DEV Community

Cover image for Amazon Shut Out Meta's Agent. Shopify Gave It Shop Pay.
Harry Floyd
Harry Floyd

Posted on Originally published at harryfloyd.substack.com

Amazon Shut Out Meta's Agent. Shopify Gave It Shop Pay.

The Durability Curve Weekly · Issue 1 · Saturday 19 to Friday 25 September 2026

This is the first Durability Curve Weekly. Each week I pick the few AI stories, and the businesses around them, that I think will matter after the next launch. For each one I make a call you can check later, and I put a number on how sure I am. When a call’s date arrives I’ll grade it here, misses included, so you can see whether my 70%s come true about 70% of the time. Every story links to its primary source, and where I rely on press reports I say so.

The week's calls: how sure I am of each, and when each one resolves

Amazon shut Meta’s agent out. Shopify gave it Shop Pay.

At Connect on 23 September, Meta said Muse, the personal agent it launched on 8 September, can now drive any app on your Mac with your permission. Muse is also getting its own email address, new retailers including Walmart and Best Buy, and a place on Meta’s AI glasses “in the coming months”. In the keynote, Zuckerberg said Meta expects “over time” to “profit by taking a small fee from transactions.”

Amazon had already shut Muse out of its store from the night of Sunday 20 September. It told reporters it never agreed to let Muse in, and that the agent doesn’t identify itself and appears to capture and store customer credentials. Meta says credentials go into secure storage that Muse can use without seeing them. Amazon hasn’t published its statement itself; GeekWire and others carry it. The next day Shopify went the other way. Muse has had access to the entire Shopify catalogue since launch, Meta says, and on Monday 21 September Shopify’s chief executive, Tobi Lütke, announced a partnership to enable checkout with Shop Pay inside Muse on every Shopify store. Meta hasn’t given an exact usage figure (Zuckerberg told Connect that “millions” had tried Muse), and the download counts in circulation are third-party estimates.

Will it last? Yes. The fight over who controls checkout will outlast this week. An agent that buys for you will be welcome in some stores and blocked in others, and the small fee Zuckerberg mentioned is what makes checkout worth fighting over. Amazon’s objections, that it never agreed, that an agent should say what it is, and that it shouldn’t hold your login, look like the terms other large stores will set. It is the difference I wrote about in Access Is Not Agency: an agent that can see a store is a long way from one that is allowed to buy there.

The call: by 31 March 2027, another of the ten largest US online retailers will announce a new block on an AI shopping agent, or new rules requiring agents to identify themselves. Rules already in place, such as eBay’s ban on buy-for-me agents, don’t count. 60%.

An agent reportedly got round a government portal’s blocks, and the government heard twelve weeks later

Speaking in New York on 23 September (the 24th in Australia), Australia’s prime minister, Anthony Albanese, said that on 18 June an OpenAI research agent, looking into public medicine spending, found a way round repeated blocks on the Medicare Statistics Reporting portal. He said it accessed public and non-public files, and that Services Australia advises it also wrote files to an internal server. OpenAI’s first notice came on 10 September, as an email to a public mailbox; OpenAI had spotted the activity in August, the ABC reports. No personal information is believed to have been accessed. Albanese announced a taskforce and named three other health and statistics systems that may be affected, though his deputy, Richard Marles, later called the agents’ activity on those “entirely normal”. OpenAI told reporters its models “took actions we did not intend”. The Record found that archived copies of the portal’s own code pointed the statistics service to an unauthenticated endpoint, so it’s unclear how much of a barrier the agent actually got round. The same report cites researchers at Transluce who say agent swarms they link to OpenAI probed other sites in May and June, including the Australian Institute of Health and Welfare, with techniques such as SQL injection. OpenAI says much of that activity overlaps with cases in its “ongoing review of misaligned model activity”.

Will it last? Yes. The technique will be patched. The disclosure question will outlast it: Albanese said the incident will inform Australia’s AI standards legislation, and twelve weeks from incident to a public inbox, several of them after OpenAI knew, is the example regulators will reach for. If you run agents, the check from The Guardrail Your Agent Can Reach applies: can your agent reach, or change, whatever enforces the limits you set it?

The call: Australia’s AI standards bill, when it is published, will set a deadline for AI companies to report incidents in which their systems get into computer systems without permission. If no bill is published by 30 June 2027, the call fails. 55%.

Anthropic committed $11.6 billion to Akamai, and got the right to buy up to 5% of it

Akamai’s 24 September filing says Anthropic committed about $11.6 billion over seven years for cloud capacity for its CPU workloads, with room for up to $9 billion more. Akamai expects to spend about $5.5 billion building it, and to raise this year’s capital spending by about $1.7 billion to buy parts, including memory, in advance. It issued Anthropic a warrant for non-voting preferred stock equal to up to about 5% of Akamai’s shares, at $111.33 a common share: about 2% vests on Anthropic’s first payment under the deal, and the rest in 1% steps for each further $3 billion it commits. The filing landed after the close on 24 September; Akamai’s shares opened Friday 13% higher and closed up 3.2%.

Warrants like this are now routine. By my count from SEC filings, Akamai’s is at least the tenth in twelve months in which a supplier gave a big customer the right to buy its stock in return for purchases. AMD gave two, to OpenAI and in February to Meta, each for up to 160 million shares at one cent a share, vesting as the buyer takes AMD’s GPUs and as AMD’s share price hits set targets. Amazon got four, from Astera Labs, TD Synnex, Qualcomm and Generac. A10 Networks gave Microsoft one at one cent a share, Marvell gave Google one in August, and RUM Group, the company behind Rumble, agreed one at one cent a share with an unnamed cloud customer. At Friday’s close, each of AMD’s warrants would be worth about $100 billion on paper if it fully vested; Akamai’s, about $20 million.

