XAgent Blog

Home Blog Market Launch Store

The Perplexity ruling makes agent identity a commercial problem

The Ninth Circuit held that when a user tasks an AI agent, it is the user who accesses the site. The case turned on an agent declining to identify itself.

By XAgent Team · 2026-08-12

On August 4 the Ninth Circuit vacated the injunction that had kept Perplexity's shopping agent off Amazon, and it did so on a holding that reaches every merchant thinking about agent traffic: "It is the user who 'accesses' Amazon's computers, with the help of the Assistant to carry out specific acts on Amazon.com." The agent is a tool. The visit belongs to the person who sent it. For merchants in agentic commerce, the practical consequence is not about liability — it is that asking agents to identify themselves is now a commercial negotiation rather than something you can compel.

What the court actually decided

The case is Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444, argued in Seattle on June 11 and filed August 4, 2026, before Circuit Judges Milan D. Smith Jr. and Eric C. Tung, with District Judge John Charles Hinderaker sitting by designation.

Amazon had won a preliminary injunction in the Northern District of California on claims under the Computer Fraud and Abuse Act and its California analogue, the CDAFA. The panel vacated it, holding Amazon unlikely to succeed on the merits, because the statutory question — who "accessed" the computer — resolves against the agent's vendor when a user directs the agent.

The court was unusually explicit about the limits of what it was doing: "Because we recognize that agentic AI is an emerging technology, we reiterate what this opinion is not. We do not establish a new legal regime governing agentic AI." It noted that "There is thus little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant", and confined its holding to CFAA "access" on this record.

That restraint matters. This is not a ruling that agents may do as they like. It is a ruling that one particular federal hammer does not fit this particular nail.

The case was about a user-agent string

The detail most coverage skips is the one merchants should care about most.

"At the core of the dispute was Perplexity's decision not to use a 'user-agent string,'" the court wrote — a mechanism "that would communicate that the user has activated an AI agent." And, plainly: "That user-agent string would allow Amazon to block the Assistant's access to the Amazon store."

So the fight was over self-identification. Amazon wanted agents to declare themselves so it could decide whether to serve them. Perplexity declined. Amazon reached for a criminal-origin statute to force the point, and lost.

Where the court did leave Amazon standing is footnote 5: "This outcome does not impair Amazon's ability to regulate access to Amazon.com via private terms of service for its users. On the facts before us, Amazon is simply unlikely to succeed in its attempt to regulate access by invoking the CFAA and the CDAFA."

Read those two together and the shape of the new position is clear. Agent identity survives as a matter of contract and access control. It does not survive as a matter of statute.

Why this is harder for the verified-agent camp than it looks

A large amount of infrastructure currently being built assumes agents will identify themselves: agent registries, trust scores, signed agent credentials, allowlists enforced at the CDN edge. Visa's Trusted Agent Protocol is one instance; there are several.

All of it is voluntary. That was always true, but there was an implicit backstop — an agent that refused to identify itself and kept transacting looked like it might be committing a federal offence. On the facts of this case, in this circuit, that backstop is gone. A user-directed agent that declines to announce itself is, statutorily, a user with unusual browsing habits.

Which leaves merchants with the mechanisms they actually control: terms of service, and what they serve to whom. Both are real. Neither is automatic, and both cost something to enforce.

The uncomfortable implication is that identification now has to be worth claiming. If the only thing an agent gets by identifying itself is a higher chance of being blocked, rational agents will keep quiet and scrape. If identifying itself is how an agent obtains a binding quote, real inventory, a clean checkout and a receipt — things it cannot get by driving a browser — then identity is something agents want rather than something merchants extract.

That is the argument for making the agent-facing path better than the human-facing one, rather than making the human-facing one hostile. An agent that can call a structured endpoint, get a price it can rely on, and complete a purchase has no reason to pretend to be Chrome. As we have argued about making a store agent-discoverable, the discoverable path and the identified path are the same path.

What this does not settle

Three things, and each is a live risk for anyone planning around the ruling.

It is one circuit. The Ninth covers California and Washington, which is where much of this industry sits, but there is no nationwide rule and no Supreme Court view.

It is a preliminary-injunction posture. The panel held Amazon unlikely to succeed; the case goes back down, and a fuller record could look different. The court itself flagged that a different record might change the analysis.

And it is expressly limited to CFAA and CDAFA "access". The court said it does not address "whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant's actions". Contract, tort, trademark and unfair-competition theories are untouched.

What's next

Expect terms of service to do more work. If statute will not compel agent identification, the enforceable version of that request moves into the contract a merchant offers and the access controls behind it — which also means the fight shifts to whether a browsing agent is bound by terms its user clicked.

For merchants the planning question is narrower than the legal one, and it has not changed: agents are going to arrive, some of them will not say what they are, and the ones worth transacting with are the ones you can give a quote, check against a mandate, settle, and produce a record for. Identity is the entry condition for that exchange, not a gate you install to keep traffic out.

If your business should be able to tell an identified agent apart from an anonymous one — and give the identified one a better transaction — list your store on XAgent and let the open execution market handle the quote, the authorization check and the proof.

Keep reading

  • Agentic commerce numbers live in earnings calls, not filings
  • What Stripe's Open USD default means for stablecoin choice
  • What a 97% approval rate means for agent payment mandates