Ninth Circuit vacates Amazon's injunction against Perplexity, ruling the logged-in user, not Perplexity, did the accessing
- The Ninth Circuit vacated the preliminary injunction Amazon won against Perplexity AI, holding Amazon unlikely to succeed on its CFAA and California CDAFA claims because the browsing user, not Perplexity, did the accessing.
- Perplexity's Comet browser carries an AI Assistant that, once a user switches it on, navigates Amazon.com on that user's behalf and sends browser screenshots to Perplexity's servers for further instruction; Amazon said it had explicitly prohibited this use.
- The district court had found unauthorized access to password-protected accounts, private information obtained, and significant response costs for Amazon, plus irreparable harm; the Ninth Circuit held the equitable factors favored Perplexity and that no injunction was warranted.
- The decision is not a ruling on the merits: the Ninth Circuit remanded the case to the Northern District of California for further proceedings.
Hacker News opinions
Okay, which one of you is going to explain what this is actually about?
Read the first couple of paragraphs, it's pretty self explanatory. The summary at the top is three paragraphs and it's not legalese at all.
My understanding of the case law here is that courts are really wary of letting terms of service violations rise to the level of a federal crime. That basically hands anyone with a domain name the power to create federal law on demand.
Isn't this how every agent works these days? Apple and Google are doing tool calling for apps, but that's going to be backstopped by screen scraping for years. Every site probably has equivalent CFAA boilerplate in its terms, so I guess all agentic automation is a crime now.
TLDR: Perplexity's agents allegedly ignored Amazon's robots.txt.
Why shouldn't they? My browser does the same thing when I ask it to open a website. robots.txt is a suggestion, not a rule, it's there to help crawlers avoid wasting time. Treating it as a security measure is like stopping an invasion with a road closed sign.
TL;DR: Amazon is mad that Perplexity's agents can browse Amazon while logged in, using credentials the Perplexity user provided. Amazon says the CFAA forbids it, sued, and got a preliminary injunction. Perplexity appealed and got the injunction thrown out. This hasn't been to trial on the merits yet.
So what's next, suing Chrome because it logs into Amazon for me after I give it my credentials?
I can't speak to the CFAA or CDAFA side, but from a business perspective AI is a real threat to Amazon because a headless Amazon makes it harder to sell ads, which is a big chunk of revenue.
I think that's backwards. Sure, one revenue source shrinks, but if agentic purchasing is a threat to Amazon it's a threat to Perplexity too. Everyone ends up with an agent and the price of controlling the shopping experience goes to zero. AI commoditizes discovery and price comparison, which is where competitors could actually reach Amazon, and leaves purchasing, inventory, and shipping alone, which is where Amazon wins. Smaller pie, bigger slice.
The threat is bigger than ads. If an AI places the order on Amazon today, tomorrow it places it somewhere else and the user never notices. You have to own the consumer experience, otherwise the underlying store is interchangeable.
SKU-level transaction data is what everyone wants. If Perplexity's agent can pull your entire Amazon purchase history back to when you opened the account, that's extremely valuable to advertisers, and Amazon does not want that leaving.
When the DoorDash CLI got announced I thought it was amazing, then I joked the marketing team must be furious because the CLI dodges about 4000 A/B tested upsells. It's not really a joke.
Amazon was a legit business threat to basically every physical bookstore and arguably a lot of publishers. That doesn't mean bookstores could have taken Amazon to court over it.