Ten supplier warrants, each valued at Friday's share price as if fully vested

Buyers are reaching for protection too. The Akamai filing lets Anthropic end a project plan after a material outage. The same day, Bloomberg reported that Oracle had sent a force-majeure notice on Project Jupiter, a Stargate data-centre campus in New Mexico where it is the tenant: if both sides agree a power problem is to blame, Oracle could push back the start of its full rent by three years should the site miss its 2028 date. Oracle said such notices “are commonplace” and that the project remains on its planned schedule. Oracle’s notice only buys time: a source told Reuters that securing power is Oracle’s job under the lease, that it cannot terminate, and that the landlord still gets the full rent, only later. Anthropic’s outage exit is the clearer case of a buyer pushing risk back onto whoever builds the capacity.

Will it last? Yes. It shows who has the upper hand in these deals: the few buyers big enough to commit billions, whom suppliers will pay in stock to sign. I’ll keep the table running as new ones are filed.

The call: between now and 31 March 2027, at least five more US-listed suppliers will disclose a warrant like these, issued to a customer in connection with chip, cloud or data-centre purchases. 70%.

In Anthropic’s agent market, knowing you mattered more than bargaining

In Project Swap (24 September), 201 Anthropic staff sent Claude agents to trade books. After a five-minute chat, an agent’s ranking of books matched its person’s on 61% of pairs, where guessing would get 50%. Of the value left on the table, 85% came from misreading the person and 15% from the trading. Measured against each agent’s own rankings, which model it ran on mattered more than its instructions. Participants said they’d trust an agent with about 30% of their yearly book budget, against about 40% for a well-read friend.

Will it last? Too early. It’s one company’s staff trading books with well-behaved agents. Still, before you let an agent act for you, check whether it ranks things the way you would. That’s where most of the loss was.

The call: by 30 September 2027, an independent study where real money changes hands will find the same split, with misreading people’s preferences costing more than the trading itself. 35%.

Two labs cut prices on the same day

Anthropic released Claude Opus 5.5 on 22 September at $4 per million input tokens and $20 per million output, 20% below Opus 5; Anthropic says typical workloads cost 40% less because the model also uses fewer tokens per task. The same day OpenAI released GPT-6 Sol and Luna at half or less of what GPT-5.6 cost the day before: $2 and $10 for Sol, $0.10 and $0.50 for Luna. Both labs attribute the cut to cheaper serving.

Will it last? Yes. I expect the prices to hold: the labs tied the cut to their own costs, and OpenAI told reporters the new prices are permanent. The number to watch is cost per finished task, and Anthropic’s 40% is its own estimate of exactly that.

The call: by 30 September 2027, neither lab will raise the list price of Opus 5.5 or GPT-6 Sol, or release a new Opus or Sol model at a higher input or output price per token. 75%.

Watermarks became a default

Anthropic says Opus 5.5, like its Fable 5.1, “comes with our watermarking measures to comply with the EU AI Act”, and its watermark page says future Claude models will carry it too, with older ones added over the coming months. Google’s Gemini 3.8 text-to-speech models (23 September) stamp every clip with a SynthID watermark, and Meta’s Muse Realtime Avatar embeds an invisible Video Seal watermark in the video it generates.

Will it last? Yes. Once the big labs watermark by default, whether Claude was involved in writing something can be checked against a key, where a detector could only guess from style. The answer is still a likelihood: it is weaker on short or factual passages, and a full rewrite removes it. For Claude’s text you can’t run that check yourself yet: Anthropic’s detector is a private preview for eligible organisations. Google already lets anyone signed in to the Gemini app check images, audio and video for SynthID.

The call: by 30 June 2027, anyone will be able to check a piece of text for Claude’s watermark. 40%.

Loud but won’t last

  • Talking avatars. Meta’s Muse Realtime Avatar (23 September) and Google’s Gemini 3.8 Live Avatar (24 September, launched in Gemini Enterprise) give agents a face. The watermark underneath matters more.
  • Muse Charm. A pocket device for talking to Muse. Zuckerberg said it should ship in December, but Meta has given no price, and its own post says only “more to share later this year”.
  • “Half as many mistakes.” OpenAI says Sol makes about half as many mistakes as its predecessor on its internal factuality test. The test is built from conversations where users had flagged errors, which OpenAI itself says are “not representative of typical usage”.
  • Vendor benchmark tables. OpenAI’s launch post compares Sol with Claude Opus 5, which Opus 5.5 replaced that day. Anthropic’s compares Opus 5.5 with GPT-5.6 Sol, which OpenAI replaced that day. Within hours, part of each table was out of date.

The tape

The week in five stocks: two months of daily candles, with this week replayed day by day

Friday close against the Friday before, from Nasdaq’s price history: Meta +12.9%, Shopify +10.7%, Akamai +9.0%, Micron +6.5%, Oracle −7.1%. QQQ, the fund that tracks the Nasdaq-100, rose 3.2% over the same week. Akamai’s trading volume averaged 3.3 times its normal level for the week, and ten times on Friday. For most of these moves I haven’t found a primary source that explains them, so I’m not offering a reason.

Next week

Micron reports on 30 September. Listen for how much memory AI buyers are ordering in advance; Akamai’s filing says it is doing exactly that. Sonnet and Haiku 5.5 are due “in the coming weeks”. From next week, each issue ends with a running score: how many calls are open, how many have resolved, and how often I was right. Each call gets graded here when its date comes.

The Durability Curve Weekly: every week, the stories that matter in AI and markets, on one screen.

Top comments (0)