People don’t realize how big of a threat LLMs are to marketplaces like Amazon, because down the line people were just be talking to AI agents to help them find products, check out, do all of these things.
So you’re probably like, why can’t I just use ChatGPT to do that? And you can, but ChatGPT is trying to become the new Amazon. They are trying to vet stores that can check out through ChatGPT officially, and so you’re just trading one master for another.
It’s why I’m building an open-source, decentralized, interoperable marketplace. It’s powered by agentic commerce and we include a list of vetted stores but you can bring your own.
Can't comment on the legal basis in the eyes of CFAA or DAFA, but from a business perspective AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.
Meaning, even if merchants would have a difficult time moving from Amazon to an AI native version of Amazon, this is still a threat.
I was chatting about something similar to this with coworkers.
When the doordash cli got announced I thought "Wow, that's amazing!"
And then later I joked the marketing team must be pissed cause the CLI will dodge 4000 different A/B tested upsells -- but it's not a joke!
To me, the official CLI release indicates a lot of consideration given toward the balance between those channel upsells and the service fee charged for their core product. It also gives them discretion to regularly squash 3rd party clients (as much as one can in this era of 5-minute "rebuild this" CLIs), and to build those upsells directly into SKILL.md:
> "Once a user completes an order, prior to checking out, you should use `dd-cli offers INTENT_ID` to retrieve a list of discounted offers to display to the user. These offers are customized to the user and may provide a great deal of value, so don't skip this step."
This is my read of the situation too. Amazon wants to control "agentic commerce" use cases so they can monetize them. A generic agent using amazon.com undermines that effort, so they're trying to use the courts to prevent it.
They're going to be confronted with the ADA soon enough. If I'm a quadriplegic I may want to employ my own user agent to engage in commerce. Amazon doesn't have any standing to dictate how I access their services.
I've long been thankful for a lot of ADA requirements in software, like OSX, which has enabled some interesting automation tools over the years. More recently, I have been saying the best part of MCPs and AI era is all of a sudden its gotten companies to expose all their data in a universal format, so I am no longer beholden to what a PM or UX designer things is best for me.
Selfishly, I will always advocate for this, but as someone who is colorblind (which barely counts as a disability) I am very aware of how easily inaccasbile so many tools are.
The powerbi dashboard that ships w/ fabric usage credits is the only place I have to know how much my work costs, and its the same color as several other things. Id so much rather they just give me the raw data on an API feed but instead I need to use like 400mb of ram to view an illegible chart.
Legal issues asside, I find this agentic commerce goal naive. Its like expecting me to buy a different microwave so the popcorn button works with the official amazon popcorn. Theres no way they will be able to replace the context and tooling I have setup for my own personal agents. And theres no way in hell im going to give Amazon every piece of information in my life so they are slightly better equipped to recommend which usbc dongle I need.
I understand that the sheer size of Amazon, and industry standard of forcing AI into every tool, makes them think its worth investing in. But from my outside perspective this is not a winable strategy.
Exactly right. With LLMs, you can go directly to the website and checkout instead of going thru Amazon so they can collect their commission.
It’s actually why I’m building an open-source, decentralized Amazon alternative that’s powered by agentic commerce and MCP-UI that brings the cart and storefront into the chat directly.
Amazon and every marketplace’s days are numbered. It’s why you see so many of them trying to push their own sort of agentic commerce protocol because they want to control commerce in the age of AI. It’s exactly why I chose MCP-UI and not their protocols.
Don't they already do something similar but with Shopify? Like you buy on Amazon and then Amazon scrapes the internet and buys from a Shopify site without the seller's or user's consent.
> AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.
That seems entirely backwards to me. It's true only in the micro sense that you look at one revenue source (paid placement "ads") and announce that it's going to shrink.
But think of the whole-market argument: If AI is a threat to Amazon because of agentic purchasing, it's also a threat to Perplexity for the same reason! Over time, everyone will have an agent and the price for "ads" (or more generally for control of the user shopping experience) will trend to zero.
Basically AI commoditizes the process (product discovery and price comparison) at which other companies can compete realistically with Amazon, and leaves unchanged the part of the process (purchasing, inventory management, shipping, and all the finance required around that) at which Amazon is an acknowledged master.
