A personal AI agent authorized to hunt for a table at New York’s 4 Charles Prime Rib was permanently banned by Resy after it queried the booking service at machine speed, illustrating how consumer automation can collide with systems designed to stop bots, scrapers, and abusive traffic.
Bahr-de Stefano, an investor at Better Tomorrow Ventures, had allowed an agent called Instinct to monitor reservation availability at the sought-after steakhouse. Resy canceled existing bookings and barred the account within hours, according to logs reviewed after the ban.
The agent’s behavior explains the platform’s response. Instinct was checking availability around the clock at roughly 200 requests per hour, scanning the next 21 days of reservations every 10 minutes. During a 9 a.m. reservation-release period, it accelerated sharply, sending requests every 0.4 seconds for about two and a half minutes.
That pattern resembles the automated traffic fraud and security teams are trained to detect. A platform receiving repeated, high-frequency queries cannot easily distinguish a user’s personal assistant from a ticket scalper, a data scraper, or an attempt to overload its servers—especially when all use similar technical methods.
User authorization does not settle platform rules
The Resy episode exposes a practical limit for AI agents built to act on behalf of users. A person can authorize software to search, book, buy, message, or compare options, but the service being accessed may not accept automated participation under its rules.
Traditional web defenses reflect a simpler model: humans are allowed in, and bots face restrictions. CAPTCHA tests, device fingerprinting, IP-based limits, and anomaly scoring are designed to identify automated behavior, often without examining whether the automation is useful to a real customer.
AI agents complicate that distinction. A reservation assistant may be acting for one diner with a genuine request, yet it can operate with a speed and persistence no person could match. Platforms must then decide whether authorization by the account holder is sufficient, or whether automation requires separate permission and technical limits.
The issue becomes especially acute where supply is scarce. Restaurant tables, concert tickets, limited-edition products, discount codes, and rapid market opportunities are often allocated through systems that assume customers are constrained by ordinary human attention and reaction time.
An agent that monitors inventory continuously and acts immediately changes that allocation process. A user who deploys faster software, more computing power, or a better-connected service could gain an advantage over someone manually refreshing a page. The contest shifts toward latency and infrastructure rather than demand alone.
Action-oriented assistants are expanding
The dispute arrives as consumer AI products move beyond generating text and into carrying out tasks across multiple apps and services.
The supplied account cited Meta’s Muse as an example of that direction, reporting that the assistant reached 730,000 downloads in five days. Muse was designed to identify products shown in Instagram Reels, turn them into shopping lists, interpret group chats for event planning, and assist with actions such as sending invitations and splitting costs.
Meta also introduced Muse Connectors, which were intended to let third-party developers package tools for agent use across services including Gmail, Calendar, Notion, Spotify, and commerce interfaces, subject to user permission, according to the account.
Those connections could make assistants more useful, but they also extend the problem faced by Resy. An agent that can retrieve information from one service and execute an action at another needs to navigate different terms of use, rate limits, account controls, and security systems.
Amazon, according to the supplied account, blocked traffic associated with Muse agent nodes after the product added cross-service purchasing features, citing concerns over unauthorized automation scripts and authorization. The episode suggests that access credentials alone may not satisfy platforms that want control over how their service is reached and how quickly requests arrive.
Existing permission tools leave gaps
OAuth, the common framework used to let an application access another service with user approval, can establish that an account holder authorized a connection. It does not necessarily establish whether a platform accepts agent-mediated transactions, whether the user is actively directing a specific action, or how aggressively an agent may query the service.
Future systems may need a more detailed model of delegated access. That could include credentials identifying an agent, the person or organization behind it, the categories of actions it may take, spending or booking limits, and maximum request rates.
Platforms also have a strong incentive to create their own channels for standing requests rather than allowing agents to mimic browser behavior. A restaurant service, for example, could accept an instruction such as: find a table for two on any Friday within the next month. It could then allocate openings through transparent internal rules rather than reward whichever automated system sends the fastest request.
Possible allocation methods include lotteries, waitlists, loyalty criteria, queues, or verified fulfillment history. Auctions and dynamic pricing may also emerge for inventory where demand substantially exceeds supply, although those mechanisms would introduce their own fairness and access concerns.
Crypto automation faces the same traffic constraints
The booking dispute has implications for cryptocurrency users who rely on scripts for price monitoring, portfolio management, automated execution, or on-chain transaction handling. Fast tools can be legitimate, but they can trigger the same defenses when they repeatedly poll websites or APIs beyond a platform’s expected usage patterns.
The supplied account cited Cloudflare chief executive Matthew Prince as saying in June 2026 that machine-generated requests accounted for 57.5% of web traffic. It also cited a DataDome report saying malicious automated traffic had increased 124% over the preceding 12 months. Neither figure separates crypto-related traffic from the broader web, but both describe the environment in which platforms are hardening anti-bot controls.
For developers, the practical distinction is between approved machine interfaces and automation that looks like browser-driven scraping. Services that offer documented APIs, streaming connections, webhooks, or other event-based updates give software a way to receive changes without constantly requesting the same data.
That design can reduce strain on a platform while giving automated tools more predictable access. Repeatedly refreshing pages or sending high-frequency calls outside a service’s published limits, by contrast, increasingly risks rate restrictions, challenges, blocked IP addresses, or account action.
The Resy ban shows that a user’s intention may be entirely ordinary while the method used by an agent remains unacceptable to the platform. As AI assistants gain authority to act across the web, services will face pressure to define a middle ground between blocking all automation and allowing machine-speed access to scarce goods, financial tools, and online services.
Want deeper insights into autonomous tools in finance? Explore our guide on AI copy trading and real-world automation risks.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
