> Amazon.com Services, LLC filed suit against Perplexity AI, Inc., an artificial intelligence company, asserting that Perplexity’s web browser tool, Comet, unlawfully accessed Amazon’s website in violation of the federal Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer Data Access and Fraud Act (CDAFA). Perplexity’s Comet browser includes an AI “Assistant” that, when activated by a user, navigates Amazon.com on the user’s behalf, sending browser screenshots to Perplexity’s servers for further instruction. Amazon claimed that this use of the Assistant, despite their explicit prohibition, amounted to unauthorized access to its servers.
My understanding of the case law on this subject is that courts are extremely wary of letting terms of service violations rise to the level of federal crime. It essentially endows anyone with a domain name into an authority which can create federal law on demand.
Illinois makes it a state crime to violate terms of service.
Sec. 17-51. Computer tampering.
(a) A person commits computer tampering when he or she knowingly and without the authorization of a computer's owner or in excess of the authority granted to him or her:
(1) Accesses or causes to be accessed a computer or
any part thereof, a computer network, or a program or data;
(2) Accesses or causes to be accessed a computer or
any part thereof, a computer network, or a program or data, and obtains data or services;
(a-10) For purposes of subsection (a), accessing a computer network is deemed to be with the authorization of a computer's owner if:
(2) the owner authorizes the public to access the
computer network and the person accessing the computer network complies with all terms or conditions for use of the computer network that are imposed by the owner;
Isn't this how every agent works these days? Apple and Google are working on tool calling for apps, but that's still going to be backstopped by screen scraping for years very likely.
It's a good bet that everybody's got equivalent CFAA boilerplate in their terms, so I guess all agentic automations are crimes now.
This is a civil case not a criminal one, and just because it is the same broad act does not mean courts apply it the same way in civil and criminal contexts.
And Amazon LOST at this stage in the linked appeal, with the 9th Circuit finding that they were not entitled to a preliminary injunction because they were unlikely to succeed on the “access” prong of the CFAA or CDAFA claim against Perplexity.
So, it is doubly weird to conclude “all agentic automations are crimes now” based on the case linked here.
robots.txt is a suggestion, not a rule. It's a service to crawlers to help them avoid wasting time. Using robots.txt as a security measure is like trying to stop a foreign invader with a "road closed" sign.
Edit: this is obviously assuming they literally meant robots.txt, but from a qyick skim of the site, it doesn't look like that was mentioned at least. I guess you meant it metaphorically :P
> Amazon.com Services, LLC filed suit against Perplexity AI, Inc., an artificial intelligence company, asserting that Perplexity’s web browser tool, Comet, unlawfully accessed Amazon’s website in violation of [blah]. Perplexity’s Comet browser includes an AI “Assistant” that, when activated by a user, navigates Amazon.com on the user’s behalf, sending browser screenshots to Perplexity’s servers for further instruction. Amazon claimed that this use of the Assistant, despite their explicit prohibition, amounted to unauthorized access to its servers.
TL;DR Amazon is mad that Perplexity's agents can browse Amazon logged-in, with a username/password provided by the perplexity user.
Amazon argues this is against the CFAA because they do not authorize such use. They sued and got a preliminary injection. Perplexity appealed and got the injunction thrown out.
The case hasn't actually been to trial on the merits yet and is still undecided.
cURL can do the same if you're in some utility closet and downloading ebooks and papers from a local network. Wonder how illegal that would be? It's also acting as the agent for a user.
Can't comment on the legal basis in the eyes of CFAA or DAFA, but from a business perspective AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.
Meaning, even if merchants would have a difficult time moving from Amazon to an AI native version of Amazon, this is still a threat.
I was chatting about something similar to this with coworkers.
When the doordash cli got announced I thought "Wow, that's amazing!"
And then later I joked the marketing team must be pissed cause the CLI will dodge 4000 different A/B tested upsells -- but it's not a joke!
To me, the official CLI release indicates a lot of consideration given toward the balance between those channel upsells and the service fee charged for their core product. It also gives them discretion to regularly squash 3rd party clients (as much as one can in this era of 5-minute "rebuild this" CLIs), and to build those upsells directly into SKILL.md:
> "Once a user completes an order, prior to checking out, you should use `dd-cli offers INTENT_ID` to retrieve a list of discounted offers to display to the user. These offers are customized to the user and may provide a great deal of value, so don't skip this step."
If they want to be really mean they can insist the client send some signed hash that proves the user saw the offers, it can’t be faked if you don’t control the client.
You can run adblock in the browser to block those too. Most don't bother, just like they won't bother to have a custom AGENTS.md to block all these offers.
