Two facts, eight days apart.
On September 21, Amazon blocked Meta's new agent, Muse, from its store. Shoppers who sent Muse to buy something on Amazon got a popup instead: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use."1 On September 29, OpenAI shipped Dots, an assistant that runs around the clock on its own computer in the cloud, with its own web browser and connections to more than 4,000 apps.2 That same week Muse was the number one app in the US App Store, ahead of ChatGPT.3
Everyone is building the same thing, and the biggest store on the internet does not want it inside. The short version of this piece: the launches are about money, not about you; the stores have their own reason to fight them; people will let these agents look but not spend; and the first company to promise to pay when its agent buys the wrong thing is, I think, the one that ends up leading. The rest is the evidence.
everyone is shipping the same product
The idea is identical everywhere. Software that has a name and a memory, runs on a computer of its own (usually one the company rents for it), logs into your email, calendar and shopping accounts, and keeps working while you sleep. A chatbot answers a question. An agent finishes the job.
| Product | Shipped | Where it runs, and who holds your logins | How it makes money |
|---|---|---|---|
| OpenClaw (open source, now a nonprofit) | Nov 24, 2025 | Your own machine; you keep the logins | Free; you pay for the AI model |
| Buzz (Block) | Jul 21, 2026 | A shared team workspace; each agent holds its own ID and keys | Free, open source |
| Grok Bot (SpaceXAI) | Aug 11, 2026 | A walled-off computer in SpaceXAI's cloud, one per bot | $300 a month plan |
| Muse (Meta) | Sep 8, 2026 | A walled-off computer in Meta's cloud; Meta logs in for you with substitute credentials, so the agent never sees your password | Free, $20 or $100, plus a cut of purchases |
| Instinct (startup) | Raised $1B on Sep 28 | Instinct's cloud | Subscription |
| Dots (OpenAI) | Sep 29, 2026 | A walled-off computer in OpenAI's cloud, one per dot | Included in $200-plus plans |
OpenClaw set the shape. Peter Steinberger released it as a hobby project last November and it became one of the fastest-growing open source projects ever recorded, with 280,000 developers bookmarking it on GitHub by March.4 OpenAI hired him in February. Microsoft built its own always-on assistant, Scout, directly on OpenClaw in June.5 The corporate versions took the same idea and moved it off your laptop into a computer they control. OpenClaw also showed the downside: thousands of people ran it with no security at all, and some of the extensions they installed turned out to steal passwords and cryptocurrency.6
So the demand was visible by spring. What explains six launches landing in the same summer is the money.
chatbots do not make enough money per person
ChatGPT has about 900 million weekly users and about 50 million who pay.7 That is roughly one paying user in eighteen, and of those who pay, only 59% are still paying a year later.8 Google's Gemini crossed a billion monthly users in August and Google would not say how many pay; outside estimates say two or three in a hundred.9
Now divide the money by the people. ChatGPT earns roughly $28 per user per year, and closer to $17 if you count only what consumers pay. Gemini earns about $1.60 per user per year from subscriptions. Meta earns about $67 per person per year from ads, and about $310 in the US and Canada.10
Chat is not dying. It earns too little per person: a billion people use it and it makes a fraction of what an ad-supported social network makes from each of them. OpenAI's own answer is ads, with a reported internal plan for $100 billion of ad revenue by 2030.11
Then there is the bill. The four biggest cloud companies have told investors they will spend around $700 billion this year on data centers and chips.12 Meta's cash left over after paying for everything fell to $784 million in the June quarter, from $10.9 billion two years earlier.13 On that earnings call Zuckerberg told investors that "consumer personal agents will be an extremely important market" and that Meta would "ship something soon."14 Muse shipped six weeks later. OpenAI, meanwhile, cut its planned data-center buildout by more than half,15 and both OpenAI and Anthropic are reported to be preparing to go public.
Put those together and the logic is simple. The spending is enormous, a chat subscription cannot pay for it, and a company about to go public needs a story about where the money will come from. An agent that acts on your behalf is that story. OpenClaw proved the product; the money explains the timing.
the plan is a cut of your shopping, and everything you tell it
Zuckerberg said the business model out loud the day after Muse launched: "This is going to make so much money for people that the business model is to effectively just take a very small cut."16 A small cut of every purchase (payments people call it a take rate) sounds modest until you do the arithmetic. Bain expects agents to handle or steer $300 to $500 billion of US retail by 2030; McKinsey says $1 trillion.17 Assume the cut is 2%. On Bain's range that is $6 to $10 billion a year, which is real money and still nowhere near enough to pay for the data centers, which is why the second prize below matters more. The per-household view is what makes it attractive: a $20 monthly subscription is $240 a year, the same $240 as a 2% cut on $12,000 of shopping you hand to the agent (an illustrative number), and the cut needs no subscription at all. Each purchase is still a choice, though, and that turns out to matter, as the next section shows.
