If an AI tool can touch your Amazon account, Amazon now has rules about how. They took effect on March 4, 2026, they apply to you even if you never read them, and the practical question they raise is simple: if the software you use steps outside the lines, whose account is on the line? Yours.
This post is a plain-language walkthrough of what changed, what it means when you evaluate any AI-assisted seller tool, and the questions worth asking a vendor before you hand over OAuth access. It is service journalism, not a pitch: our product appears near the end, once, where it is genuinely part of the answer.
What the policy actually requires
The changes arrived in two places: a new Agent Policy, and a new Section 19 ("Use of Agents") in the Business Solutions Agreement. An "Agent" is defined broadly: any software or service that takes autonomous or semi-autonomous action on behalf of, or at the instruction of, any person. The requirements, in seller terms:
- Agents must identify themselves. Every HTTP request an agent makes must say so in its user-agent string, in a prescribed format: "Agent/[agent name]".
- No pretending to be human. Agents may not mimic human keystrokes or navigation patterns, may not complete or circumvent CAPTCHAs, and must answer truthfully when asked whether they are a computer.
- Amazon controls the door. Agents may not circumvent measures that block, limit or control agent access, must stop entirely if Amazon requests it, and the BSA reserves Amazon's right to restrict agent access at its sole discretion.
- Amazon's data is not training data. A separate BSA change prohibits using Amazon materials or services to develop or improve AI and machine-learning models.
Notice what is not on that list: the policy does not require a human to approve every change an AI makes. It is a transparency-and-control policy, not a workflow mandate. The announcement is public on Seller Forums; the Agent Policy and updated BSA are in Seller Central's policy library (login required). Read the original text; a summary, including this one, is not the policy.
The part that should get your attention is who the policy addresses. It applies if you "use, allow, enable, or cause the deployment of" an agent. Not just the vendor - you. The tools you connect to your account are your compliance exposure, on the account that pays your bills.
Why Amazon drew this line
The failure mode is easy to picture. An autonomous bidder misreads a demand spike, walks bids up overnight, and spends a month's budget by morning. Or an agent with listing access "optimizes" a title into a compliance violation. When automation errors happen at machine speed inside a seller account, the seller absorbs the damage: the spend is spent, the Buy Box is lost, the listing is suppressed. Amazon's answer was not to ban AI tooling, and notably not to dictate how your tools work internally. It was to make agents identifiable and controllable: Amazon can now see which traffic is automated, throttle it, and - per the BSA - shut any agent out at its discretion. An agent that behaves badly on your account can be cut off, and the accountability for having deployed it sits with you.
What this means when you evaluate a tool
The policy gives you a concrete checklist that cuts through marketing language. Ask any vendor of AI-assisted Amazon software:
- Does your software identify itself as an agent, the way the policy prescribes? A vendor who has read the policy can answer in one sentence. A vendor who hasn't will improvise one.
- Does anything you do imitate a human? Browser automation that types like a person, solves CAPTCHAs or scrapes pages Amazon gates is now squarely against the rules - on your account.
- What happens if Amazon restricts agent access? Amazon can now shut agents out at its discretion. Ask what your workflow looks like the day your tool's access is limited, and whether the vendor honors a cease request or routes around it.
- Can the AI change my account without me - and if so, do you want that? The policy does not require a human approval on every change. We think it should be your requirement anyway: you carry the accountability, so a tool should be able to show you exactly what changed, who approved it, and what it was before.
- How does it connect? Registered API access through Amazon's own OAuth flow, with a truthful user agent. A tool that asks for your Seller Central password is answering a different question entirely.
None of this requires slower work. Analysis, drafting and diagnosis can be fully automatic. The question is whether you can stand behind what your tools did, at the moment Amazon asks.
Where AMZ Vault sits
We hold ourselves to a stricter standard than the policy asks for, because we run our own Amazon brands and never wanted software changing our accounts unsupervised. Every AI-proposed change in AMZ Vault's AI connection is staged as a reviewable diff and executes only after you confirm it; nothing reaches Amazon without a human approval, and every applied change keeps its before-value and its approval trail. That is our design choice, not a policy obligation - which is exactly why it is worth asking every vendor where they stand. The full design is on our security page.
The takeaway
Treat the policy as a buyer's tool. It converts "trust our AI" into checkable questions: does your software identify itself as an agent, does anything it does imitate a human, what happens when Amazon says stop, and - beyond the policy - can you see and approve what changes on your account. Any vendor should be glad to answer all of them in writing. If the answers are fuzzy, the risk is not the vendor's account.
Related: how we calculate true Amazon profit · try the whole platform with no signup