Website security systems designed to block unwanted automation are creating new challenges for personal AI agents attempting to shop, book flights and complete transactions on behalf of users.
Some of those blocks are intentional. Others happen even when a business supports the agent, with anti-bot defenses interrupting an otherwise permitted transaction.
These failures are prompting companies to develop shared standards that could help websites recognize authorized agents while maintaining restrictions on unwanted automation.
Why It Matters: Existing bot defenses were designed to restrict automated activity, but personal AI agents are introducing a new category of traffic that may be authorized by customers and permitted by businesses. Security teams now face the challenge of verifying that authorization, defining what agents can access and preventing malicious automation from exploiting the same pathways. Emerging commerce standards could help make those distinctions more consistent across digital platforms.
- Bot Defenses Can Block Approved Retail Agents: Amazon has blocked Meta’s Muse from browsing and making purchases on its retail site. Walmart, meanwhile, has partnered with the agent but said customers were still encountering unintended purchase failures. The apparent problem was a human-verification button that could fail if the interaction was interrupted, causing the agent to lose access. Customers end up with an unfinished purchase in either case, though Walmart’s challenge is getting its security checks to work with an agent it has already agreed to support.
- Airlines Maintain Restrictions on Automated Access: While flight booking is becoming a common use case for personal AI agents, airlines have yet to establish a consistent approach to allowing them onto their platforms. Delta said it currently has no partnership or integration that would allow third-party agents to search for or book flights on behalf of customers, although it continues to evaluate the technology. United has taken a similar stance on unauthorized automation, citing restrictions in its terms of service without confirming whether it blocks specific agents.
- Platforms Set Different Rules for Agent Authorization: Companies are taking different approaches to managing AI agent access, with some allowing certain activities while restricting others. eBay permits third-party shopping agents to complete purchases under certain conditions, while Yelp requires agents to access its content and data through a licensing program. Zillow also allows agents working on behalf of consumers, though its anti-scraping defenses can sometimes block those requests.
- Infrastructure Defenses May Be Blocking Agent Traffic: Some users have questioned whether Cloudflare and other content delivery networks are contributing to Muse’s access problems, although no direct connection has been established. The speculation follows a September 15 change to Cloudflare’s crawler settings that separates AI-training restrictions from other bot activity and alters how certain existing settings apply to pages with ads. Cloudflare said it had no specific data to share about the personal-agent incidents.
- New Standards Could Help Verify Authorized Agents: Meta is working with Walmart, Stripe and several other companies to develop an open standard for agent-to-agent communication in online commerce. The effort aims to help businesses recognize agents acting on behalf of customers while maintaining control over what those agents can access and do. Meta already maintains a connector list within Muse, though some announced partners have yet to appear.
Go Deeper -> The next hurdle for AI agents: getting websites to let them in – TechCrunch


