News Weekly
LV 10 XP
0% read
Your progress · 0/5 chapters
About 6 min total
CourtsISSUE #2 · STORY 15 OF 20Sep 21, 2026CONFIRMED

Amazon sues Perplexity, saying its agent logged in as customers

Amazon filed an updated lawsuit against Perplexity, alleging its Comet agent had Amazon's own servers log into customer accounts. Nothing has been proven yet; these are allegations.

Illustration: a comet-like autonomous shopper — a sleek cart with a small glowing sensor core — rolls through an open storefront door, a long checkout receipt unfurling behind like a tail.

Read it your way

CHAPTER 1 · THE 60-SECOND VERSIONPicked for Explorers

A new lawsuit update

On Sep 21 Amazon re-filed its case against Perplexity with a bigger claim. The center is how an AI agent reaches Amazon.

The complaint grewAmazon filed a 41-page amended suit that added a third legal claim.
The core allegationAmazon says Perplexity's cloud logged into accounts using copied customer session cookies.
No device involvedThe filing claims requests came from Perplexity's servers, not the user's phone.
Still just claimsThese are unproven allegations, and Perplexity had not answered as of research.
Finish this chapter for +15 XP
Flip the switch

From user-access to server-access

YOU GETA new claimTortious interference adds a contract path that does not need the access ruling.
YOU GETA server-side theoryAmazon alleges Perplexity servers logged in directly with copied cookies.
YOU GETA candor fightThe filing accuses Perplexity of false statements to the appeals court.
Your next move · as a Explorer

Know where your agent runs

1Check if your AI shop uses a vendor cloud
2Review saved login credentials on shopping tools
3Watch how courts split device and server access

Switch your reading mode at the top to see a different next move.

Tap to open

Things to keep an eye on

Pop quiz · unlock the Docket Detective badge

Did it stick?

0/3
What does Amazon allege Perplexity's agent used to log in?+20 XP
Is Perplexity's conduct proven in court?+20 XP
What did the amended suit add as a third claim?+20 XP
Your call · +5 XP

Should cloud-run agents be allowed to log in as users?

Deep dive

The full research, labeled and sourced

CONFIRMED21 sources · 54 min
Story identity
FieldValue
CaseAmazon.com Services LLC v. Perplexity AI, Inc., No. 3:25-cv-09514-MMC (N.D. Cal.), Judge Maxine M. Chesney
EventFirst Amended Complaint (Dkt. 122, 41 pages) filed 2026-09-21; adds a third claim (tortious interference with contract) and new factual allegations that Comet for iOS had Perplexity's own cloud servers log into Amazon with copied customer session cookies — directly, with no user device in between — while Perplexity was telling the Ninth Circuit that "no Perplexity computer ever has direct access to an Amazon computer"
Evidence statusCONFIRMED (filing/docket contents, verified via CourtListener RECAP PDF [S1] and docket page [S2]; independently corroborated by TNW [S7], Business Insider Markets [S8], AI Weekly [S9], The Fashion Law [S10]). Underlying facts about Perplexity's conduct remain ALLEGATIONS until adjudicated.
ConfidenceHigh (primary document read in full; 41-page text extracted and key-markers checked)

Evidence-status labels used below: CONFIRMED (verified record facts), COMPANY CLAIM (Amazon's allegations; quoted language from the complaint), INDEPENDENT EVIDENCE (docket/opinions + corroborating outlets), INTERPRETATION (analysis), PREDICTION (forward-looking).

✓

What happened?

🎓 For Explorer

FACT (CONFIRMED): On Monday 2026-09-21, Amazon.com Services LLC filed a 41-page First Amended Complaint in the N.D. Cal. case it opened on 2025-11-04 against Perplexity AI. The amended pleading (Dkt. 122) replaces the original two-claim complaint with three counts: (1) Computer Fraud and Abuse Act (18 U.S.C. § 1030), (2) California Comprehensive Computer Data Access and Fraud Act (Cal. Penal Code § 502), and (3) NEW — tortious interference with contractual relations under California law. Jury demand maintained.

The new material targets "Comet for iOS," the mobile version of Perplexity's Comet browser/agent that launched March 18, 2026 — nine days after Judge Chesney granted Amazon's preliminary injunction (Mar 9, 2026). Amazon alleges (COMPANY CLAIM, quoted from the complaint):

  • "When a user activates Comet's agent mode on iOS, Comet copies the user's Amazon-authenticated cookie and session data to Perplexity's cloud servers, which host a virtual browser. Perplexity's cloud servers then request pages directly from Amazon's servers using that virtual browser and the user's copied cookie... No user device touches Amazon's servers."
  • This direct server-to-server traffic was observed "day after day," from shortly after the March 18, 2026 launch until at least May 11, 2026, "all while Perplexity was representing to the Ninth Circuit that 'no Perplexity computer ever has direct access to an Amazon computer.'"
  • Requests coming from Perplexity's servers carried the user-agent string of "Google Chrome running on a Windows desktop computer" (an iOS product presenting as desktop Chrome); Comet's own in-app notice reportedly told users "[t]his request will be handled by a virtual cloud browser."
  • Amazon alleges Perplexity's statements to the Ninth Circuit (opening brief filed April 1, 2026; reply brief May 6, 2026) "were false when made"; Amazon's counsel wrote to Perplexity's counsel on May 6, 2026 identifying the misstatements by page and asking for correction; Perplexity's counsel replied on May 11, 2026 that "[a]s a measure of good-faith, Perplexity has temporarily disabled the assistant feature on Amazon.com in Comet for iOS" — without denying the direct connections or correcting the record before the appeals court.

