One sentence on page 15 flipped the whole thing
The sentence is short. "It is the user who 'accesses' Amazon's computers, with the help of the Assistant to carry out specific acts on Amazon.com." That's page 15 of opinion No. 26-1444, handed down by the U.S. Court of Appeals for the Ninth Circuit on August 4, 2026.
Here's the deal: that one sentence erased a preliminary injunction Amazon had been holding for five months. Amazon won round one. Judge Maxine M. Chesney of the Northern District of California granted the injunction in March 2026, and Perplexity's AI browser Comet was shut out of the Amazon Store. On August 4 the appellate panel vacated that order and sent the case back down.
The timeline is tight. Complaint filed November 2025. District court injunction March 2026. Oral argument June 11, 2026 in Seattle. Decision August 4, 2026. Nine months from filing to the first federal appellate answer to the question "is it hacking when an AI agent goes onto someone else's website on a user's behalf?" Reuters called it the first federal appeals court ruling to address whether AI agents acting for users can legally access online platforms.
But open the actual opinion and the court is almost aggressively humble about its own reach. Page 17 contains this: "Because we recognize that agentic AI is an emerging technology, we reiterate what this opinion is not. We do not establish a new legal regime governing agentic AI." And then it drives the point home: "The legal understanding of agentic AI will doubtless change as AI technology grows increasingly sophisticated." The winner is unambiguous. The size of the win was deliberately drawn small.
So this piece reads the footnotes rather than the headline. What got cleared, what is still dangerous, what card Amazon plays next, and why this stopped being a Perplexity story about ten minutes after it landed.
Two companies in the ring, and everybody lined up behind them
Start with Perplexity. It's the AI search company run by Aravind Srinivas, and the product at issue is Comet. The opinion's own description on page 6 is precise: Perplexity acquired a browser company called Sidekick, built Comet, and released it publicly in 2025. Comet itself is an ordinary browser — it runs locally on the user's machine and lets you navigate the internet, much like Chrome. What makes it different is an optional AI agent that the opinion simply calls "the Assistant," which "can perform tasks at the user's direction, such as browsing websites like Amazon.com to shop for requested goods."
The plumbing of that Assistant turns out to be the entire case. Page 7: when a Comet user tells the Assistant to find an item on Amazon.com, the Assistant takes screenshots of the browser view, sends those screenshots from the user's computer to Perplexity's servers, and receives instructions back on how to navigate Amazon.com. The court notes explicitly that the Assistant "cannot operate wholly independently" — it depends both on the user's direction and on instructions from Perplexity's servers. That architecture is what eventually produces the finding that Perplexity's servers never directly touch Amazon's.
On the other side is Amazon — technically plaintiff Amazon.com Services, LLC. Amazon's theory starts from the premise that its Store isn't just a website. Customer accounts are password-protected, and inside them sit order management, stored payment methods, delivery addresses, personalized recommendations, purchase history, and returns. Letting somebody else's automation walk around inside that is not something Amazon is willing to concede. And there's a single line on page 7 of the opinion that matters more than it looks: Amazon "also operates in the AI space and launched agentic AI products in 2025." Hold that thought.
The flashpoint is remarkably concrete. Per pages 7 and 8, before Comet even shipped, Amazon told Perplexity's CEO that Perplexity's AI products would not be permitted to access the Amazon Store. After Comet launched and the Assistant started showing up, Amazon told them again. And the thing the fight actually crystallized around was the user-agent string — the little identifier a browser sends a server announcing what it is. Perplexity chose not to use a user-agent string that would signal the user had activated an AI agent. Had it done so, Amazon could have identified and blocked the Assistant. Footnote 1 of the opinion records that the parties still dispute whether Perplexity knowingly altered the Assistant's user-agent string after Amazon initially succeeded in identifying and blocking it. That's an unresolved fact question, not a settled one.
Context from outside the courtroom matters here too, because the user-agent issue wasn't Perplexity's first. On August 4, 2025 — exactly one year before this ruling, as it happens — Cloudflare publicly accused Perplexity of using stealth, undeclared crawlers to evade no-crawl directives. Cloudflare's account was that when Perplexity's declared crawlers hit robots.txt restrictions or network blocks, the company would switch to a generic user agent impersonating Chrome on macOS and rotate through undeclared IP ranges, across tens of thousands of domains and millions of requests per day. Cloudflare de-listed Perplexity from its Verified Bots program. That's the reputational backdrop Amazon was leaning on when it argued this is a company that hides. Perplexity, for its part, answered Amazon's suit with a blog post on November 4, 2025 titled "Bullying is Not Innovation."
