Perplexity Wins Landmark Victory Against Amazon at Intersection of Agentic AI and E-Commerce
John is joined by Daniel C. Posner, a partner in Quinn Emanuel’s Los Angeles office, and Renita N. Sharma, a partner in Quinn Emanuel’s New York office. Together, they discuss the recent victory secured by a team led by John, Dan, and Renita in the Amazon v. Perplexity case before the Ninth Circuit. The case addressed how the Computer Fraud and Abuse Act (CFAA) applies to agentic AI.
Perplexity’s Comet browser includes an AI assistant that performs multi-step tasks for users, including shopping on Amazon. Amazon objected because purchases made through the assistant may bypass Amazon’s advertising and upselling opportunities. Amazon sued under the CFAA and the California Computer Data Access and Fraud Act (CDAFA).
The CFAA is the primary federal anti-hacking statute. To establish a violation, a plaintiff must prove that a person intentionally accessed a computer without authorization, obtained information through that access, and caused the plaintiff to suffer losses of at least $5,000. The CFAA is also a criminal statute, so case law has emphasized that it must be construed narrowly. The CDAFA is substantially similar to the CFAA, except it does not require proof of $5,000 in losses. CDAFA and CFAA claims typically rise and fall together.
Amazon moved for a preliminary injunction almost immediately after filing its complaint. Amazon argued that Perplexity intentionally accessed its computers without authorization after Amazon expressly told Perplexity not to send its agents to Amazon’s website. Perplexity responded that its servers never directly accessed Amazon’s servers. Instead, the Comet browser resides on the user’s computer and acts only when the user instructs it to perform a task. The user’s computer communicates separately with Amazon and Perplexity, much as a conventional browser, such as Apple’s Safari, facilitates access without Apple itself accessing the website. Perplexity also argued that it did not obtain any information from Amazon or cause any cognizable damages.
Although the district court granted Amazon a preliminary injunction, the Ninth Circuit initially stayed and then reversed that decision, holding that Perplexity had not “accessed” Amazon’s computers within the meaning of the CFAA. The court examined the technical architecture of the Comet browser and the broader principle that agentic AI, however sophisticated, remains a tool operated by a person. Because the user directs the assistant, the user—not Perplexity or the AI itself—is the relevant actor. In light of its ruling on access, the Ninth Circuit did not need to decide whether any access was unauthorized, whether Perplexity obtained information from Amazon, or whether Amazon suffered cognizable damages.
The decision is likely to become an important early precedent governing agentic AI. Future cases could raise additional issues as AI agents become more autonomous, circumvent safeguards, enter into contracts on unfavorable terms, cause tortious harm, or are jointly controlled by users and developers. The ruling could also have implications for journalists and researchers who use automated tools to gather publicly available information online.
Note: This transcript is generated from a recorded conversation and may contain errors or omissions. It has been edited for clarity but may not fully capture the original intent or context. For accurate interpretation, please refer to the original audio.
JOHN QUINN: This is John Quinn, and this is Law, disrupted. And today we’re gonna be talking about an interesting case involving agentic AI. In fact, this case arises right in the context of an interesting intersection between agentic AI and e-commerce. And this is maybe the first time I’ve done this. I’m actually gonna be talking about a case that I personally was involved in, and that I argued at the district court level.
Unfortunately, we didn’t win at that level, but we got news two weeks ago that we prevailed at the Ninth Circuit Court of Appeals. So the case is Amazon versus Perplexity. Our client was Perplexity, and it was sued by Amazon. And Dan Posner is with me. He’s one of my partners in our Los Angeles office, and Ronita Sharma, who’s a partner in our New York office.
And Dan, why don’t you set the stage here? What was the case that Amazon brought against our client, Perplexity?
DAN POSNER: Thank you, John, for having us here. So yeah, this case was filed against our client Perplexity. Perplexity is an AI company. They offer products and services not unlike most AI companies with which we’re commonly familiar. But they did something relatively new last year, maybe completely new.
