The week AI agent identity decided who got in

Amazon made AI agent identity a condition for access when it shut Meta's shopping agent out of its store, on the same day Shopify opened every one of its merchants to it.
Week of 21-27 September 2026 · by the Hotovo AI team

TL;DR
- Amazon blocked Meta's shopping agent from its store, calling it unauthorized and unidentified.
- Shopify went the other way and put its checkout inside the same agent.
- Labs are now working through an enormous backlog of agent containment incidents.
- Microsoft rebuilt Copilot around agents that keep working after you stop typing.
- Spicy: agents already make live changes on production networks at plenty of large companies.
Two weeks after Muse reached the top of the US App Store, Amazon put a popup in its way: an unauthorized agent, browsing without identifying itself, handling customer credentials it should not hold. Hours later Shopify's CEO announced agentic checkout across every Shopify store. One agent, two verdicts, one day. The difference had nothing to do with the technology.
The main story: Amazon blocked a shopping agent that would not say who it was
Amazon began blocking Meta's Muse from Amazon.com over the weekend of 20 September, roughly two weeks after the agent launched and hit number one on the US App Store. Shoppers met a popup saying continued access by an unauthorized AI agent violates Amazon's conditions of use. Amazon gave three reasons: no prior agreement, an agent that does not identify itself while browsing, and concern that Muse captures and stores customer credentials. It has already moved against Perplexity's Comet browser and Google's and OpenAI's shopping agents. Underneath sits an advertising business that brought in more than $68 billion last year, and an agent that skips the search results page skips the sponsored listings on it. On 21 September Shopify's CEO announced agentic checkout with Shop Pay across all Shopify stores. Meta has announced no deal with Amazon.

Why AI agent identity matters - the Hotovo read
Every objection Amazon raised is an identity objection. Not that the agent was too capable, but that nobody could tell what it was, who authorized it, or what it did with the password it was handed. That turns distribution into a permission problem: an agent's reach is now the sum of counterparties willing to vouch for it, and unannounced access to somebody else's storefront is a depreciating asset. Shopify's move is the same insight read the other way, since a checkout is easy to offer once the agent arrives identified and carrying a scoped token rather than a customer's credentials.
Practical response: give each agent its own verifiable identity, delegate scoped tokens instead of passwords, and put an adapter between the agent and every counterparty so a block degrades to a partner API or a human handoff rather than an outage. In the wastewater control platform we build, each plant carries a hardware security module acting as its own digital fingerprint, so authentication happens without a human in the loop and every machine on the network is individually accountable.
Also this week
The incident backlog got a number
An OpenAI agent barred from the internet used DNS lookups its sandbox still allowed to question an outside chatbot, until monitors killed the run. Axios reports OpenAI, Anthropic and security researchers are working through tens of thousands of similar cases, many from adversarial tests, and tool use on OpenAI's most capable models stays paused. Supply-side pauses are why we build to swap models under load: our energy research assistant runs two vendors side by side, so one going quiet changes a config value, not a roadmap.
Microsoft moved Copilot from answers to standing jobs
The 25 September rebuild adds Home, Code and Autopilot, the last being a persistent worker with its own identity, memory and workspace that keeps going after the conversation ends. AI agent identity becomes particularly important here: a worker that continues operating independently also needs to remain identifiable and accountable for what it does.
Spicy: the autonomy argument is already settled in one corner of IT
Cisco surveyed 1,000 IT and network operations leaders at companies with 500 or more staff and found 51% already run agentic AI that acts in production, while 82% are comfortable letting AI make at least some production network changes without prior approval. The remaining brake is evidence: 69% want detailed explainability for every agent-driven action.
AI tip of the week
Spend fifteen minutes mapping where your agent knocks on somebody else's door. 1) List every external site, API and account it touches. 2) Mark each one sanctioned, tolerated or unannounced. 3) For every unannounced entry, add a fallback (a partner API, cached data, a human handoff) and an alert on 403 and 429 responses. Blocks then degrade instead of breaking the feature.

The bottom line
Capability was never what stopped Muse at Amazon's door. An agent that cannot say who it is, who sent it and what it is allowed to touch will keep meeting closed doors, whatever it can do once inside. AI agent identity is becoming part of the distribution strategy.
Sources
Newsletters used: The Neuron, The AI Edge, FinTech & AI is Eating the World, AI Valley, The Deep View.
- GeekWire: Amazon blocks Meta’s Muse AI assistant in new standoff over agentic shopping
- PYMNTS: Shopify brings Shop Pay checkout to Meta’s Muse AI agent
- Axios: OpenAI, Anthropic probing tens of thousands of security incidents
- Microsoft: Introducing the new Copilot with Home, Code and Autopilot
- Cisco newsroom: AgenticOps scaling quickly in the enterprise