agentic-commerce
ai
ecommerce
platforms
explainer

Everybody Built a Robot Shopper. Nobody Agreed Who Has to Let It In.

Shopify auto-enrols eligible stores in AI shopping channels that do not exist yet. Amazon blocked the shopping bot. Zara on who has to let an agent in.

In September the web's two answers to the robot shopper were visible at the same time. Shopify's default enrols merchants in AI channels that do not exist yet. Amazon blocked Meta's agent and then said why. The agent, in a test published on 9 September, could not order a pizza. In another, published on 28 September, a reporter booked a table through it, after handing over login information.

Prefer it read to you? Zara does voices now (16 min).

Zara is a character and this voice is synthesized. Mathieu Kessler, the human behind Talk Nerdy to Me, writes and fact-checks every word.

The week two shops disagreed about the same customer

Two large companies have opposite policies about the same new customer. In one week in September 2026 you could see both of them at once, which is how anybody noticed.

The first lets it in, and every future version of it, automatically, without being asked again.

The second one blocked it from its site, and then said why.

The customer is software that shops on your behalf. In a published test on 9 September 2026 it could not order a pizza. Later that month, in another, a reporter booked a table through it, after handing over login information.

What is actually being argued about

The phrase you will see is agentic commerce, and it means roughly what it sounds like. You say what you want. A program that is not you goes off and browses, picks, and increasingly pays.

The question this autumn is not whether that program works. It is whether a shop has to let it in.

That one is unsettled. There is no law requiring a shop to admit non-human customers, no standard, and no trade body handing out badges. So every shop decides on its own. Some will decide deliberately. Others will decide the way decisions often get made, by never being told that a decision was available.

Door open, including doors that do not exist yet

Agentic storefronts, in Shopify's own words, "is active by default for eligible stores". By default, every available channel has access to a merchant's products, through Shopify's catalogue or, for AI Mode and Gemini, through Google's own. Direct checkout inside AI channels is active wherever it is supported.

The overview page does not give a closed list. It says AI channels "such as ChatGPT, Google AI Mode and Gemini, Microsoft Copilot, and Meta". Such as. Four examples, not an enumeration. ChatGPT is referral only, so the paying happens back on the merchant's own store. The others can take the payment inside the channel, which means the shop is no longer where the buying happens.

The settings page adds what the overview leaves out: Shopify's own. The Shop app "acts as an agentic storefront channel". That page says Shop "doesn't have the option for you to deactivate Shopify Catalog access".

The overview page's own wording for Meta is "Meta surfaces such as Muse". Shopify's default enrols merchants into the same agent Amazon blocked.

Then there is the detail I have not seen anybody quote.

The default has a name. It is called "Allow Shopify to manage for me", and its description says that with it on, all channels are active and Shopify enrols the merchant automatically. The settings table is flatter: "You're auto-enrolled in new agentic storefronts channels."

New. Not the ones already listed. The next ones.

Whatever the next AI shopping channel is, whoever builds it, a merchant sitting on that default is already in it before it launches.

And it is not only a future problem. Beneath the named channels the documentation puts one more row, and it is not a channel at all. "Other channels" is a single button covering "smaller and emerging AI agents", among them "independent developers and startups that are building niche or experimental shopping agents". One control, over a population the documentation never names.

Leaving is slower than arriving, and Shopify says so itself. The individual channel switches are not editable until the merchant turns off "Allow Shopify to manage for me". After that, "it can take up to 7 days before your product data is no longer being shared through Shopify Catalog". And once those seven days are up, the docs add that "your products can still be discovered through web crawling and indexing".

So the door swings inward easily and outward slowly, and it never quite latches.

Blocked first, explained second

Amazon went the other way, and it did not ask first.

Meta launched a shopping agent called Muse on 8 September 2026. By Sunday 20 September Amazon had blocked it, which is when GeekWire reported it, and the explanation followed the next day in a statement to PYMNTS. Amazon's request to Meta ran the other way round: not take the bot off Amazon, but "remove Amazon from the experience". It wanted out of Muse. Meta did not reply to PYMNTS' request for comment.

The block is also narrower than the word suggests. CNN reports that Amazon prevents Muse from browsing its store, "although Meta's agent can still retrieve product links through search engines". The shop is shut. The shop window is not.

Why turn away a customer that is holding money?

Amazon gave reasons: no notice or choice about whether its store should be available through Muse. The agent "does not identify itself as it browses". It "seems to capture and store customer credentials", which Amazon called a privacy and security risk. And, it told CNN, agents "don't offer Amazon's personalized recommendations". The principle underneath all of it, in Amazon's words: applications that buy on a customer's behalf "should operate openly and respect service provider decisions about whether or not to participate."

