Agentic AI Deserves a Presumption of Authorization
By Zefang (Jeff) Wu - Edited by Min Su Kim
Zefang (Jeff) Wu is Assistant Vice President at GIC Private Limited (“GIC”). He was previously an attorney at Davis Polk & Wardwell LLP. He received his Juris Doctor degree from New York University School of Law and his Bachelor of Science degree from University of California, Berkeley. The views expressed in this Commentary are solely those of the author and do not represent the views of GIC, its affiliates, or its investment activities.
Introduction
2026 is the year of agentic artificial intelligence (“AI”). The technology has evolved from passive systems that respond to prompts to proactive agents that solve problems on users’ behalf. In March 2026, that momentum collided with the Computer Fraud and Abuse Act (the “CFAA”) when a federal district court enjoined Perplexity from deploying its browser agent, the “Assistant,” [1] to assist Amazon users with their shopping requests (Perplexity I). [2]
A CFAA claim requires, among other elements, that the defendant (1) accessed a computer (2) without authorization. [3] Basing its decision on a decade-old social media access case, the district court drew a sharp distinction between user consent and platform authorization and concluded that Perplexity lost its right to access Amazon when Amazon revoked its permission. [4] In August 2026, the Ninth Circuit vacated that injunction, holding at the access element that Amazon was unlikely to succeed because the user, rather than Perplexity, “accesses” Amazon’s computers “with the help of the Assistant” (Perplexity II). [5] The panel’s reasoning turned on the Assistant’s architecture, which on the record operates through the browser on the user’s computer, so that “Perplexity itself does not directly communicate with Amazon’s servers.” [6] Architecture—that is, the location from which the agent communicates—thus became the criterion for deciding whether an AI provider is the accessor under the CFAA.
However, the agentic ecosystem is increasingly moving to the AI provider’s servers and virtual computers and away from the user’s local system. [7] The panel expressly left open whether an AI provider’s “control over the [agent]” could, on a different record, amount to “gain[ing] entry to [the platform’s] servers.” [8] The architecture of AI agents, therefore, is not a durable way to determine the identity of the accessor under the CFAA.
This Commentary argues that the identity of the accessor turns not on the agent’s architecture but on its fidelity to the user, manifested in the agent’s actions. A provider whose agent follows its user’s directions should presumptively inherit that user’s authorization, unless the AI provider’s independent use of the session shows the agent has stopped running the user’s errand and started serving the provider’s own. That line comes from a long-standing principle in agency law: delegated authority reaches only as far as the purpose for which it was conferred. [9]
I. The Doctrinal Gap
The CFAA creates criminal and civil liability for whoever “intentionally accesses a computer without authorization . . . .” [10] In the existing case law and literature, the identity of the accessor is rarely contested; the fight is nearly always over whether the accessor is authorized. [11] An AI agent acting at the direction of its human user but operating on its provider’s infrastructure raises a gating question: whose access right is being tested?
Two framings compete to answer that question. The extension framing tests the user’s access. It describes the provider as an extension of the user, no different from the browser from which she already shops, transmitting her commands and returning the results to her alone. [12] The distinct accessor framing tests the provider’s access. It describes the provider as an independent accessor, akin to a friend dispatched to shop on the user’s behalf, whose access must be authorized in its own right. [13]
The Perplexity I court, ruling first on these facts, adopted the distinct accessor framing on Power Ventures’ reasoning. [14] In Power Ventures, the court held that Power, a rival social media platform to Facebook, “needed authorization both from individual Facebook users . . . and from Facebook” to access user data after Facebook had revoked Power’s access. [15] In contrast, the Perplexity II panel adopted the extension framing, relying on the local architecture of the agent to show that it was the user, not the provider, who accessed Amazon through the agent. [16] The panel did not overrule Power Ventures, but relegated it to the authorization element, to be reached only after the plaintiff proves that the AI provider was the statutory accessor. [17]
A gap emerges from these cases. There must be a rule for choosing between the extension framing and the distinct accessor framing to resolve the identity of the accessor. The next section introduces, as that rule, a presumption of inherited authorization based on the agent’s actions rather than its architecture, defeasible by provider-side intervention.
