All posts
2 min readby Romiel Inolino

Customers' AI agents are getting blocked by human checks and bot defenses. Your client's site may be turning buyers away

AI agentsecommercebot protectionCloudflarecustomer experience

An agent trying to buy from your client's store might be failing at a "verify you are human" button, and nobody on the team knows.

What happened

TechCrunch reports that people using personal AI agents such as Meta's Muse are hitting blocks when those agents try to shop, book or reserve on their behalf.

Some blocks are deliberate. Amazon began blocking Muse from its retail site. Yelp told TechCrunch it does not permit non human traffic unless the agent has paid for access to its data. Delta said it is taking steps to protect customers from unauthorized automated activity.

Others look accidental. Walmart is a Muse partner, but users reported failed purchases. Walmart told TechCrunch these were not intentional, and the issue appears to be a button that verifies the visitor is human. If that check is interrupted, the agent gets booted. TechCrunch also reports that some Cloudflare protected sites are disrupting Muse traffic after a September 15 change to crawler defaults, and that Cloudflare said it had no specific data to share.

Meanwhile Meta and Sierra are developing the Personal Agent Protocol, an open standard for how personal agents interact with businesses, with partners including Shopify, Stripe and Walmart. Meta says it would let businesses steer agents toward preferred workflows or API connectors, see what agents do, and verify user identity.

My take

For the businesses I work with, this is a quiet revenue leak. If a customer's agent cannot get past checkout or a booking form, the customer just sees "it did not work" and may not try again.

What I would check for a client this month:

  1. Look at bot protection settings and logs. Are you blocking all automated traffic, or only training crawlers and abuse?
  2. Test your key flows (quote request, booking, checkout) with an agent and see where they break.
  3. Give agents an easier path: a clean booking link, a structured product feed, or an API endpoint, so they do not have to fight the UI.
  4. Decide on purpose. Blocking agents is a valid choice, but it should be a decision, not a default you never looked at.

The same applies to your own browser automations. If they scrape or fill forms on third party sites, expect more failures as these defenses tighten.

More posts