Finally, the bench. Circuit Judges Milan D. Smith, Jr. and Eric C. Tung, plus District Judge John Charles Hinderaker of the District of Arizona sitting by designation. Judge Smith wrote the opinion. The advocacy was heavyweight on both sides — Hagan Scotten of Hueston Hennigan argued for Amazon, Christopher G. Michel of Quinn Emanuel for Perplexity. And the amicus lineup tells you exactly what kind of case this is. Backing Perplexity's reading: the ACLU, the ACLU of Northern California, the Knight First Amendment Institute at Columbia, the Electronic Frontier Foundation, the Alliance for Responsible Data Collection, Mozilla, Digital Medusa, and EleutherAI. On the other side: the National Retail Federation, the News/Media Alliance, the Software & Information Industry Association, and Airlines for America. Owners of content and commerce versus defenders of an open web. That alignment is going to repeat itself for the next five years.
What the court decided — and what it pointedly refused to decide
The whole case came down to one element. Under 18 U.S.C. § 1030(a)(2), a CFAA plaintiff must show the defendant (1) intentionally accessed a computer, (2) without authorization or exceeding authorized access, (3) thereby obtained information, (4) from a protected computer, and (5) that losses over any one-year period reached at least $5,000. The panel resolved the case on element one and never reached the rest. Footnote 4 says why: the remaining factors, including the scope of the CFAA's loss provision, were "unnecessary to resolve this case." Amazon tripped at the front door.
The district court had seen it the other way. Judge Chesney's short written order found that "Amazon has provided strong evidence that Perplexity, through its Comet browser, accesses with the Amazon user's permission but without authorization by Amazon, the user's password-protected account, thereby obtaining information as to the user's private Amazon account information, and that such information is transmitted to Perplexity's servers for the purpose of conducting said user's requested tasks." On the money threshold, she found essentially undisputed evidence that Amazon had spent well over $5,000 — including the hours Amazon employees put into building tools to block Comet and to detect future unauthorized access.
The Ninth Circuit said the "access" analysis was where that went wrong. Its reasoning stacks in three layers.
Layer one is factual: Perplexity's servers do not directly communicate with Amazon's. On page 14 the court quotes the EFF-led amicus brief at length, saying it "articulates the nature of the system most clearly." When a user visits an Amazon page, only the browser talks to Amazon's server. If the user activates the Assistant, the Assistant analyzes the contents of the page already displayed on the user's own computer. If needed, it relays the user's instructions and page information to Perplexity's AI servers. "Perplexity's servers never directly access Amazon's servers." The court then states its own conclusion in its own voice: "Perplexity itself does not directly communicate with Amazon's servers."
Layer two is statutory text. Section 1030(a)(2) punishes "whoever" intentionally accesses a protected computer, and the court reads "whoever" as presupposing a person. Its line: "However advanced the Assistant currently is, it is a tool, not a person for statutory purposes." That narrows the question to whether Perplexity used that tool to access Amazon's computers — and on this record the answer is no. Layered on top is the Supreme Court's definition from Van Buren v. United States (2021), that in the computing context "access" means "the act of entering a computer system itself or a particular part of a computer system, such as files, folders, or databases." Receiving screenshots and sending instructions back, the panel held, does not by itself mean Perplexity "gained entry" to Amazon's servers.
Layer three is the rule of lenity, and it's the part with teeth. The CFAA is primarily a criminal statute, and its provisions are interpreted identically in criminal and civil contexts, so ambiguity gets construed against liability. Then the court delivers the warning that should worry every plaintiff planning a similar suit: Amazon's approach, if accepted, "could expose users themselves to criminal liability (under a conspiracy or aiding-and-abetting theory) for facilitating Perplexity's purported unauthorized access." Citing United States v. Nosal, the panel repeated the caution against "transform[ing] whole categories of otherwise innocuous behavior into federal crimes simply because a computer is involved." Its conclusion: "it is unlikely that Congress would have exposed individual users to criminal liability under the CFAA by using the Assistant and Comet browser to access Amazon.com under these facts."
