AI Agents Hit Website Roadblocks as Retailers and Airlines Tighten Access
AI agents are running into website blocks from retailers, airlines, and anti-bot systems as companies debate how automated assistants should access their sites.
Personal AI agents are moving beyond answering questions to tasks such as shopping, booking flights, and making reservations. Still, a growing obstacle is emerging: many websites aren’t prepared to let them operate. Agents including Meta’s Muse, Instinct and ChatGPT’s Dots can act on a user’s behalf. Yet, those tasks can fail when retailers, airlines or security systems treat the agent as unwanted automated traffic.
The problem is not always deliberate. Some companies intentionally restrict automated agents, while others use long-standing anti-bot protections that can block an AI assistant even when it acts for a legitimate customer.
AI agents are colliding with existing website defences
Amazon recently blocked Meta’s Muse agent from its retail site, preventing it from browsing Amazon’s catalogue or completing purchases. That case clearly showed a company deliberately limiting an external AI agent’s access.
Walmart presents a different situation. Users have reported purchase failures involving Muse in more than one social media complaint, and NBC News previously reported problems during Walmart’s testing of the agent. Walmart, however, said the failures were not intentional and noted that it is working with Meta on Muse.
One source of difficulty appears to be human-verification systems. If a site requires a visitor to click a button confirming they are human, an AI agent can lose access when that verification process is interrupted or cannot be completed correctly.
That creates a basic technical conflict. Systems built to stop spam, scraping, and malicious bots often lack a reliable way to distinguish those bots from authorised personal agents acting for real customers.
Retailers and airlines are taking different approaches
The lack of consistent rules is already confusing early users. Some have described failed agent interactions, while others have reported similar problems with online services, commerce sites and other consumer platforms.
Reports on social media have named a wide range of companies and services. Users have described agents being blocked and separately cited problems across online services, including Yelp, eBay, Zillow, Pizza Hut and Adidas.
Other users have pointed to additional access failures, problems with agent-driven transactions and difficulties involving airlines. Some users have also argued that blocking has become more noticeable recently, although individual reports do not establish whether an intentional policy caused every failure.
Airlines illustrate why the distinction matters. Delta said it does not currently have a partnership or integration that allows a third-party AI agent to shop for or book Delta flights on a customer’s behalf through its digital platforms. The airline said it continues to evaluate external AI agents but would approach any access with security and customer experience in mind.
United Airlines pointed to its Terms of Use, which restrict unauthorised robots, spiders and other automated methods used to monitor or copy its website. The airline did not confirm whether it was specifically blocking particular personal AI agents.
Some complaints have involved consequences beyond a failed task. One eBay user said an account was suspended after using agentic AI, while another user reported that Google stopped Instinct while the agent was working with Gmail. These accounts remain user reports rather than evidence of a single industry-wide blocking policy.
Some companies require formal agent access
Yelp has taken a more explicit position. The company said it does not allow non-human traffic on its platform unless an agent has paid for access through Yelp’s data licensing program. An outside agent attempting to request a quote, join a waitlist or book a restaurant without such an arrangement may therefore be unable to complete the task.
eBay said its policy is not intended to prohibit every third-party shopping agent. Instead, it restricts unauthorised agents and activities such as automated scraping and model training.
These different approaches mean users cannot assume an agent that can complete a task on one service will work the same way on another. A failure may reflect a business policy, a security mechanism, a missing commercial agreement or simply a technical bug.
Meta and partners are working on a common standard
Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE and Decagon are now working on an open standard for interactions between personal agents and businesses. The effort focuses on agent-to-agent communication for online commerce and is intended to help businesses distinguish authorised assistants acting for customers from unwanted automated traffic.
Meta has argued that businesses need clearer ways to identify and manage legitimate personal agents. In its announcement describing the standards effort, the company said rejecting a personal agent can also mean rejecting the customer who instructed it to act.
For companies, the challenge is broader than simply allowing or denying bots. Websites need controls that preserve protections against scraping, fraud, and abusive automation while giving authorised agents a way to identify themselves and operate within rules set by the business.
Cloudflare is also changing how automated traffic is handled
Cloudflare is another important part of the access question because its technology helps websites manage automated traffic. Some users have suspected that Cloudflare protections or similar services may be interfering with Muse, while others have reported similar concerns.
Cloudflare changed crawler controls on Sept. 15 to give website operators more specific choices over different types of automated activity. Its system is designed to account for mixed-use AI crawlers, including cases where site owners may want to block AI training while allowing other automated uses.
Cloudflare said it did not have specific data to share on blocking personal agents such as Muse. The company instead pointed to Cloudflare Radar, its public data service for internet traffic trends, though that data does not, by itself, separate authorised personal agents from malicious or unwanted bots.
Partnerships may determine where personal agents work reliably
Meta has increasingly relied on direct partnerships as Muse expands. The agent’s shopping capabilities have continued to expand, while Meta has also introduced Muse tools involving small businesses.
Muse maintains a list of connectors representing services that have formally integrated with the agent, although not every recently announced partner has appeared there yet. A formal integration gives both the agent provider and the participating business a clearer basis for determining whether access problems are policy decisions or technical failures.
The larger issue is becoming central to the usefulness of consumer AI agents. An assistant may be able to make a purchase or complete a reservation. Still, that capability matters only when the website on the other side recognises the agent as an authorised extension of the customer rather than another bot to block.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0