← к документу

Что изменилось

amazon.com Services, LLC v. Perplexity Ai, Inc. · редакция 1 → 2 · зафиксировано 2026-09-17 03:39 · +13 −13 строк

## FOR PUBLICATION
California enacted the Comprehensive Computer Data Access and Fraud Act (CDAFA), a similar computer access law, in 1987. See Cal. Penal Code § 502. The state legislature’s goal in passing the CDAFA was “to expand the degree of protection afforded to individuals, businesses, and governmental agencies from tampering, interference, damage, and unauthorized access to lawfully created computer data and computer systems.” Id. § 502(a). The CDAFA criminalizes “[k]nowingly and without permission access[ing] or caus[ing] to be accessed any computer, computer system, or computer network,” and also provides a private cause of action. Id. §§ 502(c)(7), (e)(1).
## II. Factual Background a.Perplexity and the Comet Browser
## II. Factual Background a. Perplexity and the Comet Browser
Perplexity is an AI startup and the creator of an AIenabled web browser, Comet. After acquiring another browser company, Sidekick, Perplexity developed Comet and publicly released it in 2025. Comet is a web browser that operates like Google Chrome, running locally on a user’s machine and enabling the user to navigate the Internet. According to Perplexity, Comet’s differentiating feature is an optional AI “agent” (the Assistant) that “can perform tasks at the user’s direction, such as browsing websites like Amazon.com to shop for requested goods.”
When a Comet user directs the Assistant to locate an item on Amazon.com, the Assistant takes screenshots of the browser view, sends those screenshots from the user’s computer to Perplexity’s servers, and receives instructions from Perplexity’s servers on how to navigate Amazon.com. In other words, the Assistant cannot operate wholly independently; it relies on direction from the user and instructions from Perplexity’s servers.
## b.Amazon and the Amazon Store
## b. Amazon and the Amazon Store
Amazon owns and operates Amazon.com, also known as the Amazon Store. Customers may create Amazon.com accounts, which, according to Amazon, allow them to “manage orders, store payment information and delivery addresses, receive personalized recommendations, track purchases, and process returns within their passwordprotected accounts.” Amazon also operates in the AI space and launched agentic AI products in 2025.
## c.The Comet Agent and the Amazon Store
## c. The Comet Agent and the Amazon Store
Before Comet’s release, Amazon told Perplexity’s CEO that Perplexity’s AI products would not be permitted to access the Amazon Store. After Perplexity launched Comet and the Assistant accessed the Amazon Store, Amazon again informed Perplexity that it did not have authorization to do so. At the core of the dispute was Perplexity’s decision not to use a “user-agent string,” a mechanism “that would communicate that the user has activated an AI agent.” That user-agent string would allow Amazon to block the
## Assistant’s access to the Amazon store.1 d.Procedural History
## Assistant’s access to the Amazon store.1 d. Procedural History
Amazon filed its Complaint in November 2025, alleging violations of the CFAA and the CDAFA. Amazon also moved simultaneously for a preliminary injunction. In March 2026, the district court held a hearing on the motion and issued a tentative ruling in Amazon’s favor, indicating that it was a close call. The district court soon after issued a written order granting Amazon’s requested preliminary injunction on the grounds that Amazon had shown a likelihood of success on its CFAA claims under § 1030(a)(2)
The party requesting a preliminary injunction must show that “(1) they are likely to succeed on the merits; (2) they are likely to suffer irreparable harm in the absence of preliminary relief; (3) the balance of equities tips in their favor; and (4) a preliminary injunction is in the public interest.” Sierra Forest Legacy, 577 F.3d at 1021 (citing Winter v. Nat. Res. Def. Council, Inc., 555 U.S. 7, 20 (2008)). We have “adopted a sliding-scale approach to the Winter factors,” where “serious questions going to the merits and a hardship balance that tips sharply toward the plaintiff can support issuance of an injunction, assuming the other two elements of the Winter test are also met.” Bennett v. Isagenix Int’l LLC, 118 F.4th 1120, 1126 (9th Cir. 2024) (internal quotation marks omitted).
## a.Amazon is unlikely to succeed on the merits of its
## a. Amazon is unlikely to succeed on the merits of its
CFAA and CDAFA claims.
## i.Amazon’s CFAA Claim
To bring a successful § 1030(a)(2) claim pursuant to the CFAA private right of action, Amazon must show that Perplexity “(1) intentionally accessed a computer, (2) without authorization or exceeding authorized access, and that [Perplexity] (3) thereby obtained information (4) from any protected computer (if the conduct involved an interstate or foreign communication), and that (5) there was loss to one or more persons during any one-year period aggregating at least $5,000 in value.” SeeLVRC Holdings LLC v. Brekka, 581 F.3d 1127, 1132 (9th Cir. 2009). We have cautioned against interpretations that “would transform the CFAA from an anti-hacking statute into an expansive misappropriation statute.” United States v. Nosal (Nosal I), 676 F.3d 854, 857 (9th Cir. 2012) (en banc).
