In India, where e-commerce, automated consumer services, and AI adoption are all expanding rapidly, the legal dispute between Amazon.com and Perplexity AI offers a useful, if also imperfect, template to think about platform governance and intermediary liability
Artificial intelligence and digital commerce have locked horns in a case Amazon.com has filed against Perplexity AI. Amazon filed the suit in November challenging Perplexity’s Comet browser, especially its ‘Assistant’ artificial intelligence (AI) feature.
While a conventional web scraper passively harvests text to train a model, an agentic system like Assistant can take multiple actions on a user’s behalf, like a typical human agent: it can log into an account, compare products, fill a cart, enter credit card details, and complete a purchase all by itself.
Amazon’s grouse is that while the Assistant accesses customers’ password-protected accounts with the users’ permission, it lacks Amazon’s own authorisation.

The technology giant brought its claims under the U.S. Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer Data Access and Fraud Act. On March 9, the judge hearing the case granted a preliminary injunction reasoning that the Assistant’s access was unauthorised “regardless of whether the Amazon users had permitted Assistant to access their own Amazon accounts”.
On August 4, a three-judge panel of the U.S. Court of Appeals for the Ninth Circuit vacated that injunction. The panel held that it was the user, not Perplexity, who had “accessed” Amazon’s servers, because Perplexity’s own systems never communicated directly with Amazon’s.
The ruling is narrow: the panel confined itself to the meaning of “access” under the CFAA and expressly left open other issues, including a potential breach of the terms of service. Still, the ruling is important for what it says about the legal identity of AI agents and the boundaries of a user’s agency online.
In India, where e-commerce, automated consumer services, and AI adoption are all expanding rapidly, the case also offers a useful, if also imperfect, template to think about platform governance and intermediary liability.
Judicial reasoningThree questions were central in the appeal.
First, the CFAA holds “whoever … intentionally accesses a computer without authorisation” liable. And the Ninth Circuit read “access” to mean an action contemplated by a person rather than by a software tool. This reasoning distinguishes the case from the one between Facebook and Power Ventures, where a third party’s own servers communicated directly with Facebook’s — i.e. true server-to-server access.
In this case, because Perplexity’s servers never contacted Amazon’s, and the Assistant operated as an intermediary within the user’s own session, the panel treated the user, assisted by the tool, as the party doing the accessing.
Second,the court had reasoned that a user consenting to use the Assistant could not stand in for Amazon’s own authorisation. This reasoning effectively treated a consumer’s authority over their own account to suffice, at least for the purposes of the CFAA, to authorise an AI intermediary acting at their direction. This is a meaningful change in how “authorisation” is allocated between platform and user, with implications for how judges decide on access and agency for the user vis-à-vis those of a service provider or a platform.

Third, Amazon sued Perplexity AI under the CFAA and the CDAFA rather than for breach of contract, and the panel did not decide whether the Assistant violated Amazon’s terms of service. In fact, it noted that “other legal theories, such as breach of terms of service, may remain available”.
This reservation can be read in light of a broader trend: to confine CFAA-type ‘anti-hacking’ statutes to breaches of technical barriers, and leaving purely contractual disputes to ordinary contract law.
Technically speaking, the case between Amazon and Perplexity AI has been decided by the technical architecture of the systems involved. To the panel, it did not matter whether the Comet browser meant to help users act against Amazon’s wishes. Here, it was a two-hop design in which a user’s browser ‘spoke’ directly to Amazon while Perplexity AI servers, working from screenshots, spoke only to the user’s own device. A centralised scraping or transaction service maintaining its own sessions with retailers’ servers would likely have fared differently. In such a case, the role of Perplexity AI might be central.
In four ActsSection 43(a) of India’s Information Technology Act 2000 penalises a person who accesses or secures access to a computer, computer system or network without the permission of its owner or the person-in-charge. Section 66 of the same Act attaches criminal liability where such access is dishonest or fraudulent.
An Indian court effectively has to decide whether a user’s own authority over their account displaces the platform’s denial of permission to third-party tools.
Since the user supplies their own credentials, the AI agent functions as a digital proxy. However, Indian jurisprudence on agency and authorised delegation would generally consider this to be “unauthorised” access.
Now, India’s major e-commerce platforms hold significant market power in several verticals. According to a May 2026 ICICI Securities Report, Flipkart held 50-60% gross merchandise value of Indian e-commerce, Amazon held another 25-30%, and Meesho accounted for roughly 10%.

