Live Commerce

The real fight over shopping bots is who owns your checkout

A court let Perplexity's AI agents back onto Amazon. The bigger question is whether retailers can keep autonomous buyers out at all.

Why it matters

Retailers with their own storefronts now face a harder time blocking third-party AI agents that shop, compare and buy on a customer's behalf. If accessing a public retail site with a bot is not by itself illegal hacking, Amazon's main legal lever against agents like Perplexity's weakens. That shifts leverage toward the companies building the shopping assistants and away from the platforms that host the products.

What changes next

Watch whether Amazon pursues the case on the merits or shifts to technical blocking and terms-of-service enforcement instead of the hacking claim. Also watch whether other large retailers publish explicit agent policies in the next few quarters, and whether Perplexity's agents can actually complete purchases at scale rather than just browse.

If you run a retail site, the Perplexity ruling is not really about one AI startup. It is about whether you get to decide who, or what, walks through your front door. PYMNTS reported that a U.S. appeals court overturned a March order that had barred Perplexity's agentic shopping tools from reaching Amazon, with Amazon leaning on a federal anti-hacking law and Perplexity arguing it never accessed anything without permission.

Why the hacking argument was always a stretch

The Computer Fraud and Abuse Act was written for people breaking into systems they had no business touching. Amazon's storefront is public. Anyone with a browser can load a product page, read the price and add an item to a cart. When a company argues that an automated agent doing the same thing is illegal access, it is asking a court to treat a bot's visit as a crime that a human's visit is not.

That is a difficult position, and the appeals court's reversal suggests it did not hold. The practical takeaway for retailers is blunt: the criminal-law route to keeping agents out is shaky. If your public pages are open to people, calling a script that reads them a hacker is unlikely to survive.

What retailers can actually control

This does not leave platforms defenseless. It just pushes the fight from courtrooms into engineering and contracts. Rate limits, bot detection, requiring logins for checkout, and terms of service that explicitly forbid automated purchasing are all still on the table. Amazon has deep experience blocking scrapers and resellers, and none of that depends on the hacking statute.

The tension underneath is commercial, not legal. An agent that shops across many stores strips away the things Amazon spends heavily to build: search ranking, recommendations, ads, the habit of opening the app. If the buyer is an AI comparing prices dispassionately, the store becomes a warehouse with an API. That is the outcome platforms want to avoid, and it explains why they will keep fighting even when a specific legal theory fails.

The catch nobody should skip

A reversal of a temporary ban is not a final verdict. The underlying dispute can still be litigated, and courts in different circuits have read the anti-hacking law in conflicting ways over the years. Perplexity winning this round does not settle whether large-scale agentic buying is durable.

There is also a gap between browsing and buying. Reading prices is easy; completing a purchase means handling accounts, payment credentials, addresses and returns, all of which a retailer can gate behind authentication it controls. So even with the legal pressure eased, an agent's ability to actually check out at scale is an open technical question, not a done deal.

For merchants outside Amazon, the smarter move is to decide now whether agents are a threat or a channel. Some will want to block them to protect margins and data. Others may find that being easy for a shopping agent to buy from is a cheap way to win sales they would otherwise lose to a competitor the agent finds first. The ruling makes that a strategy question rather than one you can outsource to a hacking claim.

Source: PYMNTS.com