For about eighteen months the advertising and retail industries have been arguing about software that shops, reads and browses on somebody's behalf. The argument has mostly been commercial: which protocol, which registry, whose checkout. A federal appeals court has now answered a narrower and more consequential question. When an assistant clicks through a retailer's pages, who is the visitor?
The answer, at least in the Ninth Circuit, is the person at the keyboard. That single finding removes the strongest legal instrument American retailers and publishers had for keeping third-party agents off their pages, and it landed in the trade press in the same week that Google began paying publishers by the use for content that feeds its AI answers, that Chrome started testing a cryptographic way to prove a browser session belongs to a human, and that two separate coalitions in Brussels wrote to the European Commission about who gets to refuse and who gets to be seen.

Different mechanisms, one subject. The web is being re-plumbed around a question that used to be trivial: is this a person, and if not, on what terms is the machine allowed in?
The court says the human is the visitor
A federal appeals court vacated the preliminary injunction that had kept Perplexity AI's Comet browser assistant out of Amazon shopping accounts. The opinion in Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444, issued on August 4, 2026, after argument in Seattle on June 11. Circuit Judge Milan D. Smith, Jr. wrote for a panel that also included Circuit Judge Eric C. Tung and District Judge John Charles Hinderaker of the District of Arizona, sitting by designation. Below, in the Northern District of California, Judge Maxine M. Chesney had granted the injunction on March 9, 2026 and called the question a close call. Hueston Hennigan argued for Amazon, with Hagan Scotten at the lectern; Quinn Emanuel Urquhart & Sullivan appeared for Perplexity, argued by Christopher G. Michel.
Amazon brought the case under two statutes written long before anything like Comet existed. The Computer Fraud and Abuse Act, enacted in 1984 and expanded in 1996 to reach any protected computer, requires a plaintiff to show intentional access to a protected computer, without authorisation or exceeding authorised access, obtaining information as a result, and loss of at least 5,000 dollars in a one-year period. California's Comprehensive Computer Data Access and Fraud Act, on the books since 1987, reaches a person who causes unauthorised access, with a broader definition covering input to or data processing with the logical, arithmetical or memory functions of a computer.
The panel never reached most of those elements. It stopped at the first one.
What matters is the architecture, and the opinion describes it with unusual care. When a user directs the assistant to find an item, the assistant takes screenshots of the browser view, sends those screenshots from the user's computer to Perplexity's servers, and receives navigation instructions back. Perplexity's own position was that the assistant cannot operate independently: it depends on user direction at one end and server-returned instructions at the other. An amicus brief filed by the Electronic Frontier Foundation, the Alliance for Responsible Data Collection, Mozilla, Digital Medusa and EleutherAI made the technical consequence explicit. Perplexity's servers never directly touch Amazon's servers. The packets that arrive at Amazon come from the user's machine.
Amazon leaned on Facebook, Inc. v. Power Ventures, Inc., where the Ninth Circuit had treated the defendant as having accessed Facebook. The panel declined to be bound by what it called an unexamined premise, noting the earlier court had assumed access without discussion. Perplexity's preferred analogy, Meta Platforms, Inc. v. BrandTotal Ltd., fared no better: the assistant appears to do more than passive data collection, which made that comparison imperfect in the opposite direction. Van Buren v. United States supplied the working definition, access as entering a system or a particular part of one, and United States v. Nosal supplied the caution against turning otherwise innocuous behaviour into a federal crime because a computer is involved. Because the CFAA is primarily a criminal statute whose interpretations carry into civil cases, the panel applied the rule of lenity and construed the ambiguity against liability.
The harm analysis is where the ruling reaches beyond agents. Amazon argued that the assistant may not select the best price, delivery method or product recommendations. The panel read that as a claim of degraded experience rather than demonstrable loss of goodwill, contrasting it with Stuhlbarg International Sales Co. v. John D. Brush & Co., where customs detention of goods already promised to named customers made the injury concrete. On security, the court observed that only one of the cyber risks cited in Amazon's expert declaration involved a shopping website at all, and that the example did not involve Amazon.com. All four preliminary injunction factors came out against Amazon. The balance of equities favoured Perplexity because an injunction would burden product development involving large sums, and the public interest favoured Perplexity because a block would impair consumer choice while limiting development of a nascent technology.