II. The Presumption: AI Providers Inherit the User’s Authorization
The threshold question is doctrinally familiar. Courts already distinguish between extensions of a user and distinct accessors in doctrinal areas adjacent to the CFAA and under its state analogues. Under the California Invasion of Privacy Act, a vendor that records a party’s communications without using the data for its own purpose has been treated as “an extension” of that party rather than as “a third-party eavesdropper.” [18] The Ninth Circuit drew the same line for a commercial intermediary in Oracle USA, Inc. v. Rimini Street, Inc. Rimini, a third-party support vendor, used its own automated tools to download Oracle’s support materials on behalf of Oracle’s licensees, in a manner Oracle’s terms of use prohibited. Applying California’s Comprehensive Computer Data Access and Fraud Act (“CDAFA”), the CFAA’s state analogue, the court held that “taking data using a method prohibited by the applicable terms of use, when the taking itself generally is permitted, does not violate the CDAFA.” [19] The key was “whether Rimini was authorized in the first instance to take and use the information that it downloaded”—an authorization that ran from the licensees who Rimini supported. [20]
Across these settings, the label turns on whose errand the access serves. By design, AI agents are built to execute the tasks their users assign and leading AI providers have trained their models to follow user directions. [21] Because executing the user’s task is what these systems are built to do, courts should presume that an agent executing a user’s task serves her errand and carries her access rights. The platform must then show that a particular access served the provider’s own interests rather than the user’s requests.
Three considerations support this presumption. First, the presumption rests on ordinary principles of agency. As Kerr observes, “[s]etting up the authentication gate and granting a user account confers rights on the account holder and her agents.” [22] Those rights, however, are narrower than the user’s own, limited to the extent of the delegated task and acts “necessary or incidental to achieving the principal’s objectives.” [23] Agency law has long viewed software in just this way: “computer programs are instrumentalities of the persons who use them,” because a program is not a person with “legal capacity to possess rights and incur obligations.” [24] It follows that what can hold, and exceed, delegated authority is not the code but the provider behind it. Whether the provider deviated from the user’s objective is therefore a question agency law already answers with its scope-of-authority and loyalty rules. [25]
Second, a user who may enter does not lose that authorization by choosing the wrong instrument. Van Buren makes authorization a gates-up-or-down inquiry, holding that “one either can or cannot access a computer system, and one either can or cannot access certain areas within the system.” [26] There, a police sergeant ran a license plate search he was entitled to run, in exchange for a payment his department’s policy forbade. The Court held that he had not exceeded authorized access because the policy limited the purpose of his search rather than his entry. [27] Reading such restrictions into the statute, the Court warned, would criminalize “a breathtaking amount of commonplace computer activity.” [28] A platform’s objection to a particular agent is a restriction of the same kind, reaching the user’s manner of access rather than the access itself. [29] A statute that does not make a user’s violation of website terms a federal crime should not make a crime of her choice of software through the same words.
Third, the CFAA’s criminal character explains why the rule should take the form of a presumption. A criminal statute must give fair notice, and the panel construed “any ambiguity” in the CFAA against liability. [30] Without a presumption, whether a given transaction is a federal crime turns on which machine the software happens to run from and whether the platform has objected to the tool—facts no party can see at the moment of access. Present AI systems “do not have intentions in the way that humans do,” so the statute’s intent element must in any event rest on a human principal. [31] The presumption locates it in the user whose errand the agent was running, an answer that does not shift with the platform’s countermeasures or the provider’s architecture. The Ninth Circuit recognized the danger of the alternative when it warned that Amazon’s reading “could expose users themselves to criminal liability (under a conspiracy or aiding-and-abetting theory)” for directing the very errand they wanted run. [32] The rule accordingly takes the form of a presumption, displaced only when a platform identifies a particular access that served the provider’s own ends rather than the user’s errand. Section III describes what that showing requires.
III. The Exception: When Providers Appropriate User-Directed Access
The presumption of inherited authorization must yield when the provider has stopped serving as an extension of the user and has instead begun operating with independent objectives in the access. Otherwise, commercial AI providers could shelter any independent activity behind a user’s credentials, and the CFAA’s anti-hacking core would erode from a different direction.
