An AI shopping agent just won a fight that could rewrite the rules of the internet. A U.S. appeals court ruled that Amazon is unlikely to prove Perplexity violated federal hacking law when its AI browsed and purchased products on behalf of users. This is the first appellate decision on whether AI agents can legally act on users’ behalf online, and the implications are massive.
This isn’t just a win for Perplexity. It’s a signal that the legal system might be catching up to how people actually use the web. For years, companies have wielded the Computer Fraud and Abuse Act (CFAA) like a club against anyone who automated access to their sites. Web scrapers, aggregators, now AI agents, all have faced the same threat. But this ruling says, essentially, that if a human user could lawfully do something, an AI acting on their behalf might be able to do it too.
My read? The court just drew a line in the sand. And Amazon, for all its legal firepower, is on the wrong side of it.
The Case That Could Define the Agent Era
Perplexity, best known for its AI-powered search engine, launched a shopping agent that could browse Amazon, compare prices, and even complete purchases. Amazon didn’t like that. It sued, claiming the agent violated the CFAA by accessing Amazon’s servers without authorization, essentially hacking. The lower court sided with Amazon, granting a preliminary injunction. But the Ninth Circuit Court of Appeals reversed, ruling that Amazon’s claims were unlikely to succeed.
The key legal question: Does an AI agent that mimics a user’s behavior constitute unauthorized access? The appeals court said no, at least not in this case. The judge noted that Perplexity’s agent didn’t bypass any technical barriers like password gates or CAPTCHAs. It just used the same interface a human would. That’s a huge distinction. The court compared it to a human using a browser, just automated.
This echoes the hiQ Labs v. LinkedIn case from 2019, where a court ruled that scraping public data didn’t violate the CFAA. But this goes further: the agent wasn’t just reading data; it was performing actions, adding to cart, checking out. That’s a new frontier. And the court said it’s not hacking.
What This Means for the AI Shopping Gold Rush
Every major tech company is racing to build AI agents that can shop, book travel, manage calendars. OpenAI, Google, even startups like Browser Use. They’ve all been watching this case with white knuckles. A ruling against Perplexity would have been a disaster, potentially forcing agents to get explicit permission from every website before acting. That would kill the model.
Now? The door is open. Expect a flood of investment into AI shopping agents. The legal risk just dropped significantly. But don’t pop the champagne yet, this is only a preliminary ruling. The full trial hasn’t happened. And Amazon could appeal to the Supreme Court. Still, the Ninth Circuit’s reasoning sets a strong precedent. Other circuits often follow.
Compare this to the chaos in the crypto world, where founder shutdowns and lawsuits drain funds, like the Eliza token disaster. That was a mess because the legal framework was unclear. Here, the court is actually providing clarity. That’s rare in tech litigation.
Second-Order Effects: Who Wins, Who Loses
Let’s break down the winners and losers.
Winners: AI agent startups. They just got a massive legal tailwind. E-commerce platforms that benefit from increased traffic, like Shopify (which doesn’t have Amazon’s anti-scraping posture). Consumers who want to compare prices across multiple sites without manual work. And law firms specializing in CFAA defense, they’ll be busy.
Losers: Amazon, obviously. But also other walled-garden retailers like Walmart, Target, and eBay. If agents can freely shop on their sites, they lose control over the user experience and data. They might try to block agents via terms of service changes, but that’s harder to enforce than technical blocks. Also, the CFAA’s scope just got narrower for everyone, not just AI agents.
And there’s a darker side: this ruling could enable bad actors. If an AI agent can legally buy things, what about bots that scalp items or manipulate prices? The court didn’t address malicious use. That’s a separate fight. But the precedent is set: automation isn’t inherently hacking.
Ironically, this ruling comes amid growing protests against AI, 37 Americans were recently arrested in AI data center protests. The public is skeptical of AI’s impact. But the courts are moving in the opposite direction, enabling more autonomous AI action. The tension between public sentiment and legal reality is palpable.
Practical Takeaways for Entrepreneurs and Investors
If you’re building an AI agent, here’s what to do now: First, document that your agent replicates user-authorized actions. Don’t bypass login walls or CAPTCHAs. The court’s reasoning hinged on the agent not exceeding what a user could do. Second, add clear user consent flows. If a user explicitly authorizes the agent to act on their behalf, that’s a strong defense. Third, expect terms of service to change. Amazon will likely update its ToS to explicitly prohibit automated agents. But ToS violations are contract law, not criminal hacking. That’s a weaker claim.
For investors: this ruling reduces regulatory risk for AI agent startups. But it’s not a blanket immunity. Watch for state-level legislation. New York and California have proposed bills targeting AI autonomy. The federal landscape is still uncertain. But the Ninth Circuit’s opinion is a green light for now.
Bottom line: the legal framework for the internet was built for humans. AI agents are forcing it to evolve. This ruling is a step in that evolution. Not a final step, but a meaningful one. The smart money will watch for the Supreme Court to weigh in, but that’s years away. In the meantime, build. The legal door is cracked open.
Frequently Asked Questions
Does this ruling mean AI agents can now do anything on websites?
No. This ruling only says that Amazon is unlikely to win under the CFAA for Perplexity’s specific agent behavior. It doesn’t grant blanket immunity. Other laws like breach of contract, tortious interference, or state computer crime laws could still apply. Also, the ruling is preliminary and from one circuit. It’s persuasive, not binding nationwide.
What is the Computer Fraud and Abuse Act (CFAA)?
The CFAA is a federal law enacted in 1986 that prohibits unauthorized access to computers. It’s often used against hackers, but also against web scrapers and automated tools. The key term is ‘without authorization’, which courts have interpreted narrowly. This ruling reinforces that simply automating a user’s actions doesn’t automatically violate the CFAA.
Could Amazon still win at trial?
Yes. The appeals court only ruled on the likelihood of success for a preliminary injunction. The full case hasn’t gone to trial. Amazon could still prove that Perplexity’s agent violated terms of service or other laws. But the CFAA claim is now much weaker. Amazon might settle or drop the case entirely.
