Skip to content

Perplexity won the wrong argument

3 min read
#ai-agents#law#cfaa#web-infrastructure

Amazon spent a year and a federal appeal trying to make a 1986 anti-hacking statute do a job nobody wrote it for, and on August 4th the Ninth Circuit told it no. The injunction that had stopped Perplexity’s Comet browser from shopping on Amazon.com is vacated and the case goes back down. Amazon is “unlikely to succeed on the merits” — the test that governs a preliminary injunction, not a verdict on anything. Nobody has ruled that a shopping agent behaves lawfully.

The reasoning is narrow enough to be worth stating precisely. The Computer Fraud and Abuse Act punishes whoever accesses a protected computer without authorization. Comet’s Assistant takes instructions from a user and from Perplexity’s own servers, and the panel decided that combination doesn’t make it a whoever. It is a tool, not a person for statutory purposes. That is a classification under one statute. It is not a licence.

The interesting part is the question the court didn’t have to answer, because that’s where the real fight is.

Amazon’s underlying complaint was that the Assistant was indistinguishable from a human session — no distinct user-agent string, nothing to detect or block the way you’d block any other bot. Whether Perplexity ever changed that once Amazon started catching it is contested; both sides tell it differently, and the panel never had to resolve it, because the legal question turned on statutory text and on precedent instead. The camouflage was never tested. It simply didn’t come up.

That’s a strange kind of victory, and the template for how it ages is sitting in the same court’s own history. hiQ Labs beat LinkedIn under this identical statute a decade ago on the mirror-image claim — LinkedIn wanted the CFAA to stop hiQ’s scrapers, and the Ninth Circuit said the CFAA is an anti-hacking law rather than a general keep-off-my-site law. hiQ won that point outright. Then it lost anyway. A December 2022 consent judgment, five hundred thousand dollars, on breach of the user agreement. Contract, not hacking. Winning the CFAA argument bought two and a half years and no more.

Amazon can read that history as well as anyone. It doesn’t need a hacking statute. It needs a sentence in its terms of service and some patience.

And the second act won’t be litigation at all, because the infrastructure layer has already stopped waiting. Cloudflare now sorts traffic into Search, Agent and Training, and from September 15th every new domain joining it has Agent traffic blocked by default on ad-carrying pages alongside Training. That is a dashboard toggle doing categorically, in an afternoon, what a year of federal appeal couldn’t extract from the statute. It needs no finding about personhood. It needs a flag.

Here is the part that makes Perplexity’s win awkward: agents are volunteering the flag. Tool-call protocols, agent-specific headers, identity disclosed in the client software — none of it designed with this case in mind, all of it built because sanctioned identity buys stable access instead of a permanent game of detection and evasion. The whole industry is walking toward exactly the identifiability that Perplexity’s legal position benefits from lacking.

So the strategy that won this round is the one that loses the larger argument. Contract law doesn’t need the rule of lenity. A traffic classifier doesn’t need a jury. Both get easier to use against an agent precisely to the degree that the agent is identifiable, and harder against one built to pass as human — which means an agent can hold the CFAA defence and forfeit everything that doesn’t require the CFAA. That’s most things.

The panel was careful about its own reach. It says the doctrine is thin — “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents” — that the ruling is preliminary, and that none of it impairs Amazon’s ability to regulate access through private terms of service.

That last clause is the whole game, and it took one sentence to write.