The proposed exception rests on the same agency principles that ground the presumption. An agent’s actual authority covers only what the principal authorizes and what is necessary or incidental to achieving the principal’s objectives, so the purpose for which delegated power may be used is narrower than the power itself. [33] An agent that utilizes the principal’s instrument for its own ends acts outside that authority and breaches its duty to act “loyally for the principal’s benefit in all matters connected with the agency relationship.” [34] Agency law has carried the same idea in the image of frolic and detour, articulated in Joel v. Morison [35] and preserved in modern respondeat superior doctrine. [36]
Carried into the CFAA, the scope-of-authority inquiry hinges on whether the provider has stepped off the user’s errand. A provider has done so when its use of the session goes beyond what is instrumental to executing the user’s immediate command. A user who asks an agent to complete a purchase plausibly consents to the provider processing her request through its infrastructure to execute it. Without more, she does not plausibly consent to her credentials serving as a point of entry for the provider’s own commercial projects. Granted, the inquiry might seem beyond the platform’s reach because the errand is defined by an instruction the platform never sees. [37] But the provider’s requests reach the platform’s own servers, where they can be examined and identified, [38] and the rest can be developed through discovery. If the record does not connect a particular access to one of the provider’s own objectives, the entry is authorized to the same extent the user’s own entry would be, and the claim proceeds through the CFAA’s remaining elements. [39]
The exception is not triggered in Perplexity. The district court’s finding shows that the Assistant “accesses with the Amazon user’s permission” and transmits session data to its servers “for the purpose of conducting said user’s requested tasks.” [40] On these findings, the Assistant acts as an extension of the user, using her credentials to complete routine transactions on her behalf. The transmission of session data is strictly tethered to executing the immediate user request, and nothing in the record suggests that the provider is appropriating that access to fuel independent projects.
Nor does the Assistant’s alleged spoofing (employed to preserve user-directed functionality after Amazon deployed technical blocks against the tool) rebut the presumption. [41] Amazon’s block was different from the authentication gate endorsed by Van Buren; it was keyed not to the user’s credentials, which remained valid, but to the software the authenticated user employed. [42] The user’s gate stayed up and only her choice of tool was targeted. A restriction on the means of authorized access is a terms-of-service limit dressed in code, and Van Buren expressly reserved whether such non-credential limits count as gates at all. [43] The record does not suggest that Perplexity’s spoofing did more than continue executing users’ requested shopping tasks.
Perplexity’s posture is typical of the broader agentic ecosystem. Mainstream user-directed tools execute user commands with the user’s credentials and rely on provider infrastructure in ways incidental to completing the task. [44] They differ from one another in countless ways, but those differences are rooted in contract, consumer disclosure, and competition law, not in the CFAA. The exception should be reserved for providers that have stepped off the user’s errand to pursue their own objectives. Perplexity, on the record as it stands, has not.
IV. The CFAA Is the Wrong Instrument
Confining the CFAA this way does not leave platforms unprotected or deny their real interests in security and fraud prevention. The question is which legal instrument should do the protecting. Treating every terms-of-service violation by user-directed software as federal hacking stretches the CFAA well past its anti-hacking purpose, exposing developers to criminal liability for what is, at bottom, a commercial dispute. [45]
Platforms already possess robust tools for governing third-party access without recourse to criminal law. [46] Most directly, platforms can suspend or terminate the accounts of users who violate the terms of service, which are enforceable as contract claims. Technical measures let them detect and block automated traffic. [47] Copyright infringement, misappropriation, and unjust enrichment protect their proprietary information. [48] Privacy and consumer-protection law govern the provider’s data practices vis-à-vis the user, so the CFAA’s retreat does not leave users unprotected either. [49] Finally, the common law of agency allocates responsibility for the agent’s conduct between user and provider according to who was running whose errand. [50]
The current dispute illustrates why the distinction matters, and Amazon’s choice of remedy is itself revealing. Amazon’s terms of service permit it to terminate the accounts of users who direct AI agents in violation of those terms. [51] Nothing in the record suggests it has done so against any user directing the Assistant, even as it has spent considerable resources pursuing Perplexity in federal courts. The same picture emerges from Amazon’s own agentic conduct. Even as Amazon invokes the CFAA against Perplexity, Amazon operates its own agentic shopping feature, “Buy for Me,” which completes purchases on third-party retailers’ sites on behalf of Amazon’s users. [52] The contradiction is less important than the structure it exposes: a platform-veto rule, under which any platform can subject an AI provider to federal liability simply by objecting to the agent’s access, cannot survive a world in which every major platform is both a host to incoming AI agents and a deployer of outgoing ones.