California's CDAFA fell with it. Amazon argued the state statute has a broader definition of "access," simpler permission requirements, and no requirement that information be "obtained." The panel allowed that Amazon might well be right about the breadth — and said it doesn't matter. The relevant prohibition still applies only to "any person" who causes unauthorized access, so the inquiry still centers on the person accessing or causing access. Same answer: the user accesses Amazon using the Assistant as a tool. The two claims rise and fall together.
The equitable analysis is worth reading too, because it wasn't a rubber stamp. The panel first rejected Perplexity's argument that the district court had simply substituted its merits finding for the other Winter factors — it found the district court did discuss each one. But it disagreed on the outcome. On irreparable harm, Amazon's evidence was thin: declarations that the Assistant "may not select the best price, delivery method, or product recommendations for a customer when shopping in the Amazon Store." The panel called that a more abstract harm than the ones recognized in cases like Stuhlbarg, where Customs detained goods already promised to specific customers. And it added a wrinkle: since users choose to run the Assistant, it isn't obvious they'd blame Amazon for a degraded experience.
The cybersecurity argument got cut down harder. Amazon claimed "multiple security researchers corroborated the security risks posed by Perplexity," but Perplexity countered that Amazon's own expert admitted he could not fully replicate those risks and that Perplexity had since addressed them. Of the cyber risks in the expert declaration, only one involved a shopping site at all — and that one wasn't Amazon.com. The panel's verdict: the evidence is "limited and counteracted, at least in part." From there the balance of equities and the public interest followed. An injunction against conduct that likely violates neither statute needlessly burdens a product Perplexity spent large sums developing, and "would impair consumer choice and needlessly limit development of a nascent technology."
| Item | Detail |
|---|---|
| Case | Amazon.com Services, LLC v. Perplexity AI, Inc., 9th Cir. No. 26-1444 |
| Court below | N.D. Cal., 3:25-cv-09514-MMC, Judge Maxine M. Chesney |
| Panel | Milan D. Smith, Jr. (author), Eric C. Tung, John C. Hinderaker (D. Ariz., by designation) |
| Argued / decided | June 11, 2026, Seattle / August 4, 2026 |
| Statutes at issue | CFAA 18 U.S.C. § 1030(a)(2); California CDAFA, Penal Code § 502(c)(7) |
| Core holding | The user, not Perplexity, "accessed" Amazon's computers |
| Reason 1 | Perplexity's servers never directly communicate with Amazon's (screenshot relay) |
| Reason 2 | "Whoever" in § 1030(a)(2) presupposes a person — the Assistant is "a tool, not a person" |
| Reason 3 | Rule of lenity — Amazon's reading could expose users to criminal liability |
| Equitable factors | Irreparable harm, balance of equities, public interest all favor Perplexity |
| Disposition | Preliminary injunction vacated, case remanded |
| Claims left alive | Breach of contract, terms of service, tort theories — expressly reserved |
| Not decided | Authorization and loss elements; a different record or new facts; agentic AI law generally |
The two most consequential rows are the last two. Footnote 5 spells it out: "This outcome does not impair Amazon's ability to regulate access to Amazon.com via private terms of service for its users. On the facts before us, Amazon is simply unlikely to succeed in its attempt to regulate access by invoking the CFAA and the CDAFA." In other words, the court handed Amazon a map. Stop using the hacking statute. Use contract law.
Who actually walked away with something
Perplexity is the obvious winner, but what it won is time rather than victory. A preliminary injunction is not a merits ruling. For five months the flagship capability of an AI browser — shopping on the largest store on the internet — was switched off, which for a company selling an agentic browser means half the product story was missing. The panel captured it exactly when it described the injunction as "needlessly impos[ing] a burden on Perplexity by preventing it from fully operating a product that it spent large sums developing." The feature is back on, and it stays on while the underlying suit grinds through district court, which could take years.
The second winner isn't Perplexity at all — it's every developer standing behind it. That's what EFF emphasized in reacting to the decision: the CFAA has long been a favorite instrument for large companies leaning on smaller ones and on individual developers who build tools that let people reach websites in new ways. This ruling gives those developers appellate-level backing for a simple proposition: writing software that helps a user do something on a website is not, by itself, hacking. Browser extensions, accessibility tools, price comparison utilities, screen readers, ad blockers — all of them sit under the same umbrella logic, because all of them run on the user's machine and act at the user's direction.