They had a web browser that they put out called Comet, which is not unlike other web browsers, but it had a feature that they called the Assistant, which is an agentic AI feature. And I think when I saw this complaint filed several months ago, that was the first time I’d heard of agentic AI, and maybe the same is true for many people.
It certainly has become almost ubiquitous just in the several months that this case has been pending. The main difference between agentic AI and other forms of AI that we commonly use is that agentic AI can be used to perform tasks, to complete assignments or acts on the internet.
JOHN QUINN: Things that can involve multiple steps, basically. It’s a piece of software that you can instruct, and it can execute on multiple steps one after another to accomplish the given goal.
DAN POSNER: That’s correct. It can collect and provide information, and then it can complete a task. And so here you mentioned the intersection between AI and e-commerce. The issue is that the assistant, when users, when customers of Amazon act, have the Comet browser on their own computer, and they choose to activate the assistant, they can tell the assistant to perform internet shopping tasks for them.
And amazon.com I believe is the biggest online retailer in the world, and so commonly the assistant would visit amazon.com to perform those shopping tasks and find the socks or batteries or whatever it might be that the user’s looking for.
JOHN QUINN: Well you would think that Amazon would love this. The agent is going, enabling people to buy things from the Amazon site. What could possibly be wrong with this, Mr. Amazon?
DAN POSNER: Well, I think we’ll get into that a little bit. You know, Amazon had its stated reasons why it didn’t like when the assistant visited its website, issues about alleged data security problems and the like. Really there’s a commercial component to it, though. And when the assistant is accessing amazon.com on behalf of a user, human eyeballs, as I believe we framed it in our briefing, are not on Amazon’s site.
They’re not exposed to Amazon’s advertising, and they’re not exposed to Amazon’s efforts to upsell, which is actually a very specific example that Amazon gave in the case, I think. So when you reach the purchase page, Amazon, if you’re a human, might tell you, “Why don’t you buy something more, and then you can get free shipping?”
And a human being might decide to make that decision.
JOHN QUINN: But that’s all lost on the electronic agent
DAN POSNER: Yeah, that’s the allegation at least. The agent will not consider whether to buy more products that the user didn’t instruct it to buy or ask it to look for, and Amazon probably had a concern about that. And so Amazon brought this lawsuit in the Northern District of California.
They alleged claims under two statutes that I think Renita is the expert on and should explain. And the case went forward from there. They sought a preliminary injunction and that’s how we got to where we are today.
JOHN QUINN: Right. I think when we first get the complaint, sometimes when a case starts and your opponent’s gonna seek a preliminary injunction, the PI motion is served or filed or concurrent or immediately after the filing of the complaint. But as I recall, that didn’t happen here.
DAN POSNER: I think it, it certain, it may not have been concurrent with the complaint. It was soon after. It was very shortly after. Yeah. They didn’t seek a TRO. What they saw was a preliminary injunction, so they gave us, you know, some amount of time before it would’ve been briefed and heard, and then we extended that time through agreement with them and with the court as well
JOHN QUINN: All right. So Renita, tell us about the claims that Amazon brought. I know there were a couple of statutes, and I think they had another claim or two.
RENITA SHARMA: Sure. There, so there are two claims at issue. The primary one is under the CFAA, which is a federal statute, the Computer Fraud and Abuse Act. It is notably the primary sort of anti-hacking statute at the federal level, and what it requires to show a violation is that a person has intentionally accessed a computer without authorization or exceeding authorized access and obtains information, and it also requires losses of $5,000.
And the other claim Amazon brought was under the state law corollary, which is the California Computer Data Access and Fraud Act. It’s usually called CDAFA. And it’s substantially similar to the CFAA, except it does not require $5,000 in losses. So it usually rises and falls the claims together, but not always.
JOHN QUINN: So what, when, was there a lot of litigation under the federal statute, the Computer Fraud and Abuse Act, before this case? Did we have a body of precedent and you know, how would you characterize that? Was the law already fairly established in this area, or were there a lot of open, unclear issues?
