top of page

Amazon Perplexity Fight Flips as Appeals Court Restores AI Shopping Agent

Aug 6
12 min read

Perplexity AI has won a major reversal in the Amazon Perplexity fight, with a federal appeals court lifting the injunction against its Comet shopping agent. The decision restores access after a lower court had blocked the agent from Amazon’s password-protected systems.

The Ninth Circuit focused on a basic but consequential distinction. Amazon customers authorized Comet to act through their accounts, so the relevant visitor was arguably the user, not Perplexity itself.

That reasoning weakens Amazon’s early claim under the Computer Fraud and Abuse Act, or CFAA, which prohibits certain unauthorized access to protected computers. It does not end Amazon’s lawsuit or give AI agents unrestricted access to online platforms.

The decision instead creates the clearest federal appellate signal yet about software acting for an authorized user. It places Perplexity’s claim of user agency against Amazon’s asserted right to control access, automation, and customer data.

That conflict extends far beyond one browser. Shopping agents need websites, payment systems, account data, and product catalogs to complete useful work. Those same systems belong to platforms that set access rules and carry the resulting security risk.

What Changed in the Amazon Perplexity Case

The appeals court removed an immediate product restriction without deciding every claim in Amazon’s underlying lawsuit.

Amazon sued Perplexity in November 2025 over Comet, a browser with an AI assistant that can navigate websites and perform requested tasks. A shopper can ask it to find an item, compare choices, access an account, and help complete a purchase.

Amazon characterized that activity as unauthorized access by Perplexity. It alleged that Comet concealed automated behavior, entered password-protected areas, transmitted account information to Perplexity’s systems, and resisted technical blocking measures.

The dispute reached a critical point on March 9, 2026. U.S. District Judge Maxine Chesney granted Amazon a preliminary injunction covering Perplexity’s access to protected Amazon systems through AI agents.

A preliminary injunction is a temporary order issued before a case receives a final judgment. The requesting party must show likely success, probable irreparable harm, favorable equities, and consistency with the public interest.

The district court order concluded that Amazon had made the required showing. It barred covered access and directed Perplexity to destroy Amazon data obtained through the disputed activity.

The district court found strong evidence that Comet entered private accounts with customer permission but without Amazon’s authorization. It also credited Amazon’s costs for investigating the activity and developing countermeasures.

Perplexity appealed immediately. The Ninth Circuit first paused the injunction while it considered the request for longer relief, allowing Comet to remain active during the appellate process.

The latest ruling goes further by reversing the preliminary injunction. According to reporting on the decision, the panel viewed the customer as the party accessing Amazon through an authorized account.

That difference matters because the CFAA does not automatically turn every violation of a website’s preferred method of access into federal computer fraud. Courts examine who entered a system, what areas they entered, and whether authorization existed.

The decision does not declare every action performed by Comet lawful. It means Amazon failed to justify this preliminary restriction under the legal theory and evidence presented at this stage.

Amazon has said it disagrees with the outcome and is evaluating its options. That response preserves the possibility of additional appellate action, revised claims, or a renewed request supported by different evidence.

The lawsuit itself remains active. Amazon can still pursue contract, state-law, security, data-handling, or interference theories as the case moves toward a fuller factual record.

That procedural distinction is essential. Perplexity won the right to keep operating during the litigation, but it did not receive permanent immunity for autonomous shopping.

Why the Amazon Perplexity Ruling Turns on the User

The court’s central move was to treat an AI agent as a tool used by the account holder, rather than an independent intruder.

Traditional web access involves a person directing browser software. The browser retrieves pages, submits forms, stores credentials, and sends instructions selected by that person.

An AI agent changes the degree of delegation. Instead of clicking each control, the user states an objective and lets software select intermediate actions.

That shift makes the software more autonomous, but autonomy does not necessarily create a new legal visitor. The appeals court’s reported reasoning places the authorized account holder at the center of the transaction.

Perplexity’s argument depends on that continuity. A person may use accessibility software, password managers, browser extensions, scripts, or human assistants to interact with an online account.

Comet is more capable than those examples because it can interpret goals and choose actions. Still, Perplexity argues that greater capability does not erase the customer’s underlying authorization.

The company presented this position in its appellate brief. It said Amazon suffered no legally cognizable harm merely because account holders selected an assistant for shopping.