The third winner is the user, and this one is not abstract. If the panel had bought Amazon's reading, the logical endpoint was a world where the person who turned on an AI agent to buy socks is a co-conspirator in unauthorized access. The court flagged that explicitly, which means any future plaintiff reaching for the CFAA against an agent developer now has to explain why its theory doesn't criminalize its own customers. That's a hard sentence to write in a brief.
What did Amazon lose? On the surface, one injunction. In practice, leverage. While the injunction stood, Amazon could tell every agent company the same thing: if you want into our store, you take our terms. That lever is gone for now. Amazon's public response was measured — "We respectfully disagree with today's decision on the preliminary injunction," and "We remain confident in our case and are evaluating our next steps." Options remain: a petition for rehearing en banc, a certiorari petition, or simply re-pleading around the CFAA in the district court.
And there's a group that gained nothing at all: everyone else who runs a website. The ruling points platforms toward terms of service and technical controls instead of the hacking statute, and both of those are more work and less powerful. Terms-of-service breach is hard to price in damages. Technical blocking doesn't work well against a counterparty that isn't announcing itself with a user-agent string in the first place. That's precisely why the National Retail Federation, the News/Media Alliance, the Software & Information Industry Association, and an airline trade group all filed briefs. For them this was never somebody else's lawsuit.
hiQ, Power Ventures, Van Buren — the road this statute has already walked
The CFAA was enacted in 1984 as part of the Counterfeit Access Device and Computer Fraud and Abuse Act. Initially it covered only computers holding national security information or financial data, plus computers operated by or for the government. In 1996 Congress broadened it to any "protected computer," which today means basically any machine used in or affecting interstate commerce — that is, nearly everything connected to the internet. From that point on the statute started getting used for things Congress never had in mind. As the Ninth Circuit put it in hiQ Labs v. LinkedIn (2022), the point of the CFAA was "to prevent intentional intrusion onto someone else's computer — specifically, computer hacking."
Start with the case that went the plaintiff's way. Facebook v. Power Ventures (9th Cir. 2016). Power Ventures ran a social aggregation service letting users "see all contacts from many social networking sites on a single page." As part of a promotional campaign, "Power caused a message to be transmitted to the user's friends within the Facebook system." Facebook sent a cease-and-desist; Power kept going; the court found CFAA liability. That is exactly the precedent Amazon built its argument on — that a "relatively ministerial, user-directed task" can still be attributed to the company whose servers direct it.
But the panel didn't overrule Power Ventures. It went around it, and the distinction is careful. In Power Ventures, the court had assumed without discussion that Power "accessed" Facebook; the bulk of that opinion went to authorization, not access. And Power Ventures' own language implied that Power's systems reached Facebook's servers — the panel quotes the line about Power reasonably thinking user consent "was permission for Power to access Facebook's computers." Here, by contrast, Perplexity's servers never touch Amazon's. Same statutory subsection, different plumbing, different result.
Perplexity's preferred precedent was Meta v. BrandTotal (N.D. Cal. 2022), where BrandTotal's UpVoice browser extension passively logged and forwarded "data that users receive from Facebook through their normal use of the website." That court held UpVoice accessed only "the data that Meta has sent to the individual users" and was "not proactively 'accessing' or 'communicating with' Meta's servers," and declined to extend CFAA liability, leaning on the rule of lenity. The Ninth Circuit didn't fully adopt that analogy either. It wrote plainly that "here, the Assistant appears to do more than passive data collection." So the panel kept both precedents at arm's length and went straight to text and lenity instead. That's a deliberate choice, and it's why this opinion is narrower than the headlines suggest.
The success story on the defense side is hiQ Labs v. LinkedIn. hiQ scraped public LinkedIn profiles to build people-analytics products; LinkedIn tried to shut it down with the CFAA; the Ninth Circuit held that "without authorization" doesn't map cleanly onto publicly available data. The lesson pointed the same direction this ruling does — don't let the CFAA become, in the words of United States v. Nosal (9th Cir. 2012, en banc), "an expansive misappropriation statute." That exact phrase shows up on page 10 of the Perplexity opinion.