Five days before the opinion issued, Amazon had reported advertising services revenue of 19.8 billion dollars for the second quarter of 2026, up 26 percent year over year. That is the commercial backdrop to a fight nominally about hacking law.
The dispute did not begin in court. In August 2025 Amazon contacted Perplexity about Comet's user-agent string behaviour and put a technical block in place. Research published the following month found most major merchants in the United Kingdom and the United States welcoming AI agents, with Amazon the primary exception. In October 2025 Cloudflare documented undeclared Perplexity crawling that used a generic Chrome user agent. Amazon filed in November 2025. After the March injunction the district court denied a bond and a broader stay, issuing only a seven-day administrative stay. Google added Google-Agent to its official crawler documentation on March 20, 2026. Perplexity filed its opening brief on April 1; publishers filed an amicus brief backing Amazon on April 29; Amazon posted an engineering role for an agentic commerce team on May 10. A footnote records that the parties still disagree over whether Perplexity knowingly altered the assistant's user-agent string after Amazon first identified and blocked it.
The alignment of amici is worth reading as an industry map. Digital Content Next, the News/Media Alliance, the National Retail Federation, the Software and Information Industry Association and Airlines for America supported Amazon. The EFF, the Alliance for Responsible Data Collection, Mozilla, Digital Medusa, EleutherAI, the American Civil Liberties Union and the Knight First Amendment Institute supported Perplexity. Publishers and retailers on one side, civil liberties organisations and open-web groups on the other, with no obvious way to satisfy both.
The panel was careful about what it did not decide. It did not establish a legal regime governing autonomous software. It did not address whether Perplexity could face liability on other theories, including tort claims. It did not reach the remaining CFAA elements, including the scope of the loss provision, and it did not touch the separate provision at section 1030(a)(4), which Amazon chose not to press on appeal. Nor did it rule out a different factual record showing an operator exercising enough control to constitute gaining entry.
The practical summary comes from the opinion itself: the outcome does not impair Amazon's ability to regulate access to Amazon.com through private terms of service for its users. What Amazon lost is the ability to convert that contractual preference into a federal computer crime claim against the agent's developer. Terms of service, rate limiting and technical blocking survive. The federal hammer does not.

Amazon has been building the commercial alternative in parallel. A formal agent policy was added to its Business Solutions Agreement effective March 4, 2026. The company joined the governance council for the Universal Commerce Protocol in April 2026, and its agentic commerce team is oriented toward controlled, API-mediated connections with outside AI platforms. That is the shape of the settlement now available to any large retailer: negotiate the pipe, because the statute will not close the door.
The regulatory vacuum around all of this is real. There is no comprehensive federal AI statute in the United States. Executive orders and agency guidance exist without defining much substantively. The TAKE IT DOWN Act, which took effect on May 19, 2026, covers non-consensual intimate imagery only. Texas brought its Responsible Artificial Intelligence Governance Act into force on January 1, 2026, California's AI Transparency Act on August 2, 2026, and Colorado repealed its 2024 high-risk framework in May 2026 in favour of a narrower automated decision-making statute effective January 1, 2027. None of them says who is doing the accessing when an agent loads a page.
Google starts metering what a publisher is worth to an answer
If the courts will not price agent access, the platforms will. Google has begun testing a pay-per-use licensing scheme for publishers whose content contributes to AI-generated responses, reported on September 14 by Jessica Davies. The programme, described internally as an AI contribution pilot, runs through Search Console: a dashboard widget shows monthly earnings when a publisher's material feeds answers across Gemini, AI Overviews and AI Mode.
The commercial terms are deliberately light. Payment is usage-based with no upfront fee, and participants can opt out at any time. What is missing is the part that would let anyone evaluate it. The calculation methodology is undisclosed. One participating executive described the available information as quite black box. Another was more resigned: do I wish they were more transparent? Definitely, the executive said, while arguing that being inside the programme beats waiting on the sidelines.
At least dozens of publishers have been approached, though the exact number is unconfirmed, and the pitch appears to land better with small and mid-sized operations than with major outlets. Unlike Google's earlier arrangements, this one includes non-news publishers. Those earlier arrangements set the benchmark: a news AI scheme covering more than 200 titles globally, and Google News Showcase, which spans more than 2,800 publications across 33 countries.
