On the night of Sunday 20 September, Americans who asked Meta's new assistant to buy something on Amazon started seeing a pop-up: "continued access by an unauthorized AI agent violates Amazon's Conditions of Use". Amazon had asked Meta to remove Amazon from the assistant's shopping experience; Meta had declined; Amazon blocked it.
The assistant is Muse, launched in the United States on 8 September. It is what the industry now calls an agent: not a chatbot that answers questions, but software that does things, browses, fills in forms, books tables, buys, and it comes with its own computer, a virtual machine in Meta's cloud assigned to each user, so that it can keep working after you close the app. By 18 September it had overtaken ChatGPT as the top-ranked free iPhone app in the US.
Amazon's stated grounds for the block are worth recording precisely, because they will recur in every dispute of this kind: Meta gave no notice that Muse would access the store; the agent does not identify itself while browsing; and, Amazon alleges, it appears to capture and store customer credentials. Meta says credentials are stored separately, outside the model's visibility; storage in the system and invisibility to the model can both be true, and neither settles whether the implementation is safe. The dispute concerns a US service and US law; the European comparison comes later.
Ben Thompson, who introduced Aggregation Theory in 2015, read the moment for what it is. An aggregator, in his framework, is a company that owns the relationship with so many users that suppliers must come to it on its terms; search did it to publishers, the App Store did it to software. In Apps, Agents, and Aggregation he argues that agents are the final form of the species, "the ultimate gatekeeper of not just user demand, but desire", and that providing them is the largest prize the industry has ever contested, because the winner is a platform and an aggregator at once. It is the movement I examined in July from the European side, in Who Controls the Interface: when the assistant becomes the point where intention meets the machine, the apps behind it recede into suppliers, and the power over access rises one level. Thompson's piece maps the prize. What it does not discuss is what the past three weeks have actually been about: how the fight over that prize is governed, and by whom.
Governance by pop-up
Look closely at the instrument Amazon used, because it is the most important detail of the whole affair. Users encountered a terms-of-service banner backed by a technical block. A block of this kind gives Amazon's access policy immediate practical force; anyone who wants to challenge that policy must bear the cost and the delay of seeking review, in court or before a regulator, while the block may remain in place. That asymmetry, who can decide instantly and who must mobilise resources to object, is the real subject of this piece. Call the arrangement what it is: governance by pop-up.
There is legal context, though it explains less than it seems to. In a parallel dispute, Amazon had obtained a preliminary injunction, a court order freezing conduct while a case is decided, against Perplexity's Comet agent. On 4 August the Ninth Circuit vacated it, holding that, on the record before it, Amazon was unlikely to show that the company, rather than the user, was accessing its computers; rehearing was denied on 10 September, and the court expressly left the contractual questions open. The ruling concerns one agent's architecture and one procedural stage; it grants no general immunity, and Muse, with its cloud browser, presents facts of its own. What it does mark is a limit that has surfaced on the computer-intrusion route, while contract remains one available avenue. Whatever the reason, what Amazon actually deployed against Muse was the banner.
And notice who can afford to deploy one. Blocking an agent is available, in principle, to any website; what differs is the price of refusal. Amazon can turn away the agent's traffic because Amazon is an aggregator in its own right, with demand of its own and something concrete to protect: Amazon's advertising business generated 19.8 billion dollars in the second quarter, video and live sports included. Its largest offering is Sponsored Products: sellers paying to be visible at the moment of choice. An outside agent would relocate exactly that moment. That documents a substantial economic interest in the block, without proving it is the whole reason. A restaurant, an airline, a utility can also refuse the assistant that brings them customers; the question each faces is what refusal costs, how many of its customers it can still reach directly, and what the agent's traffic costs it in return. Differences in bargaining power will shape the terms of access, and most businesses will have less of it than Amazon. The war, meanwhile, is between partners: Amazon has sold inside Meta's apps for years, and in April Meta signed an agreement to buy capacity on Amazon's own processors, tens of millions of cores, for its agentic workloads. The partnership stands; the fight is over who faces the user.
