Why are websites blocking AI agents in 2026?
Quick answer: Websites block AI agents for two reasons. Some do it on purpose to protect their checkout, their data and their relationship with customers. Others do it by accident, because anti-bot tools can't tell a helpful agent from a scraper. That's why booking and shopping agents keep hitting CAPTCHAs and dead ends. What works reliably today is letting an assistant search, compare and report back, then making the final booking or purchase yourself.

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.
What happened with websites blocking AI agents?
In early October 2026, reporting confirmed what many agent users had already noticed: big websites are shutting AI agents out, sometimes on purpose and sometimes by mistake. Amazon started blocking Meta's Muse agent from its retail site, so the agent can no longer browse the catalog or buy anything there. That was a policy decision, not a glitch. Walmart's case is messier. Shoppers complained online that Muse couldn't finish purchases on Walmart's site, yet Walmart is a Muse partner and said the blocks weren't intentional. The likely cause is ordinary bot verification. If an agent interrupts the check a human would breeze through, the check fails and the agent gets thrown out halfway through checkout.
Airlines and marketplaces are in the same camp. Delta and United, along with Yelp and eBay, restrict or reject agent traffic and cite security and unauthorized automation. eBay draws a finer line than most. It doesn't ban every shopping agent from buying, but its policies restrict unauthorized agents and activities such as automated scraping and model training. Then there's the infrastructure layer. On September 15, Cloudflare changed its defaults so site owners could block AI training bots while still allowing other kinds of bots. As a side effect, some sites that had been blocking AI bots for security reasons also ended up blocking AI agents on pages that carry ads. Cloudflare says it has no specific data tying that change to the agent failures, but the timing raised eyebrows.
So what's being done about it? A group that includes Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE and Decagon has started work on an open standard for how AI agents talk to businesses. The goal is to separate good bots acting for a real person from bad ones that scrape, spam or probe for weaknesses. Meta has said the protocol will focus on agent-to-agent communication for online commerce. Your agent would talk to the store's agent instead of clicking through pages built for humans. It's a sensible direction. It's also a proposal, not a switch anyone flips next week, and that gap between promise and reality is what the rest of this article is about.
| Site | What agents run into | Deliberate? |
|---|---|---|
| Amazon | Meta's Muse blocked from browsing and buying | Yes |
| Walmart | Some Muse purchases failed at bot checks | No, according to Walmart |
| eBay | Unauthorized agents, scraping and model training restricted | Partly: not all shopping agents are banned |
| Delta, United, Yelp | Agent traffic restricted or rejected | Yes, citing security and unauthorized automation |
Why does an AI agent get blocked by a website at all?
An AI agent gets blocked because, to a website, it looks exactly like the bots the site has spent years fighting off. Anti-bot systems watch for signals like how quickly pages are requested one after another, how the cursor moves, whether the browser fingerprint looks normal and whether a challenge gets solved the way a person would solve it. An agent working for you trips many of the same alarms as a scalper grabbing concert tickets or a scraper copying prices. The web never built a polite way for an agent to say, 'I'm working for Maya, she's logged in, and she wants one table for two at eight.' The only door is the one built for humans, and agents are trying to squeeze through it.
That's where the AI agent CAPTCHA wall comes from. A CAPTCHA, or a quieter background check you never see, exists to answer one question: is a human here? When the honest answer is no, the agent fails, even though a real human sent it. Some sites also have commercial reasons. A retailer that controls the shopping journey makes money from ads, recommendations, loyalty programs and upsells, and an agent that heads straight for checkout skips all of it. Airlines worry about fraud, fare scraping and resellers. Review sites guard their data because the data is the product. None of that makes a block feel fairer when you just wanted a flight to Lisbon, but it explains why the problem won't go away on its own.
The frustrating part for users is that you usually can't tell which kind of block you've hit. An accidental block and a deliberate one look the same from the outside: a stalled checkout or an endless 'verify you are human' loop. People end up annoyed with the retailer, annoyed with the agent and unsure who to complain to. My view is that a lot of this friction is fair. Software that can charge your card and book a nonrefundable fare without you should have to clear a high bar. Checking isn't the problem. The problem is that sites have no good way to tell a trusted agent from an attacker, so every agent hits the same closed door.
Will the new AI agent web standard fix the problem?
The proposed AI agent web standard could fix part of the problem, but not quickly and not everywhere. If it works as described, a store would recognize an agent acting for a verified customer and deal with it through a proper channel, instead of forcing it through pages, buttons and CAPTCHAs designed for people. That would be a real improvement over agents pretending to be browsers. It isn't the only effort, either. Several agent payment and commerce specifications are already in circulation, and people are exploring identity schemes that would give agents verifiable credentials. Early specs like these usually stay experimental for a good while before anyone outside the founding companies adopts them.
Look at who has signed up. Walmart is in. Amazon, which just blocked Muse, isn't among the companies announced, and neither are the airlines. A standard only helps on sites that choose to support it, and plenty of businesses have good reasons to keep agents at arm's length. They want you in their app, seeing their offers and collecting their points. Expect a patchwork. Some big retailers will open a front door for agents, some will open it only to partners, and many smaller businesses won't touch any of it for years. Think of the independent dentist, the local garage and the family-run hotel whose booking widget hasn't been updated since 2019.
Even when the door opens, there's a question no standard answers: do you actually want an agent to finish the purchase without you? Most people are glad to have the research done for them and much less glad to find a nonrefundable flight on the wrong date. I'll take a contrarian position here. I think the last click should stay with you even after agents are welcome everywhere. Comparing six options is drudgery, but deciding which one you'll pay for is a judgment call that belongs to you. The sweet spot isn't full autonomy. It's an assistant that does the legwork and hands you a short, clear choice you can make in ten seconds.