Amazon sees a different actor and a different technical arrangement. Comet reportedly processes information through Perplexity-controlled infrastructure, while the company develops and maintains the system that performs the automated actions.

The distinction is not semantic. It determines whether user permission can authorize the relevant access or whether Perplexity also needs separate permission from Amazon.

Amazon’s position follows what might be called a two-consent model. Under that approach, the customer must authorize the task, and the destination platform must authorize the outside agent.

Perplexity favors a user-delegation model. If customers can lawfully view information or place orders, they should generally be able to appoint software to perform those same actions.

The lower court accepted Amazon’s two-consent theory for purposes of preliminary relief. Its order said customer permission did not necessarily supply Amazon’s authorization to Perplexity.

The appeals court rejected that conclusion as an adequate basis for the injunction. Its reported reasoning reframed Comet as an instrument through which the customer accessed an existing account.

That framing narrows the role of the CFAA. The statute was enacted to address unauthorized computer access, not to convert every contested platform rule into an anti-hacking violation.

The Supreme Court has also read the statute cautiously. In Van Buren v. United States, it rejected an interpretation that would criminalize broad categories of improper computer use by otherwise authorized users.

The Amazon Perplexity dispute presents a newer variation. The user has account access, but software performs part of the work and sends some information through an outside provider’s systems.

This ruling suggests that courts cannot answer that variation by identifying the software vendor as the accessor automatically. They must examine the user’s role, technical flow, and exact information obtained.

However, the ruling does not eliminate boundaries around delegated access. An agent that evades authentication, enters prohibited areas, steals credentials, or exceeds its user’s access presents a different case.

The same is true when software performs unrequested transactions. User authorization must be meaningful, and the agent’s actions must remain connected to the authority actually granted.

Developers therefore cannot reduce the decision to a slogan that agents are simply users. The stronger lesson is that agency, authorization, and technical conduct need precise factual analysis.

Amazon Now Faces a Platform-Control Problem

Amazon must defend customer security without making its rules appear designed mainly to protect control over shopping decisions.

Amazon’s case rests on concerns that deserve serious treatment. An agent handling private account information can expose addresses, order histories, payment choices, and other sensitive details.

The company also has to manage fraud, mistaken purchases, returns, customer support, and seller obligations. Those responsibilities do not disappear because another company controls the interface.

Amazon’s cease-and-desist letter accused Perplexity of misrepresenting Comet as Chrome and modifying it to avoid identification. It demanded transparent identification and an end to disputed access.

Those allegations make transparency a central issue. A platform cannot apply agent-specific safeguards if outside software deliberately looks identical to ordinary human traffic.

Perplexity disputes Amazon’s broader legal conclusions. It argues that the retailer is using computer-access law to restrict customer choice and protect its position in AI-assisted shopping.

That counterargument creates pressure because Amazon already develops shopping automation. Its own tools can recommend products and help customers make purchasing decisions within Amazon’s controlled environment.

The commercial stakes are significant even without relying on speculative revenue figures. A shopping agent can decide which products a user sees, which attributes receive weight, and which offers reach the final comparison.

Amazon traditionally controls that presentation inside its store. Search rankings, recommendations, sponsored placements, reviews, fulfillment labels, and checkout design all shape a purchase.

A third-party agent can reorder those signals. It might prioritize unit cost, delivery time, seller reputation, sustainability, or user instructions instead of Amazon’s default presentation.

That does not make the result neutral. Perplexity has its own models, ranking methods, partnerships, and incentives, which users may not fully understand.

The contest is therefore not simply user freedom against platform control. It is a contest between two intermediaries seeking authority over the same transaction.

Amazon controls the marketplace infrastructure and bears many operational risks. Perplexity controls the conversational layer and can influence the customer before Amazon’s interface becomes visible.

The appellate ruling gives the conversational layer more room. It prevents Amazon from using this preliminary CFAA theory as an immediate veto over Comet’s customer-directed access.

Amazon can still impose technical defenses and pursue narrower legal claims. Yet aggressive blocking now carries strategic risk if courts view the customer as the true actor.

The company’s forced response is likely to involve clearer agent policies, improved technical identification, or approved access methods. Each option requires Amazon to define acceptable delegation.

A complete ban would preserve interface control but frustrate customers who want outside assistants. Open access would encourage competition but increase security, attribution, and support challenges.

