Amazon Just Blocked a Shopper's AI Agent by Citing Its Terms of Use. That Page on Your Dealership's Website Is Now a Business Decision.
Amazon cut off Meta's new Muse agent on Sunday night with a popup quoting its Conditions of Use. Six weeks earlier the Ninth Circuit took away Amazon's other weapon. Here is why that moves the AI agent fight onto a page nobody at your dealership has read.
Adam founded Savvy Dealer and has spent 30 years at the intersection of automotive retail and digital strategy.

Want to Learn More?
Book a quick demo to see these strategies in action.
On Sunday night, shoppers who asked Meta's new Muse agent to buy something on Amazon got a popup instead of a purchase. The message read: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed."
That is GeekWire's reporting, confirmed by several outlets Monday morning. Amazon says Meta never told it that Muse would be shopping the store, that the agent does not identify itself when it browses, and that it appears to capture and store customer credentials. Meta points to how Muse is built: a dedicated secure virtual machine, explicit user sign-off before a purchase, one-time virtual cards at checkout. Talks between the two companies are reportedly still going.
Read the sentence in that popup again. The load-bearing word is "agreed."
Amazon did not say the agent broke in. Amazon said the customer already promised not to send it.
Amazon lost the other argument six weeks ago
This is the second round of the same fight, and the first round is why the second one looks like this.
In November 2025 Amazon sued Perplexity over the shopping agent inside its Comet browser, arguing the company had disguised its bot as ordinary Chrome traffic. In March, a federal judge granted Amazon a preliminary injunction, finding that Comet reached into Amazon accounts with the shopper's permission but without Amazon's.
On August 4, the Ninth Circuit threw that out. In Amazon.com Services, LLC v. Perplexity AI, Inc., the panel vacated the injunction and sent the case back down. Its reasoning turns on one deceptively small question: who actually touched the server? The opinion answers plainly. "Perplexity itself does not directly communicate with Amazon's servers." Instead, "it was the user who 'accessed' Amazon's computers, with the help of Perplexity's AI agent."
The Computer Fraud and Abuse Act punishes whoever intentionally accesses a protected computer without authorization. If the shopper is the one accessing, and the shopper is allowed to be there, the statute has nothing to grab. The court was careful to fence in what it had decided: "We do not establish a new legal regime governing agentic AI."
The law firm Cooley read the limits the same way, noting the panel confined itself to the CFAA and its California analogue and left open that the identical conduct could still support claims sounding in tort or contract. Breach of terms of service survived.
So when Amazon moved against Muse six weeks later, it did not reach for the hacking statute. It reached for the user agreement. An Amazon spokesperson framed it as a matter of manners between businesses: third-party applications making purchases on behalf of customers should respect merchants' policies and decisions about their platforms.
That is the whole shift in one line. For most of the web's history, deciding who gets to touch your website was an engineering job. Robots.txt, user-agent strings, IP blocks, rate limits. All of it technical, all of it a request rather than a rule. The document that governs agentic shopping is the one your lawyer wrote and your web vendor pasted in.
What this means for your dealership
Start with the Amazon quote, because you are on the receiving end of it. A franchised dealership is a merchant with a platform and a policy. Right now, that policy is a link in your footer.
Crawling and transacting are two different fights, and dealers keep merging them. We have written a lot about letting AI crawlers in, because visibility in an AI answer depends on being readable. That argument has not changed. This is the other half. An agent that reads your VDP so ChatGPT can cite you is doing something completely different from an agent that fills out your lead form, requests an out-the-door number, books a test drive, and negotiates a trade number while its owner is asleep. You want the first one. The second one deserves an actual decision.
Meta is advertising the car version of this by name. In its own launch post, Meta lists "selling a car for more, lowering a bill" among the goals Muse can take on, and says the agent "can open a browser, fill out forms, and negotiate on their behalf." Muse rolled out in the US in September on iOS, Android, and the web. The plumbing that just got pointed at Amazon is pointed at car buying too, and your dealership's website is an unprotected, publicly reachable retail surface with forms all over it.
Your terms of use page is now a live wire. Go read yours today. Most dealer sites carry a section on automated access that was written to stop scrapers and price-harvesting bots years before shopper agents existed. Whatever it says, it now says it about your customer's assistant. If it bans all automated access, you have quietly told the fastest-growing category of car shopper that their agent is unwelcome, at the same time your marketing team is spending money to be visible to AI. If it is silent, you have no basis to complain when something abusive shows up. Neither outcome is a strategy.
Your inventory sits on platforms whose terms are not yours. If you list on third-party marketplaces, their Conditions of Use decide whether a shopper's agent may transact against your vehicles. You did not write that policy and you do not get a vote. Amazon Autos makes this concrete: it works with more than 1,000 participating dealers across 130-plus US cities, carrying new, used and CPO inventory from franchised stores. If your inventory is there, Amazon's agent policy is already your agent policy.
Agent-submitted leads will break assumptions in your BDC. Speed-to-lead scripts assume a human is holding a phone. An agent-generated inquiry may arrive at 2am, respond to email at machine speed, ask for a specific figure, and disappear if you answer with "when can you come in?" Your spam filters may also start eating these, because they look like bot traffic, which is exactly what they are. The difference between a bot to block and a buyer to greet is now a judgment call, and nobody at the store has been asked to make it.
Amazon is the loudest example of a pattern, and it keeps winning practically even when it loses legally. It sued Perplexity, it has moved to block shopping agents from Google and OpenAI, and it lost the appeal in August and then blocked Meta anyway six weeks later. A merchant does not need a court to enforce a policy in the moment. It needs a popup.
What to do about it
- Pull up your website's terms of use and read the automated access clause out loud. If you cannot find it, that is your answer. Decide, as a business, whether a shopper's agent acting on that shopper's instruction is permitted.
- Separate the two policies in writing. Crawling for visibility: allow broadly. Transacting on your forms: define what is allowed, what requires identification, and what gets blocked. They should not share one rule.
- Ask your website vendor one question. "If a customer's AI agent fills out my lead form, what happens right now?" You want to know whether it is blocked, silently dropped, tagged, or passed straight to your CRM as a normal lead.
- Tag agent traffic before you decide anything else. You cannot manage volume you cannot see. Get agent-sourced form fills labeled in your CRM so you can measure close rate against human submissions instead of guessing.
- Check the terms on every marketplace carrying your inventory. Find out whether they permit, block, or stay silent on agentic purchases. That policy governs your cars regardless of what you decide locally.
- Brief your BDC on what an agent inquiry looks like and what a good reply is. An answer that gives a real number will outperform an answer that asks for an appointment, because the thing reading it cannot drive to your store.
The companies fighting over this right now are Amazon, Meta, Google, OpenAI and Perplexity, and none of them are going to settle it in a way that considers your rooftop. What they are doing is establishing the layer where the fight happens, and that layer turned out to be the user agreement.
Every dealer has one. Almost nobody has read theirs since the day it was installed. This week is a good week to change that.
Want to know how your site currently handles AI crawlers and agents before you write a policy about them? See what our AI compatibility work looks like, or book a walkthrough and we will go through your site with you.
Get Our Answers in Your Google Results
Add Savvy Dealer as a preferred source and Google highlights our articles with a Preferred badge in AI Overviews, AI Mode, and Top Stories. One click, then check the box next to savvydealer.com.
Ready to Transform Your Dealership's Marketing?
Schedule a free demo to see how Savvy Dealer can help you sell more cars.