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.
Can AI agents shop for you or book flights today?
AI agents can shop for you and book flights today only on some sites, some of the time, and you shouldn't build your week around it. Agents booking flights run into airline restrictions, fares that change between searches, and checkouts packed with seat upsells and identity checks. Shopping agents do a little better with retailers that partner with them, but as the Walmart case showed, even a partner can bounce an agent by accident. If a task ends with a payment, a binding booking or handing over passport details, treat full automation as a nice surprise when it works, not as something you can count on.
The part before checkout is what works reliably. Reading public pages, comparing opening hours, checking prices, summarizing reviews and pulling out return or cancellation policies rarely trips the defenses that guard logins and payments. That's also most of the tedious work. 'Find me three dentists open Friday near me' is a search job. So are 'Compare direct flights from Tel Aviv to Rome on the 14th, morning departures only' and 'Which of these two drills has the longer warranty?' An assistant can answer all three, lay out the options and leave you to tap the booking link yourself. Thirty seconds of your time at the end beats thirty minutes of juggling browser tabs.
A useful rule of thumb is to delegate anything that involves reading, comparing or asking, and keep anything that involves paying, signing or sharing sensitive documents. That split roughly matches where websites draw their own lines, so you'll spend less time fighting CAPTCHAs and more time getting answers. It also protects you from the most expensive kind of agent mistake, the confidently wrong booking. When the assistant comes back with three options, prices and times, you can catch what an agent might miss, like a layover at the wrong airport or a clinic that doesn't take your insurance. Two minutes of checking is far less painful than a refund dispute with an airline's call center.
| Task | Delegate it? | Why |
|---|---|---|
| Finding and comparing options (dentists, flights, products) | Yes | Public information that's rarely blocked |
| Checking hours, prices and policies | Yes | Read-only and quick to verify |
| Asking a business a simple question | Yes, with your approval | It's a message, not a checkout |
| Entering card details or paying | Do it yourself | The most heavily guarded step |
| Final flight or hotel booking | Do it yourself | Costly to undo if it's wrong |
How does Sonic handle web tasks when sites block agents?
Agent Sonic works with what's reliable today. It searches and browses the live web for you, then reports back in your WhatsApp chat so you can make the final call. There's no app to install and no dashboard. You message Sonic like any other contact: 'Find me three dentists open Friday near me with good reviews,' or 'What time does the hardware store on Herzl Street close today?' The answer comes back in the same thread with the options laid out, and you book the one you want. Sonic doesn't pretend to be a checkout robot, which is exactly why you won't lose an afternoon stuck behind a CAPTCHA. If that sounds like how you'd rather work, here's more on getting answers straight in WhatsApp.
Sometimes the quickest way around a booking site that won't cooperate is to ask a person. On the Pro plan, Sonic's outreach tasks (in Beta, and they may be paused from time to time) let you share the clinic's contact and say, 'Ask the clinic if they have a Friday morning slot and let me know.' Before anything is sent, Sonic shows you the exact first message, and you reply 'yes,' 'no' or something like 'make it friendlier.' Sonic writes from its own WhatsApp number, introduces itself as your assistant, follows up once at most if the answer is vague, and reports back. The limits are real. You get one task at a time and up to three people a day, it works in one-to-one chats only, and first messages go out only between 8 a.m. and 9 p.m. in the recipient's time zone. The step-by-step tutorial covers the details.
Everything Sonic does follows the same pattern. Sonic finds, compares and drafts, and you approve, pay and sign. Add the rest of the toolkit and the whole errand stays in one chat. You can put the appointment you chose into Google Calendar with one message, have Sonic remind you the day before ('Remind me Thursday at 6 pm to bring the X-rays'), or forward a quote as a PDF and ask what's missing before you agree to it. None of that depends on a website deciding whether to let an agent in. If you'd like to try it, leave your details on the contact page and you'll get Sonic's number and a short onboarding.
Frequently asked questions
Why do I keep getting a CAPTCHA when my AI agent tries to book something?
CAPTCHAs and background bot checks exist to confirm a human is present, and an AI agent can't honestly pass that test, even when a real person sent it. Booking and checkout pages are the most heavily guarded parts of a site because that's where fraud, scalping and card testing happen. The agent often gets through the browsing and then stalls at the exact moment it tries to pay or reserve.
Do websites allow AI agents to shop for you?
It depends on the site. Some retailers partner with specific agents, some block particular agents outright, and others restrict only unauthorized automation such as scraping or model training while still allowing some shopping agents to buy. Airlines tend to be among the strictest. If a purchase matters to you, it's safer to use the agent for research and comparison and then complete the order yourself on the store's own site or app.
When will the new AI agent standard be available?
No public launch date has been announced. Meta, Walmart, Stripe and several customer-service and commerce companies have only just begun working on an open standard focused on agent-to-agent communication for online shopping. Even after a first version ships, each business has to choose to adopt it, so expect support to roll out gradually, starting with large retailers involved in the effort and reaching smaller businesses much later.
Can Agent Sonic book a flight or buy something for me?
No. Sonic is built around search and ask-first, not unattended checkout. It browses the live web, compares options and sends you the results in WhatsApp, for example three morning flights with prices and times, and then you book the one you want. On the Pro plan it can also message a person to ask a question for you, but only after you approve the exact first message.

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.