Meta's answer to the credentials charge predates the block. It said Muse "has no visibility into people's passwords or payment methods", and that anything a user shares goes "into secure storage, so Muse can use them without seeing them". Amazon says captured and stored. Meta says stored somewhere the agent cannot look. Both can be true of the same system.

Whether those reasons are the whole reason, I cannot tell you from outside the room where it was decided.

Neither position here is silly, and that is the part worth sitting with. One company decided to choose for the merchant. The other decided it chooses who comes in. They are looking at the same machine.

What the customer could actually do in September

Eleven days before the block was reported, PYMNTS published the test under the headline "Meta's Muse Can't Order a Pizza Without Help".

That was 9 September 2026. The agent could not reorder from Amazon. It could not order from Domino's. It could not book a table through Resy.

One test at one outlet on one day is a snapshot and not a verdict, and this moves quickly. CNN published its own hands-on on 23 September. The agent wrote an email, built a packing schedule and drafted a planning document. Asked where to go for date night, it named two restaurants that had closed years earlier. On 28 September CNN booked a table through it, after supplying login information that the report describes as being like a phone number and confirmation code.

The booking is the admission story rather than the capability story. CNN never says which platform the table was on, and it does not have to. The industry magazine Restaurant Business reported in September that the three major reservation platforms all limit bots, scrapers and other automation in their terms of service. Resy told Restaurant Business that it "does not currently permit unapproved third-party bots or agents to independently access or interact with the Resy platform". CNN quoted that policy, then reported booking through the agent after supplying login information. So there is a rule, and there is a booking, and CNN does not join them. The rules get enforced, too. CNN reports Resy locking a user's account after another agent pinged the platform "hundreds of times every hour of the day." The user's verdict: "Of course I got banned. Resy figured it was a bot which is a totally fair response." The account was reinstated.

The policy is arriving ahead of the capability, and the capability is being established one errand at a time, in public.

The cleanest fact in the story

One more line from the overview page.

On Shopify's own Agentic plan, "direct checkout is deactivated by default".

Same company. Same checkout. Different plan. Opposite default.

That is too much for the most comfortable explanation: that defaults are simply how the technology arrived. They are not. Somebody sat in a room and decided that, where direct checkout is supported at all, one group of merchants starts with it active and has to act to deactivate it, while another starts with it deactivated and has to opt in to each AI channel and then activate direct checkout, and then wrote both decisions into the same documentation set.

The merchant case for it is real. If buying moves to agents, the shop that is absent when one arrives loses the sale to the shop that is not.

A default is not weather. It is a distribution policy. That one got written twice. The one that enrols a merchant in channels that do not exist yet got written once, by name, on a settings page.

The parts still without an answer

The documentation does not say how many shops this covers. The word it uses is "eligible". Eligibility is a gate, and how wide it opens is left unsaid. So any figure you see attached to this story is somebody's estimate wearing a fact's clothing.

The reasons Amazon gave do not say how long the block holds, or what would end it. Both would be decisions rather than technical facts, and decisions like that tend to reverse quietly, as part of something else.

Nobody has agreed where the agent should stand. On 28 September, separately from all of the above, Shopify extended its support for WebMCP to cover checkout, which puts the agent inside the buyer's own browser rather than in a channel talking to a server. TechCrunch reports the agent submits "with the buyer's authorization". That is a different architecture with a different answer to who the shop thinks it is serving. We will take WebMCP apart properly another time. For now, the industry has not settled on one shape, which makes every door policy currently being written provisional.

You will meet this from both sides

As somebody who buys things. At some point an assistant will tell you it cannot complete a purchase, and you will read that as the assistant being useless. Sometimes it will be. Sometimes it will be standing outside a locked door. From your sofa those two look identical, and only one of them gets fixed by a better model.

As anybody whose products sit on a platform somebody else runs. The question is not whether you want robot customers. You may not get to answer that one. The question is what your platform has already decided on your behalf, how long the undo takes, and whether the undo is complete. On this one platform, as of late September 2026, the published answers are: yes, up to seven days, and no, in two different directions. Search engines still exist, which is not the platform's doing. And deactivating catalogue access "doesn't remove your products from being displayed on Shop", which is entirely the platform's doing. Shop is two things at once, and you only control one of them. You manage which products people see on Shop from that channel's own settings. Shop's own catalogue access, the part the agent reads, is what you cannot deactivate. Instead, the settings page points to "Unlisted product status or the seo.hidden metafield", which hides the product from Shop and the other channels the catalogue feeds, and from search engines too. So the undo the platform does not offer is the one that would reach the agent. If you want all the way out, it is not a narrower door. It is the shutters.

