Why Websites Are Blocking AI Agents (And What Happens Next)

TL;DR

A new wave of personal AI agents can shop, book and reserve on your behalf, but many websites are shutting them out. Amazon has blocked Meta’s Muse agent, airlines and review sites restrict automated tools, and Cloudflare changed its defaults in September 2026 in ways that can block agents on pages with ads. Some blocks are deliberate. Others are accidents caused by old anti-bot checks. The industry is now working on shared rules so websites can tell helpful agents from harmful bots, but until those rules arrive, expect plenty of “it just didn’t work” moments.

Imagine telling an app, “Book me a table for two on Friday,” and watching it fail with no explanation. You don’t know if the restaurant’s site is broken, the app is bad, or someone decided the AI isn’t allowed in. That’s the situation many early users of personal AI agents are in right now.


What are personal AI agents, and why does this matter?

A personal AI agent doesn’t just answer questions. It does things for you: it books flights, orders groceries, makes reservations and buys products. Meta’s Muse is one example. At Meta’s Connect conference in September 2026, the company announced shopping partnerships with Walmart, Best Buy, Gap, Sephora and Wayfair, plus deals with Stripe and Shopify so Muse can search Shopify’s product catalog and pay through options like Shop Pay and PayPal, according to TechCrunch’s coverage.

For this to work, the agent has to visit websites the same way you would. And that’s where trouble starts, because many websites were built to keep automated visitors out.

Why websites block agents

There are two very different reasons a site might turn an agent away, and users usually can’t tell which one they’re facing.

1. The block is on purpose. Amazon is the clearest example. In September 2026 it blocked Meta’s Muse from its retail site. Amazon said Meta never asked permission, and that continued access by an unauthorized agent breaks its Conditions of Use, according to Cybernews. Amazon also uses its robots.txt file to block other AI tools, including ChatGPT, Claude, Copilot, Perplexity and Grok, while allowing its own shopping assistant, Alexa for Shopping.

Other companies take a similar line. Delta told TechCrunch it has no partnership that lets a third-party AI agent book flights, and that any opening would have to be done with security and customer experience in mind. United pointed to its Terms of Use, which ban robots and automatic tools without written permission. Yelp said it allows non-human traffic only if the agent pays for access through its data licensing program. eBay said it doesn’t ban every shopping agent, but restricts unauthorized ones and actions like scraping and model training.

2. The block is an accident. Walmart is a useful case. It has an official partnership with Muse, yet some users complained they couldn’t finish purchases. Walmart told TechCrunch these failures weren’t intentional. The likely cause is a “prove you’re human” button. If an agent can’t click it properly, the check fails and the agent gets kicked out.

That’s the heart of the problem. The security checks websites use today were designed for a world of humans on one side and bad bots on the other. A helpful agent acting for a real customer doesn’t fit either box.

The role of the infrastructure companies

Many websites rely on services like Cloudflare to filter out unwanted automated traffic. On September 15, 2026, Cloudflare changed its default settings for how it treats crawlers that do more than one job. Its own blog explains that a site can now block AI training while still allowing search. For newer domains that earn money through ads, Cloudflare’s defaults go further: search stays allowed, AI training is blocked, and AI agents are blocked on pages with ads, because AI summaries and agents can reduce the number of real visitors who see those ads.

Some users suspect this is behind some of the Muse failures. Cloudflare told TechCrunch it had no specific data to share on that, so treat it as a theory, not a confirmed cause.

How much of the web is already automated?

The scale explains why websites are nervous.

  • Cloudflare’s public Radar dashboard showed bots passing humans in share of HTML requests on April 27, 2026: roughly 57.5% bot traffic versus 42.5% human, according to reporting on the data. Cloudflare’s CEO said it happened faster than he had predicted.
  • HUMAN Security’s 2026 State of AI Traffic report found AI-driven traffic grew 187% during 2025. Automated traffic grew 23.5% year over year, while human traffic grew only 3.1%. Traffic from “agentic browsers” jumped 7,851%.

With numbers like that, it’s easy to see why website owners are cautious. They aren’t only worried about helpful shopping agents. They’re worried about scrapers, fraud and unpaid use of their data, and their tools often can’t tell the difference.

What could fix it

The most likely answer is shared rules that let websites know who an agent is and who it works for.

  • The Personal Agent Protocol. Meta and Sierra are developing an open standard called the Personal Agent Protocol, which sets out how personal AI agents work with businesses. Sierra’s announcement lists Genesys, Instinct, Rocket, Shopify, Stripe and Walmart as industry partners (TechCrunch’s list also names NiCE and Decagon). The idea is to replace the current approach, where agents click through websites like a person, which Sierra calls slow and unreliable, with a direct and secure connection. It relies on OAuth sign-in: the user decides what the agent may do (read-only or able to make changes), and the business decides what agents are allowed to do through its website, its APIs or its own agent. Sierra said a first draft (version 0.1) would be published soon after the announcement, so the details may still change.
  • Universal Commerce Protocol (UCP). Another effort, announced earlier in April 2026, is an open standard covering product discovery, cart building, checkout and after-purchase steps. Its tech council started with Google, Shopify, Etsy, Target and Wayfair, and later added Amazon, Meta, Microsoft, Salesforce and Stripe.
  • Direct partnerships. Meta is also signing individual retailers, so that for those partners any access problem is a bug that can be fixed rather than a mystery.

It’s worth noting that Amazon, which blocks Muse, is also a UCP council member. That shows how split the industry still is: companies can support shared standards and still decide who gets through their front door.

What this means for different people

If you use AI agents: Expect inconsistent results, especially on big retail, travel and review sites. If an agent fails, the cause may be a deliberate policy, not a bug in the tool.

If you run a website or online store: Decide on purpose whether agents are welcome. A blanket anti-bot setting can quietly turn away real customers who shop through an agent. Review your bot-protection and CAPTCHA settings, and check whether your CDN’s defaults changed in September.

If you build AI agents: Formal partnerships and clear identification are likely to matter more than clever workarounds. Sites are more willing to let in agents that ask permission and follow shared rules.

The bottom line

Websites aren’t simply “for” or “against” AI agents. They’re split between protecting their data, their ad revenue and their security, and not wanting to lose customers who now shop through an agent. Until shared standards exist, agents will keep running into doors that were never built for them. The companies that figure out trusted, clearly identified access first will likely win the next phase of online shopping.

Related Buzz: We also covered [Why AI Startups Make Less Profit Than Normal Software Companies]