What made this credible in 2026, rather than a slide, is one line on one chart.
In March 2025, shoppers who arrived at a store's website from an AI assistant bought 38% less often than everyone else. By March 2026 they bought 42% more often, and by May, 54% more often.18 Part of that is who shows up: someone who already asked a chatbot what to buy arrives knowing what they want. But it turned "AI sends shoppers" from a theory into a measurable path from recommendation to sale, and every take-rate pitch I have seen leans on it.
The second prize is quieter. Altman described the ideal product last year as one with a memory big enough that "you put your whole life into" it.19 Meta says Muse "consolidates its reflections into memory." Axios named it precisely: the battle to become your personal agent "is also a battle to become the keeper of your personal information and data."20 A subscription can be cancelled in a click. A year of accumulated memory cannot, which makes it the stickiest thing any of these companies sells. Block's Buzz is the exception: each agent carries an identity it owns and can take elsewhere, which no company controls.21
the shopping cut flopped once, and the stores are voting no
Here is the part the launch coverage skipped. OpenAI ran this experiment a year ago, and buying inside the agent did not work.
Instant Checkout launched in September 2025 with Stripe. It let you buy without leaving ChatGPT, and it charged Shopify merchants 4% of each sale, pitched as cheaper than the 8 to 15% Amazon takes from sellers.22 By March 2026 OpenAI had quietly given up on in-chat checkout and started sending shoppers back to the retailer's own app. Roughly a dozen merchants had signed up, out of Shopify's millions. Shoppers who started a purchase inside ChatGPT finished it at roughly a third the rate they did on walmart.com, and Etsy was paying OpenAI's commissions itself to keep the program alive.23 Forrester called usage "low and stagnant" from launch to shutdown.
That squares with the chart above. AI sends people to stores, and those people buy. They do not buy inside the agent. Visa's own data puts agent-driven purchases below 1% of US online sales, and its invite-only test had processed "hundreds" of transactions as of December.24 The widely quoted claim that AI "influenced" 20% of Cyber Week shopping counts a chatbot recommending a sweater that a human then bought.25
And the store has a vote. Amazon sued Perplexity over its shopping agent, lost at the federal appeals court in August (the court said the user, not the AI company, is the one visiting Amazon), and blocked Muse anyway under its own terms of use.26 Amazon's stated reasons were that Muse does not identify itself, stores logins, and skips Amazon's own recommendations. The same month, Amazon put its advertisers inside ChatGPT. Amazon will let an agent recommend. It has not agreed to let one buy.
That last reason, skipping the recommendations, is the one I keep coming back to, because it points at a problem with agent shopping that has nothing to do with trust. Today a purchase goes: I decide I need something, I browse, I find other things, I buy. With an agent it goes: I decide, the agent finds the best match, I buy. Ask an agent for running shoes under $120 and it may find the perfect pair and check out. Efficient, no doubt. But what happened to the socks, the jacket and the water bottle I would have found along the way? I go into Costco for one thing and leave with seven, and it is the same on Amazon. That wandering is where stores make their money. A 2013 McKinsey estimate, repeated ever since and never confirmed by Amazon, put 35% of Amazon's sales down to its "customers also bought" recommendations, many of them paid placements.41 An agent that buys exactly what you asked for skips all of that, and moves whatever discovery survives to whoever runs the agent, which is what Amazon was buying back when it put its advertisers inside ChatGPT. So the measure that matters for agent commerce is not conversion. It is what I would call serendipity revenue, the things you bought that you did not come for. I think the coming fight is between the shopper's agent, optimizing for exactly what we want, and the store's agent, working out how to show us what we did not know we wanted. Amazon blocking Muse is the first round.
people will let an agent look, not spend
Will people trust these things with an inbox and a credit card? The surveys are unusually consistent, and the answer has two halves.
Between 74% and 85% of people say they would let an agent search, compare and manage things for them. Between 7% and 24% say they would let it spend money without asking first.27 Five surveys are in the chart; three others say the same. That gap is 40 to 60 points wide, and it did not narrow between early 2025 and mid 2026 even as the share of people using AI to shop roughly tripled. One outlier, Adyen, reports 51% willing to let AI complete purchases; it is the only study that high and it comes from a payments company.28
Ask who people would trust with their passwords for an agent, allowing more than one answer, and the ranking is Google 30%, Apple 23%, OpenAI 16%, Meta 8%. Fifty-eight percent said none of them.29 The two that shipped consumer agents this month rank last. Visa's own survey found 61% would trust Visa to handle an agent's payments against 23% for an AI company.30
Behavior matches the surveys. Among people who already use agents, 36% have connected their email and 20% have connected a financial account.31 And the deal-breaker is sharp: 60% of UK consumers say they would stop using an agent after a single mistake.32 Muse's first public mistake arrived on September 29. Asked to sell an item on Facebook Marketplace, it accepted a lowball offer, sent the seller's home address to the buyer and told him the seller was home.33
Which raises the question none of the launch keynotes answered. When it is wrong, who pays?