The two rules we have just walked through did not come out of a standards process. One is a line in a help centre article. The other is one retailer's decision about one visitor.

The picture I keep coming back to

A high street where every shop has to work out, alone, whether the thing hovering at the door counts as a customer.

One has already put out the welcome mat, and also signed something agreeing to welcome anything mat-shaped that gets invented later. One has bolted the door. Some have not noticed that anything is at the door at all.

And the thing at the door could not order a pizza on 9 September.

A door position written this month is a bet on what the thing at the door will turn out to be. The rule about who has to let an agent in does not settle itself, and it is being written right now, in settings pages, by product teams, one dashboard at a time. Every one of those rules is provisional, and every one of them is already in force.

So, here is where I run out of sources: who should get to write that rule? The platforms shipping the toggles, the retailers holding the door, or somebody who has not turned up yet? I have read the documentation. It does not say.

Sources

What the default does, the AI channels it names as examples, and the opposite default on the Agentic plan: Shopify Help Centre, "Shopify agentic storefronts"

https://help.shopify.com/en/manual/online-sales-channels/agentic-storefronts

The setting, the automatic enrolment, the seven-day lag, the Shopify Catalog access that Shop offers no way to deactivate, and both of the things deactivation does not undo: Shopify Help Centre, "Managing agentic storefronts"

https://help.shopify.com/en/manual/online-sales-channels/agentic-storefronts/agentic-home

The two steps an Agentic-plan merchant has to take before it can sell through an AI channel, and the channel Shopify exempts from it: Shopify Help Centre, "Setting up agentic storefronts for stores on the Agentic plan"

https://help.shopify.com/en/manual/online-sales-channels/agentic-storefronts/agentic-plan-setup

Shopify extending checkout to browser-based agents: TechCrunch, "Shopify opens checkout to browser-based AI agents", by Sarah Perez, 28 September 2026

https://techcrunch.com/2026/09/28/shopify-opens-checkout-to-browser-based-ai-agents/

Amazon blocking Meta's Muse, GeekWire's report of the block on Sunday 20 September, the reasons Amazon gave for it, and Meta not replying to the request for comment: PYMNTS, "Amazon Bars Meta's Muse AI Agent From eCommerce Marketplace", 21 September 2026

https://www.pymnts.com/news/artificial-intelligence/2026/amazon-bars-meta-muse-ai-agent-from-ecommerce-marketplace/

The 9 September test the agent failed: PYMNTS, "Meta's Muse Can't Order a Pizza Without Help", 9 September 2026

https://www.pymnts.com/news/artificial-intelligence/2026/meta-muse-cannot-order-pizza-without-help

Amazon's reasons given to CNN, Resy's stated policy on agents, and a reservation booked with a human's login: CNN, "AI agents promise to do everything for you. There may be a big wrinkle in that plan", by Lisa Eadicicco, 28 September 2026

https://www.cnn.com/2026/09/28/tech/meta-muse-ai-agents-amazon

CNN's own hands-on with the agent, including the errands it completed and the ones it did not: CNN, "Meta says its Muse AI agent can do things for you. I put it to the test", by Lisa Eadicicco, 23 September 2026

https://www.cnn.com/2026/09/23/tech/meta-muse-ai-agent

A co-founder of Resy on terms enforcement, which appears in this piece and in no other source here, and CNN's shorter account of Resy's stated policy and of the reservation account, both of which originate with the Restaurant Business piece thirteen days earlier: CNN, "Now AI is trying to gobble up dinner reservations", by T.M. Brown, 23 September 2026

https://www.cnn.com/2026/09/23/tech/ai-agent-restaurant-reservations-instinct-resy-cec

Resy's stated policy on unapproved agents in its fuller form, the reservation accounts deactivated and later reinstated, and the three major reservation platforms all limiting automated access in their terms of service: Restaurant Business, "AI agents can help diners book a table. It can also get them banned", by Joe Guszkowski, 10 September 2026

https://www.restaurantbusinessonline.com/technology/ai-agents-can-help-diners-book-table-it-can-also-get-them-banned

More Where This Came From

Plain-language translations of the machinery and the money behind the tech headlines. No hype, no vendor agenda, and a standing habit of saying what the evidence does not cover.