The Maze: Amazon lost the lock, not the lawsuit. A US appeals court vacated the preliminary injunction restricting Perplexity's Comet shopping assistant on Amazon.com. The logic was narrower than “agents can shop anywhere”: the shopper's local browser accessed Amazon, while Perplexity's servers guided a tool inside that browser. User-side agents gained room, not a universal platform pass.
The architecture decided who crossed the threshold. Comet runs on the user's device like a conventional Chromium browser. The local browser requests Amazon pages. The Assistant reads the display, sends screenshots and task context to Perplexity's servers, receives guidance, then clicks or types in the user's browser. Perplexity's servers did not directly connect to Amazon's servers on this record. The court therefore treated the shopper as the party accessing Amazon and the Assistant as a tool.
That broke Amazon's fastest legal route to an interim ban. Amazon relied on the federal Computer Fraud and Abuse Act and California's equivalent statute, both built around unauthorized computer access. A district judge had separated shopper permission from platform authorization and sided with Amazon. The appeals panel moved one step earlier: did Perplexity itself access Amazon's computers? Its answer was “unlikely,” so those claims could not support the injunction.
The ruling is deliberately narrow. The case returns to the lower court. Amazon can still enforce terms, use technical controls and pursue other legal theories. More direct control by Perplexity's servers could also change the result. The panel did not create an agentic-commerce law; it applied anti-hacking statutes to one system and warned against turning assisted browsing into a potential federal crime without clearer language from Congress.
Comet gains runway because it behaves like delegated browsing. Perplexity's help material describes an assistant that clicks, types, submits forms, compares products, reads reviews and moves through checkout after a user gives it a task. It is more capable than autofill, but still supervised software inside the shopper's browser. Product architecture, identity and where computation happens may determine legal exposure as much as the label “AI agent.”
Marketplaces still control the store, but not every route into it. Amazon's position is that shopping agents should identify themselves and respect merchant participation. An agent-identifying browser signal would give Amazon a technical switch to block the tool. The ruling says anti-hacking law does not supply that switch automatically when a shopper uses local assistance. Platforms now need explicit agent policies, authenticated access and commercial deals.
Why it matters: Product discovery is becoming a negotiation between shopper software and the marketplace interface. An agent comparing price, reviews, delivery and return risk can reorder the shelf and reduce the value of screen position or sponsored merchandising. That is an operator inference, not a court finding. Sellers need machine-legible product and fulfillment data. Marketplaces need rules for which agents enter, what data they see and how access gets paid. The court kept the gate open; it did not decide who owns it.


