ChinaChina
China Markets
CSI 3004,547.96 1.38%
Hang Seng25,311.21 1.00%
Shanghai3,941.39 0.97%
CNY/USD6.7103 0.23%
HuxiuFEATURE · TRANSLATED

Translated from Chinese · 9/2/2026 · 11 min read · 互联网法律评论

Original: AI帮你下单,谁在违法?亚马逊对Perplexity禁令出现“反转” · https://www.huxiu.com/article/4888007.html

Amazon's Perplexity Ban Reversal Raises Questions Over Liability

On August 4, 2026, the Ninth Circuit Court of Appeals issued a 21-page ruling that vacated Amazon's preliminary injunction against Perplexity.

The court ruled that since it was the user (rather than Perplexity) who used the AI assistant as a tool to access Amazon, Amazon does not have a stronger case as the district court had determined, but rather Perplexity has more favorable conditions.

Based on this, the district court should not have issued the "preliminary injunction" to prevent Perplexity from being used by users on Amazon.

But this is by no means a simple story of "Perplexity trouncing Amazon." What we need to examine is: Why did the Ninth Circuit overturn the district court's injunction? How will this disagreement shape the case's trajectory on remand, and how will it reshape the compliance logic of the AI agent industry?

The two rulings have an essential difference: from a dispute over "authorization" to a dispute over who the "visitor" is

The US District Court's logic for issuing a preliminary injunction on March 9 was based on "dual authorization" - user authorization does not equal platform authorization. After Amazon revoked permission through a lawyer's letter, Perplexity accessed password-protected accounts through the Comet browser "with user authorization but without Amazon's authorization".

The Ninth Circuit Court shifted the focus of the dispute from "authorization" back to the more fundamental verb "access" in the Computer Fraud and Abuse Act (CFAA) in its ruling on August 4.

The previous district court actually adopted Amazon's narrative logic: Comet accessed password-protected accounts → obtained users' private information → transmitted it to Perplexity servers. In this narrative, "access" seems to be self-evident.

But the Ninth Circuit Court did something more substantial in its ruling - it conducted a detailed analysis of Comet's technical architecture:

Comet's AI Assistant runs locally in the user's browser;

It sends user screenshots, along with user instructions, to the Perplexity server;

The Perplexity server returned operational instructions;

Thus, Perplexity's servers never directly access Amazon's servers.

Based on this architectural fact, the Ninth Circuit Court of Appeals reached a conclusion that was decisive to the direction of the case:

Under the technical architecture in this case, it is the user who, with the assistance of the Assistant tool, accesses Amazon's computer, whereas Perplexity itself does not "access" Amazon's computer.

The court further clarified that the "whoever" in the CFAA text's "whoever...intentionally accesses" refers to a "person" in a legal sense, which can be a natural person or a legal person, and that an "assistant" is a tool that does not constitute a "person" in a legal sense. The court stated that "the Assistant is a tool, not a person for statutory purposes."

This is the fundamental difference between the two rulings: the district court discussed "authorization", while the Ninth Circuit discussed "accessing the subject". The district court talked about authorization defects on the premise that Perplexity constitutes "access", whereas the Ninth Circuit first denied Perplexity's legal status as an "accesser".

2. Why the Ninth Circuit "Disagreed" with the Injunction: Unfolding the Four Factors

A US district court's issuance of a "preliminary injunction" has four statutory requirements: (1) likelihood of success on the merits; (2) irreparable harm; (3) balance of equities; and (4) public interest. The district court "folded" the four requirements into the first one, meaning that as long as the likelihood of success on the CFAA claim was established, the other three requirements would naturally lean in favor of Amazon. However, the Ninth Circuit Court "unfolds" them:

1. Chances of winning: The "access" requirement of the CFAA fails

The Ninth Circuit cited the US Supreme Court's definition of "access" in Van Buren v. United States (2021) as "entering a computer system itself or a specific part thereof." Under this definition, the court made two key technical determinations:

a top of a " ( top of "(s),"(s,"(s top of "(s top of "(s top of " "(s top of " "s,"(s top of " "s,"( that " "s top of " "s top of " " "s top of " "s " " "s top of " " " "s top this " " "s top of " " " "s top of " " " "s top of " " " " " " " " " " " " " that " " " " " " " " " " " " " " " " " " " " " " " " " "." " " " " " " " that " " " " " " " " " " " " " " " " " " " "ering a " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " "ubori " " " " " " " " " " " " " " " " " " " " ". " " " " " " " "

The court ruled that AI entities are "tools" rather than "legal entities." While acknowledging that AI entities may raise new legal issues, the question of artificial intelligence "intent" became moot in this case - because the "AI assistant" is merely a tool in the legal sense, operated by the user, not Perplexity.

2. Strict application of the Rule of Lenity as a fallback provision

This is a dimension that the district court did not seriously address. The Ninth Circuit explicitly stated that the CFAA is essentially a criminal statute, and its interpretation in both civil and criminal contexts should be consistent, and in cases of ambiguity, it should be interpreted in favor of the defendant.

The court raised an overflow risk that the district court did not consider - the Electronic Frontier Foundation (EFF) explicitly stated in its amicus brief that if Amazon's theory is adopted, users may face criminal complicity liability for using Assistant. The Ninth Circuit essentially accepted this argument: turning the "user's use of AI tools to access websites" into a federal crime "merely because it involves a computer" is absolutely not the legislative purpose of the CFAA.

3. Public interest requirement: From "protecting computer systems" to "user control and technological neutrality"

The district court defined the public interest as "protecting computers from unauthorized access." The Ninth Circuit wrote explicitly in its ruling: an injunction against conduct that may not violate the CFAA would not be in the public interest.