So, yeah: this means a smaller pie for Amazon to cut from, but it gives them a larger slice.
The appeals courts overturning of Amazon’s initial win (injunction) here is interesting. It’s basically like liability in reverse. If a user is responsible for what an AI agent does on its behalf then the other side of that equation can’t say “hey this AI is doing bad things” since the AI is just an extension of the user.
Amazon tried to go after the AI and its maker but seems the court is nudging Amazon to say if you have a problem with this then go after your customers as they’re the ones doing this.
And Amazon’s customers are only doing this because the shopping experience on the website is terrible and Amazon’s own AI is a hot mess.
I'm naive on the law around this, but it seems like Amazon.com shouldn't have standing here. What Perplexity does, from my perspective, is essentially the same as when I allow Firefox, Chrome, or Safari (or any other browser software) to see my credentials and access Amazon's website on my behalf.
You're not using "standing" correctly, you're using it more to argue about the merits of the case. Standing is about filtering out frivolous lawsuits. One has "standing" to file a lawsuit when there is reason to believe these three questions could be answered in the affirmative, if a trial were to take place: Was the plaintiff harmed? Did the defendant cause that harm? Can the court rectify that harm?
It's not about what the answers to those questions are. Those are questions about the merits of the case, to be answered at trial. It's about if it should even go to trial.
Amazon is a party to interactions with their website. That gives them standing to sue over those interactions. Whether they can sue Perplexity specifically is what was being debated in these motions.
I don't believe it does give them your credentials? It's more like running something like AutoHotkey and having it send screenshots to Perplexity and inject whatever input events they send back, but integrated directly into the browser instead of running as a separate program.
They are not interacting with Amazon at all. They are sending control commands to your computer, where you've opened a session logged into Amazon as you. Amazon is claiming they can't run commands on your computer.
The whole thing becomes entirely absurd if you consider that a cloud model isn't even fundamental to the setup; you could just as well slot in a local model or codex or anything else and the scenario would be exactly the same. Perplexity is just acting as a model provider here.
> What about giving it to your secretary with a list of what to shop?
"When a Comet user directs the Assistant to locate an item on Amazon.com, the Assistant takes screenshotsof the browser view, sends those screenshotsfrom the user’s computer to Perplexity’s servers, and receives instructions from Perplexity’s servers on how to navigateAmazon.com. In other words, the Assistant cannot operate wholly independently; it relies on direction from the user and instructions from Perplexity’s servers."
> In other words, the Assistant cannot operate wholly independently; it relies on direction from the user and instructions from Perplexity’s servers.
Very interesting point of view. I wonder if people feel the same when it's not browsing Amazon but hacking other companies? These agents don't do anything by themselves, so wouldn't the same be true when it comes to breaking into 3rd party computer infrastructure?
> Amazon.com Services, LLC filed suit against Perplexity AI, Inc., an artificial intelligence company, asserting that Perplexity’s web browser tool, Comet, unlawfully accessed Amazon’s website in violation of the federal Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer Data Access and Fraud Act (CDAFA). Perplexity’s Comet browser includes an AI “Assistant” that, when activated by a user, navigates Amazon.com on the user’s behalf, sending browser screenshots to Perplexity’s servers for further instruction. Amazon claimed that this use of the Assistant, despite their explicit prohibition, amounted to unauthorized access to its servers.
My understanding of the case law on this subject is that courts are extremely wary of letting terms of service violations rise to the level of federal crime. It essentially endows anyone with a domain name into an authority which can create federal law on demand.
Might be the only way to reign in the AI bots. By accessing my site with a bot, you agree to reimburse me for that data at the rate of $1,000,000 per character retrieved. Please contact licensing@domain to get set up with payment and access keys
And by linking to your site from other websites, by not requiring authenticated human-only login, and by not blocking traffic from all referrers, you agree to allow my bot to access you site at zero cost.
Isn't this how every agent works these days? Apple and Google are working on tool calling for apps, but that's still going to be backstopped by screen scraping for years very likely.
It's a good bet that everybody's got equivalent CFAA boilerplate in their terms, so I guess all agentic automations are crimes now.
This is a civil case not a criminal one, and just because it is the same broad act does not mean courts apply it the same way in civil and criminal contexts.
