The web is becoming an unstable dependency for AI assistants
I liked Meta Muse more than I expected. Two weeks later, I was already running into the thing that may limit assistants like it: the web does not have to cooperate.
A couple of weeks ago I tried Meta Muse and liked it more than I expected to. The UX is slick.
I liked the way it handled passwords and credentials. I liked that it could keep working through a browser without making me babysit every step. The Stripe Link integration was particularly smart. It gives Muse a way to pay across sites without handing the agent your underlying card details directly.
I went in somewhat skeptical because it is Meta. Meta has enough history around privacy that I am not naturally inclined to hand it more personal information. To its credit, Muse is designed around a dedicated secure VM, encrypted credential storage, approval before sensitive actions, and controls over which services it can access. Meta has made privacy and security a fairly central part of how it is positioning the product.
I still have reservations about trusting Meta with that much context. But as a product, I liked Muse. Then I tried to use it.
The web gets a vote
One of the things I asked Muse to do was close an old Etsy store of mine. This was not an ambitious task.
I was doing some personal housekeeping and had an old store I no longer needed. It was exactly the kind of annoying, low-value administrative task I want an assistant to take off my hands.
Muse got blocked. That changed how I thought about the product surprisingly quickly.
The interesting part of an agent is not that it can tell me how to close an Etsy store. A chatbot could already do that.
The interesting part is that I can say, "Please take care of this," and stop thinking about it. If the agent gets to the site and cannot proceed, a lot of that value disappears.
Muse is already running into this problem elsewhere. Less than two weeks after its launch, Amazon blocked Muse from accessing its shopping site. Amazon has also taken a restrictive stance toward other third-party shopping agents. This is probably not going to be an isolated fight.
I have started thinking about my own automations differently
I am currently in the market for a car. I have an agent workflow that automatically checks for new listings matching what I care about and sends me the interesting ones.
It is useful because I do not have to repeatedly search the same sites. I can define what I want once and let the software watch for changes.
A few months ago, I would have thought mostly about whether the workflow was reliable. Now I also find myself wondering how long the underlying access will continue to exist.
Maybe the listing site changes its markup. Maybe it rate-limits automation more aggressively.
Maybe it adds a bot challenge. Maybe it decides agents are bad for its business model and blocks them outright.
My automation currently works. I am basically waiting for the day it does not.
This is a weird foundation for a product category
The current generation of agents depends heavily on infrastructure they do not control. The browser is theirs.
The model is theirs. The agent loop is theirs.
The website is not. That distinction matters more as agents become capable of doing useful things.
When bots mostly indexed the web, sites had a fairly legible relationship with them. Search engines crawled pages and sent people back.
Agents are different. An agent can potentially sit between the customer and the site.
It can compare products without showing the customer the full storefront. It can bypass carefully designed upsells. It can transact without the person seeing an ad. It can decide which vendors the user ever encounters.
From the website's perspective, that is not necessarily an uncomplicated win. I may want my assistant to shop across twenty stores for me.
Each of those stores may prefer that I arrive personally. That tension is going to matter.
Capability is not the same as usefulness
A lot of AI discussion still focuses on model capability. Can the agent reason through a task?
Can it use a browser? Can it fill out a form?
Can it recover when something changes? Those are real technical questions.
But an agent can be perfectly capable of completing a task and still be unable to do it because the service on the other side refuses access. That creates a strange ceiling on the entire category.
The assistant gets smarter, but the environment becomes more hostile. We may end up with agents that can theoretically do almost anything a person can do online while being permitted to do a much smaller subset of it. That gap between capability and permission is starting to look important.
We are adopting and abandoning products incredibly quickly
There is another part of this I find interesting. The agent ecosystem is moving so quickly that my relationship with software feels less durable than it used to.
A new product appears. It solves something I care about.
I spend a few days imagining all the workflows I can move onto it. Then a model changes, an API changes, a site blocks it, the product changes direction, or something better appears.
And I move again. The adoption cycle is incredibly fast, but so is the abandonment cycle.
That makes it difficult to know how deeply to integrate any of these products into my life. Muse is a good example.
I liked it enough that I immediately started looking for boring tasks to hand over. Within days, I was also seeing the boundaries of where it could operate.
That does not make Muse a bad product. It makes the environment around Muse unstable.
I am not sure where this settles
There are several plausible outcomes. Sites could build official interfaces for agents and decide exactly which actions they want to allow.
Large assistant platforms could negotiate direct integrations one company at a time. Payments standards and identity systems could make agents more recognizable and trustworthy to websites.
Some sites may simply decide that third-party agents are useful distribution and welcome them. Others may insist that users interact through their own assistants.
We could end up with something that looks a little like the mobile app ecosystem, where the dream of a broadly interoperable layer gradually turns into a set of controlled platforms and bilateral integrations. I do not know yet.
What I do know is that I am becoming more cautious about treating agent capabilities as durable. When I see an assistant perform an impressive task now, my next question is increasingly not just "can it do this?"
It is "who has to keep allowing it to do this?" That feels like a much more consequential question than it did even a few weeks ago.