FACT (CONFIRMED): The same day (Sep 21), Amazon also began blocking Meta's freshly launched Muse shopping agent on Amazon.com with Conditions-of-Use popups (independent of this filing but same-week context; see S14). Perplexity had not filed a response to the amended complaint as of Sep 21–22; its public, in-case-quoted position is that Amazon is "demanding we prohibit Comet users from using their AI assistants on Amazon."

Δ

What changed?

  • Pleading scope: 2 claims (CFAA, CDAFA) → 3 claims (+ tortious interference with contract). The new claim leans on Amazon's customer agreements (Conditions of Use with Agent Terms added May 30, 2025) rather than on anti-hacking statutes alone — an explicit response to the Ninth Circuit's Aug 4, 2026 opinion, which vacated the preliminary injunction and held that (on the prior record) the user, not Perplexity, "accesses" Amazon's computers (18 U.S.C. § 1030; "the Assistant is a tool, not a person"), while noting the outcome "does not impair Amazon's ability to regulate access to Amazon.com via private terms of service for its users" (footnote 5, No. 26-1444).
  • Factual theory: Amazon pivoted from "agent impersonates Chrome in the user's local browser" to "Perplexity's own servers logged in and browsed Amazon directly, with no user device in the middle" (iOS architecture). This aims squarely at the appellate panel's open question: "We do not address whether, on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon's servers."
  • Credibility dimension: the amended complaint accuses Perplexity of making court representations "false when made" and of not correcting them — a candor-to-the-court theme that is new and, if proven, aggressive.
  • Numbers on the record (alleged, CONFIRMED as pleaded): damages "well in excess of $260,000"; ≥1,280 engineering hours (8 Traffic Engineering staff) since July 2025; ≥185,712 Comet sessions on Amazon.com as of June 15, 2026; separate Ad Traffic Quality + Traffic Engineering losses (>$5,000) from Mar 18–May 11, 2026 server-to-server detection; two technological barriers (Aug 19 and Dec 5, 2025) each evaded within days.
↔

Before → Change → After

🎓 For Explorer
  • BEFORE (2025-11-04 → 2026-08-04): Amazon sued Perplexity (Nov 4, 2025) over Comet covertly entering password-protected customer accounts — "Buy with Pro" (Nov 2024), Comet release (Jul 9, 2025), block (Aug 19, 2025), evasion (Aug 20, 2025), executive contacts (Sep 12/29, 2025), free launch (Oct 2, 2025), cease-and-desist (Oct 31, 2025). Judge Chesney granted a PI (Mar 9, 2026) on CFAA/CDAFA. Perplexity appealed; its briefs (Apr 1, May 6, 2026) said no Perplexity computer ever directly accesses an Amazon computer. Ninth Circuit vacated the PI on Aug 4, 2026 (user accesses, not the company; rule of lenity); rehearing denied Sep 10, 2026; mandate issued Sep 18, 2026 (docket entry 121). Perplexity moved to dismiss (Sep 11, 2026, docket 119).
  • CHANGE (2026-09-21): Amazon files the First Amended Complaint (Dkt. 122): new iOS direct-access theory + tortious-interference claim + "false statements to the Ninth Circuit" allegations; requests injunction, destruction of copied data, account identification, damages, jury trial.
  • AFTER: Case proceeds with Perplexity's pending motion to dismiss (hearing reset to Nov 20, 2026 per docket 120 order; responses previously due Sep 25, 2026); Perplexity must answer or amend its dismissal strategy to confront the new allegations. The amended complaint is now the operative pleading, and the contract claim gives Amazon a route that does not depend on the "access" prong the court of appeals rejected.
⚙

How it works

Mechanism as alleged (COMPANY CLAIM, corroborated by Perplexity's own in-app notice quoted in the complaint):

  1. A Comet for iOS user activates "agent mode" on a shopping task in the Amazon Store.
  2. Perplexity's iOS app copies the user's Amazon-authenticated session cookie (the credential that lets Amazon treat the holder as the signed-in customer) to Perplexity's cloud.
  3. Perplexity's servers run a "virtual browser" that requests pages directly from Amazon's servers using that cookie — the requests originate from Perplexity's infrastructure, not the user's phone ("No user device touches Amazon's servers").
  4. Amazon's servers respond to the impersonated session, including password-protected pages, directly to Perplexity's servers; screenshots are streamed back to the user's phone.
  5. Requests carried a desktop-Chrome user-agent string (per Amazon), so server logs did not self-identify the traffic as agentic; Amazon says its Ad Traffic Quality and Traffic Engineering teams had to trace the traffic to Perplexity-controlled servers manually.
  6. Contrast — Amazon's own "Buy for Me" agent (April 2025) identifies itself via an "Agent/[agent name]" user-agent and an "@buyforme.amazon" ordering identity, accesses only public pages, and respects opt-outs; Amazon's Agent Terms (May 30, 2025) require third-party agents to do the same and to stop when told.

