Meta's new personal agent Muse hit number 1 in the App Store, got Wall St excited for a new leg of the AI trade, and for most people was the first time AI felt like magic.

Then Amazon decided to ruin the fun and block it on their .com.

And that stings, because Amazon is the everything store, the place where most of the stuff in the world is. Now it shows a pop-up if you try to use Muse and calls it an "unauthorized AI agent."

Amazon, the great aggregator, fears being aggregated.

Zuckerberg said in a recent interview that Muse will monetize through subscriptions and a payments take rate. If you're Amazon reading that, it sounds like you're losing customer ownership and potentially paying a new tax when the customer buys something.

In adding that popup, Amazon has broken the spell of Muse. The magic of AI agents is that they just work. You delegate some task you can't be bothered to do and moments later it's done.

Solving this won't be easy.

I wrote in Wallet Wars Part 3 that agents would need a wallet and the wallet would need to Know Your Agent (KYA). The question is who gets to be that wallet? Who gets paid? I've seen folks pattern-matching this to card networks, or Plaid and open finance. I don't think either is quite right.

The agent wars have started, and they combine internet protocols, aggregation theory, and good old-fashioned lawsuits.

In this one:

  1. Amazon vs Muse is a fight about a fee line, risk and customer ownership

  2. Screen scraping doesn't win this time

  3. Cards are trying to Know Your Agent (KYA)

  4. The agent wars are bigger than the wallet wars

  5. The big merchants get paid

  6. The Opportunity to Know Your Agent (KYA)

Fintech Nerdcon is BACK. And it might just be the most stacked lineup of speakers ever. Co-founder of Chime, CEO of Figure, CEO of Mercury, CPO of Navan, CEO of Valon. With some incredible names coming…

The kind of speakers no other show gets. One rule: no platitudes.

San Diego Convention Center, November 18–20.

You’ll be in great company: speakers from Chime, Mercury, Figure, Valon and Forward have already joined the guild, and tickets are on track to sell out again. Grab yours here.

1. Amazon vs Muse is a fight about a fee line, risk and customer ownership

Amazon's retail business runs on 3% to 6% operating margins, and most of the profit comes from AWS and ads. This ultra-thin margin makes Amazon notoriously cost-conscious. One of their largest cost lines is payments, so they focus enormous effort on attacking that cost. For example:

  • Amazon doesn't support mobile "X-Pays" (like Apple Pay or Google Wallet) at checkout. This is a calculated mix of data protection, fee avoidance, and ecosystem control. They have their own "Amazon Pay" button instead.

  • Amazon is one of the most prominent corporate backers of the Credit Card Competition Act.

  • Amazon was one of the largest US retailers, alongside Walmart and Target, that famously opted out of the historic $7.25 billion Visa/Mastercard antitrust settlement in 2013. Why? So they could sue again. Which they did, within weeks, alongside 7-Eleven and about 30 other retailers, naming Visa, Mastercard and the big card-issuing banks. Yes really.

Now imagine a wave of new AI aggregators come along intending to monetize payments through AI agents. The first thing Amazon wants to do is shut that down and get you to use its own AI agent instead.

There's also a legitimate risk concern here.

If every agent can hold your Amazon credentials, that agent is a potential fraud risk. What happens if that agent gets compromised? Is Amazon liable? For the past two decades, giant merchants like Amazon and Walmart have hyper-optimized their websites to block bots. There's almost zero historical legitimate use case for a bot on a website like Amazon. Before AI agents, that was a lot of software just to buy toilet paper in bulk.

All of the data Amazon uses to find that balance goes if Muse intermediates the transaction.

This is also about customer ownership.

Amazon has Prime, monetizes ads (to the tune of $68bn), and runs an entire B2B marketplace built on its customer relationships and logistics infrastructure. It has done everything in its power to own the customer and lock them in. Muse takes the data, the customer relationship, and potentially removes the opportunity from those other business lines.

  1. Nobody told us

  2. The agent doesn't identify itself,

  3. It stores our customers' logins

These read almost like a term sheet. Announce the agent, identify it, and keep logins out of it. This is a pattern Amazon's own Buy for Me agent uses when it shops other brands' sites. Amazon says "Buy for Me" identifies itself and lets brands opt out. Amazon wants everyone else to play by that rulebook.

The idea that this is about who you trust with your data is entirely a talking point for the markets and the lawyers.

Muse is a phenomenal experience, and consumers will happily pile into the AI agent from the company that brought you such scandals as Cambridge Analytica, and no, we won't train on your WhatsApp messages- oh wait, we do now. Not because they trust that company, but because the experience is good. Sure, they trust Meta not to leak their data all over the internet, but they give zero f*cks if that data is read by everyone at Meta and their dog.

