The San Francisco-based 9th U.S. Circuit Court of Appeals has dealt a significant blow to Amazon's legal strategy, overturning a temporary injunction that had prevented Perplexity from deploying its artificial intelligence agents on the e-commerce giant's platform. The decision, handed down on Tuesday, represents a pivotal moment in how American courts understand the legal boundaries of autonomous AI systems operating in digital commerce, a question that has profound implications for the rapidly expanding ecosystem of agentic AI tools being developed globally, including throughout Southeast Asia where e-commerce adoption is accelerating.

The lawsuit between the two companies centres on competing interpretations of what constitutes unauthorized computer access under federal law. Amazon contended that Perplexity's system violated the Computer Fraud and Abuse Act by covertly accessing customer accounts without permission and potentially placing orders without proper authorization. The shopping agent in question, which operates through Comet, Perplexity's browser, required user credentials and could execute transactions on behalf of customers across Amazon's platform. Amazon argued this presented unacceptable security risks to its customers and that the startup had disregarded multiple cease-and-desist communications.

Perplexity mounted a fundamentally different legal argument, one that the appellate court ultimately found persuasive. Rather than accepting Amazon's characterization of its system as the actor accessing the platform, Perplexity successfully argued that the actual "access" was occurring through its users themselves, who deliberately chose to employ the AI agent as their intermediary. Under this interpretation, the end-users—not the company or its technology—held legal responsibility for the access, meaning no violation of the Computer Fraud and Abuse Act had occurred. This distinction proved crucial to the court's reasoning and reflects an emerging understanding of how liability might be allocated in an increasingly AI-mediated digital landscape.

The preliminary injunction that had been issued by a federal judge in California in March had represented a temporary victory for Amazon, based on what the lower court described as "strong evidence" supporting the company's fraud claims. That ruling had effectively shut down Perplexity's shopping functionality on Amazon, significantly constraining one of the startup's core capabilities. The appellate reversal signals that this legal theory may face significant hurdles as it progresses through the courts, though Amazon has indicated it remains committed to its case and is considering what steps to pursue next.

The broader significance of this ruling extends well beyond the immediate dispute between these two companies. This represents the first major federal appellate decision to grapple with the question of whether AI agents operating autonomously on behalf of users can legally access online platforms and execute transactions. The implications ripple across the entire ecosystem of agentic AI development, a sector experiencing explosive growth as companies race to deploy systems capable of browsing the web, making purchases, booking services, and conducting other transactions with minimal human intervention.

Agentic AI systems represent a qualitatively different technology from conventional chatbots or search interfaces. These tools possess the capacity to plan multi-step sequences of actions, reason through problems, and execute tasks across websites with limited oversight. They can log into accounts, navigate authentication systems, read terms of service, evaluate options, and complete transactions—all while operating under the user's explicit direction but without requiring constant human confirmation for each micro-action. This autonomous decision-making capability is precisely what makes them commercially valuable but also what creates legal and security complexities that existing statutes were not designed to address.

Perplexity's statement following the ruling emphasized the company's interpretation of the decision as validating users' fundamental right to choose their preferred AI tools and to have those tools act as their agents in navigating the internet. The company characterized the dispute as ultimately about whether large platforms could effectively exclude AI intermediaries simply by updating their terms of service or blocking certain access patterns. This framing resonates with broader concerns about digital gatekeeping and platform power that have gained traction among regulators and technologists alike.

Amazon countered with a more cautious response, declining to concede the legal argument and signalling that additional litigation remains possible. The company's concerns about security vulnerabilities introduced by unauthorized access patterns reflect legitimate technical considerations. When third-party systems gain the ability to authenticate as users and execute transactions, the attack surface for fraud and account compromise expands significantly. Amazon's perspective emphasizes that platform owners bear ultimate responsibility for customer security and have legitimate interests in controlling how their infrastructure is accessed.

For Malaysian and Southeast Asian readers, the significance of this decision lies partly in how it may influence the regulatory environment for AI development across the region. Southeast Asian countries are actively positioning themselves as AI innovation hubs while simultaneously grappling with how to protect consumers in a digital economy. The precedent established by American courts often influences how courts and regulators in other jurisdictions approach novel technological questions. If agentic AI tools are permitted to operate more freely in the United States, technology companies may accelerate deployment in international markets, including Malaysia, potentially presenting similar policy challenges locally.

The decision also illuminates how existing legal frameworks struggle to accommodate genuine technological innovation. The Computer Fraud and Abuse Act, enacted in 1986, was not drafted with consideration of autonomous software agents acting as legitimate user representatives. Courts must now stretch and reinterpret statutory language developed in a different technological era to address contemporary problems. This gap between legislation and technological reality creates uncertainty for developers and platforms alike and underscores the need for policymakers to engage proactively with emerging technologies rather than relying solely on retrofitting old law to new problems.

Perplexity's victory in this round does not signal unrestricted access to all platforms. The decision specifically addresses the legal question of whether the Computer Fraud and Abuse Act applies to user-authorized access through AI intermediaries. Platforms retain other tools, including contract law through terms of service, intellectual property claims, and potentially legislation specifically designed to address automated access. Amazon and other companies may pursue alternative legal theories or seek regulatory support for their position that certain types of automated access should be restricted.

The practical implications for e-commerce platforms and AI developers remain unsettled. This ruling opens a pathway for agentic AI systems to continue operating on major platforms unless those companies secure victories through alternative legal mechanisms. For consumers, particularly those in markets like Malaysia where mobile-first, AI-assisted shopping experiences are increasingly important, the decision potentially preserves the right to use AI agents as shopping intermediaries, though platforms can still implement technical measures to detect and limit such access.

Looking forward, this decision will likely prompt closer examination of how statutes governing computer access should evolve. Technology companies and legal scholars will scrutinize whether the distinction between user-authorized access through AI agents and unauthorized platform access can be meaningfully maintained, or whether new legal categories are necessary. The 9th Circuit's reasoning provides a template that other jurisdictions may follow, but given the rapid pace of AI development, the law may struggle to keep pace with the expanding capabilities and deployment of agentic systems across the global digital economy.