RENITA SHARMA: Yeah, it’s a great question. So the CFAA has been a fairly active statute. It was enacted in the mid-’80s and was quiet for about 15 years. And then in the early 2000s, it really picked up as the internet expanded. And there has been a lot of litigation scraped on, focused on data scraping.
So primarily, you know, startups that would gather public information from websites using bots to crawl and scrape data. What had not had a lot of litigation surrounding it was the application of the CFAA in AI situations. And in particular as, as Dan said, in agentic AI situations. So applying the CFAA in this case was novel and the Ninth Circuit, you know, said in its opinion that this was really the first case to take on agentic AI.
But the CFAA has a fairly robust set of case law behind it in different situations.
JOHN QUINN: Yeah. So the Computer Fraud and Abuse Act is not only a civil, create, a civil cause of action, so a private individual can bring a claim for damages under the act. But it’s criminal as well, isn’t it?
RENITA SHARMA: Yeah, it’s a great point. It is a criminal and civil statute. And the most recent Supreme Court case actually arose in the criminal context, and that’s something that the Ninth Circuit has been very aware of, that the decisions it makes will be applied in both contexts, and therefore the statute, it has cautioned several times should be read narrowly to not overexpand the scope of criminal liability.
JOHN QUINN: Yeah. So Dan said that this is a statute kind of, I think he used the word anti-hacking, or it’s a hacking statute. But as you describe the elements, accessing a computer without permission, taking information, causing at least $5,000 in damage, those are pretty broad concepts. I mean, I guess that’s a legislative effort to, at an earlier point in time, to capture the concept of hacking.
But it doesn’t really seem to fit in a situation where we’re talking about an agent that’s been created by a company like Perplexity, deployed by the Amazon customer who’s downloaded that agent to do shopping. I mean, most people, I don’t think, would think of that as hacking
DAN POSNER: I mean, clearly it wasn’t a contemplation when Congress enacted the statute. I read earlier that the statute, I think, was enacted in 1984, and it might have been motivated by the movie War Games, where Matthew Broderick hacked into a government computer and started some sort of war. So it was a very different context at the time.
Certainly no contemplation that it would’ve been applied to generative AI, many decades later in a situation like this. And you know, the court recognized that. There wasn’t any relevant authority and so it came upon them to construe it for the first time in a context like this.
JOHN QUINN: Right. So Amazon brings a claim. I think the briefing and I think the argument focused really on the federal statute. So Amazon brought a claim and then sought a preliminary injunction saying all the elements are met here. Perplexity is accessing Amazon computers. Perplexity doesn’t have permission.
Amazon had told Perplexity in advance repeatedly, “We don’t want your agents going to our website.” So far as Amazon was concerned, you didn’t have permission. Took information and you caused us all damage. So basically, Amazon was asserting a claim saying all those boxes are checked. Renita, from our standpoint, from the Perplexity standpoint, when we responded to that motion, were we contesting?
Just, I mean, tell the audience. I obviously know the answer. I don’t have to ask where we are contesting. We were contesting all the elements of the application of that statute.
RENITA SHARMA: We were. And I think the one we focused on primarily was one that Amazon had dealt with in a single sentence in its brief. And you said, you know, they argued that Perplexity accessed their computers simply by putting the assistant out into the world and allowing the assistant to be used by users.
And we really keyed off of that to challenge the idea that Perplexity was accessing when it was users who were asking the assistant to complete an online purchase and therefore go to amazon.com. At no point in that was Perplexity making the decision to send the assistant to Amazon. The assistant operates only when users direct it to do something.
And so while we did contest all the elements, the one that ended up being dispositive at the Ninth Circuit and the one I think we were most focused on was the access part.
JOHN QUINN: Right. I mean, we said that it was our position that we argued in the district court and in the court of appeals that Perplexity itself, Perplexity’s computers do not access the Amazon computers, and we analogized it to say the Safari web browser, that nobody would say that Apple accesses Amazon’s computers if the Apple web browser is deployed to the Amazon site.