The complaints are consistent and quantitative in tone even where no numbers are attached. Publishers describe the payouts as peanuts relative to advertising revenue, and lowball numbers that fail to clear internal revenue thresholds. There is also a structural worry: participating in a programme with undisclosed rate-setting may weaken whatever negotiating position a publisher has left. Luke Stillman of Madison and Wall put the imbalance plainly, observing that publishers have relatively little leverage over how AI changes content discovery. David Buttle of Spur characterised the programme as a strategic hedge rather than meaningful compensation.
Set that beside the Perplexity ruling and a pattern appears. In both cases the mechanism that decides how much a publisher or retailer gets paid for machine access is private, unaudited and set by the party with the traffic. The court left Amazon its contract; Google is offering publishers a rate card whose arithmetic it will not show.
Antitrust has begun to notice. In a separate piece published the same day, Ronan Shields reported that the enforcement fight is moving from ad tech toward AI as behavioural remedies in the search and ad tech cases move toward final decisions. Alan Chapell, a privacy attorney and co-host of The Monopoly Report, argued that the Department of Justice proposed a structural remedy that was ultimately too complex. Practices surfaced during the litigation, including the initiative known internally as Red State, which lowered rival exchange bid prices, and the Jedi Blue auction arrangement with Meta, remain unaddressed by any remedy.
The forward-looking concern is the one that connects to the Ninth Circuit. James Rosewell, co-founder of Movement for an Open Web, warned that Google has the ability to leverage its existing dominance across payments, email, search and browsers to monopolise agentic commerce. That is not a claim about crawling. It is a claim about who owns the identity, the wallet and the rendering surface at the moment an agent transacts, which is precisely the territory the Perplexity opinion declined to map.
One bit of proof that somebody is human
Chrome is testing an answer to the smaller version of the same question. Google has begun a trial of Private Verification Tokens, a cryptographic signal that lets a site tell itself an Incognito visitor is probably a person, and the striking thing about the design is how little it is willing to say.
The mechanism sits on the Anonymous Tokens with Hidden Metadata protocol. A site issues a trust signal during ordinary browsing, and the user can redeem it once per session in Incognito mode. The token carries a single bit of accumulated reputation, specified as nBuckets = 2. A session can redeem tokens for a maximum of two distinct registered domains. Transmission happens through an HTTP header named Sec-Private-Verification-Token, attached to cookieless requests. Issuance and redemption are confined to top-level origins on the same eTLD+1, and expiry is bounded on both sides so that users cannot be sorted into cohorts by key version. Every one of those limits exists to preserve unlinkability: the token is meant to say that somebody vouched for this session and nothing else.
The timeline is short. The Chrome Platform Status entry was created on April 2, 2026, Chrome 154 reached beta on September 2, and the status entry was last updated on September 3. The origin trial window runs from Chrome 154 to Chrome 165 on desktop and Android. Publishers who want to issue tokens must register and accept a policy restricting their use to trust, rate limiting and invalid traffic detection, though the registration process itself is not yet defined.
The support picture is thin. Neither Firefox nor WebKit has signalled a position. Technical Architecture Group review is pending. The design document disclaims any approval to ship. Five Google engineers are listed as owners, and the public repository carries 24 commits, nine stars and two forks. This is an experiment, not a standard.
Why build it at all is the interesting part, and it runs straight back to the first two stories. Automated traffic now accounts for more than half of web requests, which means privacy-preserving browsing modes have become statistically indistinguishable from machines. Users who turn off the identifiers get treated as bots, and collect the CAPTCHA friction that follows. Private Verification Tokens try to break the tie with the smallest signal its authors believe will work, which is a notably different philosophy from the credentialed approach taken by Web Bot Auth, where the point is for a machine to identify itself rather than for a human to be distinguished from one.
Between them the two approaches describe the whole design space. Either the machine declares itself and is admitted on terms, or the human proves personhood and everything unproven is treated as automated. The Perplexity opinion complicates both, because an agent driven from a user's own browser produces requests that come from the human's machine and carry the human's session.
Brussels argues about refusal, and about visibility
Two letters reached the European Commission in the same week, on two different files, and both concern control over a user's path to a merchant.
