In a landmark decision with far-reaching implications for the artificial intelligence industry, the 9th US Circuit Court of Appeals in San Francisco has reversed a lower court's decision that had temporarily blocked Perplexity from deploying its autonomous shopping agents on Amazon's platform. The Tuesday ruling represents the first significant federal appellate judgment on whether AI systems operating on behalf of users can legally access online shopping platforms—a question that will shape how agentic AI tools develop across the globe.
The dispute between the e-commerce giant and the San Francisco-based AI startup began in November when Amazon filed suit, alleging that Perplexity's Comet browser and associated AI agent were covertly accessing private customer accounts without authorization. According to Amazon's complaint, the system could log into users' shopping accounts and execute purchase orders independently, presenting what the company characterized as serious security vulnerabilities. Amazon claimed it had repeatedly requested that Perplexity cease this activity, but the startup continued nonetheless.
Perplexity's defence hinged on a fundamentally different interpretation of how the technology operates. The company contended that Amazon's lawsuit was baseless and represented nothing more than an attempt to prevent users from employing AI tools of their choosing. In Perplexity's view, the real concern driving Amazon's legal action was that AI agents lack the ability to view the advertising that saturates Amazon's interface—a significant loss of value for the company's marketing ecosystem. The startup framed the dispute as a matter of user rights and technological freedom rather than security or unauthorized access.
In March, a federal judge in California sided with Amazon, issuing a preliminary injunction that barred Perplexity from using its agentic AI on Amazon's platform. The judge found that Amazon had presented compelling evidence suggesting Perplexity's system violated the Computer Fraud and Abuse Act, a federal law that criminalizes unauthorized access to computer systems. This initial ruling appeared to establish a significant legal hurdle for the deployment of autonomous AI agents across major commercial platforms.
However, the 9th Circuit's reversal fundamentally reframed the legal question. The appeals court rejected Amazon's interpretation of who constitutes the "accessor" under federal computer fraud law. Rather than viewing Perplexity itself as the party gaining unauthorized access, the court determined that Perplexity's users—operating through the company's AI agents—were the actual parties accessing Amazon's platform. This distinction proved decisive: since Perplexity's users, through legitimate accounts with valid credentials, were authorizing the AI agents to act on their behalf, no unauthorized access had occurred under the statute's definition.
The ruling carries enormous significance for the rapidly expanding field of agentic AI technology. These systems represent a qualitatively different category of artificial intelligence from the chatbots and language models that currently dominate public discourse. Agentic AI can perceive its environment, formulate plans, reason through complex sequences of actions, and execute tasks across multiple platforms with minimal human intervention. They can browse the web, interface with various services, conduct transactions, and navigate digital ecosystems in ways that more closely resemble how human users interact with technology.
For Malaysia and the broader Southeast Asian region, this decision carries particular relevance. As agentic AI technology proliferates, regional e-commerce platforms—including homegrown services like Lazada and Shopee—will face similar questions about how to regulate AI agent access to their systems. The legal framework established by this US court could influence how Southeast Asian regulators and platforms approach this emerging technology. Currently, many regional e-commerce services lack clear policies governing AI agent access, creating regulatory uncertainty that this US precedent may help clarify.
Amazon issued a statement expressing disagreement with the decision while signalling its intention to pursue further legal remedies. The company emphasized its confidence in the underlying merits of its case and suggested it was evaluating additional options, which could include appealing to the US Supreme Court or seeking legislative solutions to restrict AI agent access. This determination indicates that the dispute is unlikely to end with the 9th Circuit's ruling and may continue to generate legal and regulatory developments for years to come.
Perplexity, conversely, framed the victory as a vindication of user rights and technological innovation. Company spokesperson Jesse Dwyer emphasized that the decision protected users' freedom to select their preferred AI tools and suggested that Perplexity's position had been validated by the courts. The company's framing suggests it will continue to develop and expand its agentic shopping capabilities, potentially offering similar services on other major e-commerce platforms.
The broader implications of this decision extend well beyond the immediate dispute. As artificial intelligence systems become increasingly autonomous and capable of executing complex tasks across digital networks, questions about their legal status and rights of access will become more acute. The court's decision to treat user-authorized AI actions as equivalent to direct user access creates a legal pathway for agentic AI deployment across platforms. However, this approach also raises new questions about liability, accountability, and what responsibilities AI companies bear when their agents interact with other platforms on users' behalf.
From a consumer protection standpoint, the ruling introduces both opportunities and risks. On one hand, agentic AI could streamline shopping experiences and help consumers navigate complex digital marketplaces more efficiently. On the other, it creates potential security vulnerabilities if AI agents gain access to sensitive account information or if their actions are compromised by malicious actors. The decision places responsibility on platforms and users rather than on AI companies to manage these risks—a distributional choice that remains contested and may provoke further litigation or regulation.
Looking forward, the 9th Circuit's decision will likely encourage other AI companies to develop and deploy agentic shopping tools, potentially sparking similar conflicts with e-commerce platforms that view such technology as threatening to their business models. Whether other courts will reach the same conclusions remains uncertain, particularly as the issue may eventually reach the Supreme Court. Meanwhile, Congress may seek to clarify the Computer Fraud and Abuse Act or introduce new legislation specifically addressing AI agent access to digital platforms. For Malaysian technology companies and regulators, monitoring these developments will be essential as agentic AI technology continues to mature and reshape digital commerce.
