HomeArticle

AI places orders for you, who is violating the law? Amazon's ban on Perplexity has seen a "reversal"

互联网法律评论2026-08-06 13:13
The appeal ruling in the Amazon v. Perplexity case has been overturned, reshaping the logic of AI compliance.

On August 4, 2026, the U.S. Court of Appeals for the Ninth Circuit issued a 21-page ruling vacating the preliminary injunction granted by Amazon against Perplexity.

The court found that since it is users (not Perplexity) who use the AI assistant as an artificial intelligence tool to access Amazon, Amazon does not have a higher likelihood of prevailing in this case as the district court determined, and instead Perplexity holds more favorable positions.

On this basis, the district court should not have issued the "preliminary injunction" to prevent Perplexity from being used by users on Amazon.

But this is by no means a simple story of "Perplexity's complete victory over Amazon". We need to dig deeper into: Why did the Ninth Circuit overturn the district court's injunction? How will this "disagreement" determine the direction of the case after remand, and how will it reshape the compliance logic of the AI agent industry?

I. The Essential Disagreement Between the Two Rulings: From the Dispute over "Authorization" to the Identification of the "Access Party"

The logical fulcrum for the U.S. district court to issue the preliminary injunction on March 9 is "dual authorization" — user authorization does not equal platform authorization. After Amazon revoked permission via a lawyer's letter, Perplexity accessed password-protected accounts through the Comet browser "with user permission but no Amazon authorization".

In its ruling on August 4, the Ninth Circuit Court of Appeals pulled the focus of the dispute from "authorization" back to the more fundamental verb in the text of the Computer Fraud and Abuse Act (CFAA) — "access".

The previous district court essentially adopted Amazon's narrative logic of facts: Comet accessed password-protected accounts → obtained users' private information → transmitted it to Perplexity's servers. Under this narrative, "access" seemed self-evident.

But the Ninth Circuit Court of Appeals took a more rigorous step in its ruling — it broke down the technical architecture of Comet for a detailed analysis:

  • The AI Assistant of Comet runs in the user's local browser;

It takes screenshots of the user's screen, and transmits the screenshots and user instructions to the Perplexity server;

  • The Perplexity server returns operation guidelines;

Therefore, Perplexity's servers have never directly accessed Amazon's servers.

Based on this architectural fact, the Ninth Circuit Court of Appeals reached a conclusion of decisive significance to the trend of the case:

Under the technical architecture of this case, it is the user who accesses Amazon's computer with the help of the Assistant tool, and Perplexity itself does not "access" Amazon's computer.

The court further clarified: The "whoever...intentionally accesses" in the text of the CFAA legally refers to a "person" (natural person or legal person), and the "assistant" is a tool and does not constitute a "person" in the legal sense. The court's exact words are — the Assistant is a tool, not a person for statutory purposes.

This is the most fundamental divergence between the two rulings: The district court discussed "authorization", while the Ninth Circuit discussed the "accessing party". The district court discussed authorization defects under the premise that Perplexity constituted "access", while the Ninth Circuit first denied Perplexity's legal identity as the "accessing party".

II. Why the Ninth Circuit "Disagrees" with the Injunction: Unpacking the Four Elements

The "preliminary injunction" issued by the U.S. district court has four statutory elements: (1) likelihood of success on the merits; (2) irreparable harm; (3) balance of equities; (4) public interest. The district court "folded" the four elements into the first one — as long as the likelihood of success under the CFAA is established, the remaining three elements will naturally tip in Amazon's favor. But what the Ninth Circuit did is "unpacking":

1. Likelihood of Success: The "Access" Element of the CFAA Fails

The Ninth Circuit cited the definition of "access" given by the U.S. Supreme Court in Van Buren v. United States (2021) — which refers to "entering a computer system itself or a specific part of it". Under this definition, the court made two key technical determinations:

Determination 1: Perplexity's servers do not directly touch Amazon's servers. This is the fundamental difference between this case and Facebook v. Power Ventures (2016) — in the Power Ventures case, Power's servers actually sent messages to Facebook's servers, and the Ninth Circuit assumed without discussion that Power accessed Facebook; the facts of this case are different.

Determination 2: AI agents are "tools" rather than "legal subjects". The court acknowledged that AI agents may raise new legal issues, but given the record of this case, the thorny issue of artificial intelligence "intent" has become irrelevant — because the "AI assistant" is only a tool in the statutory sense, and a tool operated by users rather than by Perplexity.

2. Backup Application of the Rule of Lenity

This is a dimension that the district court did not seriously address. The Ninth Circuit clearly pointed out that the CFAA is essentially a criminal statute, and the interpretation in civil and criminal contexts should be consistent, and when there is ambiguity, the interpretation should be favorable to the defendant.

The court raised the spillover risk that the district court did not consider — the Electronic Frontier Foundation (EFF) clearly pointed out in its amicus curiae opinion: If Amazon's theory is adopted, users themselves may face criminal accomplice liability for using the Assistant. The Ninth Circuit essentially accepted this argument: converting the whole scenario of "users using AI tools to access websites" into a federal crime "just because it involves computers" is absolutely not the legislative purpose of the CFAA.

3. Public Interest Element: From "Protecting Computer Systems" to "User Control and Technical Neutrality"

The district court defined the public interest as "protecting computers from unauthorized access". The Ninth Circuit explicitly wrote in its ruling that an injunction against conduct that may not violate the CFAA would not be in the public interest.