The first is about consent. Nineteen organisations have asked the European Union to restore a provision on automated privacy signals that was stripped from the Digital Omnibus. The Kill the cookie banner campaign, coordinated by noyb, distributed its open letter at 07:00 CET on September 10, 2026. Signatories include the European Consumer Organisation, Check My Ads, the Civil Liberties Union for Europe, European Digital Rights, the Electronic Frontier Foundation, Enforce, Stichting Data Bescherming Nederland, the AI Accountability Lab, ApTI, the Spanish consumer federation CECU, Data Rights, EKO, Forbrukerradet, Homo Digitalis, Kobler, the Sustainable Computing Lab and Que Choisir Ensemble.
The provision at issue is Article 88b of the Digital Omnibus, published by the Commission on November 19, 2025 as COM(2025) 837 final. It would require controllers to respect automated privacy signals transmitted by browsers and operating systems, with a two-year phase-in for websites and four years for browsers and operating systems. The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion supporting automated signals on February 10, 2026. Alliance Digitale called for the article's deletion on May 21, 2026, and the Council removed it from its compromise text on June 18. The coalition's framing is blunt: automated signals is the only proposal from the Commission's Digital Omnibus aimed at actually simplifying the life of consumers.
The annexed conditions are where the advertising consequences sit. The coalition wants per-controller and per-purpose granularity meeting the Article 4(11) GDPR consent standard, so a signal is not reduced to a single global toggle. It wants refusal signals to prevent corresponding access and to take precedence over later requests. It wants gatekeeper browsers and operating systems barred from controlling signal design, the legal meaning of a signal fixed in Union law rather than delegated to standards bodies, refusals that persist rather than being worn down by repeated prompts, and transmission without gatekeeper interference or attached tracking.
The industry objection, as recorded in Alliance Digitale's May 2026 document, is operational rather than philosophical: interpreting browser-level signals would demand deep adaptation of existing tracking, consent and monetisation infrastructure. noyb identifies Germany, France and Poland as the member states pushing for removal. Consultants have derived estimates of 40 to 50 billion euros potentially at stake, using Apple's App Tracking Transparency as the proxy, a comparison that assumes rather than demonstrates that browser-level refusal would behave like the iOS prompt. The letter is addressed to the Irish Council presidency, co-rapporteurs Kaljurand and Salla, Executive Vice President Virkkunen and Commissioner McGrath. Parliament has not yet adopted a position, and the provision remains out of the Council text.
The second letter is about visibility. Twelve European comparison shopping services warned the Commission on September 8, 2026 that the shopping remedy under consideration could increase Google's share rather than reduce it. The signatories are Productcaster, Booncy, adstrong, Sembot, shopmos, McDiscount, Genie Shopping, Shoptimised, Producthero, ShopForward, Shoparize and smec. Together they claim to represent more than 93,000 active European merchants and an estimated 74 percent of all third-party comparison shopping clicks across the European Economic Area and the United Kingdom.
Their objection is to a box-to-box design, under which Google would run its own closed shopping unit alongside units operated by rival comparison shopping services. The coalition's argument is that retailers would drift back to Google's own service simply to stay visible in the unit that gets the most attention, so a remedy meant to open the surface would concentrate it. What they want instead is an obligation for Google Shopping to bid inside every competing comparison box, putting Google's product listing ads in the same auction as everyone else's rather than in a reserved one. Dirk Verzijden of ShopForward allowed that the principle of more players competing for visibility sounds positive, adding that the details matter.
The timing is tight, which is why the letter exists at all. The Commission's decision of July 23, 2026 gave Google 60 days to end its self-preferencing violations, putting the deadline somewhere between September 21 and 25 depending on when notification took effect. The coalition is asking for live market testing before any final remedy design is locked, which on that calendar means asking a regulator to slow down at the exact point it has committed to move.
The announcement that would cost 3.5 billion pounds
The week's last file concerns a medium with no agents in it at all, and it makes a similar point about the gap between a stated rule and its behavioural effect.