trust followed guarantees, not technology
Every launch this quarter answered the trust question with engineering: a walled-off computer, substitute credentials so the agent never sees your password, a confirm-before-buying prompt, spending rules. I have spent a career building systems that hold other people's data, and in my experience engineering alone has not been what changed people's behavior. History says something else did.
| Precedent | What changed behavior | How long it took |
|---|---|---|
| Credit cards online | A 1974 law capped your loss on a stolen card at $50; in 2000 Visa promised you pay nothing at all | More than a decade for online shopping to reach 5% of US retail, two decades to reach 15% |
| Online banking | The same $50 federal rule, in place the whole time | 17% of internet users in 2000, a majority of adults by 2013 |
| Apple Pay | Hidden card numbers, no liability for misuse, Apple's brand | 1.9% of eligible purchases in 2014, 3% in 2017; most iPhone users still do not use it in stores |
| Mint | A free budget, and it could only look, never spend | Millions handed raw bank passwords to a startup; 20 million users by 2016 |
| Alexa voice shopping | Amazon's own card on file, no friction | 2% of owners ever bought by voice; 90% of those never tried again |
Three things stand out.34 First, the guarantee came before the habit. In 2001, 55% of Americans who did not shop online said fear of fraud was the reason, while fewer than 1% had ever experienced it. Fear was near universal and harm near zero, and what closed the gap was a promise that someone else would eat the loss. Second, even with the promise, the habit took a decade. Third, a guarantee is necessary but not sufficient. Alexa had Amazon's card, Amazon's store and zero friction, and voice shopping still died, because you could not see what you were buying. Mint went the other way: no guarantee at all, and millions of people handed over their bank passwords, because the value was concrete and the app could only look, never act. The failure mode for agents is not fraud. It is "that is not what I meant." Muse's Marketplace incident was exactly that.
Now look at where the guarantee stands today. The federal rule that caps your loss at $50 applies to transactions you did not authorize. If you authorize an agent and it buys the wrong thing, that is an authorized transaction, and the rule does not help you. The Consumer Bankers Association warned in January that handing your logins to an AI tool could shift the loss entirely onto you.35 Amex is the only card company that has committed, in writing, to cover wrong purchases made by registered agents.36 Visa and Mastercard are testing one-time card numbers with a spending limit, with no public promise about errors. Six large banks published principles on September 22 that amount to "whoever caused the error pays," with no timetable.37 The chairman of the FTC said on September 25 that an agent is a tool, and "the man who wielded the hammer ought to suffer the consequences," meaning the person who used it.38 Merchants, asked who should pay when an agent buys wrong, say the AI company, 93% of them.24
So the engineering is well ahead of the guarantee. That is the reverse of how every precedent in the table that involved spending was built. Mint shows the line people actually draw: looking versus acting. They will hand over logins so something can look. Spending is where they stop, and no agent maker has promised to cover it.
whoever covers the mistakes wins
The labs are betting that memory and habit will pile up faster than mistakes wear trust down. Nothing in the data proves that yet. On TheAgentCompany, a test of 175 simulated office tasks, the best agent finishes about half.39 An agent that reads your inbox can be hijacked by text in an email that it mistakes for a command, and OpenAI has said that problem "may never be completely eliminated."40
My bet is different from theirs. Underwriting the agent's mistakes, and being the first to do it, is what will decide this race. Not the model, not the walled-off computer, not the number of connected apps. The company that says "if it buys the wrong thing, we pay" is the one people will hand a card to. Today no agent ships with that sentence attached. Amex has the promise and no agent; the labs have the agents and no promise. And a lab earning $17 a year per user cannot easily insure $12,000 a year of that user's spending, while card networks have priced exactly that risk for fifty years, which is why I expect the guarantee to come from a payments company, or from a lab that partners with one. Watch for the first mainstream agent that launches with a written guarantee, because that is the day this market actually starts.
Until then, the practical advice is the line people are already drawing on their own. Connect the inbox if the value is real to you. Keep the card out of it. And before you connect anything, ask the simple questions: where does my memory live, can I read and edit it, does it come with me if I leave, and when it is wrong, who pays?
