Field note

Why are retailers blocking AI shopping agents?

Some large retailers now restrict AI shopping agents, blocking their crawlers in robots.txt and, in one 2026 case, winning a court order against an agentic browser, to keep shoppers, data, and ad revenue inside their own ecosystems. This explainer maps the walled-garden shift, the Amazon v. Perplexity ruling, and what it means for where AI can discover your products. Facts attributed, dated, and hedged.

Buffy Editorial2026-07-21 · 7 min read

Some large retailers are now restricting AI shopping agents, blocking their crawlers in robots.txt and, in one 2026 case, winning a court order against an agentic browser, to keep shoppers, data, and advertising revenue inside their own ecosystems. For your brand, the consequence is direct: where an agent can discover and buy your products increasingly depends on each platform's access rules, not only on how well your own site is built.

This explainer maps the walled-garden shift, sets out what is verifiable about the Amazon v. Perplexity ruling, and separates two things that are easy to confuse: gating agent access and adopting an open checkout protocol. It is the concept companion to the practical playbook on keeping your products visible to AI shopping agents.

What does "blocking AI shopping agents" actually mean?

It means a platform uses technical or legal controls to stop an AI agent from reading its pages or acting inside its accounts. There is no single lever; the blocks fall into three layers, from softest to hardest.

Layer Mechanism Effect on an agent
Crawl block Disallow an AI crawler's user-agent in robots.txt (e.g. ChatGPT-User, OAI-SearchBot) The agent can't fetch live product data from that site
Bot management CDN or WAF rules that challenge or 403 agent traffic The page is unreachable even where robots.txt allows it
Legal / access control Terms-of-service enforcement, or a court order against unauthorized account access The agent is barred from acting inside logged-in areas

The first two are the same mechanisms that can silently keep any brand out of AI answers; the difference here is that a platform is choosing to apply them deliberately, against shopping agents specifically. The third layer is newer and is where the Amazon v. Perplexity case sits.

Which retailers are restricting agents, and how?

The market split into two postures through late 2025 and 2026: a few large players closed their doors to third-party agents, while others opened partner integrations. The clearest documented case of closing is Amazon.

According to reporting from Modern Retail (late 2025), Amazon updated its robots.txt to disallow OpenAI's ChatGPT-User (the fetcher that retrieves live web pages when a user asks) and OAI-SearchBot (which powers OpenAI's search product), on top of an earlier block of the GPTBot training crawler. The same reporting cited OpenAI's own economics research estimating that these agents field on the order of 50 million shopping-related queries a day across the web, the traffic Amazon chose not to expose.

By contrast, other large retailers leaned in: Walmart and Target publicly announced ChatGPT shopping integrations over the same period, and platforms such as Shopify, Etsy, and Wayfair built toward open agent checkout. The takeaway is not "everyone is blocking"; it is that access is now a strategic choice, and it differs by platform, so an agent's ability to find your product can depend on whose storefront it is standing in.

Why would a retailer block agents it could sell through?

Because an autonomous shopping agent threatens three things a large retailer controls today: ad revenue, first-party data, and the checkout relationship.

  • Advertising. Sponsored product placements are one of the largest and fastest-growing businesses at the biggest retailers, worth tens of billions of dollars a year (reporting in late 2025 put Amazon's ad business in the mid-$50-billion range). An agent that reads a catalog and returns "the cheapest option that fits" can bypass sponsored listings entirely, and no one sees the ad.
  • Data and the relationship. When a shopper agent transacts on a user's behalf, the retailer may lose the search query, the browsing signal, and the direct relationship with the buyer. A closed assistant (built in-house) keeps all of that.
  • Checkout control. Owning the final purchase step, and its payment and returns data, is worth defending against an intermediary that inserts itself between shopper and store.

None of these motives require the retailer to think AI shopping is a fad. A platform can believe agentic commerce is the future and still prefer that it happen on rails the platform controls. That is the logic of a walled garden.

What actually happened in Amazon v. Perplexity's Comet?