Capping the arc is Van Buren v. United States (2021), where the Supreme Court read "access" narrowly and put a brake on expansive CFAA theories. That's why this opinion keeps circling back to the phrase "gain entry." Summed up: for roughly fifteen years, plaintiffs who tried to stretch the CFAA have mostly lost. Amazon attempted to restart that expansion using a genuinely new fact pattern — an AI agent — and lost too. The novelty of the technology didn't rescue the theory.
Amazon's next move, and everyone else doing the math
Amazon's first available card is the one the opinion helpfully left on the table. Contract. Page 17 says the court does "not address whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant's actions," and footnote 5 preserves Amazon's ability to regulate access through its terms of service. So the predictable path is to sharpen the terms — an explicit ban on accessing accounts via third-party automated agents — and re-plead around breach of contract and tortious interference theories. The catch is that this route is slower, damages are harder to quantify, and the awkward version of it involves accusing your own customers of breaching their user agreement. That's a terrible look for a retailer.
The second card is technical, and it's arguably what Amazon wanted all along. Remember that this entire dispute started over a user-agent string. Amazon's ask wasn't "never come here" so much as "tell us it's you." With a reliable signal that an AI agent is active, a platform can do anything it wants: block, throttle, meter, charge, or partner. Which is why the industry conversation has already shifted toward cryptographic bot identity — schemes like the Web Bot Auth work Cloudflare has been pushing, where agents sign their requests and only honest, identified agents get through. This ruling narrowed the legal path to control and, in doing so, raised the market value of the technical one.
The third card is the most interesting, because Amazon is playing the mirror image of this game on the other side of the board. In May 2026 Amazon retired Rufus and launched Alexa for Shopping, an agentic assistant built into the main Amazon experience. Among its capabilities is "Buy for Me," which finds an eligible branded product that isn't sold in Amazon's store on another retailer's website and completes the purchase on the customer's behalf using the address and card stored in their Amazon account. It also does auto-buying when an item hits a target price, and Scheduled Actions for recurring purchases. Amazon then went further and packaged the underlying technology through AWS as an agentic shopping assistant other retailers can license. Put those two facts side by side: Amazon fights to keep other companies' agents off its site while selling a product whose entire purpose is putting Amazon's agent onto other companies' sites. Some online sellers pushed back in January 2026, saying they never opted into having Amazon's agent transact on their storefronts. Which means the logic of this ruling — the entity that "accessed" the site is the user who activated the tool — is also the best available defense for Buy for Me. That is a genuinely uncomfortable position from which to petition for rehearing.
Fourth, look at how the rest of the platform world is calculating. On Amazon's October 31, 2025 earnings call, CEO Andy Jassy said the company is "having conversations with and expect, over time to partner with third-party agents," adding "I do think that we will find ways to partner." He compared AI agents to early search engines as a discovery channel — small referral volume today, but not something to dismiss. What retailers actually fear isn't agents arriving; it's agents that compare price and delivery and ignore brand placement and ad inventory entirely. Given how much of Amazon's profit now comes from advertising, agent traffic is traffic with the ad impressions stripped out. This ruling confirmed that door can't be locked with a hacking statute.
Fifth, that means the real front line moves to bot management and metering. When courts narrow the CFAA path, platforms shift to contract and technology; agent companies then either route around the controls or sign deals. Pay-per-crawl models, access control gated on verified agent identity, and revenue-share agreements between retailers and agent operators are where the next few years of this fight actually get settled. Not in a courtroom — in protocol specs and commercial terms.
So what actually changes
If you build AI agents, the practical takeaway compresses into one line: your architecture is your legal exposure. Perplexity won not because its lawyers found an elegant argument but because its servers genuinely never touched Amazon's. The browser on the user's device makes the request; the agent analyzes what's already rendered on that device; Perplexity's servers only send instructions back. Build the same feature with a server-side headless browser or direct server-to-server calls and the outcome plausibly flips. Page 15 leaves that door wide open: "We do not address whether, on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon's servers." If you're designing an agent right now, where execution happens is no longer just a latency and cost decision. It's a liability decision.
