Skip to content
TECH CEO Daily
Big TechAnalysis

AI agent access: Google, Meta and Amazon now decide which outside assistants get in

In September, platforms opened authenticated channels for approved agents, charged for some of them and blocked an unauthorized one, setting the rules for agent commerce.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Meta and Google launched MCP servers in mid-September that let approved outside agents act on WhatsApp Business and Google Home.
  • 2Amazon began blocking Meta's Muse from shopping on Amazon.com on the night of September 20, citing unauthorized agent access under its terms, TechCrunch reported.
  • 3Companies should publish their own agent access rules and check which platforms their chosen AI agents are actually permitted to use.

The news

AI agent access became a platform decision in September 2026. Google and Meta opened authenticated doors for outside AI agents, Apple routed Siri's new actions through its own app framework, and Amazon blocked Meta's Muse agent from shopping on Amazon.com.

The doors are built on the Model Context Protocol, or MCP, an open standard that lets AI agents connect to software tools through defined interfaces. On September 15, Meta (META) launched a WhatsApp Business Tools MCP server, designed to work with Claude, Cursor, Codex and ChatGPT, that lets agents set up business accounts, verify phone numbers, register for the Cloud API and manage message templates. Meta said the server is rolling out gradually and is currently discoverable on Claude, Codex and ChatGPT. Meta's developer post says access runs through Facebook Login for Business with specific permission scopes, requires admin verification, demands an authenticated person for any change and logs every call. Meta said the release is for development and testing, not production messaging at scale.

On September 16, TechCrunch reported that Alphabet's (GOOGL) Google launched an MCP server for Google Home that lets Claude, ChatGPT, Hermes, OpenClaw and Google's Antigravity control devices, review camera summaries and build dashboards. Access requires the $20-a-month Google Home Premium Advanced plan in the United States, and users must create a Google Cloud project and grant permissions. Apple's Siri AI, released September 14, acts inside third-party apps through Apple's App Intents framework, starting with WhatsApp and Audible, with Microsoft Outlook to follow.

Meta is also on the other side of the gate. Its Muse agent, launched September 8 with free, $20 and $100 monthly tiers, runs in a separate secure browser environment and completes purchases through Stripe's Link checkout, TechCrunch reported. Muse drew 1.8 million iOS downloads in the U.S. and Canada in its first 12 days, compared with 1.3 million for ChatGPT over its own launch period, according to Apptopia data cited by TechCrunch.

On September 21, TechCrunch reported that Amazon (AMZN) had blocked Muse from buying on Amazon.com. Starting on the night of Sunday, September 20, users saw an error stating: “Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed.” Separately, Amazon announced a plugin, in beta for sellers in its U.S. stores, that lets them connect their seller accounts to Anthropic's Claude, which can then act on the account with the seller's approval, as Amazon's own agentic Seller Assistant does inside Seller Central.

The numbers

Google Home Premium Advanced price for MCP access
$20 per month (U.S.)
Muse paid tiers
$20 and $100 per month
Muse iOS downloads, first 12 days (U.S. and Canada)
1.8 million
ChatGPT iOS downloads, its own first 12 days (U.S. and Canada)
1.3 million
AI clients Meta lists for WhatsApp Business MCP
4 (Claude, Cursor, Codex, ChatGPT); rolling out gradually

Why CEOs should care

Product and digital leaders need an agent policy for their own platforms. The emerging model is clear: offer an authenticated channel, such as an MCP server or API, with narrow permissions, logging and human confirmation for changes, and use terms of service to exclude agents that do not identify themselves. Decide which agents you will admit, measure agent traffic separately from human traffic, and consider how agent purchases bypass the ads and merchandising you rely on.

CISOs should look at both directions. Outbound, employees may install agents such as Muse on work Macs, where TechCrunch reported it can act on files, messages and calendars after users grant permissions. Set rules for which agents may run on managed devices and what they can reach. Inbound, Meta's design choices, including admin verification, no tokens in prompts and full call logs, are a useful baseline when evaluating any vendor that lets agents touch your systems.

Buyers of AI agents and CFOs should recognize that an agent's value depends on platform permission, not only model quality. Access can be withdrawn overnight, as Amazon showed, or placed behind a subscription, as Google did. Before committing budget, confirm which platforms the agent is authorized to use, and write continuity terms into contracts in case a major platform revokes access.

The bigger picture

Control of the action layer, where software actually books, buys and changes things, is becoming the next platform contest. Meta, Google and Amazon now each play two roles: they build their own agents, such as Muse, Google Antigravity and Amazon's Seller Assistant, while deciding how outside agents may use their services. Standards such as MCP make connections cheap, but authentication, permissions and terms of use let platform owners keep control over who connects and on what terms.

What’s next

Watch whether Meta widens its WhatsApp MCP server beyond testing, whether Google extends Home access to other plans and countries, and when Apple's Outlook integration arrives. The Amazon and Meta standoff is the test case: a negotiated, identified channel for Muse would signal that platforms prefer licensing agent access to blocking it.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

Earlier coverage of Google

All Google coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.