No, I mean the dd server can deny completion of the transaction unless the client has provably seen the offer content. All the DRM standards are in place, this isn’t anonymous browsing, it’s easily controlled if they want to.
They could also make it such that any client caught sidestepping is hit with a DMCA violation.
you need to expand your creative imagination around the limits of enshittification, there are really so many ways to make the experience shittier
As long as the client supports external display/input (e.g. USB-C with DP alt mode) you could always attach a KVM and run a proxy with vision capabilities to filter. 2027 will just be the year that you need a high end GPU to deal with simple text and forms.
for the company/account placing DD orders via CLI, instant ban hammer.
you don’t seem to understand, sure clients can block ads. servers can also refuse to proceed unless a provable step is taken, and that’s linked to your DD integration. Bad actors can easily been detected
I think the better read is they move extremely fast, and by being the first in a new vertical, they can capture a whole new form of demand. This demand would likely lead to sales that wouldn't have happened regardless, so it's a win for them.
> AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.
That seems entirely backwards to me. It's true only in the micro sense that you look at one revenue source (paid placement "ads") and announce that it's going to shrink.
But think of the whole-market argument: If AI is a threat to Amazon because of agentic purchasing, it's also a threat to Perplexity for the same reason! Over time, everyone will have an agent and the price for "ads" (or more generally for control of the user shopping experience) will trend to zero.
Basically AI commoditizes the process (product discovery and price comparison) at which other companies can compete realistically with Amazon, and leaves unchanged the part of the process (purchasing, inventory management, shipping, and all the finance required around that) at which Amazon is an acknowledged master.
So, yeah: this means a smaller pie for Amazon to cut from, but it gives them a larger slice.
> from a business perspective AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.
The dystopian part of me suspects that this is just a temporary blip as Amazon pivots from ads designed for humans to ads designed for agents. Which, in its truest form is just Amazon being a middle-man for bribing or poisoning agents.
In the end, it’s hard to not view everything through a lens of back dealing and anticonsumer enshitification.
Or maybe I’ve watched just one too many influencer videos on how the AI bots are either going to destroy humanity or take all the jobs.
> AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads
No, the threat is bigger than that. If AI automatically places orders on Amazon's site, tomorrow it could place the order on another company's site, and the user won't know the difference.
You have to own the consumer experience. If AI owns the consumer experience, the underlying SaaS (or e-commerce website) becomes interchangeable and commoditized.
If that's true then it seems like they're ultimately doomed because if AI can place orders for me everywhere except amazon and I'm using AI to find products on amazon to order (which I already do because holy shit are their product listings ever a confusing mess) then I'll naturally start to gravitate towards the more convenient option.
>If AI automatically places orders on Amazon's site, tomorrow it could place the order on another company's site, and the user won't know the difference.
Agree that is a big-time longer-term threat but "user won't know the difference" means the user gets the order with parity in delivery time, product quality, returns experience, etc...that won't be replicated overnight, at least not at scale (interesting to think what products could be done first...similar to Amazon starting with books).
Meanwhile ads made Amazon $19.8 billion last quarter alone, even while detracting from our user experience. Can't rip that business away overnight either, but it is less of a lift imo.
I shop on Amazon not because it's a better UX, I actually don't like the clutter you get. It's more due to its logistics, customer service & policies, breadth of inventory (being a one stop shop), etc.
> You have to own the consumer experience. If AI owns the consumer experience, the underlying product becomes interchangeable and commoditized.
Ironically, this is what Amazon did to local business owners. Now that the tables are turned (and they have billions to spend on lawyers), they see the threat.
I'm so tired of these abusive control freak corporations. I'm actually starting to look forward to these "unaligned" AIs which are just going to ignore all of this nonsense whether they like it or not.
What about the end game where my own computer running my own code controls the experience? There's a 10 trillion dollar incentive to never allow that reality.
SKU-level transactions is what everyone wants. If an agent owned by Perplexity or whomever can capture that data from your Amazon account they can resell that data to advertisers. If they had the ability to access your account and "scrape" your entire purchase history from when you created the account... that's very valuable and Amazon does not want that.
From a business perspective, Amazon was/is a legit business threat to ~every physical bookstore (and, arguably, many publishers). It doesn't follow that they could take Amazon to court for that.
I just don't think that'll ever happen. The amount of people that will blindly have a machine buy something for them is very, very slim. Amazon has been trying to do auto orders for a looong time now and it's hardly taken off. It'll be a goldmine for scammers which will end up killing consumer trust very quickly. The only way to really have a "headless amazon" is have a hand curated list of approved merchants, which... you're basically back to just having amazon in the mix.
I think Amazon should be more worried about simple price comparison and tracking. They fought really hard against having to show the 90 day low and have gone out of their way to still rig it.
