Personal AI agents are moving from chat into action. Tools such as Meta’s Muse, Instinct, ChatGPT’s Dots and others are being positioned as helpers that can complete tasks for users, including booking flights, making dinner reservations and ordering groceries.
The hard part is no longer only whether an AI agent can understand the request. Increasingly, the question is whether the website on the other side will let it in.
Why AI agents are getting blocked
The latest flashpoint came when Amazon began blocking Meta’s Muse AI agent from its retail site. That meant Muse could no longer browse or make purchases from Amazon’s product catalog.
But the issue is broader than Amazon or Muse. Users have complained across social media that personal AI agents are being stopped on a range of websites. Some blocks appear intentional. Others seem to be caused by existing anti-bot systems that were designed to reduce spam, fraud and malicious automated activity.
That distinction matters for consumers. From the user’s point of view, a failed transaction looks like a broken promise: the agent was supposed to complete the job, and the business was supposed to accept the customer’s order or request. The user may not know whether the block came from a deliberate policy, a security system, a failed human check or a technical bug.
Walmart shows how confusing this can get. TechCrunch saw social media complaints claiming Muse could not complete purchases on Walmart’s retail website, and NBC also reported that Walmart had faced this problem in tests of the AI agent. Yet Walmart said the blocks were not intentional. The company is partnered with Muse, a relationship announced at Meta’s Connect developer conference in September, and said it wants to be available where its customers are, including through AI agent experiences.
The problem users appeared to hit was a human-verification button. If that process was interrupted, the check could fail and the agent could be pushed out. In other words, even a retailer that wants to support agents can still be tripped up by defenses built for a different kind of automated web traffic.
The old bot rules do not map cleanly onto agent shopping
Websites have long treated automation with suspicion. That made sense in a world where bots were often associated with scraping, spam, credential attacks or other unwanted activity. Personal AI agents complicate that picture because they may be automated but still acting for a real customer.
This is the core tension. A website wants to protect itself, its users and its content. A consumer wants an assistant that can carry out a task without getting stuck at every login, checkout, waitlist or booking flow. The agent provider wants enough access to deliver the service it promised.
The airline example makes the stakes clear. Flight booking is one of the main use cases being promoted for agents, but users have reported that airlines have rejected agent requests. Delta said it is taking steps to protect customers from unauthorized automated activity and that opening up to AI agents would have to be done with “security and the customer experience in mind.”
Delta’s general manager of Global Communications, Heena Chavda, said: “While Delta does not currently have a partnership or integration that enables a third-party AI agent to shop for or book Delta flights on a customer’s behalf on our digital platforms, we’re continuing to evaluate how new technology, including external AI agents, could enhance the way customers engage with Delta,”
United pointed to language in its Terms of Use policy stating that users agree “not to use any robot, spider, other automatic device, or manual process to monitor or copy this website or the content contained therein or for any other unauthorized purpose without United’s prior written permission.” United did not respond to a follow-up question about whether it was blocking specific personal AI agents such as Muse.
Some companies want partnerships before access
Different businesses are drawing the line in different places. Yelp told TechCrunch it does not permit non-human traffic on its platform unless the agent has paid to access Yelp’s content and data through its data licensing program. That means agents trying to use Yelp to get a quote, add a user to a waitlist or book a table will likely fail without a formal partnership.
eBay said its approach is not to prohibit all third-party shopping agents from completing purchases. Instead, its policies restrict unauthorized agents and actions such as automated scraping and model training.
Other brands named in early adopter complaints include Yelp, eBay, Zillow, Pizza Hut, Adidas and various airlines. Some users believe the blocking has increased recently. A couple of people said eBay suspended their accounts because of agentic AI use, and another complained that Google kicked out Instinct while it was cleaning up their Gmail inbox.
Adidas, Zillow and Pizza Hut either did not respond or declined to comment by the time of publication.
Cloudflare sits near the center of the traffic problem
Cloudflare is also part of the broader picture because it provides website protection against AI agents that could be training on site data and manages other automated activity. Some suspect that Cloudflare and similar content delivery networks are disrupting Muse traffic.
That suspicion has been linked to a change to crawler defaults on September 15. The change allows site owners to block AI training while still allowing other kinds of bots. Existing sites that had previously blocked AI bots for security reasons were then shifted to block AI agents on pages with ads.
Cloudflare told TechCrunch it did not have specific data to share about the blocking of personal AI agents such as Muse. It pointed instead to Cloudflare Radar, its free public data hub. That site shows the increase in bot activity, but it does not separate helpful bots from harmful ones.
Cloudflare also has a business interest in shaping this traffic. It now runs a marketplace where AI bots have to pay for the data they access, and it recently began testing a new web browser built specifically for AI agents.
The next step is trusted agent access
Industry partners including Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE and Decagon have begun working on an open standard for how AI agents can communicate with businesses. Meta said the protocol will focus specifically on agent-to-agent communication for online commerce.
The goal is to separate good bots acting on behalf of users from bad ones. That would give businesses a clearer way to decide which automated requests to allow, while giving consumers fewer unexplained failures when they ask an agent to complete a task.
Meta’s strategy for Muse points in the same direction. The company has formed brand partnerships and keeps a list of “connectors,” or partners, inside the Muse app. Many newly announced partners have not yet appeared in that list, but Muse’s expansion now includes partnered tools for small businesses, and a larger reorganization of the connector list is likely soon to be underway.
Meta framed the issue directly in its announcement: “Turning away a personal agent means turning away the customer behind it. We’d rather work with businesses to address the underlying concerns than see them lose that customer,” The company added: “There is a path that is good for users and good for businesses. It starts with clear norms, gives businesses more predictable control, and evolves toward a more efficient way for agents to work together.”
That is the unresolved future of AI agents on the web. Agents may be able to act for users, but the web’s businesses still have to decide when automated action counts as customer service and when it counts as unauthorized traffic.