If you're on the other side — running a site that agents want to reach — you have the inverse homework. Telling legal to "block them under the hacking statute" is not a strategy anymore, at least not in the Ninth Circuit, which covers California, Washington, and most of the western United States. Three concrete things to do instead. One, audit whether your terms of service actually address automated agent access at the account level, and whether that term is enforceable against the account holder. Two, design the identification layer now — declared user agents, signed bot identity, or a purpose-built agent API — because you cannot make policy about traffic you can't see. Three, rerun the math on whether blocking is even the right call. If agent-mediated sessions convert, gating them with conditions and instrumentation beats pretending you can keep them out.
For investors, one large risk just shrank. Over the past year the biggest unknown hanging over AI browser and agentic commerce startups was whether an incumbent platform could switch the product off with a single lawsuit. This ruling answers that for the most powerful weapon available — a criminal statute with civil teeth and a relatively easy path to preliminary relief. Two caveats worth pricing in, though. First, this is a preliminary-injunction ruling; the merits are still live in district court. Second, the contract and tort routes are untouched, and the risk on those paths did not go down at all. Diligence on any agentic commerce company should now include a hard look at the target platforms' terms of service, not just the statutory analysis.
For ordinary users, the immediate change is small: you can shop Amazon through Comet again. The longer-term change is that the boundary of "what can an AI I turned on do inside my account" is going to get drawn on top of this opinion's logic. The court treated the Assistant as the user's tool — which cuts both ways. If the agent is your tool, a lot of what it does is arguably attributable to you. Who eats the cost when an agent buys the wrong item, ships to a stale address, or falls for a prompt injection embedded in a product page? This opinion doesn't answer that. That's the next lawsuit.
And one note for policy and compliance people. The real meaning of this decision isn't "AI agents are legal." It's confirmation that a 1984 anti-hacking law can't resolve a 2026 agent problem. When a panel says twice in one opinion that it is not building a new legal regime, that's effectively a referral to the legislature. Agent identity disclosure, the formal mechanics of delegating account authority, and allocation of liability for automated transactions are rule-shaped problems, not case-law-shaped problems. Somebody is going to have to write those rules, and right now nobody has.
🥄 Three Things You're Probably Wondering
— So what does this mean for me? Directly, not much beyond being able to shop Amazon through an AI browser again. But if you're building anything that acts on a website on a user's behalf, this matters a lot. Whether that code runs on the user's device or on your servers is now the line between two very different legal risk profiles.
— Why is this happening now? Because agents moved from demos to checkout. Nobody sued when browsers were just summarizing pages. Once an agent started logging into password-protected accounts and paying with a stored card, platforms reacted. Amazon warned Perplexity off before Comet even shipped and sued in November 2025 — the conflict tracked the feature's maturity almost exactly.
— Does this mean Amazon lost? Amazon lost at the preliminary injunction stage. The underlying case is still alive in district court, and the panel expressly left breach of contract and tort claims untouched, so there's plenty of room for Amazon to re-plead. Rehearing en banc and a certiorari petition are both still on the table. The opinion itself says the legal understanding of agentic AI "will doubtless change," so calling this settled would be premature.
Sources
- U.S. Court of Appeals for the Ninth Circuit — Amazon.com Services, LLC v. Perplexity AI, Inc. (No. 26-1444), full opinion
- Cooley — Ninth Circuit Rules on AI Agent 'Access' to Third-Party Websites Under CFAA
- Electronic Frontier Foundation — Appeals Court Agrees with EFF that Building a Web Browser Doesn't Violate the CFAA
- Courthouse News Service — Ninth Circuit lifts block on AI-powered shopping assistant
- PYMNTS — Ninth Circuit Narrows CFAA Reach in Perplexity Agentic Commerce Ruling
- Engadget — Perplexity has successfully overturned Amazon's injunction on its AI shopping bot
- Perplexity — Bullying is Not Innovation (November 4, 2025)
- Cloudflare — Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives
- Amazon — Meet Alexa for Shopping, your personalized, agentic AI assistant on Amazon
- Amazon — AWS Agentic Shopping Assistant: Amazon's AI shopping tech, now for any retailer
- Modern Retail — Amazon CEO expects to 'find ways' to partner with third-party AI shopping agents in the future
- CourtListener — Amazon.com Services LLC v. Perplexity AI, Inc. (3:25-cv-09514) docket
- Medianama — What the Perplexity vs Amazon ruling means for AI agents acting on users' behalf
Numbers and criteria are as of announcement and may change.