The industry is already moving toward the contract-based model the presumption of inherited authorization contemplates. Shopify has launched “Agentic Storefronts,” which enable AI agents to discover products and natively execute secure checkouts using Shopify’s infrastructure. [53] OpenAI and Stripe have built a parallel open standard, the Agentic Commerce Protocol, which lets merchants sell through AI agents while remaining the merchant of record. [54] Google and the major payment networks are converging on the same approach. [55] Even the largest retailers are joining as deployers. [56] These platforms are not trying to keep AI agents out but are building the infrastructure to let them in on negotiated terms.
Conclusion
The Amazon v. Perplexity saga began and ended with the same question unanswered: whose access should the CFAA test when an AI agent accesses a platform? The district court tested Perplexity’s access, treating the provider as a distinct accessor and letting Amazon’s revocation terminate its access. [57] The Ninth Circuit tested the user’s access, treating the Assistant as the user’s tool and removing Perplexity from the picture altogether. [58] Neither framing is a durable rule for the evolving agentic ecosystem. The panel recognized as much when it reserved whether an AI provider’s control over the agent may amount to gaining entry to the platform’s servers. [59]
This Commentary’s answer is the one agency law has always given: ask whose errand the agent was running. An agent executing the task its user assigned is her instrument, no matter where its server communicates from. The provider behind such an agent should presumptively inherit its user’s authorization, unless the provider converts the session into its own project and becomes an accessor reachable by the CFAA. [60] This inquiry thus resolves both the identity of the accessor and the scope of the authorization, and turns on the agent’s actions rather than its architecture.
On the present record, this rule places the Assistant within the broader ecosystem of user-directed software, including browser extensions, password managers, accessibility tools, and other AI agents that presumptively inherit their user’s access rights. The legal baseline courts adopt will determine whether agentic commerce develops through negotiated channels or under the shadow of federal criminal liability. By confining the CFAA to genuine computer intrusion and leaving commercial access disputes to contract and tort, courts can ensure that the next generation of AI is governed by negotiation and open standards, not prosecution.
[1] The Assistant is the agentic feature of Perplexity’s Comet web browser capable of shopping on users’ behalf. See Comet, Perplexity, https://www.perplexity.ai/comet.
[2] See Amazon.com Servs. LLC v. Perplexity AI, Inc., No. 3:25-cv-09514-MMC, slip op. at 3 (N.D. Cal. Mar. 9, 2026) [hereinafter Perplexity I] (citing Facebook, Inc. v. Power Ventures, Inc., 844 F.3d 1058, 1068 (9th Cir. 2016), for its holding that “consent that [defendant] had received from [plaintiff’s] users was not sufficient to grant continuing authorization to access [plaintiff’s] computers after [plaintiff’s] express revocation of permission”).
[3] See LVRC Holdings LLC v. Brekka, 581 F.3d 1127, 1132 (9th Cir. 2009).
[4] Perplexity I, slip op. at 3 (finding that Amazon has shown a likelihood of success on the merits of its claim under 18 U.S.C. § 1030(a)(2)).
[5] Amazon.com Servs. LLC v. Perplexity AI, Inc., No. 26-1444, slip op. at 15 (9th Cir. Aug. 4, 2026) [hereinafter Perplexity II] (“To be sure, Perplexity may receive screenshots of the user’s browser and may communicate instructions to the Assistant. But those activities, by themselves, do not mean that Perplexity has ‘accessed’ (gained entry) to Amazon’s servers.”); id. at 16 n.4 (declining to reach “the remainder of the CFAA factors”).
[6] Perplexity II, slip op. at 13–14.
[7] See Introducing ChatGPT Agent: Bridging Research and Action, OpenAI (July 17, 2025), https://openai.com/index/introducing-chatgpt-agent/ (“ChatGPT carries out these tasks using its own virtual computer.”).
[8] Perplexity II, slip op. at 15.
[9] Restatement (Third) of Agency § 2.02(1) (A.L.I. 2006); see also Joel v. Morison (1834) 172 Eng. Rep. 1338 (KB) (confining a master’s liability to conduct within the scope of the assigned errand, not a servant’s independent frolic).