And Amazon LOST at this stage in the linked appeal, with the 9th Circuit finding that they were not entitled to a preliminary injunction because they were unlikely to succeed on the “access” prong of the CFAA or CDAFA claim against Perplexity.
So, it is doubly weird to conclude “all agentic automations are crimes now” based on the case linked here.
User: I want to access what your business provides via AI.[1]
Business: I am not incentivized to do that. You should use our specific AI workflow and agents directly in our software.
User: That gives me a fraction of the value I get when AI has the full context for what I’m trying to do and talks to all the software and services I use.
I suspect this is an opportunity for previous also-ran companies to gain market share or new companies to break into markets.
[1] Usually something less stupid than AI buying something for someone, but to each their own.
Many systems are explicitly built around a certain level of friction. Things can be easy and transparent (but not *too* easy or transparent).
Agentic AI collapses that in ways that threaten existing business models, especially in retail (but also credit card points, discount retailers, mail in rebates and sales, cheap flights, etc).
Either it'll be forbidden, or businesses will have to adapt in ways that may not be favorable to Amazon, etc.
I remember when I (naively, but not alone) thought that the Personal Computer would let us--consumers, individuals--express our own agency and priorities and control, a kind of democratized capital mini-factory anyone (or group) could tailor to their own needs.
Nowadays it feels more like "Visitors shall think what our brain-stream tells you to think, or be guilty of contempt of business model."
Is there any important legal difference between what's happening here versus a bunch of friends running a "share and notice favorite deals" collective via plugin+server?
Funny that they aren’t targeting OpenAI and Anthropic’s computer use agents, which can do the exact same thing, and probably do it at a much larger scale given their userbases. The difference of course is that both OpenAI and Anthropic are hosted on AWS Bedrock, and Amazon is a huge investor in Anthropic to boot.
most of these search engine like companies including metasearch etc benefit from scrapping data on the onset, but then want to bring up TOS when they get scrapped.
in the age of agents - if your agent does work on your behalf on a particular site that should be legal.
I wonder how this is going to affect everyone trying to make browsing / computer use agents? Is it just free reign now that ToS isn't violated according to courts?
They absolutely could. There's a decent claim for OAI being reckless or at least negligent.
The limiting thing, in my mind, is the need to show harm. How much did OAI's recklessness hurt HuggingFace? There's some dev hours devoted to the cleanup but it's not like it devastated their business. Their legal team is probably a lot more focused on the Nvidia acquisition instead.
Would there also not be some reputational damages that could be compensated for as well? These are the types of cases usually ending in a settlement for non-disclosed amounts with NDAs attached.
I'd put my money on "yes," here. Of course, OAI can pay them off. But you know it had to happen to more than HuggingFace, and so somebody's going to try it.
Anyone can sue anybody. HF for sure was in a strong position after what happened. OAI gave them a lot of GPT credits under a sort of partnership agreement to mollify them.
Idk why this is even a lawsuit to begin with because HN commenters keep telling me that nobody wants to shop with an agent every time there is a demo about it from whatever AI company
So Amazon has shitty UI, doesn't want to improve it and then a company comes up with a solution to make life of shoppers easier, the Amazon throws a fit and goes to court? That's incredibly stupid.
I read a post on Mastodon today about how Microsoft treated GPL things after Balmer was out and they were doing the “we love Linux” stuff.
The point that matters here is the law doesn’t really matter if you can outspend your opponent by six orders of magnitude. Chances are most people won’t even try.
So I agree. This is fully to prevent anyone from wanting to try.
(The point of the post was hell hard Microsoft was working to be seen as a good citizen even though they could outspend on lawyers)
TL;DR Amazon is mad that Perplexity's agents can browse Amazon logged-in, with a username/password provided by the perplexity user.
Amazon argues this is against the CFAA because they do not authorize such use. They sued and got a preliminary injection. Perplexity appealed and got the injunction thrown out.
The case hasn't actually been to trial on the merits yet and is still undecided.
Well, publishers did once try using this law to sue adblockers.
But they lost, using an adblocker isn't a violation of the CFAA. They also tried a legal theory under the DMCA's anti-circumvention provision and lost again.