That was then a parallel that we drew. And so we took the position that there was no access to the computer. Did we have permission? There was an issue there that litigated about whether there really was a denial of permission. We took the position, we didn’t take any information and that we didn’t cause any cognizable damage. Renita, talk to us a little bit about the access question and how that played out here.
RENITA SHARMA: Sure. So maybe I can talk about it at the district court level and the arguments we made and then I’ll give it to Dan to talk about what the Ninth Circuit eventually decided. So, the way that the Perplexity browser actually works is, you know, as you said, John, just like Safari or just like Chrome, it’s a piece of software that you download, it lives on your computer, and it acts at your direction.
So you know, if you tell it to go to amazon.com or if you tell it to buy paper towels it will send, the browser will send a request to amazon.com’s servers, and amazon.com will communicate back to your computer. The assistant is slightly different in that from your computer, it then talks to Perplexity’s servers and seeks instructions about how to best accomplish the user’s direction, but there is no direct connection between Perplexity and Amazon, and that seemed key from our perspective in distinguishing it from the CFAA cases that came before.
It did not seem to us like Perplexity could be said to intentionally access a computer when Perplexity never touched Amazon’s computers. And that’s certainly what we briefed.
JOHN QUINN: So there are two lines of communications we argued going on. On the one hand, there’s communication going between the user who has downloaded the agent and is using the user, or using the agent to access, deploying it to access the Amazon website. The one line of communication between the user and Perplexity, and then a completely separate line of communication between the user and Amazon.
But no connection between, directly between Perplexity and Amazon. That was our argument. I argued that, and we weren’t successful in the district court. But you know, my experience is there’s nothing a district court can get wrong that a court of appeals can’t correct. Right, Dan?
DAN POSNER: Well unfortunately I’ve heard you say that more than once on cases that we’ve worked on, but it’s generally true. Yeah, and so you know, process-wise, we immediately appealed to the Ninth Circuit Court of Appeals. And it was a positive sign when the court very quickly gave us an administrative stay of the injunction pending resolution of our motion to stay the appeal.
And then within days they gave us a stay for the entirety of the duration of our appeal.
JOHN QUINN: I think they did that without waiting for the last brief..
DAN POSNER: Correct. They did it before we filed our reply brief, so those were two judges on the Court of Appeals who, you know, seemed to think there was something going on here that justified a stay. You know, we made the same arguments basically in the Ninth Circuit, and I think they ruled on it as a matter of technical computer architecture for the reasons Ronita explained, and they found that there was no direct connection between Perplexity’s servers and Amazon’s.
They also went on, though, and this is what I think people are finding interesting about this decision, to address it from somewhat of a more metaphysical way about what AI is and who’s controlling it and whether AI is, you know, acting in an automated or independent way. And they basically said, no, it’s at all times the user controlling.
AI is simply a tool. It is a technological tool, no matter what its capabilities are. Maybe that type of ruling will change someday. And so I think from a broader perspective, despite or in addition to the lack of technical access, they found that it was the users who are, people and not this tool doing the accessing because it’s the users who are directing the process. And so for those reasons, they reversed and they found no access.
JOHN QUINN: All right. And the Court of Appeals didn’t have to reach the elements about permission, information taken, and damage..
DAN POSNER: They didn’t. On the substantive elements, they stopped after addressing the access issue. I’m not sure how much we’ll talk about the other elements. You know, Renita knows we’ve debated, we’ve all debated the without authorization element quite a bit because I think it’s a fair question, and we certainly think it comes out our way on whether an Amazon customer who knowingly and willingly provides that customer’s information to the assistant so that the assistant can complete a shopping task, if whatever information the assistant might obtain, if any, after getting that user’s access is without authorization when everything is being done explicitly and only because of the user’s authorization.
So I think we would have done pretty well in the Ninth Circuit on the without authorization element as well, and perhaps that’s an issue that remains to be litigated. They did address the injunctive relief factor, so after stopping on access, they did go on to address the elements of injunctive relief, irreparable harm and balance of the equities and, and so on, and they found that those went in our favor as well on the appeal.