## i. Amazon’s CFAA Claim
To bring a successful § 1030(a)(2) claim pursuant to the CFAA private right of action, Amazon must show that Perplexity “(1) intentionally accessed a computer, (2) without authorization or exceeding authorized access, and that [Perplexity] (3) thereby obtained information (4) from any protected computer (if the conduct involved an interstate or foreign communication), and that (5) there was loss to one or more persons during any one-year period aggregating at least $5,000 in value.” See LVRC Holdings LLC v. Brekka, 581 F.3d 1127, 1132 (9th Cir. 2009). We have cautioned against interpretations that “would transform the CFAA from an anti-hacking statute into an expansive misappropriation statute.” United States v. Nosal (Nosal I), 676 F.3d 854, 857 (9th Cir. 2012) (en banc).
In its short written order, the district court stated: “Amazon has provided strong evidence that Perplexity, through its Comet browser, accesses with the Amazon user’s permission but without authorization by Amazon, the user’s password-protected account, thereby obtaining information as to the user’s private Amazon account information, and that such information is transmitted to Perplexity’s servers for the purpose of conducting said user’s requested tasks,” and “Amazon has submitted essentially undisputed evidence that it has expended significantly more than $5,000 in responding to such circumstances, including, for example, costs attributable to numerous hours spent by Amazon employees in developing tools to block Comet’s access to its private customer accounts and detecting future unauthorized access by Comet.” The district court erred, however, in its “access” analysis.
## CFAA claim.4
This conclusion is further reinforced by the rule of lenity. As previously discussed, the CFAA is “primarily a criminal statute” and courts’ interpretation of its provisions are “equally applicable” in the civil and criminal contexts. Brekka, 581 F.3d at 1134. Thus, the rule of lenity guides our interpretation, meaning we construe “any ambiguity” as to statutory meaning against liability. Id. at 1135 (internal quotation marks omitted). To be sure, the rule of lenity applies only where the statute at issue “is truly ambiguous.” United States v. LeCoe, 936 F.2d 398, 402 (9th Cir. 1991); see alsoShular v. United States, 589 U.S. 154, 165 (2020). Even accepting Amazon’s approach as reasonable, imposing liability here would require a novel interpretation far afield from the statute’s purpose “to prevent intentional intrusion onto someone else’s computer—specifically, computer hacking.” hiQ, 31 F.4th at 1196. Another note of caution: Amazon’s approach, if accepted, could expose users themselves to criminal liability (under a conspiracy or aiding-and-abetting theory) for facilitating Perplexity’s purported unauthorized access to Amazon’s servers. We are conscious of precedent cautioning against “transform[ing] whole categories of otherwise innocuous behavior into federal crimes simply because a computer is involved” or “criminaliz[ing] a broad range of day-to-day activity.” Nosal I, 676 F.3d at 860, 862 (internal quotation marks omitted). In our view, it is unlikely that Congress would
This conclusion is further reinforced by the rule of lenity. As previously discussed, the CFAA is “primarily a criminal statute” and courts’ interpretation of its provisions are “equally applicable” in the civil and criminal contexts. Brekka, 581 F.3d at 1134. Thus, the rule of lenity guides our interpretation, meaning we construe “any ambiguity” as to statutory meaning against liability. Id. at 1135 (internal quotation marks omitted). To be sure, the rule of lenity applies only where the statute at issue “is truly ambiguous.” United States v. LeCoe, 936 F.2d 398, 402 (9th Cir. 1991); see also Shular v. United States, 589 U.S. 154, 165 (2020). Even accepting Amazon’s approach as reasonable, imposing liability here would require a novel interpretation far afield from the statute’s purpose “to prevent intentional intrusion onto someone else’s computer—specifically, computer hacking.” hiQ, 31 F.4th at 1196. Another note of caution: Amazon’s approach, if accepted, could expose users themselves to criminal liability (under a conspiracy or aiding-and-abetting theory) for facilitating Perplexity’s purported unauthorized access to Amazon’s servers. We are conscious of precedent cautioning against “transform[ing] whole categories of otherwise innocuous behavior into federal crimes simply because a computer is involved” or “criminaliz[ing] a broad range of day-to-day activity.” Nosal I, 676 F.3d at 860, 862 (internal quotation marks omitted). In our view, it is unlikely that Congress would
4 We do not address the remainder of the CFAA factors, including the scope of the CFAA’s loss provision, because they are “unnecessary to resolve this case.” Safari Club Int’l v. Haaland, 31 F.4th 1157, 1178 n.1 (9th Cir. 2022).