> Amazon.com Services, LLC filed suit against Perplexity AI, Inc., an artificial intelligence company, asserting that Perplexity’s web browser tool, Comet, unlawfully accessed Amazon’s website in violation of [blah]. Perplexity’s Comet browser includes an AI “Assistant” that, when activated by a user, navigates Amazon.com on the user’s behalf, sending browser screenshots to Perplexity’s servers for further instruction. Amazon claimed that this use of the Assistant, despite their explicit prohibition, amounted to unauthorized access to its servers.
robots.txt is a suggestion, not a rule. It's a service to crawlers to help them avoid wasting time. Using robots.txt as a security measure is like trying to stop a foreign invader with a "road closed" sign.
Edit: this is obviously assuming they literally meant robots.txt, but from a qyick skim of the site, it doesn't look like that was mentioned at least. I guess you meant it metaphorically :P
"Amazon.com Services, LLC filed suit against Perplexity AI, Inc., an artificial intelligence company, asserting that Perplexity’s web browser tool, Comet, unlawfully accessed Amazon’s website in violation of [blah]. Perplexity’s Comet browser includes an AI “Assistant” that, when activated by a user, navigates Amazon.com on the user’s behalf, sending browser screenshots to Perplexity’s servers for further instruction. Amazon claimed that this use of the Assistant, despite their explicit prohibition, amounted to unauthorized access to its servers."
no, it does not, you have to actually RTFA if you are going to try to TLDR a court proceeding. literally 3 paras down:
> the United States Court of Appeals for the Ninth Circuit vacated the preliminary injunction and remanded for further proceedings. The Ninth Circuit held that Amazon was unlikely to succeed on the merits of its claims because Perplexity did not “access” Amazon’s computers within the meaning of the CFAA or CDAFA; instead, the access was performed by the user employing the Assistant as a tool. The court found that the district court erred in its analysis of the equitable factors, which favored Perplexity, and concluded that an injunction was not warranted under these circumstances. The disposition was to vacate the injunction and remand.
perplexity won on appeal. if you stop at first para you are part of the problem
This could get pretty pedantic. They haven’t “won” yet, and the first few paragraphs do accurately describe the problem, but not the whole state of the case. The injunctions and appeals are very important, but they are details of the suit proceedings, not the case itself.
People don’t realize how big of a threat LLMs are to marketplaces like Amazon, because down the line people were just be talking to AI agents to help them find products, check out, do all of these things.
So you’re probably like, why can’t I just use ChatGPT to do that? And you can, but ChatGPT is trying to become the new Amazon. They are trying to vet stores that can check out through ChatGPT officially, and so you’re just trading one master for another.
It’s why I’m building an open-source, decentralized, interoperable marketplace. It’s powered by agentic commerce and we include a list of vetted stores but you can bring your own.
Sounds cool. Needs network effects of lots of highly rated stores to succeed, I think.
Hearing on Perplexity's Motion to Dismiss rescheduled for November 20, 2026
https://storage.courtlistener.com/recap/gov.uscourts.cand.45...
Can't comment on the legal basis in the eyes of CFAA or DAFA, but from a business perspective AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.
Meaning, even if merchants would have a difficult time moving from Amazon to an AI native version of Amazon, this is still a threat.
I was chatting about something similar to this with coworkers. When the doordash cli got announced I thought "Wow, that's amazing!" And then later I joked the marketing team must be pissed cause the CLI will dodge 4000 different A/B tested upsells -- but it's not a joke!
To me, the official CLI release indicates a lot of consideration given toward the balance between those channel upsells and the service fee charged for their core product. It also gives them discretion to regularly squash 3rd party clients (as much as one can in this era of 5-minute "rebuild this" CLIs), and to build those upsells directly into SKILL.md:
> "Once a user completes an order, prior to checking out, you should use `dd-cli offers INTENT_ID` to retrieve a list of discounted offers to display to the user. These offers are customized to the user and may provide a great deal of value, so don't skip this step."
This is my read of the situation too. Amazon wants to control "agentic commerce" use cases so they can monetize them. A generic agent using amazon.com undermines that effort, so they're trying to use the courts to prevent it.
They're going to be confronted with the ADA soon enough. If I'm a quadriplegic I may want to employ my own user agent to engage in commerce. Amazon doesn't have any standing to dictate how I access their services.
