The compliance date everyone circled has been and gone. Amazon’s Agent Policy took effect on March 4, 2026, and for most sellers nothing visibly happened that morning. That is the problem with a deadline that passes quietly: it stops feeling like a deadline and starts feeling like a false alarm. The rules are not coming. They are the current terms of the Amazon Services Business Solutions Agreement, and they have been in force for months.
What follows is what the policy actually requires, and then a question most of the coverage skipped: when an automated tool does something wrong on your account, who answers for it. The answer is not the company that sold you the tool.
What the Agent Policy actually requires
Amazon posted notice of the update on February 17, 2026, giving sellers two weeks before the revisions took effect, according to EcommerceBytes. The change added a standalone Agent Policy to the agreement, and its scope is deliberately wide: a seller-side legal writeup describes it as covering any automated software, bot, AI tool, or system that accesses Amazon Services.
Three obligations sit at the center of it. An automated system must clearly identify itself as an automated system. It must comply with the Agent Policy at all times. And it must immediately cease access if Amazon requests, a requirement the seller community has been calling a kill switch, per the same legal writeup.
Alongside those, the agreement added prohibitions with a longer reach. EcommerceBytes reports that Amazon now bars using Amazon materials to “develop or improve AI/machine learning models”, along with data mining, reverse engineering, and deriving source code. Scraping or extracting Amazon data at scale falls on the wrong side of that line.
The tools in scope are the ordinary ones: pricing and repricing automation, inventory management, listing software, browser automation, AI drafting tools operating inside Seller Central, and the agencies that run any of the above on your behalf. If it logs in and does something without a person watching, it is an Agent.
Two things make this more than paperwork. The consequences named for non-compliance are access restrictions, account enforcement, and suspension. And Amazon wrote itself broad discretion: PPC Land notes that Amazon may restrict agent access in certain instances without the agreement specifying thresholds or a process. There is no published appeals path for a tool that gets flagged.
Who answers for it: the obligation attaches to your account
Read the requirements again and notice who they are addressed to. Not the vendor. You. It is the seller who must ensure the systems touching their account identify themselves, comply, and stop on request. EcommerceBytes puts the practical version plainly: sellers should read the full agreement and request that all third-party vendors provide information about their compliance.
That framing is worth sitting with, because a second authority arrived at the same place from the opposite direction this summer, in a case with the same company on the letterhead. In August 2026 the Ninth Circuit held that an AI shopping agent does not access a website, the user does, and the agent is a tool. Amazon was the party that lost that argument. Perplexity was the party that won it.
Keep the scope of that honest, because it matters: the panel vacated a preliminary injunction and addressed one claim under one statute, so it is an early-stage order rather than a verdict, and the case is not over. But the reasoning is the part worth borrowing. Amazon lost a fight over whether the agent’s operator is the one doing the accessing, and Amazon’s own seller contract assumes the same answer it failed to win in court. A contract and a federal appeals court, on opposite sides of the same dispute, both located responsibility with the human whose account the tool operates under.
The practical consequence is unglamorous and worth saying without hedging. “My vendor told me it is handled” is not a position. It is a hope. Under the agreement you signed, the automated actions taken on your account are your automated actions, and the enforcement lands on your seller account rather than on the software company’s revenue.
The four-move audit
None of this requires an engineer. It requires an afternoon and a willingness to write things down.
1. Write the list. Name every tool, service, agency, and script that touches your Amazon account, including the ones you inherited and stopped thinking about. The repricer counts. The listing tool counts. The virtual assistant running a browser extension counts. The freelancer who logs in on Thursdays counts, and so does whatever software that freelancer uses. A list you can hand to someone else is the deliverable, because the rest of the audit is impossible without it.
2. Ask each vendor in writing. Send one email per vendor asking a specific question: does your product comply with Amazon’s Agent Policy under the Business Solutions Agreement, and does it identify itself as an automated system. Ask for the answer in writing rather than on a call. A vendor that will not put it in an email has told you something, and a vendor that answers in a paragraph has just given you the document you will want if a flag ever lands on your account.
