Potential of AI agents for task execution faces integration challenges with major online services
Read more
Egypt Independent
www.egyptindependent.com

Potential of AI agents for task execution faces integration challenges with major online services

AI agents promise to take on a wide range of user tasks, but their implementation depends on the willingness of popular applications and services to provide them with the necessary access. These agents go beyond simply answering questions or generating images; they are capable of performing multi-step actions on the internet, such as price comparison, making purchases, booking, and filling out forms, provided the relevant companies grant permission.

This potential shift could trigger a new competitive battle in the online services sector. For instance, Amazon recently blocked access to its store for Meta's AI agent Muse, which some experts believe foreshadows a dilemma for online businesses.

If users begin actively using AI agents in daily life, companies will have to make an important decision: either cooperate with entities like Meta, risking the obsolescence of their platforms, or miss the opportunity to reach billions of customers through what could become the future of human interaction with services.

Following the announcement of new updates for its Muse agent, stocks of companies such as Airbnb, Expedia, and Trip Advisor dropped by approximately 5% last week.

The concept of AI agents is not new; Meta, OpenAI, Google, Apple, and Amazon have been working on this direction for several years, gradually implementing features similar to agent functionality. However, Muse quickly gained popularity, ranking first in the free apps list on the Apple App Store just 10 days after its debut on September 8th. The agent's success is largely attributed to Meta's extensive presence on the internet, owning Instagram, Facebook, and WhatsApp, as well as the application's relatively simple interface.

According to Francisco Heronimo, an analyst at the International Market Research Corporation, Meta has demonstrated the capabilities of Muse to consumers better than other tech giants. He noted: 'Others haven't talked as loudly about using agents for shopping as Meta did with Muse, and I think that's the main difference.'

Meta has formed partnerships with Walmart, GameStop, Sephora, Expedia, OpenTable, and Shopify to integrate its services into the Muse app. Nevertheless, e-commerce giant Amazon refused to cooperate with Meta. Amazon blocked the agent, stating that there was no notification or choice regarding the availability of its store through Muse. The company also expressed concerns about the handling of data and Amazon account credentials, noting that agents do not provide personalized Amazon recommendations.

In a statement addressed to CNN, Amazon said: 'We consider it quite obvious that third-party applications offering to make purchases on behalf of customers in other companies should operate openly and respect the service providers' decisions on whether or not to participate.' Similarly, the online restaurant booking platform Resy informed CNN that it 'currently does not allow unauthorized third-party bots or agents' access to its services. The platform blocked a user's account after attempts by their AI agent, a helper named Instinct, to book hundreds of tables per hour earlier this month.

Resy warned: 'Unauthorized automated activity can create risks for the platform and disrupt a fair booking experience for visitors.' Meanwhile, CNN managed to book a table through Muse by providing credentials such as a phone number and confirmation code. Resy integrates with ChatGPT and Claude and stated that it will 'continue to evaluate the possibilities' as AI agents develop.

Although Amazon may be an exception, some experts believe that AI agents pose real risks that could cause many online service providers to hesitate before allowing agents to use their platforms. Firstly, there is a possibility of reduced web traffic if tasks are predominantly solved through AI agent applications. Furthermore, brands may lose the ability to study customer purchasing habits or attract users to additional purchases through in-app promotions or product recommendations.

Mandeep Singh, a senior industry analyst at Bloomberg Intelligence, noted: 'You browse Amazon looking for something you need, but then you also see other things that you know you can buy.'

Moreover, Meta CEO Mark Zuckerberg announced on Wednesday that the company plans to eventually charge a commission for transactions made through Muse. This means that other companies may lose part of their sales.

The impact may not only affect stores and booking apps. AI agents excel at research-intensive tasks, such as comparing insurance policies or mobile operator plans. This could potentially make it easier for users to switch tariffs to obtain more favorable conditions.

However, the potential benefit could also be enormous. According to market intelligence firm Sensor Tower, Muse has already been downloaded over 2.5 million times, providing businesses visibility among millions of people worldwide. This could make Muse particularly attractive to small and medium-sized brands, such as those operating on Shopify.

Katrin Heinz, Vice President of Enterprise and AI Alliances at Expedia, told CNN that this was part of the appeal for the Expedia travel platform, as it aims to 'be where travelers are searching.' She added that about two-thirds of Expedia's traffic comes through its own platforms.

Some may view this as a step toward securing the future of their business. Heronimo from International Data Corporation believes: 'I think in the long run we will see exactly this: AI platforms will become the layer and primary interface for most of us when we shop.'

Similar stories

Meta launches AI assistant Muse, which achieves many downloads but creates conflict with Amazon
Read more
olhardigital.com.br

Meta launches AI assistant Muse, which achieves many downloads but creates conflict with Amazon

Meta has introduced Muse, a new personal artificial intelligence agent that has gained rapid acceptance in the United States. The application reached the top of the App Store and positively contributed to the company's stock performance, although it is already facing criticism regarding security, privacy, and access to third-party systems.

Within days of its launch in the American market, Muse surpassed 2.5 million installations, according to data provided by Sensor Tower. In response to this success, Meta's shares rose by 11% on Monday. Truist Securities projects that this feature could add US$ 28.5 billion (approximately R$ 146.4 billion) to the company's revenue by 2030.

To optimize its operation, Muse has the ability to access emails, calendars, and messages, implying that the user must deposit a considerable amount of personal data into the agent. A survey conducted by Oppenheimer & Co. illustrates this hesitation, indicating that only 8% of American consumers declared confidence in sharing their passwords with Meta, compared to 30% for Google.