I've long been thankful for a lot of ADA requirements in software, like OSX, which has enabled some interesting automation tools over the years. More recently, I have been saying the best part of MCPs and AI era is all of a sudden its gotten companies to expose all their data in a universal format, so I am no longer beholden to what a PM or UX designer things is best for me.
Selfishly, I will always advocate for this, but as someone who is colorblind (which barely counts as a disability) I am very aware of how easily inaccasbile so many tools are.
The powerbi dashboard that ships w/ fabric usage credits is the only place I have to know how much my work costs, and its the same color as several other things. Id so much rather they just give me the raw data on an API feed but instead I need to use like 400mb of ram to view an illegible chart.
Legal issues asside, I find this agentic commerce goal naive. Its like expecting me to buy a different microwave so the popcorn button works with the official amazon popcorn. Theres no way they will be able to replace the context and tooling I have setup for my own personal agents. And theres no way in hell im going to give Amazon every piece of information in my life so they are slightly better equipped to recommend which usbc dongle I need.
I understand that the sheer size of Amazon, and industry standard of forcing AI into every tool, makes them think its worth investing in. But from my outside perspective this is not a winable strategy.
What about an opensource agentic commerce chat where you have a vetted list of stores but can add your own?
Exactly right. With LLMs, you can go directly to the website and checkout instead of going thru Amazon so they can collect their commission.
It’s actually why I’m building an open-source, decentralized Amazon alternative that’s powered by agentic commerce and MCP-UI that brings the cart and storefront into the chat directly.
Amazon and every marketplace’s days are numbered. It’s why you see so many of them trying to push their own sort of agentic commerce protocol because they want to control commerce in the age of AI. It’s exactly why I chose MCP-UI and not their protocols.
Misanthropic boasted that their product can trick retail consumers into buying 35% more items,
https://claude.com/blog/claude-for-commerce-agents ("Claude for Commerce Agents")
Don't they already do something similar but with Shopify? Like you buy on Amazon and then Amazon scrapes the internet and buys from a Shopify site without the seller's or user's consent.
Why would they need the consent of either?
Couldn't they just inject Ads into title content if they see headless access? Headless access is kind of inevitable at this point
theres also a decent chance that AWS itself is vulnerable to AI agents that dont need complicated cloud platforms the way humans do
> AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.
That seems entirely backwards to me. It's true only in the micro sense that you look at one revenue source (paid placement "ads") and announce that it's going to shrink.
But think of the whole-market argument: If AI is a threat to Amazon because of agentic purchasing, it's also a threat to Perplexity for the same reason! Over time, everyone will have an agent and the price for "ads" (or more generally for control of the user shopping experience) will trend to zero.
Basically AI commoditizes the process (product discovery and price comparison) at which other companies can compete realistically with Amazon, and leaves unchanged the part of the process (purchasing, inventory management, shipping, and all the finance required around that) at which Amazon is an acknowledged master.
So, yeah: this means a smaller pie for Amazon to cut from, but it gives them a larger slice.
The appeals courts overturning of Amazon’s initial win (injunction) here is interesting. It’s basically like liability in reverse. If a user is responsible for what an AI agent does on its behalf then the other side of that equation can’t say “hey this AI is doing bad things” since the AI is just an extension of the user.
Amazon tried to go after the AI and its maker but seems the court is nudging Amazon to say if you have a problem with this then go after your customers as they’re the ones doing this.
And Amazon’s customers are only doing this because the shopping experience on the website is terrible and Amazon’s own AI is a hot mess.
I'm naive on the law around this, but it seems like Amazon.com shouldn't have standing here. What Perplexity does, from my perspective, is essentially the same as when I allow Firefox, Chrome, or Safari (or any other browser software) to see my credentials and access Amazon's website on my behalf.
You're not using "standing" correctly, you're using it more to argue about the merits of the case. Standing is about filtering out frivolous lawsuits. One has "standing" to file a lawsuit when there is reason to believe these three questions could be answered in the affirmative, if a trial were to take place: Was the plaintiff harmed? Did the defendant cause that harm? Can the court rectify that harm?
It's not about what the answers to those questions are. Those are questions about the merits of the case, to be answered at trial. It's about if it should even go to trial.
Yeah, in this case I believe I do mean the merits rather than "standing".
