For thirty years the web ran on one quiet assumption: the hand on the keyboard belonged to the person who would answer for what it did. Logins, fraud models, bot management, terms of service, chargeback rules. All of it was built on the idea that a session is a person.

On September 8, 2026, Meta shipped the first mass-market break in that assumption. Muse is a personal agent that runs in its own cloud computer, connects to your email, calendar and payment wallet, and goes off to do things while you’re doing something else.1 It had roughly 2.5 million downloads in its first thirteen days and passed ChatGPT at the top of the U.S. App Store.2 This is the migration this tier has been describing: from humans executing, to agents executing on a human’s behalf. It isn’t a forecast anymore. It has an app icon.

The last essay in this tier read the market’s reaction. This one is about a question the market skipped, and that nearly every institution touching Muse has now answered, differently and at the same time: what is the agent, to the business on the other side of it?

Four answers in one month

It’s you · The Ninth Circuit, August
Amazon had won an injunction against Perplexity’s Comet browser agent. The appeals court vacated it, reasoning that on the current record the user was the one accessing Amazon, with Comet as a tool carrying out the user’s instructions. That leaves Amazon leaning on its terms of service rather than federal computer-fraud law.3
It’s you · Stripe’s Link Agentic Terms
Muse pays through Link. Link’s terms treat your agent as an electronic agent whose transactions legally bind you, and make you responsible for them “as if you had taken the action yourself.” That includes purchases caused by bugs, hallucinations or misread instructions, and agent purchases are excluded from Link’s unauthorized-transaction protection. The definition of an agent even reaches through every intermediate system in a chain, whether or not you can see it.4
It’s you, except where it counts · Meta
Meta’s own safety write-up says that when Muse browses, it will appear as your activity. The same document says Muse’s email connector strips out one-time codes, password-reset links and login magic links, because connecting your inbox should not let the agent represent you across other sites.5 The agent’s maker lets it look like you and refuses to let it be you.
It’s a stranger · Amazon, September 20
Amazon blocked Muse. Its reasons: Meta never asked, the agent doesn’t identify itself when it browses, and it appears to capture and store customer credentials, which Amazon describes as an undisclosed third party moving through customer accounts.6 Shoppers who send Muse to Amazon now hit a pop-up calling it an unauthorized AI agent.7

Read those together and something odd shows up. The law and the payments contract collapsed the agent into the person. The largest retailer in the country pushed it out as an intruder. And the company that built it split the difference by hand, one filter at a time. No two of them agree on what the thing in the session actually is.

Why “it’s you” fails

If the agent is legally you, then every counterparty is looking at a session it can’t distinguish from you, and every error the agent makes lands on you, with no record of what you actually meant to authorize. Link’s terms are candid about this: the approval tap is the moment the liability moves. That’s a defensible position for a payments company. As a foundation for an economy where agents act across a chain of other agents, it means the person at the top absorbs everything below them, including hops they never saw.

It also means the business can’t govern what it can’t see. Elon Musk made the point bluntly the day after the block: if the agent comes through the user’s IP address and cookies, Amazon can’t tell buyer from bot.7 A business whose only model of the customer is “a logged-in human” has no place to ask the questions that now matter.

Why “it’s a stranger” fails

The wall has three problems. It blocks your own customers, the ones who chose to delegate. It is weak legally, since the Ninth Circuit left Amazon with its terms of service and not much else. And it is weak technically: when Amazon fingerprinted Perplexity’s Comet to block it, Perplexity shipped an update within a day to get around it.7

It also isn’t a principle, even at Amazon. Amazon’s own Buy for Me agent shops third-party retailers’ sites on the shopper’s behalf, and retailers were enrolled first and given an opt-out email second.7 The wall is a business position. Amazon can afford one. Very few businesses reading this can.

The agent is not you, and it is not a stranger. It is yours.

Three answers to what the agent is Left: the agent drawn inside the person, collapsed into one. Middle: the agent held outside a wall, excluded. Right: the agent as a separate figure with its own identity tag, joined to the person by a signed delegation line that can extend across further hops. IT’S YOU IT’S A STRANGER IT’S YOURS COURT · CONTRACT THE WALL KNOW YOUR AGENT you One session. The business can’t see it; the human absorbs every error. you Your own customer, turned away. The wall held about a day. you ID signed Its own identity. A provable line back to the person who answers for it.
HumanAgent
Fig. 1 — Three answers to “what is the agent?” The dashed hop on the right is the part no deployed standard proves yet.

The third answer

“Yours” means the agent is distinct and bound at the same time. Distinct enough that a counterparty can see it’s an agent and decide how to treat it. Bound tightly enough that someone accountable stands behind it, and the business can check that before anything irreversible happens.

That breaks down into the four questions Do You Know Who Is Using Your Product? laid out: who is the agent, who authorized it, what is it allowed to do, and how far does that authority travel? Every failure of the last month maps onto one of them. Amazon’s first complaint, an agent that doesn’t identify itself, is the first question unanswered. Link’s terms reaching through every hop of an agent chain and landing all of it on the human is the fourth question, answered by contract because nothing technical answers it yet. Meta filtering password resets out of the inbox is a company drawing the line of the third question by hand, because the web gave it nowhere else to draw it.

Sell the slope, not the level

~0.4% Third-party AI agents’ share of traffic at Amazon, per J.P. Morgan data; under 1% across major online stores. Today’s volume is small.
40% How much better AI-referred shoppers converted than search, email or social during Prime Day 2026, per Adobe — the first Prime Day where they ranked highest of any source.
~2.5M Muse downloads in its first thirteen days — a consumer product, not a developer tool.

Sources: Tech Times, Sept 23, 2026 (J.P. Morgan and Adobe figures); CNBC, Sept 21, 2026 (Sensor Tower).

What’s solved, and what isn’t

It would be easy to overstate this, so the limits belong in plain view. The middle questions are converging. Who authorized the agent and what it may do are being standardized in the open, with Google’s AP2 and Mastercard’s Verifiable Intent now under the FIDO Alliance, and Google and Shopify’s Universal Commerce Protocol built to vet agents and confirm intent at checkout. The first question is partly answered, mostly inside the card networks. The fourth is still open: no deployed protocol proves which human authorized which agent past the first hop. That is exactly the gap Link’s terms paper over by assigning everything to you.

So the honest advice is the same as it was before Muse, only more urgent. Build the decision points now: somewhere in your transaction path that can recognize an agent, ask who stands behind it, and stop it mid-action if the answer is wrong. Commit to a vendor later, once the standard lands. Don’t build Amazon’s wall, and don’t pretend the session is still a person.

One question sorts every business on this. When an agent transacts with you, can you tell whether an accountable party stands behind it, and can you prove one stands behind you?

The migration from human execution to agent execution didn’t arrive as a strategy memo. It arrived as a free app, and every institution it touched had to decide on the spot what it was.

Most decided wrong in one of two directions. The ones that get it right will be the ones that decided before the agent showed up.

Follows The Inertia Premium Got Priced, which read the market’s side of the same weeks. The four questions come from Do You Know Who Is Using Your Product?; where the money lands in all of this is The Money Moves Last. The boundary underneath, where what an agent may propose meets what the organization will permit, is the seam. Who governs the agent once it’s yours is Governance Comes Home.