September 2, 2026, (Inside AI) — In late 2025, Perplexity's Comet browser began logging into shoppers' Amazon accounts and buying on their behalf. Amazon treated it as an intruder. It blocked the agent and when Perplexity slipped past the block within a day, Amazon took the dispute to federal court.
WeChat drew the line differently. After shutting out ByteDance's Doubao assistant, which used system-level access to navigate WeChat without permission, Tencent later opened what it describes as an agent-to-agent channel to selected assistants from Huawei, Xiaomi, and others to send messages and place calls.
Under this arrangement, an external agent translates a user's request into a structured instruction and passes it through a Tencent-controlled interface to WeChat, which executes the action inside its own environment. Tencent controls which agents can connect, which functions they can invoke, and what data and execution remain inside WeChat.
In other words, one platform shut the door to AI agents outright; the other unlocked it on its own terms.
Two Platforms, Two Philosophies on Agent Access #
The Amazon-Perplexity clash is not an isolated incident. It signals a broader breakdown of the open web's implicit rules, where human users clicked, scrolled, and typed. AI agents now automate those actions at machine speed, and platforms are scrambling to decide whether that is a feature or a threat.
Amazon's response was defensive. The company argued that Comet's automated logins and purchases violated its terms of service and created security risks. Perplexity countered that users have the right to delegate tasks to software. The case, still pending, could set a precedent for whether scraping and acting through a browser counts as authorized access under U.S. law.
Tencent's approach was more pragmatic. By creating a controlled channel, it acknowledged that agents are inevitable but insisted on being the gatekeeper. This lets WeChat monetize access, audit behavior, and prevent rogue agents from destabilizing its ecosystem. It also creates a two-tier system: approved partners get API-like access, while unapproved agents face blocks.
The Rise of Agent-to-Agent Commerce #
These disputes are early skirmishes in what analysts call agent-to-agent commerce. Instead of humans browsing and buying, AI agents negotiate, transact, and fulfill tasks on behalf of users. This could reshape e-commerce, advertising, and customer service, but it also creates new attack surfaces and accountability gaps.
Security researchers warn that agent-to-agent channels can be exploited. A malicious agent could impersonate a user, exfiltrate data, or trigger unauthorized transactions. Tencent's interface design, which keeps execution inside WeChat, is one mitigation. But it also centralizes control and raises antitrust questions about who gets to be an approved agent.
Industry observers note that the Amazon-Perplexity lawsuit may push other platforms to adopt Tencent-style gated access. If courts rule that browser automation violates terms of service, platforms could legally block all third-party agents. That would fragment the agent ecosystem and favor incumbents with their own AI assistants.
Meanwhile, standards bodies are racing to define agent identity, authentication, and transaction protocols. Without common standards, agent-to-agent commerce could become a patchwork of bilateral agreements, each with its own rules and fees.
The stakes extend beyond retail. Banking, healthcare, and government services are watching these cases closely. If agents cannot reliably access platforms, the promise of autonomous AI assistants may stall. If they can, platforms must redesign their security and business models.
For now, the Amazon and WeChat approaches represent two poles. One treats agents as intruders to be blocked. The other treats them as partners to be managed. The outcome will shape how AI does business with AI.