A dominant platform that selectively blocks third-party AI agents while favouring its own proprietary assistant could come under the Competition Commission of India (CCI) scanner. This can be for denying market access and leveraging dominance in one market to protect another, categories that the CCI has already invoked against e-commerce platforms, including two cases involving MakeMyTrip (in 2019 and 2020).
Indian e-commerce platforms also make heavy use of click-wrap terms of use — where a user clicks a button saying ‘I agree’, thus accepting a contract — to restrict automated access. Under the Contract Act 1872, terms that unreasonably restrict a consumer’s use of their own account or which amount to an unconscionable bargain remain open to challenge.
That is, where a consumer has knowingly delegated a shopping task to an AI tool, a blanket platform ban on third-party assistants becomes an unreasonable restraint on consumers’ preferences. Assuming such bans are automatically enforceable denies consumers a meaningful choice.
Finally, under the Digital Personal Data Protection Act 2023, platforms such as Amazon function as data fiduciaries and consumers as data principals. When an AI agent logs in using a user’s own credentials, it processes personal data under that data principal’s explicit direction.
The Act’s framework allows ‘consent managers’ to help data principals give, manage, review or withdraw consent. An agentic shopping tool could plausibly operate within this framework as an automated intermediary with managed consent — but which could also complicate any platform strategy that tries to block such agents outright.
Implications for IndiaThe Ninth Circuit’s ruling turned on where “access” technically occurred rather than Perplexity’s commercial intent. So Indian AI start-ups building agentic tools would be well advised to favour client-side, user-mediated execution, keeping the point of contact anchored to the user’s own device or session. This will minimise server-to-server liability and align with the technical distinction that Indian courts are likely to find persuasive under Section 43 of the IT Act.
Second, platforms such as Flipkart, Amazon India, Tata Neum and Meesho are likely to receive traffic from AI agents, if they already aren’t. These agents read a page’s underlying structure rather than its visual layout. As a result, they may bypass banner advertisements, sponsored placements, and other monetisation mechanisms designed for human attention. This could push platforms towards agent-facing APIs or new monetisation models.

Next, if Indian courts interpret “unauthorised access” to mean bypassing a technical barrier, then existing e-commerce platforms will not be able to rely on computer fraud law in a scenario where an AI agent accessed data simply by browsing a platform.
On the other hand, if the courts assign a broader reading to “unauthorised access” to include browsing by an AI agent, it could disproportionately favour dominant platforms.
A platform may then be able to invoke computer fraud provisions as a readymade instrument against agentic competitors, strengthening their control over the market at the cost of innovation and consumer choice.
Allowing AI agents to access under reasonable conditions is thus a better strategy than relying on technical barriers or blanket restrictions.
Looking ahead, e-commerce platforms should treat the terms of service as a weak and largely untested line of defence against agentic tools. Such terms did not form the basis of Amazon’s claim in its case against Perplexity AI. Instead, they should invest in structured, official agent APIs that allow an agent to interact with a platform while also controlling the interactions, such as by limiting the number of data requests per minute or turning away suspicious bots. Such APIs can also protect monetisation.
As for policymakers and regulators, India’s e-commerce booms, the advent of agentic AI should be met with laws that precisely define the rights and responsibilities of agents working on behalf of users. They should clarify when user authorisation suffices and they should identify when a platform’s security interest should prevail. Overall, the laws should balance platform security, fair competition, and consumer autonomy.
It is time to start developing sandboxes and test multiple technical and legal options so that regulators are not found wanting.
Krishna Ravi Srinivas is DPIIT IPR Chair Professor & Director, Centre of Excellence in AI & Law. Feba Sara and Gaurangi Kapoor are Research Assistants with IPR Chair, NALSAR University of Law, Hyderabad. Views expressed are personal.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | United States: Legal Accountability for AI Agents | 0 | 10 | 01-07-2026 |
| 2 | India’s international trade in times of AI | 0 | 6.31 | 28-09-2026 |
| 3 | India Inc's legal bill swells as global ambitions grow | 0 | 9.89 | 29-09-2026 |
| 4 | Could AI really take over the internet? Here's what experts say. | 0 | 7.2 | 28-09-2026 |
| 5 | AI, Scams, the Law, and Governance: A Conversation With David Tan | 0 | 8.34 | 27-08-2026 |
| 6 | First Steps For Companies Facing AI-Assisted Pro Se Suits | 0 | 9.5 | 28-09-2026 |
| 7 | The AI safety debate is confusing. Here's our guide to the different factions | 0 | 5.7 | 26-09-2026 |
| 8 | AI Cybersecurity Threats: Intelligence vs. Authority | 0 | 6.33 | 29-09-2026 |
| 9 | Study examines risks companies face when relying too heavily on AI systems | 0 | 8.82 | 28-09-2026 |
| 10 | Governance and Responsible Deployment of AI-Enabled Pediatric Care | 0 | 10.98 | 28-09-2026 |