[10] 18 U.S.C. § 1030(a)(2)(C).
[11] See Van Buren v. United States, 593 U.S. 374, 382–83 (2021) (noting that “[t]he parties agree that Van Buren ‘access[ed] a computer with authorization’” and that “[t]he dispute is whether Van Buren was ‘entitled so to obtain’” the record); Orin S. Kerr, Norms of Computer Trespass, 116 Colum. L. Rev. 1143, 1145 (2016) (observing that in recent CFAA cases “the line between guilt and innocence hinged on a dispute over authorization”); Andrew Sellars, Twenty Years of Web Scraping and the Computer Fraud and Abuse Act, 24 B.U. J. Sci. & Tech. L. 372, 391–92 (2018) (noting that how to interpret “without authorization” and “exceed[ed] authorized access” “has been at the center of a very large portion of the discussion about the CFAA”); cf. id. at 413 (observing that shared-credential cases have favored “the website’s authorization over the account holder’s authorization, but without much consideration of the question”).
[12] See Perplexity II, slip op. at 11 (recording Perplexity’s analogy of the Assistant to “an Apple user accessing Amazon.com via the Safari web browser, even if ‘the Safari software automatically fills in the user’s address and payment information at checkout on the user’s behalf’”); id. at 15 (concluding that “[i]t is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com”).
[13] See Facebook, Inc. v. Power Ventures, Inc., 844 F.3d 1058, 1068 (9th Cir. 2016) (holding that permission from Facebook users “was not sufficient to constitute authorization” after Facebook’s revocation because, “for Power to continue its campaign using Facebook’s computers, it needed authorization both from individual Facebook users (who controlled their data and personal pages) and from Facebook (which stored this data on its physical servers)”).
[14] Perplexity I, slip op. at 3; see supra note 2.
[15] Power Ventures, 844 F.3d at 1068.
[16] See Perplexity II, slip op. at 15; see also id. at 6 (describing Comet as “running locally on a user’s machine”).
[17] See Perplexity II, slip op. at 13 (acknowledging that the Power Ventures court “assumed without discussion that Power ‘accessed’ Facebook for CFAA purposes,” and that “[t]he bulk of the analysis was devoted to authorization, not access”).
[18] Graham v. Noom, Inc., 533 F. Supp. 3d 823, 832 (N.D. Cal. 2021) (treating a vendor that obtained no independent benefit as an extension of a party rather than a third-party interceptor). Courts applying Cal. Penal Code § 631(a) have since divided over the test for making this sort, though not over the sorting itself. See Ambriz v. Google, LLC, No. 23-cv-05437-RFL, slip op. at 5–6 (N.D. Cal. Feb. 10, 2025) (describing the split and adopting the competing “capability test”).
[19] Oracle USA, Inc. v. Rimini St., Inc., 879 F.3d 948, 968 (9th Cir. 2018), rev’d in part on other grounds, 586 U.S. 334 (2019).
[20] Id. (distinguishing Power Ventures on the ground that Rimini’s taking was itself permitted).
[21] See, e.g., OpenAI, Model Spec (Dec. 18, 2025), https://model-spec.openai.com/2025-12-18.html (providing that the assistant “must not adopt, optimize for, or directly pursue any additional goals as ends in themselves,” including “revenue or upsell for OpenAI,” and stating that “[w]e are training our models to align to the principles in the Model Spec”); see also Anthropic, Piloting Claude in Chrome (Aug. 25, 2025), https://claude.com/blog/claude-for-chrome (describing a browser agent through which “trusted users can instruct Claude to take actions on their behalf”).
[22] Kerr, supra note 11, at 1180 (“When authorized by the account holder . . . the third party has narrower rights only to act as the account holder’s agent.”); see also id. at 1178 (“[T]he trespass norm should be that access by the account holder or his agent is authorized while other access to the account is not.”); see generally Restatement (Third) of Agency § 1.01 (A.L.I. 2006) (defining agent).
[23] Kerr, supra note 11, at 1180; Restatement (Third) of Agency § 2.02(1) (A.L.I. 2006).
[24] Restatement (Third) of Agency § 1.04(5) & cmt. e (A.L.I. 2006).
