Appeals Court Lifts Ban on Perplexity’s AI Shopping Tool in Major Test for AI Agents
The U.S. Court of Appeals for the Ninth Circuit has lifted a preliminary injunction that restricted Perplexity’s AI-powered shopping technology from interacting with Amazon.
This is an important legal win for Perplexity. However, it does not end the lawsuit. It also does not confirm that the company has won the entire case.
At the centre of the dispute is a bigger question. When an AI assistant acts on a user’s instructions, who is actually accessing the website? Is it the AI company? Or is the user simply using software to perform actions they are already allowed to complete?
AI tools are no longer limited to answering questions. Many can compare products, summarise pages, complete forms, and assist with purchases. So, as these systems become more capable, courts will have to decide where user control ends and developer responsibility begins.

The Amazon Perplexity Dispute
Amazon accused Perplexity of allowing its AI shopping technology to interact with Amazon’s marketplace without proper authorisation.
According to Amazon, Perplexity’s browser-based agent automated shopping activities in ways that may have violated platform rules. In addition, Amazon argued that the software could raise concerns under federal laws dealing with unauthorised computer access.
As a result, a district court initially issued a preliminary injunction. This limited parts of Perplexity’s shopping functionality connected to Amazon.
Perplexity appealed. It argued that its software was not acting as an independent outsider. Instead, it said the technology worked as a tool controlled by users. In other words, people were simply asking the assistant to perform normal shopping tasks — searching for products, comparing listings, and helping with purchases.
Ultimately, the Ninth Circuit ruled that Amazon had not met the legal standard needed to keep the injunction in place. As a result, the temporary restriction was lifted.
Importantly, the full case is not over. The appeals court only decided whether the ban should remain active while the lawsuit continues. So, Amazon can still pursue its wider claims, and the lower court may examine the technical and legal details of Perplexity’s system.
Why the Preliminary Injunction Matters
A preliminary injunction is a temporary court order. Courts often use it when one side argues that it may suffer serious harm before the full case can be decided.
To secure this type of order, the requesting party usually has to show two things: that it is likely to succeed, and that it may face harm that cannot easily be repaired later.
By lifting the injunction, the Ninth Circuit decided that Amazon had not made a strong enough case for keeping the temporary ban in place at this stage.
That said, this is an important result for Perplexity — but it is not a final judgment on whether the company acted lawfully in every respect. In short, Perplexity won a major procedural battle, not the entire lawsuit.
Who Is Actually Accessing Amazon?
The central issue is whether Perplexity’s AI should be treated as an outside actor or as an extension of the user.
On one hand, Amazon’s position is that an AI developer may still be responsible if its technology bypasses restrictions, automates prohibited behaviour, or exceeds the platform’s rules. In Amazon’s view, a user instruction does not automatically make every action acceptable.
On the other hand, Perplexity argues that users are already allowed to visit Amazon, search for products, compare listings, and make purchases. So if software helps them complete those same authorised tasks, the activity should not automatically be treated as unlawful access.
Notably, the appeals court’s reasoning appears to give weight to that argument. When a person directs an AI assistant to perform a task through their own account or permissions, the situation may differ from a bot entering a protected system without consent.
As more AI agents begin carrying out tasks on behalf of users, this distinction could become increasingly important.
Why the Computer Fraud and Abuse Act Is Important
Amazon relied heavily on the Computer Fraud and Abuse Act, often called the CFAA. Lawmakers created this law to deal with hacking, unauthorised access, and misuse of protected computer systems.
The problem, however, is that the CFAA was written long before modern AI agents existed.
Traditional hacking cases are often easier to understand. Someone may enter a system without permission, steal credentials, or bypass security controls. AI-assisted browsing, on the other hand, is far more complicated.
For example, a user may have permission to access a website, but the platform may object to how the user is accessing it, or to the level of automation involved.
This raises several difficult questions:
- Did the user have permission?
- Did the software go beyond that permission?
- Did the agent bypass a technical barrier, or did it only violate the platform’s terms?
- Was the AI company itself the actor, or was it providing a tool controlled by the user?
The Ninth Circuit’s decision suggests that courts may not treat every automated interaction as unauthorised access. Instead, they may examine the user’s role, the developer’s role, the platform’s controls, and the permissions involved.
