The San Francisco-based 9th U.S. Circuit Court of Appeals has dealt Amazon a significant legal setback by overturning a lower court's temporary ban on Perplexity's artificial intelligence shopping capabilities. The August decision represents a watershed moment in technology law, with implications stretching far beyond the immediate dispute between the two companies. At stake is the fundamental question of whether autonomous AI systems—tools that can browse websites, make purchases, and conduct transactions with minimal human intervention—enjoy the same legal rights to access online platforms as individual users do.
Amazon had launched its lawsuit against the San Francisco-based startup in November, alleging that Perplexity was covertly accessing customer accounts through Comet, its AI-powered browser agent, and was placing orders on behalf of users without proper authorization. The e-commerce giant framed the dispute as a security threat, arguing that Perplexity's system posed risks to customer privacy and that repeated requests to cease operations had gone unheeded. More provocatively, Perplexity countered that Amazon's legal challenge was essentially an attempt to preserve its advertising ecosystem by preventing AI agents from bypassing the visual advertising that dominates Amazon's shopping interface.
In March, a federal judge in California appeared to side with Amazon, issuing a preliminary injunction that blocked Perplexity from deploying its agentic AI on Amazon's platform. The judge determined that Amazon had presented sufficient evidence suggesting Perplexity violated the Computer Fraud and Abuse Act, a landmark US statute enacted in the 1980s to criminalize unauthorized computer access. That temporary ban seemed to herald a restrictive approach to AI's relationship with established online platforms. However, the 9th Circuit's reversal demonstrates that the legal landscape governing AI agency remains unsettled and contested.
The appeals court's reasoning hinged on a subtle but consequential distinction. When Perplexity's AI agents accessed Amazon's website to retrieve information or execute transactions, the court ruled, it was fundamentally the end-user who was "accessing" the platform within the meaning of the Computer Fraud and Abuse Act, not Perplexity itself. This interpretation aligns agentic AI systems with traditional user-agent tools—browsers, mobile apps, automated scrapers—by treating them as digital extensions of the human choices they execute. The ruling implies that as long as a user has authorized their AI agent to act on their behalf, the legal responsibility for access resides with the user rather than the AI provider.
For Malaysia and the Southeast Asian region, this decision carries profound implications as AI adoption accelerates throughout the region's digital economy. E-commerce platforms like Lazada and Shopee, which dominate regional online retail, may find themselves navigating similar legal and technical challenges as agentic AI tools become more sophisticated and prevalent. The US ruling suggests that platforms cannot simply prohibit AI agents from accessing their services merely because those agents operate without human eyeballs perceiving the interface. Instead, restrictions would need to be grounded in more substantial claims—actual security breaches, unauthorized account access, or violations of terms of service.
Amazon's statement signaled reluctance to accept defeat, with company representatives insisting they remain "confident in our case" and are "evaluating next steps." This leaves open the possibility of further appeals, legislative action, or settlement negotiations. The company's determination to fight reflects the broader stakes involved: if agentic AI systems become widely accepted as legitimate users of e-commerce platforms, the advertising revenue models that underpin many major online retailers could face significant disruption. Perplexity's pointed observation that Amazon's advertising becomes invisible to non-human agents strikes at the heart of platform economics.
Perplexity characterized the ruling as vindication of user choice and internet freedom. Company spokesperson Jesse Dwyer emphasized that the decision protects "the right of internet users to choose whatever AI they want," framing the dispute in terms of consumer autonomy rather than technological rights. This rhetorical positioning is strategically important because it appeals to broader anxieties about corporate gatekeeping and monopolistic control of digital services. As agentic AI tools proliferate, users may increasingly expect the ability to deploy autonomous agents to manage their online shopping, research, and other digital activities without interference from platforms seeking to preserve their own business models.
The ruling's significance extends beyond the immediate parties involved. It establishes the first federal appeals court precedent addressing how the Computer Fraud and Abuse Act applies to agentic AI systems, providing crucial guidance for both technology companies and platform operators. As more sophisticated AI agents enter the market—capable of autonomous decision-making, reasoning about complex problems, and executing multi-step transactions—legal clarity about their status becomes increasingly vital. Companies developing these tools need to understand the regulatory environment they operate within; platforms need to know what restrictions they can legitimately impose.
The broader agentic AI ecosystem encompasses tools far beyond shopping agents. These systems can conduct research, manage schedules, monitor information feeds, negotiate prices, and perform countless other functions across the open internet. A permissive legal interpretation of user-authorized AI access could unleash dramatic changes to how platforms operate and how users interact with digital services. Conversely, an overly restrictive approach might stifle innovation and limit consumer choice. The 9th Circuit's decision leans toward permissiveness, at least within the bounds of the Computer Fraud and Abuse Act.
For Malaysian technology companies and investors watching these developments, the implications are significant. The region's growing AI capabilities and ambitions to become a regional tech hub depend partly on clarity about which applications are legally viable. If US courts establish that agentic AI can legally access major platforms under certain conditions, this likely encourages investment in agentic AI startups throughout Southeast Asia. Conversely, if platforms successfully restrict AI access through updated terms of service or tailored legal theories, development of these tools may slow. The ruling thus shapes not just a single dispute but the entire trajectory of agentic AI commercialization globally.
Amazon may pursue additional legal remedies, but the 9th Circuit's decision suggests that relying on the Computer Fraud and Abuse Act alone will prove insufficient to block user-authorized AI access. The company might instead pursue claims centered on breach of contract, violations of specific terms of service, or intellectual property infringement—arguments that would need to be tailored to particular circumstances rather than relying on blanket prohibitions against all agentic AI. This shift in legal strategy would likely produce outcomes more favorable to AI developers, provided they respect reasonable platform restrictions and obtain user authorization for their activities.
As agentic AI technologies mature and become more capable, the legal framework governing their operation will evolve through cases like this one. The 9th Circuit's ruling establishes that the default position in federal appellate law is one of permission rather than prohibition, at least absent clear statutory violations or contractual breaches. This positioning reflects a judicial recognition that attempting to exclude agentic AI entirely from online platforms may be neither feasible nor desirable in an era when autonomous agents are becoming routine business tools. The decision effectively places the burden on platforms to articulate specific harms or contractual violations rather than relying on general access restrictions.