Where the old complaint's theory was "the agent uses the user's browser as a cover," the amended theory is "Perplexity's computers themselves entered Amazon's computers using customers' copied credentials." The legal stakes: CFAA/CDAFA "access" by the company (vs. by the user), plus contract liability for inducing customers to breach the Conditions of Use.

!

Why it matters

🎓 For Explorer
  • First major federal test of agentic-shopping architecture itself. The Ninth Circuit's Aug 4 opinion left an explicit door open ("on a different record or new facts"). Amazon walked through it on Sep 21 with the iOS direct-access record. If the allegations hold, the "user did it, the agent is just a tool" defense collapses for cloud-virtualized agents — a pattern (per Meta's own Muse materials and P.K. Sharma's comparison table) that Muse and other "buy for me" products also use.
  • Timing is deliberate and demonstrative: the filing landed the same weekend Amazon blocked Meta's Muse with Conditions-of-Use popups — i.e., contract enforcement in the market and in the courthouse, exactly the lever footnote 5 of the appellate opinion preserved.
  • It extends the platform-vs-agent rulemaking wave of this window (UN IIASPAI brief on losing human control over agents, S05; Shopify/Meta Muse launch, S14; California's N-9-26 kill-switch EO, S04) into concrete private-law litigation about who may log in as a customer.
✦

What became possible?

🎓 For Explorer
  • Retailers/platforms can now point to a live, on-spec complaint alleging that server-side cookie replay by an agent vendor is computer fraud + tortious interference — a litigation template (federal CFAA + California CDAFA + common-law interference) any platform operator can adapt.
  • The amended complaint formally put "agent vendors must self-identify in the user-agent string" (the Agent Terms "Agent/[name]" rule) into a federal pleading — a technical norm now being litigated.
  • Agents that stay on the user's device (client-side execution) gained a clearer safe-ish lane: the appellate record says that pattern is the user accessing; server-side virtual browsers are the exposed lane.
◎

Implications

Technical

  • Session/cookie security: the case treats copied auth cookies as the "access key" to protected computers. Expect platform-side hardening: binding sessions to device/IP signals, short-lived tokens for agent-style flows, and agent-dedicated APIs (Amazon's Universal Commerce Protocol participation and agentic-commerce team are the constructive alternative).
  • User-agent honesty: a concrete standard is being litigated — agents should send Agent/<name> strings. Tooling that rotates/spoofs UAs to evade detection is now on the wrong side of a federal pleading.
  • Detection economics: Amazon alleges it costs real engineering (1,280+ hours, dedicated fingerprinting cycles, ad-traffic-quality filtering) to distinguish agent traffic from human traffic when agents lie about their UA. This is an operational, not theoretical, cost of opaque agent traffic.
  • Remote-browser isolation (RBI)/virtual browsers: cloud-rendered browsing is now legally loaded; providers need consent/terms architecture (who authorized the server-side log-in?) rather than just security design.

Developer

  • If you build agents for third-party sites, self-identify (UA string, opt-out respect, credentials-handling policy) or you inherit the Comet pattern: impersonation claims, CFAA/CDAFA exposure, and tortious interference.
  • Architecture choice is now a legal choice: client-side agents (user's browser does the walking) currently sit on the "user accesses" side of the Ninth Circuit record; server-side virtual browsers sit on the "developer accesses" side per Amazon's allegations. Document which one you built.
  • Credentials: forwarding/copying a user's session cookie to vendor cloud (as alleged for Comet for iOS) is the exact fact-pattern being called computer fraud. Treat session data as sensitive PII with retention/redaction controls; destroy on request (Amazon seeks destruction of copied data).
  • Watch Agent Terms-style contractual walls: platforms can contractually ban your agent even where statutes fail — plan for opt-out compliance APIs.

Enterprise

  • E-commerce/retail operators get a playbook for governing third-party agents: transparent-identification requirements, technical barriers + forensic fingerprinting processes, agent-acceptance terms tied to customer contracts, and a litigation theory that survives CFAA-setbacks on contract grounds.
  • Enterprises deploying "shop on my behalf" assistants (or any agent with saved credentials) must re-audit: who holds the session? Where do requests originate? Can the vendor's server impersonate an employee's account? — the exact risk the complaint alleges.
  • Compliance/legal teams should track this docket: a ruling for Amazon on "server-side cookie replay = unauthorized access" would raise the liability floor for every buy-for-me agent (Shopify/Meta Muse, OpenAI/Google shopping agents) and for enterprise RPA/agent tools reusing corporate sessions.
  • Risk-management angle: the "1,280 hours / $260k+ damages / ad-fraud exposure" recital is a template for quantifying agent-trespass losses.