A U.S. federal court granted Amazon a preliminary injunction against Perplexity in an early legal test of agent access. The verifiable facts, corroborated across CNBC, GeekWire, Engadget, and Retail Brew:

  • The order. On 10 March 2026, District Judge Maxine Chesney, in San Francisco federal court, granted Amazon a preliminary injunction. It directed Perplexity to stop using its Comet browser agent to access shoppers' password-protected Amazon accounts and to destroy Amazon data it had previously collected.
  • The allegation. Amazon, which sued in November 2025, argued that Comet accessed logged-in accounts "with the Amazon user's permission but without authorization by Amazon", and (per Amazon's filings, as reported) disguised its agent traffic to look like an ordinary Chrome browser. Reporting indicated Amazon's claims leaned on the federal Computer Fraud and Abuse Act; treat the exact statutory basis as reported rather than settled.
  • The response. Perplexity called the suit a bully tactic, said it would "continue to fight for the right of internet users to choose whatever AI they want", and signaled an appeal.

Two cautions matter for how you read this. It is a preliminary injunction in active litigation, not a final judgment, and it turns on a narrow point, an agent acting inside a logged-in, password-protected account without the site's authorization, not on whether AI agents may read public pages at all. Public product pages and open feeds are a different question from automated action inside someone's account.

Is blocking agents the same as leaving an open protocol like UCP?

No, and conflating the two is the most common misread. Gating agent access and adopting an open checkout protocol are separate decisions that live at different layers.

  • Access control is about who may crawl your pages and act in your accounts, set through robots.txt, bot management, and terms of service.
  • Protocol adoption is about the plumbing of a transaction once an authorized agent is transacting, standards like the Universal Commerce Protocol (UCP) and the Agentic Commerce Protocol (ACP).

A retailer can back an open commerce standard for the partners and agents it authorizes and still block crawlers or agents it hasn't sanctioned, the two are not in tension. So "Amazon blocked ChatGPT's crawlers" and "Amazon is among the platforms associated with UCP" can both be true: one is a decision about unauthorized access, the other about interoperable checkout for chosen partners. When you assess a platform, ask both questions separately: can an agent reach me here, and if it transacts, on whose rails?

A walled garden isn't a bet against agentic commerce. It's a bet that the commerce will happen on the platform's own terms, with its ads, its data, and its checkout intact.

What does the walled-garden shift mean for your brand's AI visibility?

That you should optimise for the surfaces you can control and never assume the whole web is reachable. Three durable implications:

  1. Your own storefront is your most reliable agent surface. You set its robots.txt, its schema, and its checkout, so it is the one place a closed marketplace can't lock an agent out of. Keeping it open and legible is the highest-leverage move; that is the whole point of discovering in AI but buying on your site.
  2. Don't be the one accidentally blocking. Many brands sit behind a CDN that quietly 403s AI agents. In a world where big platforms block on purpose, an accidental block is an unforced error, check whether your CDN is blocking AI crawlers.
  3. Be present on more than one surface. If one marketplace closes, open partner surfaces, your site, and third-party corroboration still carry you. Single-surface presence is fragile when access is a moving target.

The strategic picture is that AI product discovery is fragmenting, the same theme as how discovery differs across ChatGPT, Google, and Perplexity, and access decisions are now part of that fragmentation. The action companion, how to keep your products visible to AI shopping agents, turns this into a checklist.

Knowing which agents and engines can actually reach and recommend your products, across surfaces and over time, is exactly what Buffy Intel tracks. Keep your own storefront open and legible; verify where an agent can still find you.

Frequently asked

Why would a retailer block an AI shopping agent?

To protect three things it controls today: advertising revenue, first-party shopper data, and the checkout relationship. When an AI agent shops on a user's behalf, it can skip sponsored listings and the retailer's own recommendation surfaces, so a large retailer with a big ad business has a direct financial reason to keep those shoppers inside its app. Reporting in late 2025 and 2026 documented Amazon restricting OpenAI's ChatGPT crawlers on this logic.

Did Amazon really win a court order against an AI shopping agent?

Yes. On 10 March 2026 a federal judge in San Francisco, District Judge Maxine Chesney, granted Amazon a preliminary injunction against Perplexity, ordering its Comet browser agent to stop accessing shoppers' password-protected Amazon accounts and to destroy Amazon data it had collected. It is a preliminary order in ongoing litigation, not a final ruling, and Perplexity said it would keep fighting and pursue an appeal.

Does a walled garden mean I can't be found by AI shopping agents at all?

No. Blocking happens at the level of an individual platform's access rules, not the whole web. Your own site, your product feeds, and open partner surfaces remain reachable if you keep them open and legible. The practical takeaway is to make sure you are not the one accidentally blocking agents, and to be present on more than one surface so a single platform's closed posture doesn't erase you.