The Court of Appeals re-expanded the connotation of public interest to: protect users' independent choice of browsers, maintain an open network, and avoid exposing the development of ordinary technical tools to criminal risks. The opinions of amicus curiae such as the Knight First Amendment Institute at Columbia University and the ACLU were adopted by the court — computer crime laws like the CFAA should not be extended to punish tools that automatically access users' personal information.

4. Irreparable Harm and Balance of Equities: Amazon's Evidence is Weak

The Court of Appeals pointed out that the evidence of "degraded shopping experience" and "cybersecurity risks" claimed by Amazon is weak — its expert testimony even failed to fully reproduce the alleged risks; while granting the injunction would unreasonably increase the burden on Perplexity, restrict consumer choices, and hinder the development of emerging technologies.

It is worth mentioning that the court clearly stated in Footnote 5: This ruling does not affect Amazon's right to regulate user access through its Terms of Service (ToS). This is equivalent to leaving a door open for the platform — the CFAA path is blocked, but the paths of contract law and terms of service are still open.

III. The Decisive Significance of This "Phased Outcome"

As predicted in the platform's previous article "Amazon Wins Court Injunction: AI Agents Under the "Dual Authorization" Dilemma" — the "dual authorization" dispute is just the prelude. The ruling issued on August 4, regardless of the final substantive outcome of the case, has already produced a phased but extremely decisive impact on the overall landscape:

1. Amazon's CFAA path is basically blocked

The Ninth Circuit Court of Appeals has set a very high threshold for the "access" element of the CFAA. If Amazon wants to continue to advance under the CFAA framework, it must prove that Perplexity directly accessed Amazon's servers — which is impossible under the current Comet architecture.

Amazon stated in a statement that it is "evaluating next steps".

2. The "Architecture Dependence" Tone for AI Agent Liability Attribution Is Set

The Ninth Circuit Court of Appeals emphasized in its argument that this ruling is "based on the current state of affairs". This characterization is temporary and architecture-dependent. When agent technology evolves to the point where its servers directly log in to Amazon, independently retain user credentials, and make discretionary decisions, this characterization will most likely be overturned.

Therefore, the ruling of the Ninth Circuit establishes a highly architecture-dependent liability attribution rule: if the AI company's servers do not directly touch third-party servers, the liability rests with the user, and the AI company is a tool provider.

IV. The Transformation and Deficiency from "Dual Authorization" to "Architecture Compliance"

The role of AI agents is that users delegate operations that they could originally complete in person to programs, which cannot be simply equated with crawlers that copy data and resell it. At present, there is a lack of specific regulatory rules for agent artificial intelligence in all countries: which platforms can be blocked, under what conditions they can be blocked, what objective reasons are required, and what kind of external supervision is needed.

The Amazon v. Perplexity case raises a more specific and necessary question that must be answered: Can a platform unilaterally define the terms of user interaction with it, and block the tools chosen by users accordingly? From another perspective, if a user authorizes Comet to act on their behalf, does Amazon have the right to terminate this authorization chain?

Before regulation comes into place, the judge's ruling on the Amazon v. Perplexity case will influence people's perception of the entire AI agent ecosystem.

1. From "Dual Authorization" to "Architecture Compliance" — Setting the Tone of Architecture Dependence for AI Agent Liability Attribution

The Ninth Circuit's ruling reveals an important trend: the legal liability of AI agents will no longer be abstractly discussed as "whether it is a tool or a subject", but will specifically review its technical architecture. This "architecture-dependent" characterization avoids simply classifying AI agents into the category of "unauthorized access", and the Ninth Circuit insists on clarifying the factual nature of the technical architecture before applying the law.

The three elements of "architecture compliance" established by this ruling are: whether the AI server directly touches third-party servers, whether the agent is characterized as a "tool", and whether the agent independently makes discretions beyond the user's clear instructions. When the answers to these three elements are "No - Yes - No", the liability rests with the user.

This is a clear signal to AI agent developers: The choice of technical architecture is the allocation of legal risks.

2. The "Architecture Compliance" Window Period for Chinese AI Agent Enterprises

Combined with China's existing judicial practice — the "triple authorization" principle established in Sina v. Maimai still plays a role in mainstream cases, but the Supreme People's Court's Guiding Case No. 263 in the 47th batch of guiding cases has begun to open up limited space for "cross-platform data transfer under user authorization".

The "architecture compliance" characterization of the U.S. Ninth Circuit provides a referable technical-legal design guide for Chinese AI agent enterprises: figuring out how to make agents "not access" third-party servers in the legal sense will likely directly reduce CFAA-like risks and enhance the defense strength of "user authorization" under Chinese law.

3. Unresolved Issue: Whether the User Authorization Chain Can Defy Platform Terms of Service

If a person can instruct family members, employees or assistants to shop on Amazon, why should software controlled by the same user be treated differently? Neither the trial court nor the Court of Appeals avoided the legal and philosophical difficulties brought about by this question.

The Ninth Circuit Court of Appeals also did not explicitly state that user autonomy should be regarded as an independent source of authorization that can defy the platform. Its judge clearly stated in the ruling: This outcome will not undermine Amazon's ability to regulate access to the Amazon website through the private terms of service of its users.

In other words, users can use AI tools to access Amazon, but Amazon still seems to be able to regulate user access through terms of service. This is equivalent to kicking the real conflict between "user authorization vs. platform terms of service" back to the field of contract law.

This article is from the WeChat official account "Internet Law Review", author: Zhang Ying, published with authorization from 36Kr.