The month's other two moves show that losing the interface is not one thing. On 15 September Salesforce announced that its software can be used from inside Claude, in beta: the incumbent offering itself as a capability behind someone else's agent, while keeping the data, the permissions and the business rules on its own side of the line. Ceding the surface can coexist with holding what the surface depends on, and how much that residual control is worth is now one of the open questions of the period. Ten days later Microsoft announced the broadened preview of the new Copilot with Autopilot, a long-running agent that, in the words of a Microsoft vice-president, "lives in your tenant with its own identity, memory, computer, and workspace", with permissions and audit behind it, while Satya Nadella described the goal as an operating system for work. Seventeen days, three moves: the shop that blocks, the incumbent that retreats behind the surface, the platform that builds the agent a corporate identity.
Europe is already in the room, slowly
The European situation needs stating more carefully than the usual line about regulation lagging. The Digital Markets Act, the EU law that imposes obligations on designated gatekeeper platforms, has listed virtual assistants among the services it can cover since 2022. No assistant has been designated as such; on the official register that box is still unfilled. But the law has started reaching assistants through a side door. On 16 July the Commission adopted binding measures telling Alphabet how Android, a designated service, must open its functionalities to competing AI assistants, so that a rival agent can do on the phone what Google's own can. Adoption is not implementation: the official timetable runs to 1 August 2027 for the specified measures, and to 1 August 2028 for concurrent wake-word detection across multiple services.
Put the two clocks side by side, because this is the finding of the month. Amazon's access policy took effect overnight, by pop-up; the mandated opening of Android follows the timetable above. Blocking access and implementing interoperability are different operations, and their timing nevertheless shapes who can exercise power now. Private ordering moves at the speed of deployment, the public counterweight at the speed of proceedings, and in the gap the operative rules of the agent economy are being written by whoever controls a destination, enforceable by block, while challenging them demands time, expertise and persistence that are unevenly distributed.
The cloud proceedings set the yardstick: in June the Commission reached a preliminary position, not yet a designation, that AWS and Azure should be treated as gatekeepers, following a qualitative assessment. The law can assess dependence and entrenched market position even where the quantitative thresholds are not met. Among the reasons cited is the growing weight of AI in cloud decisions. Those are positions consolidated over years, so the precedent does not show the regulator arriving early; what it shows is that the law can weigh dependence and accumulated position alongside scale. That is the yardstick that would matter for an agent: not downloads, but intentions mediated, context accumulated, businesses that can no longer reach their customers except through it.
On identification, the casus belli itself, the technical means largely exist: standards for fine-grained authorisation, and protocols under construction in the payments industry for agents to identify themselves and carry proof of what they may do. What no mechanism settles is which agents a destination must accept, on what terms, and how a refusal can be challenged. That settlement is not a technical artefact. It is the political content of the period, currently being supplied, by default, in banner form.
The computer is not free
One more fact belongs in the ledger. Meta is provisioning an actual computer for every Muse user, and that is not a launch stunt but the recurring cost of running an agent: every free task consumes compute that someone paid to build. Meta sells subscriptions above the free tier, but the free tier is the bid for the mediation position. The ability to subsidise recurring compute costs gives the largest providers an advantage in reaching mass-market users; entrants need not own the infrastructure, but the price and terms of access to it shape their room to compete. This is where the interface story meets the one this site has been following all year: the capacity the agents run on is the build-out of the munition economy, financed through the leases, guarantees and vehicles described in The Debt Beneath the Compute. The relation between the two stories is industrial, not contractual, but it points one way: the fewer the balance sheets that can sustain free agents at scale, and the more the terms of access to compute are set by the same few, the shorter the list of possible winners was before the war began.
Which is why the celebration of the aggregator wars deserves a colder eye. Rivalry between gatekeepers does not by itself make the mediation layer contestable: it can improve users' options while leaving entry, access and switching dependent on terms set by incumbents. Meta, to its credit, says a user's files and memory can be downloaded; the question that matters is how much of that export another agent could actually use, without rebuilding every integration and habit from zero, because that is the difference between a formal right and a real exit.
So the useful question is no longer who controls the interface, and not even who wins the war for it. It is this: under what conditions could users, businesses and new entrants withdraw from the winner's power, change agent without losing themselves, reach a customer without paying the gate, enter the contest without matching the incumbents' subsidies? The three levers of the July piece, separable architecture, public capacity, rules attentive to dependence as well as scale, were an answer to exactly that question, written when it was still hypothetical. September's disputes have made the stakes concrete.
The information and views set out in this article are those of the author and do not necessarily reflect the official opinion of the European institutions.