Strategic

  • Amazon is drawing the marketplace line: block Muse (contract), sue Perplexity (CFAA/CDAFA/contract), negotiate with Google/OpenAI agents, while building its own transparent agent stack (Buy for Me, Alexa-in-search, agent policy in Business Solutions Agreement effective Mar 4, 2026, Universal Commerce Protocol council). The message: agents are welcome on Amazon's terms, not by impersonation.
  • Perplexity's position — Comet is the user's tool; "no Perplexity computer ever has direct access to an Amazon computer" — is now factually contested on the iOS record; the company's credibility before the Ninth Circuit (and in the press) is the collateral issue Amazon is pressing.
  • Precedent direction: if Amazon wins on the new claims, "customer-authorized" is not a defense for vendors whose infrastructure performs the access; expect agent vendors to shift to platform-sanctioned APIs and overt identification.
  • Coalition effects: EFF/Mozilla/EleutherAI amici backed the "user accesses" line for client-side agents; a server-side distinction (like the one Amazon pleads) could become the dividing line regulators and courts adopt.
⚠

Risks & limitations

Risks
  • To Perplexity: injunction/broad relief (destruction of copied Amazon data, account identification, certification under oath); damages (statutory/punitive potential); reputational hit from "false statements when made" allegations; distraction from product/competitive pressure (this window already saw Grok 4.7 and MiMo-V2.6 top the open-weight charts).
  • To Amazon: if the iOS architecture evidence is contested, the "misled the court" narrative could backfire as overheated advocacy; a ruling that even server-side replay is "the user's access" would harden precedent against platforms; the case also publicizes that session cookies are portable enough to be replayed — a consumer-trust exposure.
  • To agents/ecosystem: chilling effect on legit buy-for-me tools; uncertainty about which architectures are compliant; possible criminal-law shadow (CFAA is a criminal statute; the rumor mill about "hacking" charges for shopping agents).
  • First Amendment/automation policy: CFAA-based platform control over agent access continues the hiQ-vs-LinkedIn-type debate about who owns the "access" layer — now with consumer agents, not scrapers.
Limitations
  • Unadjudicated allegations: everything in the amended complaint about Perplexity's conduct is Amazon's version; Perplexity has not answered it (as of 2026-09-22) and previously called the suit a "bald attempt" to block Comet (Reuters, Aug 4, 2026).
  • No Perplexity primary source: Perplexity's public statement (as quoted in Amazon's filing) is "Amazon is demanding we prohibit Comet users from using their AI assistants on Amazon"; no Perplexity blog/press statement responding to the amended complaint was located. DISCOVERY_RAW listed MLex as the primary reporter (Sep 21, 15:20 GMT) — the specific MLex article URL could not be located in open web; every new-allegation detail was verified instead from the docket PDF (primary) and TNW/AI Weekly/Business Insider/The Fashion Law (independent).
  • MLex-specific color not independently sourced: the discovery record's "ATTRP/anti-bot responses" phrasing maps in the primary document to Amazon's Ad Traffic Quality and Traffic Engineering teams — the term "ATTRP" does not appear in the complaint and was not corroborated; not used as fact.
  • PACER primary docket not directly consulted (paywalled); the RECAP/CourtListener copy of Dkt. 122 (full text read) and the CourtListener docket page are authoritative mirrors of the filing itself.
  • The Ninth Circuit opinion (Aug 4, 2026) relied on a different record; it expressly reserved the "different facts" scenario.
?

Open questions

  1. How will Perplexity respond to the amended complaint — amend its pending motion to dismiss, or answer with a factual rebuttal of the iOS architecture?
  2. Will Judge Chesney's Nov 20, 2026 hearing on the pending dismissal motion now address the amended pleading (claims 1–3), and what survives?
  3. Was the Comet-for-iOS server-side architecture actually in place for the full Mar 18 → May 11, 2026 window, and what do Perplexity's engineering records show?
  4. Does the "false when made" candor allegation affect the Ninth Circuit's pending posture, rehearing, or any future appeal?
  5. Will Amazon's contract-based (tortious interference) approach become the model against Muse, Google and OpenAI agents — and will any of those vendors sue back (Amazon already blocked their agents)?
  6. Does data-destruction relief (copied session data, screenshots, HTML snapshots) set a consent/retention standard for agent vendors?
↗

What happens next?

🎓 For Explorer
  • Perplexity's response to the amended complaint (due per schedule; its pending dismissal motion predates the amendment — expect a revised or supplemental motion targeting all three claims).
  • Motion-to-dismiss hearing: Nov 20, 2026 (reset from Oct 16 by docket 120 order) — first substantive district-court test of the iOS allegations and the new interference claim.
  • The Ninth Circuit carries the August opinion (mandate issued Sep 18, 2026); any new appeal will test whether the Comet-for-iOS record "gains entry" under the panel's own reservation.
  • Watch the Muse block interplay: contract-popups and the Amazon v. Perplexity docket form a matched pair; a ruling on the interference claim could directly shape the Muse standoff and agent blocks by Google/OpenAI agents.
  • PREDICTION (explicitly forward-looking): the case resolves via compliance architecture rather than a sweeping merits ruling — expect an identification/opt-out settlement framework or a narrow holding that server-side logged-in browsing by an agent vendor can constitute access; a broad "all agent shopping is illegal" ruling is unlikely given the panel's caution and amicus climate.
★