The appeals court has redefined the implications of public interest to include: protecting users' autonomy in choosing browsers, maintaining an open network, and avoiding exposing the development of ordinary technical tools to criminal risk. The court has adopted the opinions of amici curiae, including the Knight First Amendment Institute at Columbia University and the ACLU, that computer crime laws like the CFAA should not be extended to punish tools that automatically access users' personal information.

4. Irreparable harm and balance of interests: Amazon's evidence is weak

The appeals court noted that Amazon's claims of "degraded shopping experience" and "cybersecurity risks" were based on weak evidence - its expert testimony even failed to fully replicate the alleged risks; issuing an injunction would unreasonably burden Perplexity, limit consumer choice, and hinder the development of emerging technologies.

It is worth noting that the court explicitly stated in footnote 5 that this ruling does not affect Amazon's right to regulate user access through its Terms of Service (ToS). This essentially leaves a door open for the platform - the CFAA route may not be viable, but the path of contract law and service terms remains open.

Third, the decisive significance of this "interim result"

As predicted by this platform in "Amazon Wins Court Injunction: AI Entity in 'Dual Licensing' Dilemma" - the "dual licensing" controversy is only the beginning. The ruling on August 4, regardless of the final outcome of the case, has already produced a phased but highly decisive landscape impact:

Amazon's path under the CFAA has been largely blocked

The Ninth Circuit has set a high bar for the "access" requirement under the CFAA, and for Amazon to proceed under the CFAA framework, it must prove that Perplexity directly accessed Amazon's servers - something that is impossible under the current Comet architecture.

Amazon said in a statement that it is "evaluating its next steps".

The attribution of responsibility for AI intelligent entities is "architecturally dependent"

The Ninth Circuit Court emphasized in its argument that the ruling is "based on the current state of affairs". This qualification is temporary and architecture-dependent. As AI technology evolves to the point where its servers can directly log in to Amazon, retain user credentials autonomously, and make discretionary decisions, this qualification will likely be overturned.

Thus, the Ninth Circuit's ruling established a highly architecture-dependent liability rule: if the AI company's servers do not directly interact with third-party servers, liability falls on the user, with the AI company being merely a tool provider.

4. The Transition from "Dual Licensing" to "Architecture Compliance" and its Shortcomings

The role of AI agents is to entrust programs with operations that users can originally complete personally, and cannot be simply equated with crawlers that replicate and resell data. Currently, various countries lack specific regulatory rules for intelligent agent AI: which platforms can be blocked, under what conditions can they be blocked, what objective reasons are needed, and what kind of external supervision is required.

The Amazon vs Perplexity case raises a more specific and pressing question: can a platform unilaterally define the terms of user interaction and use this to block user choice of tools? From another angle, if a user authorizes Comet to act on their behalf, does Amazon have the right to terminate this chain of authorization?

Before regulation emerges, judges will influence people's perception of the entire AI ecosystem through rulings such as the Amazon vs Perplexity case.

From "Dual Licensing" to "Architectural Compliance" - The Architectural Dependence of AI Entity Responsibility Attribution

The Ninth Circuit's ruling reveals an important trend: the legal liability of AI entities will no longer be discussed in the abstract terms of "whether it is a tool or an entity," but rather by specifically examining their technical architecture. This "architecture-dependent" qualification means that AI entities will not be simply categorized as "unauthorized access," but instead, the Ninth Circuit insists on first clarifying the factual nature of the technical architecture before discussing legal applicability.

The ruling established three key elements for "architectural compliance": whether the AI server directly interacts with third-party servers, whether the intelligent entity is classified as a "tool", and whether the intelligent entity makes discretionary decisions beyond the user's explicit instructions. If the answers to these three elements are "no, yes, and no", the liability falls on the user.

"I's a top of a top of a top of a a top of a a top of a " " " " " " " " " " " " " " " " " " " " " a " " " " " " " " " " " " " " " " " " " " " just " " " " " " " "." " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " only " " " " " " " " " " " " " only " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " "-only " " " " " " " " " " " " " " " " " " " " " a " " " " " " " " " " " " " " " " " " " " a " " " " " " " of " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " " "

China's AI Intelligent Enterprise "Architecture Compliance" Window Period

In line with existing judicial practices in China, the "three-step authorization" principle established in the "Sina vs. Maimai" case still plays a role in mainstream cases, but the Supreme Court's 47th batch of guiding cases, No. 263, has begun to create limited space for "data transfer across platforms under user authorization".

The US Ninth Circuit's "architectural compliance" qualification provides a referable technical-legal design guide for Chinese AI intelligent entity enterprises: how to make intelligent entities "not access" third-party servers in a legal sense, which is likely to directly reduce CFAA-class risks and enhance the defense of "user authorization" under Chinese law.

3. Unresolved issues: Can user authorization chains withstand platform service terms

If a person can instruct family members, employees or assistants to shop on Amazon, why should software controlled by the same user be treated differently? Both the trial and appellate courts sidestepped the legal and philosophical difficulties this question raises.

The Ninth Circuit also did not explicitly hold that user autonomy should be viewed as an independent and antagonistic source of authorization to platforms. Its judges made it clear in the ruling that this outcome would not undermine Amazon's ability to regulate access to its website through its users' private terms of service.

In other words, users can access Amazon with the help of AI tools, but Amazon seems to still be able to regulate user access through its terms of service, which is equivalent to kicking the real conflict of "user authorization vs platform terms of service" back to the realm of contract law.

Source: www.huxiu.com/article/4888007.html · Syndicated under attribution policy