A controlled agent interface offers a middle path. Amazon could authenticate agents, limit data exposure, record delegated consent, and enforce transaction-level safeguards.

Such an interface would also let Amazon determine who qualifies for access. That gatekeeping could become the next competitive conflict if approval favors selected partners or Amazon’s own services.

For enterprise buyers, the lesson is immediate. A useful agent needs more than model accuracy. It needs stable permission, transparent identity, audit records, and a credible way to operate across third-party systems.

AI Shopping Agents Still Carry Unresolved Risks

The court restored Comet’s access, but it did not validate the safety, reliability, or commercial neutrality of autonomous shopping.

The first unresolved issue is consent quality. A general request to buy an item does not answer every choice an agent encounters during checkout.

The agent may need to select a seller, shipping option, subscription setting, warranty, quantity, or replacement policy. Each choice can create a financial commitment.

Good agent design must define when software can proceed and when it must ask the user. That boundary becomes more important as tasks move from research into payment.

The second issue is data handling. Comet may need access to private account information to perform requested tasks, and the lower court examined transmission to Perplexity’s servers.

Users need clear answers about which information leaves the destination site. They also need retention limits, security controls, and a reliable method for revoking access.

The appellate decision does not settle those questions. Treating the customer as the accessor does not give an agent permission to collect or retain every visible field.

The third issue is identity. Amazon alleges that Perplexity obscured automated access and worked around countermeasures, while Perplexity challenges Amazon’s characterization of its conduct.

A durable agent economy cannot depend on endless disguise and detection. Platforms need to recognize legitimate agents without granting them unnecessary data.

The agents also need protection from arbitrary exclusion. Otherwise, a platform can identify outside software only to block competitors while favoring its own assistant.

The fourth issue is instruction security. Browser agents can encounter malicious text designed to redirect their actions, a problem known as prompt injection.

A product page, review, advertisement, or hidden instruction might tell an agent to ignore the user’s goal. A vulnerable system could expose data or initiate an unwanted action.

Legal permission does not solve that engineering problem. A user-authorized agent can still behave unsafely after processing hostile content.

The fifth issue concerns remedy. Amazon sought emergency relief partly because it said continued access created harm that later damages could not repair.

The appeals court’s rejection of the injunction raises the bar for that immediate remedy. It does not prevent Amazon from proving actual harm through discovery or trial.

Evidence of account compromise, fraudulent orders, measurable system damage, or misuse of private data would materially change the case. So would evidence showing reliable consent and limited data processing.

This is why the ruling should not be described as a complete legalization of AI agents. It is a decision about preliminary relief based on the present record.

The ACLU and Knight First Amendment Institute supported Perplexity’s position through an internet freedom brief. They warned that an expansive CFAA theory could affect research, journalism, accessibility, and other user-directed tools.

That concern extends beyond shopping. Agents may eventually submit forms, organize travel, manage subscriptions, compare insurance, or gather information from authenticated services.

If every destination can characterize the agent vendor as an unauthorized accessor, users gain little practical ability to delegate online work. Platform terms would determine which assistants can function.

The opposite extreme creates its own danger. If user permission always defeats platform restrictions, malicious services could invoke nominal consent while extracting sensitive data at scale.

Courts will need to distinguish genuine delegation from independent commercial collection. Technical architecture, agent identification, purpose limits, and data retention will all matter.

Companies deploying agents should document these elements now. A vague claim that the agent acts for the user will not answer how credentials, data, and transaction authority move through the system.

Teams also need records showing what the user requested and what the agent did. Those records can support troubleshooting, dispute resolution, regulatory review, and meaningful user control.

Knowledge workers evaluating browser agents should apply the same discipline. Before connecting an account, examine permissions, confirmation rules, storage practices, and the provider’s response to hostile content.

A searchable record of agent activity can also help users review consequential decisions. Personal knowledge tools such as an AI second brain can organize related research, but they should not replace transaction-specific controls.

Agentic Commerce Is Becoming a Contest Between Interfaces

The most important competitive question is who becomes the customer’s primary shopping interface, not who owns the final checkout page.

Amazon built its marketplace around direct customer attention. People search its catalog, review options, respond to recommendations, and complete purchases inside one environment.

A general-purpose agent changes the entry point. The customer may begin with Perplexity, ChatGPT, Gemini, or another assistant rather than visiting a retailer.