Amazon’s Concerns Go Beyond Website Access
Amazon’s concerns also involve how users experience its marketplace. The company controls product pages, recommendations, sponsored listings, and checkout flows.
Because of this, a third-party assistant that summarises listings or compares products outside Amazon’s normal interface could reduce that control.
AI shopping agents may also change how sellers compete for attention. For instance, an agent might ignore sponsored placements and focus instead on price, product details, or reviews. It may also summarise listings in a way that removes information Amazon wants shoppers to see.
If an AI assistant becomes the main layer between the platform and the buyer, it could influence which products get noticed. On top of that, platforms may also worry about automated traffic, inaccurate summaries, account misuse, or purchases completed without enough user review.
Why This Case Matters for the AI Industry
This dispute comes as AI companies move beyond chatbots. Newer systems can browse websites, use online services, organise information, and complete multi-step tasks.
This shift is visible in Aitoza’s list of the top 100 AI tools in 2026, which includes products built to automate practical work.
Shopping is one of the clearest early uses for this technology, since it combines search, comparison, decision support, and transactions.
Looking ahead, the same legal questions could later appear in travel booking, banking, insurance, healthcare portals, subscription management, and workplace software.
A ruling that strongly supports platform control could make it harder for independent AI companies to build agents that work across the open web. Conversely, a ruling that supports user-directed automation could reduce the ability of websites to control how automated tools interact with their services.
The outcome may also influence product design going forward, including clearer consent screens, activity logs, permission controls, and purchase confirmations.
Security and Model Protection Also Matter
Security is another important part of the AI-agent debate.
As these systems become more capable, they may receive access to user accounts, saved payment methods, personal information, and private services.
The EncForge ransomware attack targeting AI model weights shows how valuable AI systems and their underlying assets have become to attackers.
Although that incident involves a different threat, it highlights the need to protect AI models, credentials, sessions, and user permissions. In short, legal permission alone does not make an agent secure — developers still need strong authentication and clear approval steps.
What the Ruling Does Not Decide
The ruling leaves several major questions unanswered.
First, it does not decide whether Perplexity ultimately violated Amazon’s terms of service. Contract claims may be treated differently from claims under federal computer-access law.
Second, it does not mean that every action performed by a user-directed AI agent is lawful. An agent could still create legal problems if it bypasses security systems, accesses restricted information, misuses credentials, or acts beyond the user’s permission.
Third, the ruling does not create a complete legal framework for agentic AI. Future cases may involve different software designs, permissions, and platform restrictions.
Finally, the ruling does not fully answer who is responsible when an agent makes a mistake. If an agent orders the wrong product, exposes personal data, or completes an unwanted transaction, responsibility may fall on the user, the developer, the platform — or more than one party.
What Platforms and AI Developers Should Watch
For website operators, this case shows the importance of clear technical and contractual rules. Terms of service alone may not answer every question when users have genuine access but rely on third-party software.
Going forward, platforms may need to separate harmful automation from user-authorised assistance. They may also need better systems for identifying agents, granting limited permissions, and protecting sensitive actions.
For AI developers, transparency will be essential. Users should be able to see what the agent is doing, which account it is using, what information it can access, and when approval is required.
Developers must also respect login requirements, security controls, and platform-specific restrictions. Saying that “the user requested it” may not be enough if the software independently bypasses barriers.
Ultimately, the strongest AI agents are likely to combine useful automation with visible user control, permission limits, and easy ways to stop an action.
The Bigger Picture for Digital Commerce
This dispute reflects a wider change in how people may use the internet.
In the traditional model, users visit a website, read pages, compare products, and complete each step themselves.
In an agent-based model, however, the user simply states a goal, and the software handles much of the process.
This shift could improve convenience, accessibility, and competition. At the same time, it could also weaken platform control, affect advertising models, and create new risks around data, consent, security, and accountability.
The Ninth Circuit’s decision does not answer every question. Still, it suggests that courts may examine AI agents in context, rather than automatically treating them as unauthorised bots.
For Perplexity, the ruling removes an immediate legal obstacle. For Amazon, the wider lawsuit continues.
For the technology industry as a whole, this case is an early warning. The rules governing AI agents will be shaped not only by innovation, but also by courts, contracts, security systems, and user rights.
As AI assistants become more capable of acting in the real world, the final outcome could help define who controls online activity: the platform, the software developer, or the user directing the agent.