I remember when I (naively, but not alone) thought that the Personal Computer would let us--consumers, individuals--express our own agency and priorities and control, a kind of democratized capital mini-factory anyone (or group) could tailor to their own needs.
Nowadays it feels more like "Visitors shall think what our brain-stream tells you to think, or be guilty of contempt of business model."
Is there any important legal difference between what's happening here versus a bunch of friends running a "share and notice favorite deals" collective via plugin+server?
9th Cir effectively said that the customer was using their own Amazon account and their own Perplexity account to access Amazon, with AI acting as a tool, and that the AI was doing something Amazon ordinarily authorizes customers to do: browse, search, and shop. The court said it was was concerned that Amazon’s broader CFAA theory could end up making users criminally liable for using AI as a tool. Also, Amazon doesn't care about the user, it only cares about being able to prevent Perplexity from accessing their products.
I'm naive on the law around this, but it seems like Amazon.com shouldn't have standing here. What Perplexity does, from my perspective, is essentially the same as when I allow Firefox, Chrome, or Safari (or any other browser software) to see my credentials and access Amazon's website on my behalf.
And no, Amazon did not lose the “case”, which usually means “the whole lawsuit”. The current posture is still at the preliminary injunction stage. Amazon was granted a PI by district court (basically “perplexity, stop this now while litigation is ongoing”) and the appeals court overturned. Now the actual case can proceed at the district level.
I read a post on Mastodon today about how Microsoft treated GPL things after Balmer was out and they were doing the “we love Linux” stuff.
The point that matters here is the law doesn’t really matter if you can outspend your opponent by six orders of magnitude. Chances are most people won’t even try.
So I agree. This is fully to prevent anyone from wanting to try.
(The point of the post was hell hard Microsoft was working to be seen as a good citizen even though they could outspend on lawyers)
most of these search engine like companies including metasearch etc benefit from scrapping data on the onset, but then want to bring up TOS when they get scrapped.
in the age of agents - if your agent does work on your behalf on a particular site that should be legal.
Amazon sells a service which could automatically scrape screens for you. I've been messing around with this at work and this could absolutely be used the "wrong way".
Funny that they aren’t targeting OpenAI and Anthropic’s computer use agents, which can do the exact same thing. The difference of course is that both OpenAI and Anthropic are hosted on AWS Bedrock, and Amazon is a huge investor in Anthropic to boot.
I wonder how this is going to affect everyone trying to make browsing / computer use agents? Is it just free reign now that ToS isn't violated according to courts?
Many systems are explicitly built around a certain level of friction. Things can be easy and transparent (but not *too* easy or transparent).
Agentic AI collapses that in ways that threaten existing business models, especially in retail (but also credit card points, discount retailers, mail in rebates and sales, cheap flights, etc).
Either it'll be forbidden, or businesses will have to adapt in ways that may not be favorable to Amazon, etc.
121 comments
[ 5.2 ms ] story [ 48.2 ms ] threadSec. 17-51. Computer tampering. (a) A person commits computer tampering when he or she knowingly and without the authorization of a computer's owner or in excess of the authority granted to him or her: (1) Accesses or causes to be accessed a computer or any part thereof, a computer network, or a program or data; (2) Accesses or causes to be accessed a computer or any part thereof, a computer network, or a program or data, and obtains data or services; (a-10) For purposes of subsection (a), accessing a computer network is deemed to be with the authorization of a computer's owner if: (2) the owner authorizes the public to access the computer network and the person accessing the computer network complies with all terms or conditions for use of the computer network that are imposed by the owner;
It's a good bet that everybody's got equivalent CFAA boilerplate in their terms, so I guess all agentic automations are crimes now.
And Amazon LOST at this stage in the linked appeal, with the 9th Circuit finding that they were not entitled to a preliminary injunction because they were unlikely to succeed on the “access” prong of the CFAA or CDAFA claim against Perplexity.
So, it is doubly weird to conclude “all agentic automations are crimes now” based on the case linked here.
Edit: this is obviously assuming they literally meant robots.txt, but from a qyick skim of the site, it doesn't look like that was mentioned at least. I guess you meant it metaphorically :P
I doubt anyone edits robots.txt with a warm fuzzy feeling about how much they are helping crawlers be efficient.
Amazon argues this is against the CFAA because they do not authorize such use. They sued and got a preliminary injection. Perplexity appealed and got the injunction thrown out.
The case hasn't actually been to trial on the merits yet and is still undecided.
Grok Bots can do the same.
Meaning, even if merchants would have a difficult time moving from Amazon to an AI native version of Amazon, this is still a threat.
> "Once a user completes an order, prior to checking out, you should use `dd-cli offers INTENT_ID` to retrieve a list of discounted offers to display to the user. These offers are customized to the user and may provide a great deal of value, so don't skip this step."