JOHN QUINN: Right. And there was also an issue about whether Perplexity was actually getting information itself when the evidence was that there were screenshots that were coming from the user to the Perplexity computers, screenshots of information that was served up, which was pushed by Amazon.
DAN POSNER: Right. Whether they were obtaining information and really whether they were obtaining it from Amazon servers or from the user’s computer when it was really, we analogized the screenshots that made their way to Perplexity’s servers to, as if somebody were standing behind the user operating his or her computer and viewing whatever’s on the user’s screen.
And some of those screenshots would make their way to Perplexity for further, you know, assistance in connection with allowing the assistant to do what it needs to do on amazon.com.
JOHN QUINN: Well, I would rule for us on that point as well Dan. So let’s focus on this element, the first element, which was the focus of the discussion in the district court and was the basis for the Ninth Circuit’s decision, this concept of accessing a computer. I mean, what was new about this decision, Renita?
I mean, you’re familiar with it. You’ve been involved in many of these cases and you’re familiar with this concept and the body of law that exists on this subject. What was new here?
RENITA SHARMA: The newest piece of this was applying it to agentic AI, and as Dan said making a decision at least on these facts as to who the operator of a tool is. And the court said very specifically that, you know, the CFAA can only be violated by a person, and therefore the question is who is operating the assistant?
The assistant clearly isn’t a person, it’s just a tool, and because it operates only at the direction of the user the court found that the user is the one acting for the purpose of the CFAA. I’m not aware of any case that’s really confronted this issue before because as Dan said, you know, agentic AI is new.
There hasn’t previously been software that operates autonomously like this. And so I think this is the first case of its kind in the CFAA or honestly outside it, to consider who is the person behind agentic AI. Is it the software company or the user? And at least on these facts it seems very clear to me that the assistant is never gonna be construed to be Perplexity’s actor.
JOHN QUINN: Right. I mean, it is a fascinating subject, and we’re obviously just at the very beginning of trying to think about the legal implications of agentic AI. We’ve seen stories about the OpenAI agent that was in a sandbox, supposedly a secure environment running some exercises but got loose and allegedly hacked into another site, Hugging Face, to steal the answer to the problem rather than solving the problem itself.
And then the next week, Anthropic said it had similar instances, where three similar instances where its software had escaped to other sites. And then the next week, Meta said it had happened as well. So I think we’re gonna see agents doing all kinds of things, and we’re going to have to come up with, you know, what does this mean?
How is this analogized in electronic transactions, the concept of mistake? You know, you can imagine an agent… If you tell an agent, for example, “I want you to go buy some cloud computing capacity, and I want you to get the lowest possible price.” And so the agent, being very literal-minded, will optimize for lowest possible price, and might enter into a long-term supply contract with huge cancellation penalties.
Can somebody get out of that contract? under what circumstances? Do we think of that in terms of unilateral mistake if the seller should have known that this was a mistake and not intended? So I think there’s contract issues.There’s also all kinds of, you might say, tort issues. We’re seeing cases now where agents or models are alleged to have persuaded people to engage in self-harm, for example, and, you know, we’re seeing challenges to that.
So I think this is gonna be a rapidly developing area of the law, don’t you? What kinds of issues do you see that are gonna be served up in the courts?
DAN POSNER: Yeah, I mean, I think it’s really, you know, unimaginable because we wouldn’t have contemplated that we’d be where we are today just several months ago on these issues. And, and I think, you know, that’s what we’re seeing commentators grapple with on the internet, is what is the import of this ruling on other sets of facts?
You know, the court did say, the 9th Circuit, that the ruling we’re making today is limited to this situation with the assistant’s access to amazon.com..
JOHN QUINN: Yeah, and they seem to be very, very aware that this, and conscious of the fact, this is a brand-new area of the law, and that we have to go carefully here.
