Amazon blocked its own customers to protect its advertising tollbooth.

The sequence took ten days. Meta launched Muse on Sept. 8; by the Friday that ended the following week, the app sat at No. 1 on Apple’s U.S. App Store. By Monday, Meta’s stock had risen 11%. By Tuesday, Charles Schwab had fallen more than 6%, with wealth managers, brokerages, travel companies and insurers selling off across the same stretch of tape. Sensor Tower counted 2.5 million downloads. Truist put $28.5 billion of incremental annual revenue onto Meta’s 2030 model.

That number is not a forecast. It is a permission slip.

Muse runs on a dedicated virtual computer. It can read a user’s email, calendar and text messages. It can shop on Shopify, Instacart and Dick’s Sporting Goods. It cannot, after Amazon’s Sunday-night intervention, shop on Amazon. Amazon’s spokesperson said the company had not been informed in advance and had not authorized the action. The practical result is simpler than the corporate language: a Muse user who wants to buy something on Amazon must leave Muse, open a browser, type amazon.com, log in, search, and buy.

Amazon did not block Meta. Amazon blocked its own buyers.

The company has a reasonable technical complaint in the narrow sense. An agent acting for a user does not behave like a human shopper. It does not arrive to browse sponsored results, absorb placement-based persuasion, or click the item Amazon most wants to sell. It receives an instruction, compares eligible products, and completes the purchase. One Raymond James analyst called that “net negative” for the marketplace.

That description is correct as far as it goes. It also identifies the business model Amazon is protecting. The marketplace is not merely a shelf on which products happen to appear. It is an advertising system whose revenue depends on controlling the route between the buyer and the purchase. The agent removes part of that route. It turns sponsored placement into an optional suggestion and the marketplace’s interface into overhead.

So Amazon closed the door.

Shopify said yes. Instacart said yes. Dick’s Sporting Goods said yes. Those partnerships are not decorative launch announcements. They are the first map of an agent-first checkout layer, and each agreement gives Muse another place where the user’s instruction can become a transaction without passing through the old sequence of search, ranking, persuasion and click.

This is the chokepoint. The agent does not need to own every store if it becomes the place where the user decides what to buy. The store that refuses access protects its immediate advertising revenue while making itself a worse destination for customers who have already delegated the work. The stores that participate gain a place in the new route. A marketplace can preserve its old tollbooth, or it can remain connected to the person carrying the money. It may not be able to do both.

That is why the wealth managers and brokers sold off Tuesday. Charles Schwab’s six-percent drop was a six-percent tantrum about the future, but the fear underneath it is rational. An agent can compare an annuity, select a different brokerage, or choose a no-fee index fund without carrying a sales quota or a preferred-product list. It has a user instruction instead.

Booking Holdings and Allstate belong in the same sentence. Their businesses exist partly because people have historically needed intermediaries to navigate long-tail decisions in travel, insurance and finance. An agent does not need to be perfect to damage that position. It needs to become the default first click, and the first default compounds with every transaction it absorbs.

The advantage is not mysticism. It is captured behaviour.

Only 8% of U.S. consumers told Oppenheimer they would hand their passwords to Meta. Thirty percent would hand them to Google. The trust gap is real, and Google owns it. But 2.5 million downloads in two weeks are also real. The agent does not need a user to trust it with every password on the first day. It needs the user to tap Install.

Trust compounds later. Behaviour is captured now.

That does not make Meta’s security problem imaginary. A credential leak would set the entire category back, and the analysts projecting tens of billions in revenue have said so. Meta has tried to address the risk with a separate virtual computer for each agent and a launch posture that emphasizes security over capability. That is a meaningful architectural choice. It is not a guarantee. A dedicated environment can limit what an agent can reach; it cannot turn a compromised credential into a harmless event.

The technical distinction matters. “The agent” is not a little employee living inside the phone. It is a software process operating with delegated permissions, external services and a particular set of isolation boundaries. If those boundaries are weak, the agent is a new attack surface. If they are strong, the agent is still a new gatekeeper between the user and the services the user once visited directly.

The security question is therefore not only whether Muse can keep a password secret. It is who gets to act when the user is no longer the person making each individual request.

The competitive field remains open. OpenAI is expected to announce a consumer agent within the next week or two. Apple is moving. Google has the computing capacity to redeploy and the trust advantage that Meta lacks. Instinct is invite-only and gaining traction. The same Truist analyst who put $28.5 billion on Meta’s 2030 model said, in substance, that Google and OpenAI could duplicate what is on the shelf within a couple of weeks.

That is the narrow case against calling Muse a permanent monopoly. The product is early. The rivals are real. The advantage may be measured in days rather than years.

The stronger point is that the shelf currently has one product on it.

That changes the value of being first. The agent that becomes the user’s default in week one is not merely another app in month six. It is the place where the user’s email, calendar, messages, shopping preferences and delegated decisions begin to accumulate. Every successful instruction reduces the need to open another app. Every partnership makes the agent more useful. Every completed transaction makes the next instruction easier to give.

This is not a prediction about artificial intelligence. It is a record of switching costs being assembled in public.

The agent is not asking for permission. It is asking for an install button. After that, the remaining friction is choreography: the user states a goal, the agent acts across services, the marketplaces decide whether to participate, and the firms that once owned the customer relationship discover that the relationship has moved one layer upward.

The wealth managers are not wrong to be frightened. Amazon is not wrong that an agent threatens its sponsored-search economics. Meta is not wrong that a secure delegated computer could be more useful than another chatbot. But the conduct of each company reveals the distributional question beneath the product language.

Who gets to stand between the user and the transaction?

Amazon wants to remain the tollbooth. Meta wants to become the instruction layer. Shopify, Instacart and Dick’s Sporting Goods have chosen to meet the user there. The platforms are not merely competing to sell products or answer questions. They are competing to receive permission to act.

The Muse story is therefore not a product story. It is a permission story. Ten days ago, consumers had no widely adopted agent acting across the open internet on their behalf. Now 2.5 million of them do.

Permission is not given back once it has been spent.