A report published in late August argues that announcing a 2034 switch-off for United Kingdom digital terrestrial television would devalue broadcaster advertising immediately, years before any transmitter goes dark. A Risk Too Far was written by Ian Whittaker of Liberty Sky Advisors and commissioned in April 2026 by Arqiva, the terrestrial network operator, which has a direct commercial interest in continuation to 2044. That interest should be weighed against the findings rather than substituted for them.
The modelled numbers are specific. Commercial public service broadcaster advertising revenue would fall roughly 16 percent by 2034 under the earlier switch-off scenario, with cumulative losses of about 3.5 billion pounds across 2028 to 2036. ITV would take a decline near 12 percent, Channel 4 nearer 20 percent. The leakage assumption does most of the work: only 15 pence of every pound leaving linear returns to broadcaster streaming, against roughly 25 cents in the United States.
Whittaker calls the central mechanism the announcement effect. Confirming an end date would trigger reclassification of television inside advertiser boardrooms, moving it from a protected budget line to a declining medium well before the infrastructure changes. Four structural features are said to make that reclassification sticky: separate agency buying silos, BARB measurement standards, planning conventions that treat linear as a distinct strategic category, and agency economics that favour programmatic inventory.
The pricing detail explains where the money goes. Linear trades at roughly 4 to 5 dollars CPM, close to platform rates, while broadcaster streaming asks 22 to 25 dollars. Whittaker describes the resulting pattern as cheap-tier retention: advertisers holding a low-cost linear allocation until it disappears, then moving to the platforms or YouTube rather than paying four to five times as much for the broadcaster's own streaming inventory. The United Kingdom advertising market was worth 46.7 billion pounds in 2025, with about two thirds going to Google, Meta and Amazon, so the destination of displaced budget is not much in doubt. The July 6, 2026 acquisition of ITV Media & Entertainment by Sky, at 1.6 billion pounds, has already redrawn part of the commercial map the report models.
Channel 4 is identified as the leading indicator, because advertising supplies around 90 percent of its revenue and its state-owned structure leaves it unable to raise equity. The report offers three falsification tests, which is rarer in commissioned research than it should be: significant Channel 4 underperformance, early scaling back of independent commissioning, and convergence of broadcaster streaming prices toward YouTube levels. Whittaker also raises a non-commercial argument, positioning terrestrial broadcast as the only sovereign, terrestrial and broadcast communications layer in a country otherwise dependent on United States cloud platforms and content delivery networks.
Line the week up and one thread runs through all five. A court decided that the packets arriving at a retailer come from a human, which leaves private contract as the only lever over agent traffic. A platform began paying for machine consumption of publisher content at rates it will not explain. A browser started testing a one-bit way to say that a session probably belongs to a person. A consumer coalition asked Brussels to make refusal machine-readable while an industry association argued that reading refusals would require rebuilding the monetisation stack. And an analyst argued that merely stating a date in 2034 would reprice an entire medium in 2027.
In each case the technical fact and the commercial consequence have come apart. The mechanism is legible; the price of it is not.
Also noted
- September 13: Florida sued Netflix in the Circuit Court of the Seventh Judicial Circuit, St. Johns County, over children's data, seeking up to 50,000 dollars per violation of the state Digital Bill of Rights alongside four counts under the Florida Deceptive and Unfair Trade Practices Act, and naming LiveRamp, Experian, Acxiom, Display & Video 360, The Trade Desk, Yahoo DSP and Amazon DSP as recipients of behavioural data.
- September 13: Taboola renewed its Goal.com arrangement through December 2028 across a property drawing more than 125 million monthly visits in 19 languages, extending Feed and header bidding across five Footballco titles with no financial terms disclosed.
- September 13: Azerion integrated microm's PLZ-8 grid into its Hawk platform, dividing Germany into about 82,000 zones of roughly 500 households each for cookieless targeting across digital out-of-home, connected television, audio, mobile and desktop.
- September 12: Pinterest rewrote its advertising policies effective November 12, 2026, banning binary options, synthetic media misrepresentation, scam tooling and fictitious shopfronts, while relaxing landing page rules to permit dismissible interstitials.
- September 12: LaLiga shut its direct-to-consumer platform, with LaLiga+ going dark at midnight on June 30, 2026 after seven years, scattering minority-sport inventory across federations in a market where Spanish connected television advertising grew 48.4 percent to 174.9 million euros in 2025.
Discussion