E-Commerce Sites and Airlines Ramp Up Blocks Against Consumer AI Agents
Retailers and travel platforms are turning away autonomous assistants like Meta’s Muse over security concerns and data policy enforcement.

As consumer-facing artificial intelligence software like Meta Platforms Inc.’s Muse, ChatGPT’s Dots, and Instinct expand beyond standard query responses to perform tasks such as booking flights, ordering groceries, and making restaurant reservations, developers are hitting a major operational obstacle. Destination websites and digital platforms are increasingly blocking these autonomous agents from navigating their services, preventing automated transactions on behalf of users who rely on the software without maintaining technical configurations like OpenClaw.
The access restrictions stem from both explicit corporate policies and automated security protocols. As first reported by TechCrunch AI (https://techcrunch.com/2026/10/06/the-next-hurdle-for-ai-agents-getting-websites-to-let-them-in/), e-commerce giant Amazon recently began blocking Meta’s Muse assistant from navigating its retail platform and placing orders. Technical disruptions are also affecting other major retailers. Although Meta announced a partnership with Walmart at its Connect developer conference in September, users have reported failed transactions. Walmart explained that standard anti-bot security checks, such as interactive human-verification buttons, frequently interrupt automated agent workflows and cause verification failures, rather than reflecting an intentional effort to ban the tool.
To resolve these operational friction points, Meta is coordinating with an industry coalition including Walmart, Stripe, Sierra, Genesys, Rocket, NiCE, and Decagon to design an open protocol for digital commerce. The proposed open standard aims to establish agent-to-agent communication guidelines, allowing commercial websites to distinguish legitimate consumer-driven software from malicious automated scrapers. In a corporate blog post, Meta stated that turning away a personal agent effectively turns away the customer behind it, advocating for clear norms and predictable control mechanisms for web managers.
Travel platforms represent another significant point of friction, despite flight booking being marketed as a core use case for agentic software. Delta Air Lines Inc. General Manager of Global Communications Heena Chavda stated that the carrier does not currently maintain integrations or partnerships permitting third-party AI agents to shop or book flights on its digital channels, adding that the company continues to evaluate emerging technologies with security in mind. United Airlines Holdings Inc. pointed to its terms of service policy, which restricts unauthorized automated devices, spiders, or robots from monitoring or copying site content without prior written permission.
User reports across social media highlight access rejections from a broad array of commercial operators, including Yelp, eBay, Zillow, Pizza Hut, Adidas, and several air carriers, with some users citing account suspensions or interrupted tasks. Yelp clarified that it prohibits non-human traffic unless operating entities pay for data access through its official licensing program. Conversely, eBay told TechCrunch AI that its policies target unauthorized data scraping and machine learning model training rather than imposing a blanket ban on all third-party purchasing tools. Adidas, Zillow, and Pizza Hut either declined to comment or did not respond to requests for clarification.
Network infrastructure providers are also playing a central role in how automated traffic is handled. Cybersecurity vendor Cloudflare Inc., which offers bot protection services and manages a marketplace where AI crawlers pay for data access, updated its default crawler settings on September 15. The change allowed website operators to restrict AI training bots while permitting standard web crawlers, but existing security rules on ad-supported pages inadvertently led to blocks on personal AI agents. Cloudflare stated it had no specific tracking data regarding personal agent blocks, pointing to general traffic trends on its Cloudflare Radar portal. The company is currently testing a web browser built specifically for autonomous agents.
In response to widespread site restrictions, AI developers are increasingly leaning on direct commercial agreements to maintain service availability. Meta maintains a growing registry of approved third-party connectors within its Muse app. As agentic AI adoption accelerates across consumer and small business tools, establishing standardized authorization frameworks will remain critical to ensuring digital assistants can navigate the web without triggering automated security defenses.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.