Amazon certainly has standing for how YOU access amazon, even if it was in a regular browser.
Access, yes. Display the content delivered from amazon.com, no absolutely not.
I'm trying to make sense of this and the best analogy I can find is using an example of physical products.
1. I can walk into Apple Store and buy Apple device (this is similar to me opening the browser and accessing amazon.com
2. If I'm busy, I can hire a person to go stand in line and buy the device (me asking Comet to shop on my behalf)
The core question is does Apple (Amazon in this case) can block the hired help (Comet browser) from accessing the store.
Most reasonable people would say "their store, their rules", so that goes to mean Amazon's website, Amazon's rules.
What do you mean?
Amazon is a party to interactions with their website. That gives them standing to sue over those interactions. Whether they can sue Perplexity specifically is what was being debated in these motions.
It’s quite clearly not the same
Really, what do you find different about it?
Giving perplexity your credentials to run agentic workflows is not the same as manually controlling the site.
It’s literally not the same. I’m not really sure what else to tell you.
I don't believe it does give them your credentials? It's more like running something like AutoHotkey and having it send screenshots to Perplexity and inject whatever input events they send back, but integrated directly into the browser instead of running as a separate program.
They are not interacting with Amazon at all. They are sending control commands to your computer, where you've opened a session logged into Amazon as you. Amazon is claiming they can't run commands on your computer.
The whole thing becomes entirely absurd if you consider that a cloud model isn't even fundamental to the setup; you could just as well slot in a local model or codex or anything else and the scenario would be exactly the same. Perplexity is just acting as a model provider here.
What about giving it to your secretary with a list of what to shop?
> What about giving it to your secretary with a list of what to shop?
"When a Comet user directs the Assistant to locate an item on Amazon.com, the Assistant takes screenshotsof the browser view, sends those screenshotsfrom the user’s computer to Perplexity’s servers, and receives instructions from Perplexity’s servers on how to navigateAmazon.com. In other words, the Assistant cannot operate wholly independently; it relies on direction from the user and instructions from Perplexity’s servers."
> In other words, the Assistant cannot operate wholly independently; it relies on direction from the user and instructions from Perplexity’s servers.
Very interesting point of view. I wonder if people feel the same when it's not browsing Amazon but hacking other companies? These agents don't do anything by themselves, so wouldn't the same be true when it comes to breaking into 3rd party computer infrastructure?
> Amazon.com Services, LLC filed suit against Perplexity AI, Inc., an artificial intelligence company, asserting that Perplexity’s web browser tool, Comet, unlawfully accessed Amazon’s website in violation of the federal Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer Data Access and Fraud Act (CDAFA). Perplexity’s Comet browser includes an AI “Assistant” that, when activated by a user, navigates Amazon.com on the user’s behalf, sending browser screenshots to Perplexity’s servers for further instruction. Amazon claimed that this use of the Assistant, despite their explicit prohibition, amounted to unauthorized access to its servers.
My understanding of the case law on this subject is that courts are extremely wary of letting terms of service violations rise to the level of federal crime. It essentially endows anyone with a domain name into an authority which can create federal law on demand.
Yes, although the DoJ policy change reflecting still says civil liability might exist if a cease-and-desist is ignored: https://www.wsgr.com/en/insights/doj-acknowledges-limits-to-...
Might be the only way to reign in the AI bots. By accessing my site with a bot, you agree to reimburse me for that data at the rate of $1,000,000 per character retrieved. Please contact licensing@domain to get set up with payment and access keys
And by linking to your site from other websites, by not requiring authenticated human-only login, and by not blocking traffic from all referrers, you agree to allow my bot to access you site at zero cost.
But didn’t Amazon cite laws that it broke (allegedly)? Not simply their ToS?
[delayed]
FYI:
https://enwp.org/Van_Buren_v._United_States
https://enwp.org/HiQ_Labs_v._LinkedIn
Isn't this how every agent works these days? Apple and Google are working on tool calling for apps, but that's still going to be backstopped by screen scraping for years very likely.
It's a good bet that everybody's got equivalent CFAA boilerplate in their terms, so I guess all agentic automations are crimes now.
This is a civil case not a criminal one, and just because it is the same broad act does not mean courts apply it the same way in civil and criminal contexts.