Editorial takeaway

🎓 For Explorer

This is the week's cleanest example of the agent-economy legal frontier: a retailer says "your agent logged in as my customer, on your servers, while telling a court it never touches my systems." The amended complaint is significant not for naming a wrongdoer — nothing is proven — but for naming the failure class (cookie-replaying, non-identifying, server-side shopping agents) and turning a technical architecture dispute into federal pleading, exactly when consumer "buy for me" agents reached mass market (Shopify/Meta's Muse; Amazon blocking agents from Google and OpenAI). The durable lesson for builders: how your agent represents itself and where its requests originate is now a compliance decision with federal-law consequences, not just an engineering detail. And the durable lesson for audiences: an AI that "shops as you" from someone else's servers is a very different legal object than an AI that helps you click — and courts, contracts and platforms are all starting to enforce that distinction.

Illustration: frame: a sleek comet-like shopping cart with a small glowing sensor core rolls through an open doorway, a long receipt ribbon trailing behind — an artistic impression of an AI shopping agent report…
⌘

Lab: VERIFY

Step 1 — Pull and verify the primary document from the public docket mirror
  • Fetch Dkt. 122 from CourtListener RECAP storage: curl -sL -o s15_ac.pdf "https://storage.courtlistener.com/recap/gov.uscourts.cand.459191/gov.uscourts.cand.459191.122.0.pdf"
  • Check the HTTP response: curl -sI → HTTP/2 200, content-type: application/pdf, content-length 769629, last-modified Mon, 21 Sep 2026 12:59:05 GMT (file is a genuine RECAP copy of the Sep 21 filing).
  • Extract text and verify structural markers (PyPDF2 on the extracted PDF):
    • Page count = 41 → matches "41-page amended complaint" in TNW/AI Weekly.
    • Footer string "Document 122" appears 41 times; "Filed 09/21/26" appears 41 times (every page footer) → confirms docket number and filing date from the document itself.
    • Key-quote/term counts in the text: "no user device touches" ×1; "virtual cloud browser" ×1; "185,712" ×1; "1,280" ×2; "260,000" ×1; "TORTIOUS INTERFERENCE" ×3; "March 18, 2026" ×4; "May 11, 2026" ×5.
  • Verify the docket entry independently: the CourtListener docket page (https://www.courtlistener.com/docket/71874820/amazoncom-services-llc-v-perplexity-ai-inc/) shows entry 122 "AMENDED COMPLAINT … Filed on 9/21/2026 (Entered: 09/21/2026)", entry 121 (Ninth Circuit mandate, 9/18/2026), entry 119 (Perplexity motion to dismiss, 9/11/2026).
  • Result: filing CONFIRMED from the primary record; all headline facts in the discovery record reproduce in the primary text.
Step 2 — Cross-check the key claims against independent coverage
Claim / numberPrimary doc (Dkt. 122)Independent coverageVerdict
Filed 2026-09-21, 41 pages, 3 counts (CFAA, CDAFA, tortious interference)footer + caption + countsTNW ("41 pages… computer fraud, the California computer data access statute, and tortious interference"); BI headlineCONFIRMED
Comet for iOS copies user's Amazon cookie to Perplexity cloud; virtual browser; direct server requests; "No user device touches Amazon's servers"¶66TNW, AI Weekly (same quotes)CONFIRMED as pleaded (allegation)
Direct server-to-server traffic Mar 18 → at least May 11, 2026; observed daily¶6, ¶66, ¶68TNW, AI Weekly, TFLCONFIRMED as pleaded (allegation)
"no Perplexity computer ever has direct access to an Amazon computer" (Ninth Circuit briefs Apr 1 / May 6, 2026)¶67 (quoted from Opening Br. at 9, No. 26-1444)TNW, AI Weekly, BICONFIRMED that the statement was made (briefs on record); falsity = allegation
May 6, 2026 letter; May 11 "temporarily disabled" response¶68 + Ex. 12/13TNW, AI WeeklyCONFIRMED as pleaded
Damages >$260,000; 1,280 hours (8 engineers); 185,712 sessions by Jun 15, 2026¶79–85TNW, AI WeeklyCONFIRMED as pleaded
Step 3 — Simulate the identification problem (why the "device" is invisible to the server)

Run a minimal origin-server experiment (local Python HTTP server + 3 requests):

  1. Request A — human: Chrome UA + session cookie session-id=xyz-customer-session.
  2. Request B — "agentic virtual browser": the same Chrome UA + the same cookie (simulating a Perplexity cloud server replaying a copied cookie, per the complaint's iOS allegations).
  3. Request C — well-behaved agent: self-identifying UA Agent/BuyForMe-1.0 (transparent agent) + same cookie (simulating Amazon's Buy for Me / the Agent Terms standard).