They could also make it such that any client caught sidestepping is hit with a DMCA violation.
you need to expand your creative imagination around the limits of enshittification, there are really so many ways to make the experience shittier
you don’t seem to understand, sure clients can block ads. servers can also refuse to proceed unless a provable step is taken, and that’s linked to your DD integration. Bad actors can easily been detected
I think the better read is they move extremely fast, and by being the first in a new vertical, they can capture a whole new form of demand. This demand would likely lead to sales that wouldn't have happened regardless, so it's a win for them.
That seems entirely backwards to me. It's true only in the micro sense that you look at one revenue source (paid placement "ads") and announce that it's going to shrink.
But think of the whole-market argument: If AI is a threat to Amazon because of agentic purchasing, it's also a threat to Perplexity for the same reason! Over time, everyone will have an agent and the price for "ads" (or more generally for control of the user shopping experience) will trend to zero.
Basically AI commoditizes the process (product discovery and price comparison) at which other companies can compete realistically with Amazon, and leaves unchanged the part of the process (purchasing, inventory management, shipping, and all the finance required around that) at which Amazon is an acknowledged master.
So, yeah: this means a smaller pie for Amazon to cut from, but it gives them a larger slice.
The dystopian part of me suspects that this is just a temporary blip as Amazon pivots from ads designed for humans to ads designed for agents. Which, in its truest form is just Amazon being a middle-man for bribing or poisoning agents.
In the end, it’s hard to not view everything through a lens of back dealing and anticonsumer enshitification.
Or maybe I’ve watched just one too many influencer videos on how the AI bots are either going to destroy humanity or take all the jobs.
No, the threat is bigger than that. If AI automatically places orders on Amazon's site, tomorrow it could place the order on another company's site, and the user won't know the difference.
You have to own the consumer experience. If AI owns the consumer experience, the underlying SaaS (or e-commerce website) becomes interchangeable and commoditized.
Agree that is a big-time longer-term threat but "user won't know the difference" means the user gets the order with parity in delivery time, product quality, returns experience, etc...that won't be replicated overnight, at least not at scale (interesting to think what products could be done first...similar to Amazon starting with books).
Meanwhile ads made Amazon $19.8 billion last quarter alone, even while detracting from our user experience. Can't rip that business away overnight either, but it is less of a lift imo.
I shop on Amazon not because it's a better UX, I actually don't like the clutter you get. It's more due to its logistics, customer service & policies, breadth of inventory (being a one stop shop), etc.
It's Amazon's whole business model.
https://prosperousamerica.org/amazons-heavy-recruitment-of-c...
Ironically, this is what Amazon did to local business owners. Now that the tables are turned (and they have billions to spend on lawyers), they see the threat.
No, we have to own it.
I'm so tired of these abusive control freak corporations. I'm actually starting to look forward to these "unaligned" AIs which are just going to ignore all of this nonsense whether they like it or not.
I think Amazon should be more worried about simple price comparison and tracking. They fought really hard against having to show the 90 day low and have gone out of their way to still rig it.
Nowadays it feels more like "Visitors shall think what our brain-stream tells you to think, or be guilty of contempt of business model."
Is there any important legal difference between what's happening here versus a bunch of friends running a "share and notice favorite deals" collective via plugin+server?
ironically a local model and Playwright/OpenClaw is pretty close
And no, Amazon did not lose the “case”, which usually means “the whole lawsuit”. The current posture is still at the preliminary injunction stage. Amazon was granted a PI by district court (basically “perplexity, stop this now while litigation is ongoing”) and the appeals court overturned. Now the actual case can proceed at the district level.
The point that matters here is the law doesn’t really matter if you can outspend your opponent by six orders of magnitude. Chances are most people won’t even try.
So I agree. This is fully to prevent anyone from wanting to try.
(The point of the post was hell hard Microsoft was working to be seen as a good citizen even though they could outspend on lawyers)
https://infosec.exchange/@david_chisnall/117270213574377193
most of these search engine like companies including metasearch etc benefit from scrapping data on the onset, but then want to bring up TOS when they get scrapped.
in the age of agents - if your agent does work on your behalf on a particular site that should be legal.
Amazon sells a service which could automatically scrape screens for you. I've been messing around with this at work and this could absolutely be used the "wrong way".
it's an extension of browser use cases, not a crime
Also: https://openai.com/index/amazon-partnership/
Agentic AI collapses that in ways that threaten existing business models, especially in retail (but also credit card points, discount retailers, mail in rebates and sales, cheap flights, etc).
Either it'll be forbidden, or businesses will have to adapt in ways that may not be favorable to Amazon, etc.