When Meta Muse Works for Someone Else: Governing Brand Risk in Agentic Commerce

Key takeaways

Meta Muse now decides which brands a buyer sees. When the agent's owner also earns from the transaction, brand discovery stops being neutral. Here is how to tell the difference and what to govern.

The myth: Meta Muse is your customer's advocate

The comfortable story about Meta Muse goes like this. A buyer tells Muse what they want. Muse researches every option, ignores sponsored placements, and returns the objectively best product at the best price. The buyer wins. Good products win. The middlemen who profited from confusion lose.

Some of that is true. Muse does collapse comparison work that used to take an hour of tab-switching. It does ignore the visual noise of a search results page. And it does punish businesses whose entire model was built on customer inertia, which is exactly why Expedia, Booking Holdings, and several banks saw their shares slide in the days after it launched.

But the comfortable story has a hole in it. Muse is not a neutral referee. It is a product, owned by a company, with a business model. When that company also earns from the transaction Muse completes, the recommendation stops being purely a function of product quality.

This article is about that hole, how to tell when it matters, and what a brand can actually govern.

Why the myth spreads

The myth is appealing because it matches how Meta describes the product. Meta's own framing positions Muse as working for the user: it asks for approval before sensitive actions, it runs in an isolated per-user VM, and Meta says it cannot see your passwords or payment methods.

All of that can be true and still leave the incentive question open. A concierge who cannot see your wallet is still a concierge who gets paid by certain hotels.

The myth also spreads because the alternative is uncomfortable. If agent recommendations are partly shaped by commercial relationships, then "optimize your product data" is necessary but not sufficient. Brands would have to think about which agent surfaces they can be reached on, and on what terms. That is a harder conversation than a checklist.

The more useful reality

Treat the agent as a distribution channel with its own economics, not as a neutral utility.

That single reframe resolves most of the confusion. Distribution channels have always had their own incentives. Retail shelf space is sold. Search results carry ads. App stores take a cut and set placement rules. Agentic commerce does not invent this dynamic. It moves it up a layer, from the results page to the decision itself.

The question to ask is not "is the agent biased?" Every channel is. The question is: where does the agent's owner make money, and does that align with my product being recommended?

There are three distinct business models in play right now, and they produce very different outcomes for brands.

Model

Who earns

What it means for you

Permissioned partner channel

Platform takes a transaction fee from completed orders

Being in the catalog matters; data quality and availability drive selection

Walled garden

Platform keeps the customer relationship and the ad revenue

You may be excluded regardless of product quality

Agent-owned commerce

The agent's owner sells its own inventory or takes the margin

You compete against the house, on the house's terms

Shopify's arrangement with Muse looks like the first model. Amazon's block looks like the second. Amazon's own Alexa for Shopping and Buy for Me sit closer to the third, since Amazon both runs the agent and sells the goods.

Comparison table of three agent business models: permissioned partner, walled garden, and agent-owned commerce

The three agent business models produce very different outcomes for brands. Which one you are in determines how much of your visibility you actually control.

What the Amazon block actually revealed

The most instructive thing about Amazon's September 20 block is not that it happened. It is how it happened.

Amazon did not win this argument in court. It tried. In November 2025 Amazon sued Perplexity over the Comet browser's agent. In March 2026 a federal judge barred that agent from password-protected parts of Amazon's site. Then on August 4, 2026, a federal appeals court reversed that order, reasoning that when an agent follows a shopper's instruction, the shopper is the one using the site.

Faced with that, Amazon changed tactics. Instead of arguing the agent broke in, it invoked the terms every customer already accepted. The popup Muse users saw said continued access by an unauthorized AI agent violates Amazon's Conditions of Use "to which our customers have agreed."

That is a governance move, not a technical one. It puts the decision back on the customer's own contract and lets Amazon set the terms of entry without needing a court to agree that the agent did something wrong.

For brands, three lessons follow.

First, access is contractual, not technical. A robots.txt directive and a terms-of-service clause are separate doors. Either can close. If your channel strategy assumes open access, you are assuming something no platform has promised.

Second, the platform holding the customer account holds the leverage. Amazon could block Muse because Amazon owns the shopper's account, order history, and payment relationship. Meta could bar general-purpose chatbots from WhatsApp's business messaging for the same reason. Whoever owns the account sets the rules.

Third, precedent cuts both ways. The appeals court ruling that favored agents also means platforms cannot easily claim an agent "broke in" when it follows a user's instruction. That pushes disputes out of the courtroom and into terms of service, where platforms have more control and brands have less visibility.