Observed output (logged this research):

  • req1: UA=Chrome…, cookie-present=True, ip=127.0.0.1
  • req2: UA=Chrome…, cookie-present=True, ip=127.0.0.1 → byte-identical to req1
  • req3: UA=Agent/BuyForMe-1.0…, cookie-present=True → distinguishable only because it says so

Result: at the HTTP layer the origin sees only self-reported UA + cookie; it cannot see "which device" — so a cloud server replaying a user's cookie with a Chrome UA is indistinguishable from the human user. This is precisely why Amazon alleges it needed forensic fingerprinting (six-week analysis, ~240 hours) and Agent Terms requiring Agent/[name] identification — and why the amended complaint's iOS mechanism, if proven, is a materially different fact pattern than the client-side architecture the Ninth Circuit ruled on in Aug 2026.

Step 4 — Log the evidence-status boundary
  • Mark every substantive fact about Perplexity's conduct as allegation/COMPANY CLAIM (unadjudicated; Perplexity had not answered as of 2026-09-22).
  • Record that Perplexity's quoted position ("Amazon is demanding we prohibit Comet users from using their AI assistants on Amazon") is carried inside Amazon's own filing, not a Perplexity primary statement.
  • Flag discovery-record items that did NOT survive verification: "ATTRP" (term absent from the complaint; primary doc says Ad Traffic Quality teams) and the MLex URL (not located; superseded by primary + TNW/AI Weekly/BI/TFL).

Expected outcome

A one-page verification log: (1) Dkt. 122 fetch → 41 pages, footer-verified filing date, key markers present; (2) claim cross-check table all CONFIRMED-as-pleaded; (3) simulation output proving the invisibility of the "device" and the necessity of self-identification (Agent Terms rationale); (4) a clear allegation-vs-fact boundary. Total time ~45–60 minutes. This leaves a reusable audit pattern for any story whose core is "who really accessed which computer."

