💥Mains Ready By December. Smash Mains & Smash PYQ Admissions Open

Amazon v. Perplexity: who’s in control when an AI agent acts for you?

Why in the News

A three-judge US Court of Appeals for the Ninth Circuit panel has lifted an injunction (a court order to stop) that Amazon won against the “Assistant” in Perplexity AI’s Comet browser. The panel held that the user, not Perplexity, “accessed” Amazon’s servers, because Perplexity’s systems never contacted them directly. This reopens who controls an AI agent acting for a person.

What is an AI agent, and why did Amazon sue?

  1. What it is: An agentic AI acts for a user like a human assistant. Unlike a web scraper, which only copies text, it can log in, fill a cart and pay.
  2. Amazon’s grievance: Assistant entered customers’ password-protected accounts with their permission but without Amazon’s authorisation.
  3. Legal basis: Amazon sued in November under the US Computer Fraud and Abuse Act (CFAA), an anti-hacking law, and a California computer fraud law, not breach of contract.
  4. The takeaway: The case asks whether a user’s permission is enough when a platform says no, which decides how freely agents can shop for people.

How did the Ninth Circuit reason?

  1. Trial court view: On 9 March the trial judge granted a preliminary injunction, a temporary ban until trial, holding access unauthorised even with users’ permission.
  2. Meaning of access: The CFAA punishes access “without authorisation”, and the panel read access as a person’s act, not software’s. Facebook v. Power Ventures differed because servers contacted servers directly.
  3. User authority: A consumer’s authority over their own account was enough to authorise an AI intermediary, shifting power from platform to user.
  4. Two-hop design: Only the user’s browser contacted Amazon. Perplexity’s servers, working from screenshots, spoke only to the user’s device, so a centralised service would likely have fared worse.
  5. Narrow ruling: The panel left open a claim for breach of terms of service. Courts increasingly keep anti-hacking laws for technical break-ins and leave broken terms to contract law.

How would Indian law treat an AI agent?

  1. Information Technology Act, 2000: Section 43(a) penalises access to a computer without the owner’s permission. Section 66 makes it a crime where the access is dishonest or fraudulent.
  2. Digital proxy: An agent using the user’s login is their digital proxy. Indian law on agency and delegation would still generally treat its access as unauthorised.
  3. Competition risk: A dominant platform blocking rival agents but favouring its own could face the Competition Commission of India (CCI). Eg. CCI’s MakeMyTrip cases (2019, 2020).
  4. Indian Contract Act, 1872: Click-wrap terms, accepted by clicking “I agree”, bar automated access. Unconscionable terms, such as a blanket agent ban, remain open to challenge.
  5. Digital Personal Data Protection (DPDP) Act, 2023: Platforms are data fiduciaries that process data, and users are data principals whose data it is. Consent managers could let agents operate with managed consent.

Why does the reading of “access” matter?

  1. Narrow reading: If access means breaking a technical barrier, platforms cannot use computer fraud law against browsing agents.
  2. Broad reading: If agent browsing counts, dominant platforms gain a weapon against agentic rivals, hurting innovation and consumer choice.
  3. Start-up design: Indian start-ups should favour client-side, user-mediated execution, keeping contact on the user’s device to limit Section 43 liability.
  4. Revenue impact: Agents read a page’s code, not its look, so they skip sponsored ads, pushing platforms to new revenue models.

Challenges

  1. Legal uncertainty: No Indian court has ruled on AI agents, so liability is unclear.
  2. Fraud and security: Agents holding card details and logins attract account takeover attacks.
  3. Liability for errors: No law says who pays for an agent’s unwanted purchase.
  4. Weak contract defence: Terms of service are largely untested against agents.

Way Forward

  1. Official agent APIs: Platforms should offer agent application programming interfaces (APIs) that cap request rates and block suspicious bots.
  2. Clear statutory rules: Parliament should define agents’ rights and duties, and when user authorisation outweighs platform security.
  3. Regulatory sandboxes: Regulators should test technical and legal options in sandboxes.
  4. Consent manager route: The Data Protection Board should clarify how agents use consent managers.

Conclusion

In the US, who accessed the platform is settled for now, but whether an agent breaches a platform’s contract is still open. In India, how courts read unauthorised access will set the balance between platform security, competition and consumer autonomy.

Key numbers

  1. Flipkart: 50 to 60 per cent of e-commerce gross merchandise value, GMV (ICICI Securities, May 2026, all three figures).
  2. Amazon: 25 to 30 per cent of GMV.
  3. Meesho: about 10 per cent of GMV.

Matching Previous Year Question

“[2026] Which of the following statements with regard to Large Language Models (LLMs) used in machine learning is/are correct? 1. LLMs assign probabilities to the next possible words and then pick the one with the highest probability. 2. LLMs process data through mathematical optimization to minimise prediction errors. 3. LLMs produce unbiased outputs. (a) 1 only (b) 1 and 2 only (c) 2 and 3 only (d) 1, 2 and 3 Answer: B”


Join the Community

Free Daily News, Daily Prelims and Mains questions.