The question now is whether Amazon's complaints and pop-ups will work, or whether, like open finance, screen scraping wins in the end.

2. Screen scraping doesn't win this time

One common reaction on X was that this ends like open banking, where screen scraping won because banks couldn't stop it. Before banks made trusted APIs, services like Plaid used bots to physically log in to banking portals with your credentials. And the bank lobby argued this wasn't secure. Sound familiar?

As much as I love and respect Alex, I don't think the incumbents lost* when it came to screen scraping with open banking. It was a 2-2 draw. Open finance has revolutionized how consumers sign up for new finance services and have their transaction data used for lending (cashflow underwriting).

But the banks got paid. Even in the UK, where arguably the regulators did the most to commoditize the banks and let fintech companies win, we're now implementing "premium APIs" with fee arrangements.

What's this got to do with Amazon and Muse?

The merchant vs agent use case is remarkably nuanced.

  1. Merchants have more data. A scraper logging into a bank pastes a username and password and pulls a balance. An agent on a merchant site moves the mouse, searches, clicks, fills a form and hits checkout.

  2. They have better blocking tools. For twenty years a bot on a retail site was a sneaker scalper, a card tester or a fraudster. Merchants built serious tooling to find and block them because the bot was almost never a customer.

  3. They have a better excuse. In open banking, blocking the scraper meant blocking your own customer from their own data. Retail fraud teams got to say "if it looks like fraud, decline it" with a clear conscience.

Screen scraping won in banking because working 70% of the time was good enough for a balance check.

An agent that fails to buy the thing once is an agent you stop trusting.

3. Cards are trying to Know Your Agent (KYA)

The other reaction on X was "the card schemes will eat this."

For commerce, maybe. But it will take a while.

There are too many standards, and everyone is jockeying for position. In payments nobody can be the aggregator and everyone wants to be. Visa and Mastercard maintain an equilibrium by incentivizing everyone, especially the big banks, to play nice.

But now we have big tech at the party, in a much bigger way than they ever were in the Apple Pay / Google Pay era.

  • Visa has Trusted Agent Protocol

  • Mastercard has Verifiable Intent

  • Ant has Agentic Mobile Protocol

  • Google has the Universal Commerce Protocol (which Shopify's Muse channel runs on),

  • OpenAI and Stripe built the Agentic Commerce Protocol

And Stripe Link keeps showing up in every agent's checkout. I'm not going to count them as a protocol; more of a wallet. My point is there are a lot.

None of these have broad-scale industry adoption or standardization, so for now the only thing that still works is an agent using a browser and screen scraping.

Standards are coming.

I'm paying a lot of attention to an announcement from 10 September, where Visa, Mastercard and Ant said they'd combine their three standards into a shared KYA framework. It checks who operates the agent, who certified it, and how it has behaved on every transaction, and an agent can lose its certification.

Will ChatGPT follow it? Will Muse? Nobody knows yet. Standards take years, and every company on that list would rather own the standard than share it. The card networks, at least, are very used to co-opetition, and balancing what merchants, issuers, and wallets all want. They also issue scheme mandates, which, begrudgingly, everyone accepts eventually.

The problem is every day that standard doesn't exist, the magic of personal agents is broken.

Are there too many cooks?

4. The agent wars are bigger than the wallet wars

This problem is part internet native infrastructure, for folks like Cloudflare and CDNs to solve. Part consumer platform shift, what comes after Instagram and iMessage. And part payments, the evolution of Apple Wallet vs. the merchants blocking it.

The internet infrastructure is going to matter when it comes to agents or "bots."

On 15 September, a week before Amazon blocked Muse, Cloudflare changed its defaults so that any new site behind it blocks "agent" traffic on pages that carry ads. Cloudflare sits in front of roughly a fifth of the web. It already charges AI crawlers per crawl, and it already lets an agent sign its requests with a key so a site can tell a real agent from a fake one.

This makes the agent wars much harder than the wallet wars that came before it. Meta is a client, partner and competitor of Amazon across multiple lines of business. I doubt KYA will be solved just in payments, by payments people.

China has always been an exception when it comes to fintech, because its largest tech companies are also fintech companies. The western fintech audience stopped paying attention to Alipay, but it is perfectly positioned to fix agentic commerce.

  • Alipay's sister company Alibaba is the Amazon of China. It doesn't have to fight.

  • Alipay+ has all the volume it needs single handedly, it connects 150m merchants, 50+ wallets and 2bn user accounts

  • Alipay AI Pay passed 100m users in February

  • It ran 120m transactions in one week over Chinese New Year

This is the same group that also made the excellent open-weight model Qwen, and has built the most sophisticated multicurrency settlement infrastructure in the world.