What to do instead

You cannot govern Meta's or Amazon's incentives. You can govern your own exposure and your own evidence.

Map your agent-reachability by channel. For each channel that produces revenue, write down which agents can complete a purchase there today, and who owns the customer account. This is a one-page artifact, not a project. Update it quarterly, because the terms change faster than the technology.

Read the terms that govern automated access. Not the marketing page. The Conditions of Use or the merchant agreement. Look specifically for language about automated agents, data collection tools, and third-party purchasing on behalf of customers. Amazon's clause predates Muse by years and was sitting there the whole time.

Build the evidence an agent needs to recommend you confidently. This is the part you control, and it is the same work regardless of which agent is asking. Agents cross-check claims against third-party sources: reviews, comparison pages, editorial coverage, forum discussion. If your product's stated advantages are not corroborated anywhere outside your own site, the agent has less reason to trust them.

Diversify the surfaces you can be reached on. A brand that can only be bought through one agent-reachable channel has a single point of failure that someone else controls. Shopify, PayPal, and Stripe Link merchants are reachable today. Direct storefronts are reachable if they accept an agent-capable payment rail. Owning at least one path you control is a risk decision, not a growth tactic.

Log what you cannot yet measure. Agent-originated orders are tagged in some systems and invisible in others. Start recording what you can see now, even when the number is zero, so you have a baseline when volume arrives.

Example: weak posture vs defensible posture

Question

Weak posture

Defensible posture

Where can agents buy from us?

"We're on Amazon"

Named list of agent-reachable channels, with account owner noted

What do our terms allow?

Never read

Reviewed annually, flagged for automated-access clauses

Why should an agent trust us?

Our own product page says so

Third-party reviews, comparisons, and coverage corroborate claims

What if a channel closes?

No plan

At least one agent-reachable path we control

How do we know it's working?

"AI traffic is up"

Recommendation share and completed agent orders, logged monthly

The left column is where most brands are today. It is not a failure of effort. It is a failure of framing: they are optimizing content for a channel they have not audited for access.

Guardrails

Three things to avoid as this space develops.

Do not assume partnership equals permanence. Shopify and Meta can change terms. PayPal's integration is new. Expedia's economics are undisclosed. Treat every open channel as open today, not open forever.

Do not optimize for a ranking formula that has not been published. Meta has not disclosed how Muse selects products. Shopify says ranking factors vary by platform and may include data quality, relevance, availability, pricing, and engagement. Anyone offering a guaranteed Muse placement is selling something they cannot deliver.

Do not confuse visibility with reachability. Being cited in an AI answer and being purchasable through an AI agent are different achievements. A brand can win the mention and still lose the sale because the agent cannot complete checkout. Track both.

FAQ

Is it proven that Meta favors its partners in Muse recommendations? No. Meta has not published its selection logic, and no partner has disclosed ranking influence or commission terms. The concern is reasonable and testable, but it is not established fact. Treat it as a risk to monitor, not a conclusion to act on.

Does this mean I should avoid agent-reachable channels? No. Shopify's Q1 2026 data showed AI-driven traffic to its stores up 8x year over year and AI-originated orders up roughly 13x. Avoiding the channel means avoiding the demand. The point is to enter with your eyes open about who controls access.

What is the single highest-value thing I can do this quarter? Map agent reachability by channel and read the automated-access terms for your top three revenue channels. It takes a few hours and it tells you where you are actually exposed.

How is this different from normal platform risk? It is the same category of risk with a faster clock. Platform rules have always mattered, but agent terms are changing monthly right now, and the decisions are being made by a small number of companies.

Will regulators step in? Unknown. The Perplexity litigation shows courts are willing to treat the shopper as the actor in charge, which favors agents. But that ruling addressed access, not recommendation fairness. Whether anyone regulates agent recommendation incentives is an open question.

Auspia's view

The shift worth taking seriously is not that agents will shop. It is that the decision layer is consolidating into a handful of companies that also have commercial interests in the outcome.

That does not make agentic commerce a trap. It makes it a channel, and channels have owners. The brands that handle this well will do what good operators have always done with a powerful intermediary: understand the terms, diversify the paths they control, and build evidence strong enough that a recommendation is defensible on the merits.

GEO work does not disappear in this world. It gets a second requirement attached. Being understood by the agent is the first job. Being reachable by it is the second. Brands that only do the first will keep wondering why the mention did not turn into an order.

Author: Grace Miller, AI Search Risk Analyst Tracking 200+ Policy Shifts at Auspia. Grace writes about platform rules, agent commerce risk, and policy-aware optimization for growth teams.

Explore this topic

Keep following the same growth thread