
An injunction win is not a licence for every shopping agent
The Ninth Circuit’s Perplexity opinion turns on who accessed Amazon in the record before it. Architecture matters more than a sweeping claim that agent commerce is settled.
I would put an architecture diagram beside this ruling before putting a victory headline in a product plan. The useful question is whether the behaviour the court analysed resembles the system we intend to ship.
On August 4, the Ninth Circuit vacated the preliminary injunction against Perplexity and remanded the case. Its analysis of access under the Computer Fraud and Abuse Act treated the user as accessing Amazon through the Assistant on the record before it. Perplexity receiving screenshots and providing instructions did not, by themselves, establish its access in those circumstances.
The opinion expressly limits the reach of that conclusion. It does not announce a new legal regime for agentic AI or decide every possible arrangement. The procedural posture also remains relevant: this was an appeal concerning a preliminary injunction.
That is a meaningful ruling. Calling it merely procedural would understate the analysis. Calling it universal permission for shopping agents would overstate it.
The opinion does not hand liability to users
One tempting interpretation is that identifying the user as the accessor transfers liability from the vendor to the user. I would not make that claim. The opinion discusses potential criminal exposure for users as a reason to reject the broader interpretation advanced by Amazon, not as a new liability regime it is imposing on them.
That distinction changes the takeaway. We should read what the court decided and the reasoning it used, rather than convert a discussion of an undesirable consequence into the holding itself.
It also leaves room for unresolved questions. A decision about a particular statutory issue and record cannot answer every contractual, privacy or operational question a product team might have. Identifying those limits is part of using the ruling accurately, not an attempt to make the result disappear.
Compare the control flow before borrowing the conclusion
Consider two hypothetical designs. In one, a person directs an assistant operating through their browser. In another, a service independently visits websites from infrastructure it controls and later presents the results to a customer. Describing both as “an agent shopping for a user” hides differences that deserve examination.
I am not assigning a legal outcome to either design. I would document who initiates access, where actions run, which credentials are used, what the provider receives and how much independent control it exercises. Qualified reviewers can then assess the actual facts against the opinion and the rest of the relevant law.
The same exercise is useful when the product changes. Moving an operation from a user's device to a server may look like a performance improvement on a roadmap. It can also change the facts on which a previous assessment depended.
I would therefore keep the legal review attached to a versioned description of behaviour. A note that says “Perplexity won” is not enough to show which design was assessed or why the reasoning was considered relevant.
The opportunity for useful agent commerce remains worth pursuing. It becomes easier to reason about when the team can distinguish a court's actual conclusion from the much larger category of products that commentators place beneath it.
Borrow the reasoning of a ruling only after comparing the actual control flow; a shared product label does not establish shared legal facts.