≡

Research sources

Primary Sources (6)
Primary
Original complaint (Nov. 4, 2025) — DocumentCloud mirror (Retail Dive upload)cross-check of original-complaint allegations (identical case caption, counts, factual narrative) against the Court House News copy. — primary court record mirror (CONFIRMED).Date: 2025-11-04 (filed)
Visit source ↗
Primary
Original complaint (Nov. 4, 2025) — Court House News upload of the complaint PDFthe pre-amendment baseline — original two counts (CFAA, CDAFA) only; "Buy with Pro" (Nov 2024) allegations; Comet first release July 9, 2025 and free launch Oct 2, 2025; Chrome user-agent impersonation; Aug 19/20, 2025 barrier-and-evasion cycle; Sep 12/29, 2025 executive contacts; Oct 31, 2025 cease-and-desist; Conditions of Use / License and Access Terms / Amazon Software Terms / Agent Terms references. — primary court record — baseline for "what changed" (2 claims → 3 claims) (CONFIRMED).Date: 2025-11-04 (filed)
Visit source ↗
Primary
Justia — case-law mirror of the Ninth Circuit opinion (26-1444, published 2026-08-04)text and pagination of the same opinion (cross-check of quotes and holdings: "whoever" language, Van Buren definition of access, Nosal caution, CDAFA "any person" analysis, equitable factors). — primary appellate record mirror (CONFIRMED).Date: 2026-08-04
Visit source ↗
Primary
Ninth Circuit opinion — *Amazon.com Services, LLC v. Perplexity AI, Inc.*, No. 26-1444 (Aug. 4, 2026), official PDF from the Court of Appealsthe vacatur of the preliminary injunction; holding that the *user* (not Perplexity) accesses Amazon's computers under the CFAA and CDAFA ("the Assistant ... is a tool, not a person"; rule of lenity); the reservation that a different record/facts showing Perplexity control "in such a way as to gain entry to Amazon's servers" was not addressed; footnote 5 that Amazon may still regulate access via private terms of service; procedural history (complaint Nov 2025, PI Mar 9, 2026, appeal timeline, brief dates Apr 1/May 6, 2026). — primary appellate record — the legal backdrop the amended complaint responds to (CONFIRMED; INDEPENDENT EVIDENCE).Date: 2026-08-04
Visit source ↗
Primary
CourtListener — docket page for *Amazon.com Services LLC v. Perplexity AI, Inc.* (3:25-cv-09514, N.D. Cal., Judge Maxine M. Chesney)docket-entry 122 ("AMENDED COMPLAINT against Perplexity AI, Inc. ... Filed on 9/21/2026 (Entered: 09/21/2026)"), entry 121 (Ninth Circuit MANDATE, 9/18/2026), entry 119 (Perplexity Motion to Dismiss, 9/11/2026, hearing reset to 11/20/2026), entry 1 (original complaint 11/4/2025), procedural-history entries (PI motion, stays, sealing, reassignment to Judge Chesney); "Date of Last Known Filing: Sept. 21, 2026." — primary docket record (CONFIRMED).Date: docket updated Sept. 22, 2026 (entries 2025-11-04 → 2026-09-21)
Visit source ↗
Primary
First Amended Complaint (Dkt. 122) — PDF, CourtListener RECAP storage (downloaded in full; 41 pages; text extracted and verified)the entire operative news event — case caption (3:25-cv-09514-MMC), "FIRST AMENDED COMPLAINT", footer "Document 122 / Filed 09/21/26" on all 41 pages; three counts (CFAA 18 U.S.C. § 1030; Cal. Penal Code § 502 CDAFA; tortious interference with contract); Comet for iOS mechanism ("copies the user's Amazon-authenticated cookie and session data to Perplexity's cloud servers... No user device touches Amazon's servers"); March 18 → at least May 11, 2026 direct server-to-server period; "no Perplexity computer ever has direct access to an Amazon computer" quote from Perplexity's Ninth Circuit opening brief (Apr 1, 2026) and repeated in reply (May 6, 2026); Amazon's May 6, 2026 counsel letter and Perplexity's May 11, 2026 letter ("temporarily disabled the assistant feature on Amazon.com in Comet for iOS"); user-agent misrepresentation (Chrome-on-Windows from iOS); damages "well in excess of $260,000"; 1,280 hours / eight Traffic Engineering staff since July 2025; Ad Traffic Quality and Traffic Engineering team losses; ≥185,712 Comet sessions on Amazon.com as of June 15, 2026; barriers of Aug 19 and Dec 5, 2025 and evasion; request for injunction, destruction of data, identification of accounts, certification under oath, damages, jury demand; dated/filed September 21, 2026. — primary court record; the only source from which unadjudicated facts are quoted (COMPANY CLAIM / allegations; filing facts CONFIRMED).Date: 2026-09-21 (filed; Dkt. 122)
Visit source ↗
Independent Sources (10)
Independent
PacerMonitor — public case page, *Amazon.com Services LLC v. Perplexity AI, Inc.* (3:25-cv-09514)cross-check of docket history — case filed Nov 4, 2025; PI order Mar 9, 2026; Perplexity Motion to Dismiss (doc 119) filed Sep 11, 2026, hearing set Oct 16, 2026 then reset to Nov 20, 2026 (doc 120 order); judge assignment (Chesney). — secondary docket mirror (CONFIRMED for cited entries).Date: docket last updated 2026-09-11
Visit source ↗
Independent
ppc.land — "Ninth Circuit frees Perplexity's shopping agent from Amazon's hacking claim"background chronology — Aug 2025 Amazon contact and technical block; Sep 2025 merchant research; Oct 2025 Cloudflare Chrome-UA crawling report; Nov 2025 filing; Mar 9, 2026 injunction; Mar 20, 2026 Google-Agent crawler documentation; Apr 1/May 6, 2026 brief dates; EFF/Mozilla/EleutherAI amicus; Amazon's Mar 4, 2026 Business Solutions Agreement agent policy and Universal Commerce Protocol council participation; "negotiate the pipe, because the statute will not close the door" framing. — independent analysis (background; CONFIRMED).Date: 2026-09-14
Visit source ↗
Independent
Legal500 — "Ninth Circuit Vacates CFAA Injunction Against Perplexity's Comet AI Agent"background/analysis — first appellate decision on computer-access statutes applied to agentic AI; Power Ventures vs. BrandTotal line; "tool, not a person"; rule of lenity; scope of holding. — independent legal analysis (background; CONFIRMED).Date: 2026-09-16
Visit source ↗
Independent
Superpower Daily — "Perplexity Seeks Dismissal of Amazon AI-Agent Suit After Appeals Court Ruling"background — Perplexity's Sep 11, 2026 motion to dismiss (filed days before the amendment); the appellate ruling's fact-specificity; the list of open liability lanes the panel left (direct provider control, direct communication with servers, credential control, bypassing technical restrictions) — exactly what the amended complaint now pleads. — independent reporting (background; CONFIRMED).Date: 2026-09-13
Visit source ↗
Independent