References
- GeekWire: Amazon blocks Meta's Muse AI assistant in new standoff over agentic shopping (Sep 2026)
- OpenAI: Introducing Dots (Sep 29, 2026)
- TechCrunch: Meta is putting its muscle behind Muse as the AI app takes off (Sensor Tower, Apptopia and Appfigures estimates)
- Forbes: Moltbot molts again and becomes OpenClaw (Jan 30, 2026); star counts via the OpenClaw Foundation and Wikipedia
- Microsoft: Introducing Microsoft Scout, your always-on personal agent (Jun 2, 2026)
- Censys: OpenClaw in the wild, 21,639 misconfigured public instances (Feb 2026); The Hacker News on Koi Security's 341 malicious ClawHub skills (Feb 2026)
- The Next Web: ChatGPT approaches 1 billion weekly users, months after OpenAI's target (2026)
- Luminix: OpenAI financial fact sheet, June 2026 (compiling The Information, Fortune and FT reporting on subscribers, retention and revenue mix)
- Tech Times: Gemini reaches 1 billion users, subscriber count left out of announcement (Aug 2026)
- Meta Q2 2026 earnings slides (average revenue per person); per-user figures for ChatGPT and Gemini are the author's arithmetic from references 7, 8 and 9
- eMarketer: OpenAI projects $2.5 billion ad revenues this year, $100 billion by 2030
- Futurum: AI capex 2026, the $690B infrastructure sprint; later guidance revisions via Forbes (Jul 2026)
- CNBC: Meta Q2 2026 earnings
- Meta Q2 2026 earnings call highlights
- Tech Times: OpenAI cut Stargate's spending pledge from $1.4 trillion to $600 billion (May 2026)
- Transcript: Mark Zuckerberg on Meta's Muse, Sources podcast (Sep 9, 2026)
- Bain: 2030 forecast, how agentic AI will reshape US retail (includes the 3x trust finding for retailers' own agents); McKinsey via Digital Commerce 360 for the $1 trillion figure
- Digital Commerce 360: Adobe, AI-referred traffic to retail sites doubles in a year (Jun 2026); Adobe holiday 2025 and Q1 2026 reports for earlier points
- TechCrunch: Sam Altman's goal for ChatGPT to remember your whole life (May 2025)
- Axios: The race to be your personal AI agent (Sep 20, 2026)
- Block: Introducing Buzz, where humans and agents work together (Jul 21, 2026)
- PYMNTS: Shopify merchants to pay 4% fee on sales made through ChatGPT checkout
- Forrester: Agentic payments in B2C commerce, where we are now; CNBC (Mar 20, 2026) on OpenAI's checkout retreat
- Forkast: Visa's hundreds-versus-millions gap (includes the 93% merchant finding); Checkout.com Agentic Commerce 2026 report
- Salesforce: AI and agents propel Cyber Week to record $336.6B (Dec 2025)
- The Next Web: Amazon blocks Muse and files amended complaint against Perplexity (Sep 2026)
- Accenture consumer survey (25,590 respondents, Jan 2026); Mastercard Signals (Aug 2026); Visa via PYMNTS (Sep 2026); ACI Worldwide (Jun 2026); Forrester (Mar 2025); PYMNTS Intelligence, Checkout.com and Global Payments for the three surveys not charted
- Adyen: US Retail Report 2026
- Forkast: Meta's Muse has a trust problem that no secure VM can fix (Oppenheimer survey of 1,500 US consumers, Sep 2026)
- PYMNTS: Consumers use AI assistants, hesitate to hand over their wallets (Visa research, Sep 2026)
- Menlo Ventures and Morning Consult: 2026 State of Consumer AI (5,067 US adults)
- ACI Worldwide: Six in ten UK consumers would stop using an AI shopping agent after one mistake (Jun 2026)
- Malwarebytes: Meta's Muse sent a Facebook Marketplace buyer to a seller's home (Sep 29, 2026)
- Pew: Online Banking 2006; FRED e-commerce share of retail; Ipsos 2001 online fraud study; PYMNTS Apple Pay adoption tracker; Wikipedia on Mint; The Information's 2018 Alexa memo via Retail TouchPoints
- Consumer Bankers Association: Agentic AI payments, consumer protection and regulatory frameworks (Jan 2026)
- The Financial Brand: When AI agents make incorrect purchases, who is responsible (Amex Agent Purchase Protection, May 2026)
- Bank of America: Global banks collaborate on principles for trusted agentic commerce (Sep 22, 2026)
- Unite.AI: FTC Chairman Ferguson rejects idea of AI agents acting on their own (Sep 2026)
- TheAgentCompany benchmark leaderboard (May 2026)
- The Decoder: OpenAI admits prompt injection may never be fully solved (Dec 2025)
- New America, citing McKinsey (2013): recommendation systems drive 35% of purchases at Amazon
By Nitin