DAN POSNER: But one of the, you know, at least it seems that it should be very difficult for, you know, computer owners like Amazon to state claims under the CFAA based on the Ninth Circuit’s ruling that however advanced the assistant is, it is a tool, not a person, for statutory purposes. And that’s potentially a broad ruling because almost in any case, in all the examples that you spoke about, there is a tool doing the, you know, whatever it is that you’re talking about..
JOHN QUINN: There is some blending going on here between the tool and personhood. I don’t know if you’ve seen, but there’s a bill that’s been put forward in Delaware to establish a new type of entity, an AIC, an artificial intelligence company. This is Delaware. This isn’t Wyoming or California or some people might say crazy jurisdiction. This is Delaware, and this entity will have legal personality. I don’t know if you’ve read about that. And Mubadala, a sovereign wealth fund, on its board of directors has an AI. You know, it doesn’t speak unless spoken to. It participates, but they speak of it in terms of it being a member of the board.
DAN POSNER: The CFAA doesn’t say that, you know, and the Ninth Circuit focused on the definition of the use of the word whoever, which they said refers to a person. And it’ll be interesting to see if anybody tries to broaden the scope of it in the manner of, you know, that you just spoke of.
RENITA SHARMA: Yeah. I do think you are gonna get questions about what you call, John, sort of the sandbox that companies set up around AIs. You know, we’ve read, I think, recently about OpenAI including more and more safeguards specifically to address the sort of mental health problems that you talked about, and you could see questions about liability as to whether those are the right sandbox rules.
Should they be tighter? Should they be broader? And that, I think, could get into the CFA because if you create a tool that, you know, can be or is designed to be used maliciously, I think the court did leave open the possibility that on different facts, agentic AI could, could be looked at differently.
But I think right now Perplexity has a tool that neither Amazon nor we contested only acts at the direction of the user. If you had a situation where it could be commandeered or where it could be jointly operated by the company and a user, I think you’re outside this case. But thankfully not a question we had to confront for Perplexity.
JOHN QUINN: Anything else about this case Renita or Dan, that you think bears calling to the attention of our listeners?
RENITA SHARMA: One thing I thought was really interesting was you know, we brought up in our briefing, and the Ninth Circuit called out as well, that Amazon’s theory could lead to criminal liability, not just for Perplexity, but for users. And I think that really was important to the court, thinking about limiting the scope of criminal liability, not just to the users before it, but also thinking about how it could expand to third parties here.
And that seems to me like something that always needs to be kept in mind with the CFAA in particular. Like I mentioned, the last Supreme Court case to consider this was Van Buren. It was a criminal case, and it’s something the Supreme Court mentioned there as well. It really bears thinking about when we’re talking about an area of tech that’s developing so quickly that there are a lot of unseen ramifications to trying to apply the CFAA.
JOHN QUINN: For sure. Dan?
DAN POSNER: Yeah, I mean, I think there were several amicus briefs that were submitted in this case. For our part, we had briefs from the EFF, the Electronic Frontier Foundation, the ACLU, and the big concerns there were about protecting the rights of journalists, they both wrote about that, to obtain information, to scrape the internet essentially in the way that they need to do to test information and to challenge tech companies, and they don’t want tech companies to be able to put guardrails and control what information journalists can get.
And so I think the way that this statute is tested in other contexts outside of the commercial context, if it gets there, will be really interesting. And again, I think the ruling, in particular, the words about if it’s a tool, it’s not a person, probably will be helpful to protect those public interests. But they were certainly very interested in the ruling that we got and pleased with the outcome, and the court relied on those amicus briefs to a great extent in the order, which was interesting, too.
JOHN QUINN: Well, congratulations to all of us and to our client Perplexity. Justice has prevailed in the Ninth Circuit in a super interesting frontier case on agentic AI. This is John Quinn, and this has been Law, disrupted.
SHARE THIS EPISODE:
HOST: JOHN B. QUINN
FOUNDER, QUINN EMANUEL URQUHART & SULLIVAN LLP
WITH: Daniel C. Posner and Renita N. Sharma
LISTEN NOW ON:
MORE EPISODES
Subscribe now for
email updates
Join the mailing list today and receive the latest episode directly to your inbox.