The 9th U.S. Circuit Court of Appeals in San Francisco delivered a significant defeat to Amazon on Tuesday by striking down a temporary ban preventing Perplexity from deploying its artificial intelligence agents to shop on Amazon's platform. The decision represents the first major federal appellate ruling to grapple with the legality of AI agents acting autonomously on behalf of users accessing online services, a question that carries far-reaching consequences for the rapidly evolving sector of agentic AI tools capable of browsing, purchasing and conducting transactions across the internet.

Amazon initiated its legal challenge against the San Francisco-based AI startup in November, alleging that Perplexity had been surreptitiously gaining access to customer accounts through its Comet browser and associated AI agent technology. The company contended that these systems, which can authenticate into users' shopping accounts and execute purchases without direct human intervention, posed material security threats and that Perplexity had disregarded multiple cease-and-desist requests. This case thrust into the courtroom a tension that has been simmering in the technology sector: whether autonomous AI systems operate within existing legal frameworks designed for human conduct, or whether they require entirely new regulatory approaches.

Perplexity's counter-argument hinged on a fundamentally different interpretation of how the technology functioned. The startup maintained that its systems did not independently breach Amazon's defences or violate federal computer fraud statutes because it was ultimately the users themselves—utilising Perplexity's AI agents—who were accessing the platform. This distinction proved pivotal to the appeals court's analysis. Perplexity further reframed Amazon's motivations, suggesting the lawsuit represented a transparent attempt to prevent users from deploying AI tools that could navigate Amazon's interface without being subjected to what Perplexity characterised as Amazon's intrusive advertising ecosystem.

In March, a federal judge in California had initially sided with Amazon's position, issuing a temporary injunction after determining that the company had presented substantial evidence that Perplexity's system violated the Computer Fraud and Abuse Act. That decision appeared to signal judicial concern about unauthorised access and AI systems operating beyond the boundaries of explicit consent. However, the appellate panel reversed course this week, finding fault with the lower court's application of the statute to this novel technological scenario. The three-judge panel determined that the relevant legal prohibition—which targets individuals who access computers and extract information without authorisation—applied to Perplexity's users rather than to Perplexity itself, since the users remained in control of the underlying instruction and authentication process.

The ruling carries profound implications for the architecture of emerging AI technologies and how courts will interpret traditional computer crime legislation in light of agent-based systems. If users themselves maintain agency over what actions they authorise their AI tools to perform, the court's logic suggests that intermediate platforms cannot be held liable for the downstream activities of those agents. This principle aligns somewhat with how courts have historically treated proxies and intermediaries, yet introduces novel complications when the intermediary is a sophisticated machine learning system rather than a human representative. The decision thus establishes a framework—at least within the 9th Circuit's jurisdiction, which covers much of the western United States—that tilts considerably toward permitting such agentic technologies provided that user agency remains central to their operation.

Amazon responded to the defeat with measured language, stating through a company representative that it remained confident in the underlying merits of its case and was deliberating on subsequent legal strategies. The company faces a choice of whether to appeal further, potentially seeking review before the full circuit panel or the U.S. Supreme Court, or to pivot toward alternative enforcement mechanisms such as enhanced technical barriers or more aggressive terms-of-service enforcement. The decision also complicates Amazon's broader technology strategy at a moment when the company itself is investing heavily in AI capabilities and considering how to integrate automated systems into its own operations.

Perplexity, meanwhile, characterised the decision as vindication of a principle that end users should retain freedom in selecting their preferred AI tools. The company's spokesperson framed the dispute not merely as a legal matter but as a fundamental question about user autonomy in an era of intelligent assistants. This rhetorical positioning reflects how agentic AI tools have become entangled with broader debates about corporate power, data privacy, and whether technology platforms should have gatekeeping authority over what third-party services can integrate with their ecosystems. For Perplexity, the ruling legitimises its business model and potentially opens pathways to similar integrations with other major e-commerce and service platforms.

The broader ramifications extend well beyond the immediate commercial rivalry between these two companies. Agentic AI systems represent a distinct paradigm shift from earlier generations of AI assistants, as they can engage in planning, reasoning, and executing multi-step tasks with minimal human supervision during execution. Banks, healthcare providers, government agencies, and countless other institutions operate platforms that contain sensitive information. If agentic AI systems can legally access these platforms provided that users maintain nominal control over instructions, the implications for cybersecurity, fraud prevention, and identity verification become substantial. Organisations may need to fundamentally reconsider how they authenticate users and constrain what activities authenticated parties can perform.

For Malaysian technology companies and regulators, this precedent carries instructional value as the region develops its own artificial intelligence governance frameworks. Southeast Asian economies are increasingly positions as destinations for AI innovation and adoption, yet the legal infrastructure governing agentic AI remains nascent. The 9th Circuit's interpretation suggests that courts in common-law jurisdictions may be inclined toward permitting autonomous agent access if user agency is preserved, rather than adopting blanket prohibitions. However, this approach may create blind spots around scenarios where users are manipulated, deceived, or inadequately informed about what their AI agents are actually executing on their behalf.

The decision also raises questions about intellectual property and competitive dynamics. By permitting Perplexity's AI agents to access Amazon's platform and extract product information, prices, reviews, and purchasing patterns, the court has implicitly endorsed a form of automated data collection that Amazon had sought to constrain. The distinction between authorised browsing and unauthorised scraping becomes murkier when an AI agent intermediate is involved. This murkiness could incentivise companies to deploy increasingly sophisticated technological barriers rather than relying on legal prohibitions, potentially fragmenting the internet into walled gardens that respond differently to automated access depending on the specific tools and techniques employed.

Moving forward, the software engineering implications warrant close attention. Agentic AI systems must be designed with transparency and accountability mechanisms that allow users to understand exactly what actions their AI is authorising on their behalf. Whether current implementations of tools like Perplexity's Comet meet this standard remains contested, but the legal framework established by the 9th Circuit provides strong incentives for developers to prioritise user visibility and control. Companies offering such tools may seek to differentiate themselves through robust logging, user review of pending actions, and granular permission controls that exceed minimum legal requirements.

The Amazon versus Perplexity case will likely be examined in law schools, corporate boardrooms, and regulatory agencies as a foundational example of how traditional legal categories are being stretched and reinterpreted in response to artificial intelligence capabilities. It is probably not the final word on the subject—the Computer Fraud and Abuse Act remains vaguely worded regarding scenarios involving sophisticated intermediaries and delegated action—but it represents a significant moment in which the judiciary rejected the intuition that autonomous systems operating on commercial platforms constitute inherent legal violations. Whether this remains good law, and how it applies to agentic systems beyond shopping and browsing, will likely occupy courts and policymakers for years to come.