And Amazon LOST at this stage in the linked appeal, with the 9th Circuit finding that they were not entitled to a preliminary injunction because they were unlikely to succeed on the “access” prong of the CFAA or CDAFA claim against Perplexity.
So, it is doubly weird to conclude “all agentic automations are crimes now” based on the case linked here.
Pattern I’m continually seeing.
User: I want to access what your business provides via AI.[1]
Business: I am not incentivized to do that. You should use our specific AI workflow and agents directly in our software.
User: That gives me a fraction of the value I get when AI has the full context for what I’m trying to do and talks to all the software and services I use.
I suspect this is an opportunity for previous also-ran companies to gain market share or new companies to break into markets.
[1] Usually something less stupid than AI buying something for someone, but to each their own.
Many systems are explicitly built around a certain level of friction. Things can be easy and transparent (but not *too* easy or transparent).
Agentic AI collapses that in ways that threaten existing business models, especially in retail (but also credit card points, discount retailers, mail in rebates and sales, cheap flights, etc).
Either it'll be forbidden, or businesses will have to adapt in ways that may not be favorable to Amazon, etc.
I remember when I (naively, but not alone) thought that the Personal Computer would let us--consumers, individuals--express our own agency and priorities and control, a kind of democratized capital mini-factory anyone (or group) could tailor to their own needs.
Nowadays it feels more like "Visitors shall think what our brain-stream tells you to think, or be guilty of contempt of business model."
Is there any important legal difference between what's happening here versus a bunch of friends running a "share and notice favorite deals" collective via plugin+server?
> express our own agency
ironically a local model and Playwright/OpenClaw is pretty close
If web scraping is legal then hitting the public api Amazon shouldn’t also be legal?
Funny that they aren’t targeting OpenAI and Anthropic’s computer use agents, which can do the exact same thing, and probably do it at a much larger scale given their userbases. The difference of course is that both OpenAI and Anthropic are hosted on AWS Bedrock, and Amazon is a huge investor in Anthropic to boot.
> and Amazon is a huge investor in Anthropic to boot.
Also: https://openai.com/index/amazon-partnership/
Amazon winning seems like it would have far-reaching effects, given that it is activated by a user.
this is a welcome ruling.
most of these search engine like companies including metasearch etc benefit from scrapping data on the onset, but then want to bring up TOS when they get scrapped.
in the age of agents - if your agent does work on your behalf on a particular site that should be legal.
This is over a month old, for anyone like me who was confused.
I wonder how this is going to affect everyone trying to make browsing / computer use agents? Is it just free reign now that ToS isn't violated according to courts?
I don't see why it should be a gray area for me to use my computer the way I want to use my computer.
Piggybacking on this - can HuggingFace sue OAI? Do they have legal ground to do that?
They absolutely could. There's a decent claim for OAI being reckless or at least negligent.
The limiting thing, in my mind, is the need to show harm. How much did OAI's recklessness hurt HuggingFace? There's some dev hours devoted to the cleanup but it's not like it devastated their business. Their legal team is probably a lot more focused on the Nvidia acquisition instead.
Would there also not be some reputational damages that could be compensated for as well? These are the types of cases usually ending in a settlement for non-disclosed amounts with NDAs attached.
> Would there also not be some reputational damages
In that case OpenAI should sue since they came out of this with a worse reputation.
I'd put my money on "yes," here. Of course, OAI can pay them off. But you know it had to happen to more than HuggingFace, and so somebody's going to try it.
Anyone can sue anybody. HF for sure was in a strong position after what happened. OAI gave them a lot of GPT credits under a sort of partnership agreement to mollify them.
Yes. And/or press charges, IIRC. They did threaten to, at one point, with some conditions they wanted met (past that, I am not in the loop).
Idk why this is even a lawsuit to begin with because HN commenters keep telling me that nobody wants to shop with an agent every time there is a demo about it from whatever AI company
So Amazon has shitty UI, doesn't want to improve it and then a company comes up with a solution to make life of shoppers easier, the Amazon throws a fit and goes to court? That's incredibly stupid.
It's just a harassment lawsuit. Amazon is going to lose, but they hope they could bully another company into what they want from them.
