AI shopping agents just won the right to browse Amazon
On 4 August 2026 the US Ninth Circuit Court of Appeals ruled that Amazon cannot use the main federal anti-hacking law to block Perplexity's Comet, an AI agent that shops on a user's behalf. The court decided it is the user, not the AI company, who 'accesses' Amazon when the agent acts, so one of the strongest legal tools retailers had for walling agents out just weakened. Agentic commerce is getting a clearer runway, and that raises the stakes on being the brand an agent picks when it fills a cart.
What the court actually ruled
Amazon sued Perplexity in November 2025, alleging that its Comet browser covertly used logged-in customer accounts and broke the Computer Fraud and Abuse Act, the US statute written decades ago to prosecute hacking. A district judge agreed in part and granted a preliminary injunction on 9 March 2026, blocking Comet from Amazon's account pages.
The appeals court vacated that injunction. As the law firms Cooley and Wilson Sonsini both noted in their analyses of the decision, the panel found Amazon unlikely to win because Perplexity's tool routes its actions through the user's own computer, so it is the user who enters Amazon's systems, not Perplexity. The court treated the agent as a tool rather than a person for the purposes of the statute, and applied the rule of lenity to avoid exposing ordinary users to criminal liability.
This is narrow, and worth reading as such. The ruling covers only the preliminary stage, so the case now returns to the district court for a full hearing. It binds only the states in the Ninth Circuit. And as PYMNTS reported, the court was explicit that Amazon can still regulate access through its terms of service, which is a contract question rather than a hacking one. What changed is that the bluntest legal instrument for blocking shopping agents, the hacking statute, looks a lot less reliable than it did in March.
Why this matters for your AI visibility
For two years the anxiety about AI search was lost clicks: assistants summarise the web and people stop visiting the pages underneath. Agents change the shape of the problem again. When someone tells an agent to reorder printer ink or find a mid-range monitor under £300, the agent navigates the retailer, compares options and adds something to the basket. The product it names is the product that gets bought. There is no results page where a rival can catch the shopper's eye, and no shelf to browse past.
The legal fight matters because it decides whether agents can reach your category at all. Retailers have been trying to keep third-party agents out, and a hacking claim was the heaviest club available. With that club now looking unreliable in a major jurisdiction, the safer assumption for brands is that agents will keep turning up in your category rather than being shut out of it. So the practical question shifts from whether an agent will act to which product it chooses when it does, and that comes down to what it can find and verify about you. We cover the mechanics in how AI assistants choose brands to recommend.
A wrong answer now has a checkout attached
An engine that misremembers your product used to cost you an impression. Handed to an agent with a cart, the same error can cost you the sale, or route it to a competitor whose details the model holds with more confidence.
The scale of that risk is measurable. In our July 2026 test of 30 brands, 27 of 30 (90 per cent) were described with at least one materially false claim when the model answered from memory. With live web search switched on the figure fell to 13 of 30 (43 per cent), which still leaves nearly half misdescribed. Those error rates were survivable when the output was a paragraph a person would sense-check. They are harder to live with when the output feeds an action nobody reads before it happens.
What to do now
Start by finding out what the engines actually say about you today. Discoverable's free AI visibility check runs live queries about your brand through Claude with web search and needs no login, and it shows the specific claims an assistant makes about you. Paid runs cover ChatGPT, Perplexity and Gemini as well.
Because Perplexity is the agent at the centre of this case, and it is retrieval-first by design, it is a sensible engine to watch closely. Our Perplexity visibility tracker page covers how it sources what it says. Alongside that, keep your product facts easy for a machine to lift: pricing, availability and specifications as plain crawlable text, so an agent has something solid to ground on at the moment it is choosing.
Be wary of anyone selling certainty here. No one can promise that an agent will pick your brand, and the honest work is the unglamorous kind: measure what the engines say, correct what is wrong, and keep the sources they read accurate. The law is starting to treat AI agents as extensions of the person using them rather than as trespassers. That means the agent is going to keep arriving in your category. The brands that come out ahead will be the ones whose facts it can find and trust when it does.
Related
Keep exploring: Free AI visibility checkerWhat is GEO?The 9 best GEO tools (2026)AI Visibility Index: 40 brands measuredGEO statistics 2026ChatGPT visibility trackerPerplexity visibility trackerGemini visibility tracker