← All posts / Policy

The Reply Brief That Contradicted the Servers: Inside Amazon's Amended Attack on Perplexity

Amazon's 41-page amended complaint alleges Comet for iOS copied session cookies to Perplexity cloud servers that talked directly to Amazon — directly contradicting what Perplexity's lawyers told the Ninth Circuit, and moving the agent wars from hacking law to contract law.

The Reply Brief That Contradicted the Servers: Inside Amazon's Amended Attack on Perplexity

On September 21, 2026, Amazon opened a second front in its war on AI shopping agents — and this one is aimed at the paper trail, not the code. Filed the same day the company began blocking Meta’s Muse from its storefront, a 41-page amended complaint in Amazon.com Services, LLC v. Perplexity AI, Inc. accuses Perplexity of telling the Ninth Circuit something its own server logs contradicted. If the allegations hold up, they do more than revive a wounded lawsuit: they challenge the factual foundation of one of the most important agentic-AI rulings of the year.

What the amended complaint alleges

The new material centers on Comet for iOS, a version of Perplexity’s agentic browser that launched on March 18, 2026 — nine days after a district court judge enjoined the desktop product from shopping on Amazon. The timing alone is provocative. But the architecture is the real allegation.

On iOS, Amazon claims, Comet copies the user’s Amazon session cookie to Perplexity’s own cloud servers. Those servers then run a virtual browser and request pages from Amazon directly. “No user device touches Amazon’s servers,” the complaint states. The distinction is surgical, because of what Perplexity told the appeals court.

In briefs filed on April 1 and May 6, 2026, Perplexity represented to the Ninth Circuit that “no Perplexity computer ever has direct access to an Amazon computer.” That claim sat at the heart of its defense: if the user’s own browser is the thing talking to Amazon, then under the Computer Fraud and Abuse Act it is the user — not Perplexity — who “accesses” the protected computer.

Amazon says its traffic engineers watched exactly that server-to-server traffic every day between March 18 and at least May 11.

The sequence Amazon lays out is pointed. Its counsel wrote to Perplexity’s counsel on May 6, identifying each allegedly false statement by page number and asking for a correction. Perplexity filed a reply brief later that same day repeating the statements. Five days later, its counsel wrote back with a quieter concession: “As a measure of good-faith, Perplexity has temporarily disabled the assistant feature on Amazon.com in Comet for iOS.”

The numbers Amazon is putting on it

The damages claims give a sense of scale. Amazon says damages exceed $260,000 — the threshold for certain claims under the CFAA — and that eight members of its traffic engineering team have spent at least 1,280 hours on the agent since July 2025. As of June 15, 2026, Comet had run at least 185,712 sessions on Amazon.com.

The complaint also returns to the user-agent string — the line of text a browser sends to identify itself. Comet sends Google Chrome’s. “Perplexity chooses that value, Perplexity codes it into the software Perplexity distributes,” the filing reads, noting that the string has been changed each time Amazon learned to detect the agent. The complaint cites Cloudflare’s August 2025 finding that Perplexity ran an undeclared crawler impersonating Chrome on macOS — conduct that got the company removed from Cloudflare’s list of verified operators.

The amended pleading adds tortious interference with contract to the original computer-fraud claims, alongside the federal CFAA and California’s CDAFA. Perplexity has not yet filed a response. Its public position, quoted in Amazon’s own filing, is that Amazon is “demanding we prohibit Comet users from using their AI assistants on Amazon.”

Why the ground shifted to contracts

Context matters here, because this filing is Amazon’s second act after a major legal defeat.

Amazon sued Perplexity in November 2025 and won a preliminary injunction in March 2026, when a district judge found “strong evidence” of unlawful access. That win evaporated on August 4, when the Ninth Circuit vacated the injunction. The panel held that it was the user — “with the help of Perplexity’s AI agent, the ‘Assistant’” — who accessed Amazon’s computers, not Perplexity itself. A petition for rehearing was denied on September 10.

Statutory hacking claims against agent companies are, for now, dead ends in the Ninth Circuit. So Amazon has pivoted: from statute to contract, and from architecture arguments to credibility arguments.

The cookie-to-cloud allegation is designed to thread the needle the appeals court left open. If no user device sits in the middle of the iOS traffic — if Perplexity’s own servers are requesting Amazon pages with a session cookie Amazon’s systems can’t distinguish from Chrome — then the “it was the user” holding doesn’t apply to that conduct. And the alleged misstatements to the court, if proven, independently damage Perplexity’s credibility on the exact question the panel decided.

What’s actually at stake

The commercial backdrop is the part Amazon spells out in its own language. The company generated more than $68 billion in advertising revenue last year, a business that depends on people browsing its pages and seeing sponsored products. Agent traffic forces Amazon to build new detection systems, the complaint argues, so that advertisers are billed only for human impressions.

Amazon is not opposed to agents as such — its position is more precise than that. It put Alexa in the search bar in May. Its “Buy for Me” feature shops external brand sites, identifies itself, and honors brand opt-outs. This month it struck a deal to put its advertisers into ChatGPT. What it demands is symmetry: agents on its turf must follow the same identification rules its own agent follows everywhere else.

That symmetry argument now has a legal vehicle. Amazon amended its Conditions of Use on May 30, 2025 to add an Agent Terms section requiring agents to identify themselves in the user-agent string as “Agent/[agent name]”. The Muse popup unveiled this weekend cites those Conditions of Use. The amended complaint is the courtroom version of the same theory: consent isn’t just about the user’s permission — it’s about the platform’s terms.

The road ahead

For an industry racing to make agents the default interface for commerce, the filing marks an uncomfortable turn. The first wave of agent litigation asked whether agents hack. The Ninth Circuit said no. The second wave asks two harder questions: whether agents honor the contracts users clicked through, and whether the companies that build them can be trusted when they describe their own architecture to a court.

Amazon’s evidence — dated logs, a letter identifying page numbers, a reply brief filed hours later — is the kind of paper trail litigation over “he said, she said” technical claims rarely produces. Perplexity’s response, when it comes, will have to explain the same logs. And every other company building an agent that touches someone else’s platform is now on notice that its court filings are discoverable statements about its infrastructure — ones its own servers may later contradict.