The agent can gather options across several stores before choosing where to transact. That weakens each retailer’s ability to define the complete shopping journey.

Retailers are responding differently. Some are developing proprietary assistants, while others are exploring partnerships that place products inside third-party conversational services.

Amazon’s strategy includes its own shopping assistant and agentic features. That gives the company experience with the benefits of automation while intensifying questions about outside access.

Perplexity’s approach begins from the browser. Comet can operate across sites, letting the company argue that it represents the user rather than any single retailer.

General-purpose assistants have another route. They can form direct commercial integrations with merchants, avoiding browser automation and receiving structured product information.

Structured integrations offer reliability and clearer permission. They can expose inventory, pricing, policies, and checkout functions through defined interfaces.

However, integrations also require negotiation. Smaller agents may struggle to secure access, and platforms can use commercial terms to influence which assistants reach customers.

Browser-based agents offer broader reach without waiting for every platform. Their flexibility creates more uncertainty about identity, consent, interface changes, and permitted data use.

The Amazon Perplexity decision gives that browser route an important legal advantage. It limits one method for stopping an agent before the underlying dispute receives full examination.

It does not decide which architecture will win. Approved integrations may still outperform improvised browser navigation on speed, reliability, safety, and customer support.

Customers will judge outcomes rather than legal theories. An agent that selects the wrong variation or adds an unwanted subscription will lose trust quickly.

Merchants will judge attribution and control. They need to know which agent initiated a transaction, which representations reached the customer, and who handles mistakes.

Agent providers will judge access stability. A product cannot promise reliable task completion when a destination can change its interface or block traffic without warning.

These incentives point toward a shared identity and authorization layer. The agent could present a verifiable identity, user mandate, requested scope, and expiration time.

The platform could return permissions and require confirmation for sensitive actions. Both sides could preserve an audit trail without exposing unnecessary private data.

Standards alone will not remove commercial conflict. Amazon may still prefer interactions that preserve advertising, recommendations, and direct customer relationships.

Perplexity may prefer results that minimize retailer influence and strengthen its own interface. Other assistant providers will bring different business models to the same transaction.

That is the larger reversal behind this case. Websites once assumed that users would interact through interfaces chosen by website owners.

AI agents challenge that assumption by separating access from presentation. The customer may use one company’s software to interact with another company’s service.

The appeals court has now recognized that distinction as legally relevant. Product teams should treat it as a design constraint, not a permanent legal guarantee.

What to Watch After Perplexity Returns to Amazon

Three signals will show whether this ruling becomes a durable foundation for user-directed agents or remains a narrow procedural victory.

The first signal is Amazon’s next legal filing. Amazon can seek further review, sharpen its remaining theories, or build a more detailed record of technical and customer harm.

A successful request to reconsider the appellate result would weaken the user-delegation theory. Continued denial of emergency relief would strengthen Perplexity’s operating position during the case.

The second signal is any change to Comet’s identity and consent controls. Perplexity can reduce legal and product risk by making agent activity visible, limiting data transmission, and requesting confirmation before consequential actions.

Greater transparency would support its claim that Comet acts as a legitimate user-appointed assistant. Continued disputes over concealment or countermeasure evasion would strengthen Amazon’s security narrative.

The third signal is Amazon’s product and platform response. A published third-party agent policy or authenticated access framework would show that Amazon accepts outside agents under controlled conditions.

A policy favoring only selected commercial partners would shift the dispute toward competition and gatekeeping. A continuing technical battle would show that shared rules remain distant.

The underlying case also deserves attention as discovery develops. A preliminary injunction depends on probabilities, while a final judgment follows a more complete factual record.

That record should reveal how Comet identifies itself, where account data travels, what users authorize, and how Amazon’s controls respond. Those facts matter more than broad claims from either company.

Developers should avoid reading the decision as permission to ignore platform security. Build explicit consent, minimal data access, clear agent identity, and logs that connect every action to a user request.

Enterprise buyers should ask whether an agent has stable authorization across critical services. A successful demonstration means little if the workflow depends on disputed access that disappears during deployment.

AI users should watch the confirmation boundary. The safest assistant is not the one that completes every step automatically, but the one that knows when to return control.

The Amazon Perplexity fight has moved one step toward user choice, yet the final rules remain unsettled. Which agent would you trust to act through your accounts, and what proof would you require before letting it buy?

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page