I read a post on Mastodon today about how Microsoft treated GPL things after Balmer was out and they were doing the “we love Linux” stuff.
The point that matters here is the law doesn’t really matter if you can outspend your opponent by six orders of magnitude. Chances are most people won’t even try.
So I agree. This is fully to prevent anyone from wanting to try.
(The point of the post was hell hard Microsoft was working to be seen as a good citizen even though they could outspend on lawyers)
https://infosec.exchange/@david_chisnall/117270213574377193
TL;DR Amazon is mad that Perplexity's agents can browse Amazon logged-in, with a username/password provided by the perplexity user.
Amazon argues this is against the CFAA because they do not authorize such use. They sued and got a preliminary injection. Perplexity appealed and got the injunction thrown out.
The case hasn't actually been to trial on the merits yet and is still undecided.
> Perplexity's agents can browse Amazon logged-in, with a username/password provided by the perplexity user.
Grok Bots can do the same.
what's next? suing Chrome because it logs in to amazon on my behalf after i give it my amazon credentials?
Well, publishers did once try using this law to sue adblockers.
But they lost, using an adblocker isn't a violation of the CFAA. They also tried a legal theory under the DMCA's anti-circumvention provision and lost again.
i was building an agent, local llm, that would access my browser and do whatever I tell it to do.
it's an extension of browser use cases, not a crime
Amazon services is just an LLC?
Remembering years ago when we lost $5MM of Bezo's money...
> Amazon.com Services, LLC filed suit against Perplexity AI, Inc., an artificial intelligence company, asserting that Perplexity’s web browser tool, Comet, unlawfully accessed Amazon’s website in violation of [blah]. Perplexity’s Comet browser includes an AI “Assistant” that, when activated by a user, navigates Amazon.com on the user’s behalf, sending browser screenshots to Perplexity’s servers for further instruction. Amazon claimed that this use of the Assistant, despite their explicit prohibition, amounted to unauthorized access to its servers.
TLDR: Perplexity agents allegedly ignored Amazon's robots.txt
robots.txt is a suggestion, not a rule. It's a service to crawlers to help them avoid wasting time. Using robots.txt as a security measure is like trying to stop a foreign invader with a "road closed" sign.
Edit: this is obviously assuming they literally meant robots.txt, but from a qyick skim of the site, it doesn't look like that was mentioned at least. I guess you meant it metaphorically :P
Why should they not? So does my browser when I ask it to open a website.
All right, which one of you is going to go through the trouble of explaining what this is about?
If you read the first couple paragraphs it’s very self explanatory
you dumbass the kind of person who reads only news titles and say dumb@$$ $hit.
then you will have missed the third para which reverses the decision from the first two para. jesus christ how many people on HN only read first paras
The summary at the top is 3 paragraphs and not legalese at all.
First para really does the job:
"Amazon.com Services, LLC filed suit against Perplexity AI, Inc., an artificial intelligence company, asserting that Perplexity’s web browser tool, Comet, unlawfully accessed Amazon’s website in violation of [blah]. Perplexity’s Comet browser includes an AI “Assistant” that, when activated by a user, navigates Amazon.com on the user’s behalf, sending browser screenshots to Perplexity’s servers for further instruction. Amazon claimed that this use of the Assistant, despite their explicit prohibition, amounted to unauthorized access to its servers."
no, it does not, you have to actually RTFA if you are going to try to TLDR a court proceeding. literally 3 paras down:
> the United States Court of Appeals for the Ninth Circuit vacated the preliminary injunction and remanded for further proceedings. The Ninth Circuit held that Amazon was unlikely to succeed on the merits of its claims because Perplexity did not “access” Amazon’s computers within the meaning of the CFAA or CDAFA; instead, the access was performed by the user employing the Assistant as a tool. The court found that the district court erred in its analysis of the equitable factors, which favored Perplexity, and concluded that an injunction was not warranted under these circumstances. The disposition was to vacate the injunction and remand.
perplexity won on appeal. if you stop at first para you are part of the problem
This could get pretty pedantic. They haven’t “won” yet, and the first few paragraphs do accurately describe the problem, but not the whole state of the case. The injunctions and appeals are very important, but they are details of the suit proceedings, not the case itself.
The first paragraph is enough for context.
The real case is in the future. The appeal was just for the injunction.