The U.S. Court of Appeals for the Ninth Circuit vacated a preliminary injunction that had barred Perplexity from letting users of its AI-powered browser perform tasks on Amazon.com, finding Amazon was unlikely to show that Perplexity itself accessed Amazon’s computers in violation of the Computer Fraud and Abuse Act (CFAA) or California’s similar statute. The court concluded that, on the record before it, the relevant access was carried out by the human user directing the tool, not by the AI assistant as an independent actor, undercutting Amazon’s argument that Perplexity’s routing around blocking measures amounted to unauthorized access by the company.
The ruling was described by supporters including the Knight First Amendment Institute and the ACLU as a win for user control and for research and journalism that scrutinize online platforms, but the opinion was also framed as narrow and fact-specific. Commentary on the decision noted that the court addressed only the CFAA’s access element in this user-directed shopping context, leaving open potential liability for users or companies under different circumstances, including cases where agentic AI systems are intentionally configured or misconfigured in ways that lead to unauthorized intrusions.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
The U.S. Court of Appeals for the Ninth Circuit vacated the preliminary injunction that had prevented Perplexity from enabling users of its AI-powered browser to perform tasks on Amazon.com. The court held that, on the record before it, the relevant access was performed by the user with the assistant's help rather than by Perplexity itself.
The Knight First Amendment Institute, the ACLU, and the ACLU of Northern California filed an amicus brief urging the court to reject Amazon's broader interpretation of the CFAA and California's analogous law.
A district court granted Amazon a preliminary injunction barring Perplexity's tools from reaching Amazon.com after Amazon argued that Perplexity's agentic browser assistant was engaging in unauthorized access under the CFAA.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.