3. Prove you can stop it. The requirement is immediate cessation on request, which means the interesting question is not whether the vendor has a kill switch but whether you can reach one. For each tool on your list, find out how you would halt it today, without waiting on a support ticket. If the honest answer for any tool is that you would email the vendor and wait, that tool is a compliance gap wearing a subscription.
4. Kill the scraping. If any part of your operation pulls Amazon data at scale, whether for competitor tracking, price monitoring, or feeding a model, that practice is now squarely prohibited. This is the move most likely to cost you something you liked, and it is also the one least likely to be forgiven, because it sits next to the reverse-engineering language rather than in the housekeeping section.
What the stack costs, which is what a rebuild would cost
The audit has a bill attached, and it helps to know the number before a vendor fails step two rather than after. The tools most sellers would be replacing are priced in public.
Helium 10 lists Platinum at 129 dollars a month, discounted to 99 at the time of writing, and Diamond at 359 discounted to 279. Jungle Scout’s Catalyst plans run 29 dollars a month for Starter, 49 for Growth Accelerator, and 129 for Brand Owner. SellerApp starts its Pro plan at 99 dollars a month and its Smart plan with automation at 149.
Those are the real numbers, and they are why the honest reading of step two is a budgeting exercise as much as a compliance one. Switching a repricer mid-quarter is not a line item you want to discover in an enforcement email.
The part I would argue for hardest
The instinct this policy triggers in a lot of sellers is to automate less, and I think that is the wrong lesson. A repricer working a large catalog is doing something no person could keep up with by hand, and that is the reason a very small operation can run an inventory that would otherwise need more people than it can pay. That capacity is real and worth keeping.
What the Agent Policy actually insists on is that a person stays attached to it. The tool identifies itself as a tool, and someone can stop it. That is a description of automation as extended reach rather than as an independent worker, which is the same shape the Ninth Circuit reached for when it called an agent a tool with somebody’s hand on it. It is a better standard than the one a lot of the market was operating under, where nobody could say who authorized a given action at three in the morning.
The version of this that goes wrong is not the seller who automates more. It is the seller who automates without knowing what has the keys, which is the same discipline worth applying before you give any AI tool more access than it needs, and the same one that matters as browser-driving agents start clicking real buttons on real screens.
Start with the list
Open a blank document today and write down every tool that can log into your Amazon account. Not the audit, not the vendor emails, just the list. The test of whether it is finished is uncomfortable and simple: could you hand it to someone else and have them recognize everything on it. Anything you cannot name, you cannot vouch for, and under this agreement you are the one being asked to vouch.
Frequently Asked Questions
Does the Agent Policy ban AI tools for Amazon sellers?
No. It sets conditions rather than prohibitions on ordinary use. Automated systems accessing Amazon Services must clearly identify themselves as automated, comply with the Agent Policy at all times, and immediately cease access if Amazon requests, per a seller-side legal writeup of the change. What is genuinely prohibited is narrower: using Amazon materials to develop or improve AI and machine learning models, plus data mining, reverse engineering, and scraping Amazon data at scale.
Am I responsible if my third-party tool breaks Amazon’s Agent Policy?
Treat the answer as yes. The obligations in the agreement run to the seller, and EcommerceBytes reports that Amazon’s guidance is for sellers to request compliance information from all third-party vendors rather than assume it. The consequences named for non-compliance are access restrictions, account enforcement, and suspension, and those land on the seller account rather than on the vendor.
The March 4 deadline already passed. Is it too late to do anything?
No, and the framing is the trap. March 4, 2026 was the date the terms took effect, not a window that closed. The Agent Policy is simply the operative agreement now, so an audit done today has the same value it would have had in February. The one thing that changed is that a tool out of compliance has been out of compliance for months rather than days.