They're the only group that's all of the warring houses of agentic-commerce-westeros in one. The lab, the merchant, and the fintech company (walk into a bar). And the only party at the KYA table that has already run agent payments at this volume.

We can learn a lot from what that looks like. But I suspect the answer in the West will be messier.

5. The big merchants get paid

Large news publishers are split into two camps.

Those who signed licensing deals (News Corp, Financial Times, Associated Press, and the Washington Post) and the holdouts (the New York Times, the New York Daily News and the Alden Global Capital papers).

The holdouts are no doubt waiting on the lawsuit, which has yet to play out. In December 2023, The New York Times filed a copyright and trademark infringement suit in the Southern District of New York against OpenAI and Microsoft. It remains the bellwether case for the entire AI industry.

Amazon is likely in the holdout camp on agentic commerce. Just as they've used litigation and lobbying to fight for basis points in payments, they'll continue that pattern in agentic commerce, and they have.

Amazon has already sued Perplexity, and blocked similar efforts by ChatGPT. It lost the hacking claim in the Ninth Circuit in August, where the court said the user, not the AI company, is the one accessing Amazon's computers. The contract claims survived, which is why the Muse block cites Conditions of Use and not a new lawsuit.

I think there is a version where Amazon just loses, though.

Waiting for the courts to decide is high stakes, and even when they do, they can't uninvent AI. The outcome is likely to be some settlement or framework agreement.

6. The Opportunity to Know Your Agent (KYA)

Which leaves us with a question. What will all of this do to acceptance?

We need a single way to build trust. Most people are calling that KYA. If we get that even half right, those agents have at least an Apple-Wallet-sized opportunity, and at most, something much, much larger, as our personal assistants start to take on more delegated responsibility in our financial lives.

But to get there, we have to solve some gnarly problems. There are two questions every agent has to answer, according to the identity guru himself, Dave Birch. Paraphrasing him:

Who delegated this task, and within what boundary? And if this agent gets it wrong, who pays?

Muse launched with Stripe’s Link. It added PayPal this week. And a teardown of the app shows Meta building Meta Pay into it alongside both. Three weeks in, the wallet slot inside the agent is already contested. The platform wants the wallet fee as well as the take rate.

Wallets help answer “who delegated this task” and become a crucial part of agents. It issues the agent's "identity," defines its operating bounds, and signs a cryptographic delegation approving the user who delegated that task (like paying for a Fintech Nerdcon ticket).

But what about the second question? Commercial liability.

Visa, Mastercard, and Ant stepped in with their joint KYA (Know Your Agent) framework. Rather than build a big centralized registry (which Dave says will never work, and I agree), they're standardizing trust and pricing liability.

AI has a habit of being slow, then sudden

Early mobile commerce was awful at conversion too. Today, mobile is anywhere between 60% and 75% of all retail e-commerce.

This will be quite the battle:

  • At the infrastructure layer, Cloudflare and the CDNs charge the agent to get in the door.

  • At the platform layer, Meta, and whoever follows it, charges the merchant a take rate for the sale.

  • At the payments layer, the schemes and Stripe Link charge for the stamp that says this agent is real and this person delegated the task.

  • And at the Merchant layer: Amazon is fighting all three at once, which is why it's the loudest.

We haven't seen what Apple, Google, or OpenAI's v2 attempt at a consumer agent looks like yet.

But we have seen the merchants begin to push back already.

The merchant wants a trusted agent. That needs a trust framework.

And whoever builds and enforces that standard gets a powerful position in the network.

ST.

*I actually don't disagree with what Alex is saying, just the framing, but you can forgive a guy for starting a pretend fight with a friend for the clicks.

If you enjoy this kind of content, I can guarantee you’ll love being in a room of 1,500 other folks who love to go deeper into where finance meets AI. That’s a huge theme for us at this year’s Nerdcon in San Diego on the 18th to 20th November. I’m bringing my audience, the operators, the people who read this newsletter. And it’s the perfect place to find your next hire, client, or just get inspired. Let’s make events awesome again.

That's all, folks. 👋

Remember, if you're enjoying this content, please do tell all your fintech friends to check it out and hit the subscribe button :)

Want more? I also run the Tokenized podcast and newsletter.

(1) All content and views expressed here are the authors' personal opinions and do not reflect the views of any of their employers or employees.

(2) All companies or assets mentioned by the author in which the author has a personal and/or financial interest are denoted with a *. None of the above constitutes investment advice, and you should seek independent advice before making any investment decisions.

(3) Any companies mentioned are top of mind and used for illustrative purposes only.

(4) A team of researchers has not rigorously fact-checked this. Please don't take it as gospel.

(5) Citations may be missing, and I've done my best to cite, but I will always aim to update and correct the live version where possible. If I cited you and got the referencing wrong, please reach out