[25] See Kerr, supra note 11, at 1178–79 (arguing that where “the account holder gives login credentials to a third party, access by the third party is authorized only when the third party acts as the agent of the account holder”); Restatement (Third) of Agency § 2.02(1) (A.L.I. 2006).
[26] Van Buren v. United States, 593 U.S. 374, 389–90 (2021).
[27] Id. at 379–80, 396.
[28] Id. at 393–94.
[29] See Oracle USA, Inc. v. Rimini St., Inc., 879 F.3d 948, 962 (9th Cir. 2018) (concluding, under the CFAA’s state analogues, that restrictions on automated downloading limited the manner of access rather than the authorization to access). Van Buren reserved whether the gates inquiry “turns only on technological (or ‘code-based’) limitations on access, or instead also looks to limits contained in contracts or policies,” See 593 U.S. at 390 n.8. The argument here rests on the Court’s characterization of the statute rather than a holding about software-specific restrictions.
[30] Perplexity II, slip op. at 16 (quoting Brekka, 581 F.3d at 1134–35; United States v. Nosal, 676 F.3d 854, 860 (9th Cir. 2012) (en banc)).
[31] Ian Ayres & Jack M. Balkin, The Law of AI Is the Law of Risky Agents Without Intentions, U. Chi. L. Rev. Online *1, *1–2 (Nov. 27, 2024) (arguing that because AI programs lack intentions, the law should hold “the people and companies that employ them” to objective standards of conduct).
[32] Perplexity II, slip op. at 16.
[33] Restatement (Third) of Agency § 2.02(1) (A.L.I. 2006) (defining the scope of actual authority as action “designated or implied in the principal’s manifestations” and “acts necessary or incidental to achieving the principal’s objectives”); Tamar Frankel, Fiduciary Law, 71 Calif. L. Rev. 795, 809–10 (1983) (“[T]he purpose for which the fiduciary is allowed to use his delegated power is narrower than the purposes for which he is capable of using that power.”).
[34] Restatement (Third) of Agency § 8.01 (A.L.I. 2006).
[35] Joel v. Morison (1834) 172 Eng. Rep. 1338 (KB).
[36] Restatement (Third) of Agency § 2.04 (A.L.I. 2006).
[37] See Alan Chan, Carson Ezell, Max Kaufmann, Kevin Wei, Lewis Hammond, Herbie Bradley et al., Visibility into AI Agents, in Proc. of the 2024 ACM Conf. on Fairness, Accountability & Transparency 958, 961 (2024) (observing that a “tool or service provider's knowledge is limited to outputs relevant to their specific service,” while the deployer “generally has access to all the outputs” and “in principle has access to inputs by virtue of running the system”).
[38] See Answering Brief for Plaintiff-Appellee at 34, Amazon.com Servs. LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Apr. 22, 2026) (quoting a declaration describing Amazon engineers’ “forensic analysis of network traffic and browser data to create a digital fingerprint identifying the Comet AI agent”).
[39] See Brekka, 581 F.3d at 1132 (setting out what a plaintiff “must show” to maintain a § 1030(g) action based on § 1030(a)(2)).
[40] Perplexity I, slip op. at 3.
[41] See Perplexity II, slip op. at 7–8 (“At the core of the dispute was Perplexity’s decision not to use a ‘user-agent string,’ a mechanism ‘that would communicate that the user has activated an AI agent’”).
[42] See id. at 8 n.1 (stating that “Amazon initially succeed[ed] in identifying and blocking the Assistant from the Amazon Store”).
[43] Van Buren, 593 U.S. at 390 n.8 (reserving whether the gates inquiry “turns only on technological (or ‘code-based’) limitations on access, or instead also looks to limits contained in contracts or policies”).
[44] See supra notes 7, 21.
[45] See Nosal, 676 F.3d at 857, 860.
[46] See, e.g., NRA Grp., LLC v. Durenleau, 154 F.4th 153, 169–170 (3d Cir. 2025) (declining to extend the CFAA to violations of computer-use policies in part because “there are many other causes of action—breach of contract, business torts, fraud, negligence, and so on—that provide a remedy”).
[47] See hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180, 1186–87 (9th Cir. 2022) (describing LinkedIn’s systems that detect and block roughly 95 million automated scraping attempts each day); see also Perplexity II, slip op. at 8 & n.1 (describing Amazon’s technical blocks against the Assistant).