Because we recognize that agentic AI is an emerging technology, we reiterate what this opinion is not. We do not establish a new legal regime governing agentic AI. We do not address whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant’s actions. Our holding here is limited to “access” as contemplated by the CFAA and as applied to the Assistant’s interactions with Amazon.com on the record before us, not the broader legal landscape surrounding agentic AI. The legal understanding of agentic AI will doubtless change as AI technology grows increasingly sophisticated. For now, this opinion reflects and applies to the state of technology only as presented in the filings in this case.
## ii.Amazon’s CDAFA Claim
## ii. Amazon’s CDAFA Claim
The CDAFA, the California state law analogue to the CFAA, similarly focuses on “conduct such as hacking into and tampering with computer systems and data, and the disruptions and costs of such conduct to the business of public and private entities.” Teran v. Superior Ct., 334 Cal. Rptr. 3d 299, 308 (Cal. Ct. App. 2025). However, the “statutes are different” in certain ways. United States v. Christensen, 828 F.3d 763, 789 (9th Cir. 2016). Amazon argues that the CDAFA has a broader definition of “access,” simpler permission requirements, and no requirement that information is “obtained.”
Ultimately, Amazon’s CFAA and CDAFA claims rise and fall together. The CDAFA defines “access” to mean, among other things, “caus[ing] input to [or] data processing with . . . the logical, arithmetical, or memory functions of a computer, computer system, or computer network.” Cal. Penal Code § 502(b)(1). And the relevant prohibition applies only to “any person” who causes unauthorized access. Id. § 502(c)(7). While Amazon might be correct that “access” under the CDAFA is broader than the CFAA’s definition, the focus of the inquiry is still on the person accessing or causing the access. Accordingly, we arrive at the same conclusion: the user (not Perplexity) accesses Amazon using the Assistant as an AI tool, and thus Amazon is unlikely to succeed on the merits of its CDAFA claim.
## b.The district court erred in concluding that the
## b. The district court erred in concluding that the
remaining injunction factors favored Amazon.
## Irreparable Harm
The district court reasoned that Amazon would suffer irreparable harm absent an injunction because Perplexity “will continue to engage in the above-referenced challenged conduct.” While the district court might be correct that a showing of likelihood of success on the merits is sufficient to establish a likelihood of irreparable harm, seeFacebook, Inc. v. Power Ventures, Inc., 252 F. Supp. 3d 765, 782 (N.D. Cal. 2017), aff’d, 749 F. App’x 557 (9th Cir. 2019), Amazon failed to make that showing here. Irreparable harm is thus a closer question.
The district court reasoned that Amazon would suffer irreparable harm absent an injunction because Perplexity “will continue to engage in the above-referenced challenged conduct.” While the district court might be correct that a showing of likelihood of success on the merits is sufficient to establish a likelihood of irreparable harm, see Facebook, Inc. v. Power Ventures, Inc., 252 F. Supp. 3d 765, 782 (N.D. Cal. 2017), aff’d, 749 F. App’x 557 (9th Cir. 2019), Amazon failed to make that showing here. Irreparable harm is thus a closer question.
As a general matter, “[e]vidence of threatened loss of prospective customers or goodwill certainly supports a finding of the possibility of irreparable harm.” Stuhlbarg Int’l Sales Co. v. John D. Brush & Co., 240 F.3d 832, 841 (9th Cir. 2001). But Amazon puts forth only weak evidence as to the actual threat of such harm. It cites declarations claiming that the Assistant “may not select the best price, delivery method, or product recommendations for a customer when shopping in the Amazon Store,” which suggest that the Assistant leads to a degraded shopping experience. These types of harms, though, are more attenuated than the harms recognized in other “threat of harm” cases. In Stuhlbarg, for example, the risk of harm arose from the United States Customs Service’s detention of goods already promised to new customers with large orders. Id. at 840–41. The harm to goodwill was obvious because those customers would not receive the specific product they ordered. By comparison, the degradation of the overall Amazon.com shopping experience is more abstract, as is the degree to which users would hold the Assistant responsible for any such degradation given their choice to employ it.
Because Amazon has failed to show a likelihood of success on the merits of its claims, its arguments regarding the harm to Perplexity from an injunction fall flat. An injunction here, where it is unlikely that Amazon will be able to establish statutory violations, needlessly imposes a burden on Perplexity by preventing it from fully operating a product that it spent large sums developing. As a result, the balance of the equities favors Perplexity and weighs against an injunction.
Similarly, an injunction against conduct that likely does not violate the CFAA or the CDAFA would not serve the public interest. Instead, such an injunction would impair consumer choice and needlessly limit development of a nascent technology.5 The public interest thus favors Perplexity.
Similarly, an injunction against conduct that likely does not violate the CFAA or the CDAFA would not serve the public interest. Instead, such an injunction would impair consumer choice and needlessly limit development of a nascent technology. 5 The public interest thus favors Perplexity.
## CONCLUSION
6 Perplexity’s motion to file documents under seal, Dkt. 28, is GRANTED.