Meta assures that the development of Muse prioritized security, stating that each agent operates on a dedicated and protected computer. Prior to the launch, Alexandr Wang, the company's head of AI, mentioned that the main concern was preventing leaks of personal data or accidental deletion of important emails.

Nevertheless, security concerns persist. Youssef Squali, an analyst at Truist, warned that a large-scale incident compromising credentials or credit card information could undermine trust not only in Muse but in the entire AI agent sector.

The first significant challenge for Muse arose in the e-commerce segment when Amazon blocked the agent on its website, preventing it from browsing or making purchases on behalf of users. Amazon stated that it had not received prior notice of such access nor authorized the action. An Amazon spokesperson emphasized that external applications making purchases for customers must operate transparently and respect the access permission guidelines established by the services.

Behind this block lies also a concern related to the business model. If AI agents start making purchases in place of individuals, users might have less exposure to pages displaying advertisements. For several analysts, this could generate resistance from major internet platforms, especially those whose revenue depends on advertising.

Meta, for its part, signals partnerships with Shopify, Instacart, and Dick’s Sporting Goods. Muse's advancement also generated reactions in other segments: there was a decline in the stocks of asset managers, brokers, and banks, with Charles Schwab registering a drop of over 6%. Booking Holdings and Allstate were also impacted.

Meta holds a crucial advantage, given that Facebook and Instagram offer vast distribution infrastructure, in addition to their services already accumulating data from millions of users. Currently, the only comparable product is the Instinct startup's agent, which is available only by invitation.

However, this landscape is expected to change soon. Analysts predict that OpenAI will announce a consumer-focused AI agent in the coming weeks. Google is also cited as a potential competitor, and Apple may enter this market later.

In this context of fierce competition, being a pioneer can be decisive. According to Ken Gawrelski, an analyst at Wells Fargo, the effectiveness of these assistants improves as consumers become familiar with them and direct their functionalities. Furthermore, Muse demands high computational capacity, as each agent runs on its own virtual computer, which represents a factor in the dispute; however, analysts cited by the Wall Street Journal indicate that Google possesses sufficient infrastructure to develop a similar solution.

So far, the rapid implementation of Muse has positioned Meta at the epicenter of this new dispute. However, the agent's success will not depend solely on the number of users, but also on the willingness of platforms to allow an artificial intelligence to perform tasks on behalf of their customers.

AI agents should be treated as privileged users due to their expanded access to corporate systems
Read more
techcentral.co.za

AI agents should be treated as privileged users due to their expanded access to corporate systems

Autonomous artificial intelligence agents and AI models themselves are no longer part of isolated experiments but are now integrated into the core business processes of enterprises. They connect to databases, business applications, cloud platforms, internal APIs, and third-party services, bringing real value to the business.

However, this creates a serious security problem: what happens if an AI system gains access to more organizational information than it needs? The risk is not that the model will give an incorrect answer, but that the application, agent, or connected AI tool could be compromised, manipulated, or misconfigured, using its access to reach confidential systems, disclose data, or initiate unintended actions.

As AI becomes more autonomous and capable, companies must consider not only the functionality of the models but also the places they can connect to.

How AI Agents Become Privileged Corporate Applications

Many companies use AI services that interact with critical infrastructure and sensitive information. These systems are capable of extracting customer records, querying financial databases, generating software code, initiating workflows, and calling external services. In essence, this makes them another class of privileged applications.

Unlike traditional applications, which have clearly defined network requirements, clear ownership, and approval processes, AI environments are evolving much faster. New tools, plugins, and integrations appear within days, often without a full understanding of the connectivity they require. The consequence is overly broad access, unrestricted outbound communication, and unnecessary exposure between AI workloads and sensitive business systems.

If an AI agent is compromised—whether through prompt injection, malicious content, or a vulnerable third-party integration—the extent of the damage is determined by this excessive level of connectivity. The problem is not that the model went outside the network; the problem is that it was initially granted access to systems it should never have been able to reach.

Controlling Risks Through Connectivity Management

A secure AI strategy requires implementing connectivity management: there must be a clear understanding of all systems that the AI workload can communicate with, including internal applications, databases, cloud services, development platforms, and third-party APIs. Each such connection must be verified against a simple question: is it necessary? — and limited to its intended business purpose.

This implies that security and infrastructure teams must map AI application dependencies, assess the risk of each proposed connection, and ensure the principle of least privilege is applied. Instead of allowing an AI service to access the entire internal network and the internet in general, organizations can restrict it only to the specific applications, services, ports, and endpoints it needs. If the workload behaves unexpectedly or is compromised, the damage remains localized.

Securing Connections with Third Parties

The danger is not that an AI agent might encounter malicious instructions through a third-party source or plugin. The danger is that these instructions could reach an agent that has already been provided with powerful tools, credentials, and access to corporate systems.

The Open Worldwide Application Security Project (OWASP) classifies 'excessive agency' as one of the main risks in applications built on large language models, linking it to three primary causes: unnecessary functionality, unnecessary permissions, and unnecessary autonomy.

Most AI implementations rely on external providers of models, Software as a Service platforms, plugins, data sources, and APIs. These dependencies provide functionality but also expand the attack surface.

Protecting the model itself is not enough. Organizations must manage the entire environment around it—its identity, permissions, tools, APIs, applications, and network connections. The AI agent should only be able to access what is necessary to perform its job, and security teams must be able to see, justify, and continuously re-verify every such connection. AI changes the way applications work, but it does not change the principle of least privilege; it only increases the cost of ignoring this principle.

Popular