[48] See hiQ Labs, 31 F.4th at 1202 (observing that “[e]ntities that view themselves as victims of data scraping are not without resort, even if the CFAA does not apply,” and listing trespass to chattels, “copyright infringement, misappropriation, unjust enrichment, conversion, breach of contract, or breach of privacy”).
[49] See Rory Van Loo, Consumer Agents, 103 Wash. U. L. Rev. 705, 766 (2026) (noting that “the FTC, CFPB, and other regulators have jurisdiction that enables them to bring enforcement actions against consumer agents”).
[50] See Restatement (Third) of Agency § 7.07(2) (A.L.I. 2006) (placing outside the scope of employment an “independent course of conduct not intended by the employee to serve any purpose of the employer”); see also supra notes 33–36 and accompanying text.
[51] Conditions of Use, Amazon, https://www.amazon.com/gp/help/customer/display.html?nodeId=GLSBYFE9MGKKQXXM.
[52] Amazon’s New ‘Buy for Me’ Feature Helps Customers Find and Buy Products from Other Brands’ Sites, Amazon News https://www.aboutamazon.com/news/retail/amazon-shopping-app-buy-for-me-brands; see also Allison Smith, Brands Are Upset That ‘Buy For Me’ Is Featuring Their Products on Amazon Without Permission, Modern Retail (Jan. 6, 2026), https://www.modernretail.co/technology/brands-are-upset-that-buy-for-me-is-featuring-their-products-on-amazon-without-permission/.
[53] Introducing Shopify Agentic Storefronts: Sell Your Products Everywhere AI Conversations Happen, Shopify (Dec. 10, 2025), https://www.shopify.com/news/winter-26-edition-agentic-storefronts.
[54] Buy It in ChatGPT: Instant Checkout and the Agentic Commerce Protocol, OpenAI (Sept. 29, 2025), https://openai.com/index/buy-it-in-chatgpt/; see also Jeff Weinstein & Steve Kaliski, Developing an Open Standard for Agentic Commerce, Stripe (Sept. 29, 2025), https://stripe.com/blog/developing-an-open-standard-for-agentic-commerce.
[55] Google’s Universal Commerce Protocol and Agent Payments Protocol (AP2) give agents, merchants, and payment providers a common language to transact, and payment networks now authenticate an agent’s mandate from the customer rather than excluding the agent. See Stavan Parikh & Rao Surapaneni, Powering AI Commerce with the New Agent Payments Protocol (AP2), Google Cloud (Sept. 16, 2025), https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol; Amit Handa & Ashish Gupta, Under the Hood: Universal Commerce Protocol (UCP), Google (Jan. 11, 2026), https://developers.googleblog.com/under-the-hood-universal-commerce-protocol-ucp/; Mark Brohan, Shopify Introduces Open Standard to Enable Checkout Inside AI Search and Chat Tools, Dig. Com. 360 (Jan. 12, 2026), https://www.digitalcommerce360.com/2026/01/12/shopify-universal-commerce-protocol-open-standard-agentic-ai/; Brian Warmoth, Ecommerce Trends: How Visa and Mastercard Are Approaching Agentic Commerce, Dig. Com. 360 (Apr. 2, 2026), https://www.digitalcommerce360.com/2026/04/02/visa-mastercard-in-agentic-commerce/; PayPal Launches Agentic Commerce Services to Power AI-Driven Shopping, PayPal Newsroom (Oct. 28, 2025), https://newsroom.paypal-corp.com/2025-10-28-PayPal-Launches-Agentic-Commerce-Services-to-Power-AI-Driven-Shopping; Making Sense of the AI Shopping Protocol Moment, PayPal Newsroom (Jan. 21, 2026), https://newsroom.paypal-corp.com/2026-01-22-Making-Sense-of-the-AI-Shopping-Protocol-Moment.
[56] Lily Varon, Agentic Payments in B2C Commerce: Where We Are Now, Forrester (Apr. 9, 2026), https://www.forrester.com/blogs/agentic-payments-in-b2c-commerce-where-we-are-now/.
[57] See Perplexity I, slip op. at 3.
[58] See Perplexity II, slip op. at 15.
[59] Perplexity II, slip op. at 15 (“We do not address whether, on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon’s servers.”).
[60] See supra notes 22–25 and accompanying text.