiders and other automated methods from monitoring or copying its site without prior written permission.

A common protocol bridge links retail, airline and restaurant doors with uneven access.
Partnerships and a proposed commerce standard may clarify where agents are welcome, but adoption and technical details remain unsettled.

Other platforms draw their boundaries around commercial agreements and authorized use. Yelp said it does not allow non-human traffic unless an agent has paid for access through its data-licensing program, meaning an unpartnered assistant may fail when trying to request a quote, join a waitlist or reserve a table. eBay said it does not prohibit every third-party shopping agent, but restricts unauthorized agents and activities such as automated scraping and model training. Reports that some users had accounts suspended remain user claims rather than a conclusion established by TechCrunch.

Infrastructure providers add another layer. Cloudflare offers tools that let sites manage automated traffic and block AI systems that may be collecting training data. TechCrunch notes that a September 15 change to crawler defaults may have affected how existing protections treat agents on pages carrying ads, but Cloudflare said it had no specific data to share about personal-agent blocking. Its public Radar service shows rising bot activity without separating useful agents from harmful ones.

The result is a permission problem disguised as a performance problem. Agents cannot become dependable substitutes for browsing if every transaction depends on a CAPTCHA, a terms-of-service restriction or a private partnership the user cannot see. Meta’s connector list gives Muse users some indication of where the agent is officially welcome, and its brand partnerships create a route for reporting access failures as bugs. A broader solution will require websites to recognize delegated authority while retaining control over fraud, scraping and unwanted automation—a balance that the proposed standard has not yet proved it can deliver.