Courthouse News Service — "Ninth Circuit lifts block on AI-powered shopping assistant" (Margaret Attridge)background — panel quotes (user "accesses" Amazon, "tool, not a person"), Judge Chesney's Mar 9, 2026 PI reasoning, Perplexity valuation note ($21B as of early 2026), Amazon spokesperson statement. — independent reporting (background; CONFIRMED).Date: 2026-08-04
Visit source ↗
Independent
Reuters — "Amazon loses US court ban on Perplexity's AI shopping tools" (Blake Brittain)background — Ninth Circuit outcome (Aug 4, 2026); Amazon's Nov 2025 suit; Comet can log into accounts and place orders; Perplexity's response that the suit lacks merit and is a "bald attempt" to block Amazon users from using Comet ("AI agents don't have eyeballs to see the pervasive advertising"). — independent reporting (background; CONFIRMED).Date: 2026-08-04
Visit source ↗
Independent
The Fashion Law — "Amazon v. Perplexity Is Testing Who Controls AI Commerce"independent legal analysis of the amended complaint — the two Ninth Circuit issues it answers (Perplexity itself accessed Amazon; contract-based claim via Conditions of Use); "Comet is Perplexity's instrument" characterization; direct access Mar 18 through at least May 11, 2026 "while Perplexity was telling the Ninth Circuit that 'no Perplexity computer ever has direct access to an Amazon computer'"; Agent Terms (since May 2025) identification/restriction/opt-out duties; case cite 3:25-cv-09514 (N.D. Cal.); Aug 4 vacatur and Sep 10 rehearing denial. — independent legal analysis (CONFIRMED).Date: 2026-09-23
Visit source ↗
Independent
AI Weekly — "Amazon Alleges Perplexity Misled Ninth Circuit on Comet Traffic" (Alexis Dufresne)corroboration of the 41-page amended complaint (filed Sep 21); direct server-to-server traffic logged daily Mar 18 → at least May 11, 2026; the "no Perplexity computer ever has direct access" brief statements (Apr 1, May 6); May 6 letter / May 11 "good-faith" disable response; 185,712 sessions by June 15; 1,280 hours / eight traffic-engineering staff; Chrome UA echoing the Cloudflare Aug 2025 report; Ninth Circuit Aug 4 ruling and Sep 10 rehearing refusal; same-weekend Muse block context. — independent reporting (CONFIRMED).Date: 2026-09-22
Visit source ↗
Independent
Business Insider (Markets) — "Amazon files amended complaint against Perplexity"headline-level corroboration — "Amazon claims that when Comet users on iOS shopped Amazon, **Perplexity's own computers logged in with the customers' credentials**"; contrast with Perplexity's Ninth Circuit statements (Apr 1 and May 6, 2026). — independent reporting (CONFIRMED).Date: 2026-09-22
Visit source ↗
Independent
The Next Web — "Amazon blocks Meta's Muse and accuses Perplexity of misleading a court" (Ana Maria Constantin)same-day (Sep 21, 3:59 pm UTC) independent confirmation of the amended complaint (41 pages; CFAA + California computer statute + tortious interference); Comet for iOS cookie-copy/virtual-browser mechanism; "No user device touches Amazon's servers"; Apr 1/May 6, 2026 briefs; May 6 letter; May 11 response; damages beyond $260k; 1,280 hours / 8 engineers; 185,712 sessions as of June 15; Chrome UA ("Perplexity chooses that value, Perplexity codes it into the software Perplexity distributes"); Cloudflare August 2025 undeclared-crawler report; Agent Terms added May 30, 2025; Perplexity's quoted position ("demanding we prohibit Comet users from using their AI assistants on Amazon"); same-day Muse block context (GeekWire/Bloomberg links). — independent reporting (CONFIRMED; full text fetched).Date: 2026-09-21
Visit source ↗
Secondary Sources (3)
Secondary
Jason Del Rey (The Aisle) — X post flagging the amended-complaint filing (cited by TNW)contemporaneous discovery of the filing by the retail journalist who first flagged it publicly; referenced within TNW's article. Not directly fetched (X login wall). — secondary reference (as cited by TNW; NOT directly verified).Date: 2026-09-21
Visit source ↗
Secondary
Cloudflare blog — "Perplexity is using stealth, undeclared crawlers to evade website 'no crawl' directives"background to the user-agent allegations — Cloudflare's August 2025 finding that Perplexity ran an undeclared crawler impersonating Chrome on macOS and removed Perplexity from its verified-operator list (as cited in the amended complaint and in TNW's coverage; not directly fetched by this researcher, quoted via TNW and complaint recital). — secondary background (as cited in primary/independent sources).Date: 2025-08
Visit source ↗
Secondary
UniCourt — case page, *Amazoncom Services LLC v Perplexity AI, Inc* (3:25-cv-09514)background — original complaint entry, Perplexity's Apr 7, 2026 stay motions (docs 95/96) pending the Ninth Circuit appeal, case status "Open," Judge Chesney. — secondary docket mirror (background; CONFIRMED for cited entries).Date: page current as of research (case filed 2025-11-04)
Visit source ↗
Unverified Sources (2)
Unverified
Discovery-record phrasing "triggering ATTRP/anti-bot responses" (research/DISCOVERY_RAW.json, S15 entry) - **No URL recorded** (reason: the term "ATTRP" does not appear in the First Amended Complaint or in any consulted source. The primary document refers to Amazon's **Ad Traffic Quality** and Traffic Engineering teams being forced to detect and trace Comet for iOS server-to-server traffic (Mar 18–May 11, 2026). Treated as an unverified discovery artifact; deliberately not used as fact in the analysis.)UNVERIFIED / corrected by primary source. *Limitation note: the full PACER docket was not directly consulted (paywalled); the CourtListener RECAP copy of Dkt. 122 is a faithful full-text mirror of the filed pleading and was read in its entirety (41 pages). Perplexity has not answered the amended complaint as of 2026-09-22; no Perplexity primary statement responding to the amendment was located (its quoted position is carried in Amazon's own filing).*Date: n/a
URL unavailable
Unverified
MLex — Amazon v. Perplexity amended-complaint report (per DISCOVERY_RAW.json, "Sep 21, 15:20 GMT") - **No URL recorded** (reason: the specific MLex article URL could not be located in open web search; MLex is a subscription service. The discovery record lists it as the initial independent source. Every new-allegation detail attributed to that report in the discovery record — iOS customer login, cookie use, direct-access period, CFAA/CDAFA claims — was independently verified against the primary docket PDF (S1) and TNW/AI Weekly/Business Insider/The Fashion Law (S7–S10), so no claim in this research depends on MLex.)UNVERIFIED (not directly accessed; superseded by primary + independent verification).Date: 2026-09-21 (per discovery record)
URL unavailable