A Court Just Cleared a Non-Amazon AI Agent to Shop Your Listing
๐Ÿ“ข
← Back to Blog

A Court Just Cleared a Non-Amazon AI Agent to Shop Your Listing

John Aspinall · · 9 min read

For two years, the honest answer to "who reads your Amazon listing" was: a shopper, and Amazon's model. Everything I've published about the AI layer has been about the second one โ€” Rufus, then Alexa for Shopping, reading your bullets and your attributes and your A+ copy to decide whether you make the consideration set. That's Amazon's model, reading Amazon's catalog, using the structured fields Amazon assigned you.

As of August 4 there is a third reader. It doesn't work for Amazon, Amazon tried to keep it out, and Amazon lost.

What happened

On August 4, 2026, the Ninth Circuit vacated the preliminary injunction that had blocked Perplexity's Comet browser agent from shopping on Amazon on a user's behalf (opinion 26-1444). Amazon sued in November 2025 under the Computer Fraud and Abuse Act and California's CDAFA; a district court granted the injunction on March 9, 2026; the appeals panel reversed.

The reasoning is the part that matters. The panel held that when a user tasks an agent with doing something on Amazon.com, it is the user who accessed Amazon's computers, not the company that built the agent. The case went back down for further proceedings, and the court was explicit that the holding is narrow โ€” it's tied to how Comet is architected, running inside the user's own session, and an agent talking more directly to a site's servers could still be on the hook.

This is two weeks old, not two days old, and I've sat on it while the legal write-ups landed. Nobody has written it from the seller's chair.

The two dumb takes

"AI agents are going to eat the marketplace." No. Adoption is a rounding error. Etsy has reported agent platforms at under 1% of traffic, and roughly half of shoppers say they'd let an agent actually complete a payment. Nothing about this shows up on your P&L this quarter, and I'd rather say that out loud than manufacture urgency.

"Not my problem then." Also no, and this is the one that costs you later. The number is small. The category is new. For the entire history of this marketplace, every reader of your detail page was either a human Amazon served the page to, or a model Amazon built. Both of those read the page the way Amazon decided to present it. This one doesn't. It reads whatever your page renders, in whatever order it renders, with no curation layer in between and no incentive to make you look good.

That's the signal: a reader arrived that Amazon didn't build, doesn't control, and can't merchandise for.

What actually changes for a $200K/mo brand

Four things, in order of how soon they bite.

1. Nothing about your creative. Today. Say it plainly so nobody sells you a rebuild off this. Your hero image, your stack, your Q4 plan โ€” none of it changes because of a court ruling. If somebody quotes you for "agentic commerce readiness" this month, ask them what the deliverable is in one sentence.

2. Your reporting has a new blind spot, and it's the same shape as every other one. An agent-driven session is a session. It frequently has no search term behind it, because the agent may never run a search on Amazon at all โ€” it was pointed at a page, or working off a shortlist assembled somewhere else entirely. So it doesn't land in Search Query Performance as a query you can act on. It doesn't attach to a keyword. It doesn't click an ad. It shows up in your numbers as traffic that converted or didn't, blended into an average, with nothing you can do about it because there's no line item.

Same class of problem as the shopper who bounced off your customer review photos: unmeasured doesn't mean small, it means unassigned.

3. The assets that do the work for this reader are the ones with no alarm. An agent operating a logged-in browser session is reading text: title, bullets, structured attributes, A+ copy, alt text, price, the review summary. I'll hedge the obvious โ€” some agents are multimodal and can process images, and I have no visibility into what any given one weights. What I can say is that a page whose argument lives entirely in a 2000-pixel infographic is making that argument to a reader who has to work harder to receive it, and the fields that transmit cleanly are exactly the ones nobody in your business owns.

Attributes nobody filled. A+ copy nobody read out loud. Alt text left blank because it's a field in a module and no dashboard turns red when it's empty.

The good news is that this is not new work. It's the same work you'd do for Amazon's own AI layer. Complete attributes, natural-language A+ that reads like a person wrote it, populated alt text, an Item Highlights field that isn't a comma salad. Two different readers, one job. That doesn't happen often.

4. The frame it never reaches is the search card. If a shortlist got assembled off-Amazon and the agent arrives at your PDP directly, your thumbnail didn't happen. Your 75 characters didn't happen. The new Item Highlights line under your product name didn't happen. None of that is an argument for caring less about them โ€” they still decide the overwhelming majority of your traffic โ€” but it's the first time a share of your qualification is occurring on a surface you own nothing on.

The asymmetry nobody has pointed at

Here's the part I find genuinely interesting.

Amazon's own Business Solutions Agreement added Section 19 effective March 4, 2026, covering "Agents" โ€” automated tools, AI systems, bots accessing Amazon Services. Among other things it requires agents to identify themselves as automated, comply with the policy, and stop if Amazon asks. That's your repricer. Your PPC automation. Your listing tool. Your browser extension. Enforcement kicked in after a 90-day window.

So: the seller side of this marketplace is under a written obligation to declare its automation, on a deadline, with an account-health consequence behind it. And on August 4, the buyer side got a ruling saying the agent's access is the shopper's access.

That is not a conspiracy. Different statutes, different parties, different questions, and Amazon's contract claims against Perplexity are still live. But the practical shape is worth naming out loud, because it's a fair description of where the paperwork burden sits, and it's your side.

What I'd do this week

  1. Read your own detail page with the pictures off. Reader mode, or paste the page into a document and strip the images. Five minutes on your top revenue SKU. That text is what a non-visual reader gets, and most brands have literally never looked at it. What you'll find is empty attribute fields and an A+ section whose entire argument was carried by a graphic.
  2. Fill the fields with no alarm. Category attributes to completion. Alt text on A+ modules โ€” seconds per module, and it's the accessible description of an image that is otherwise invisible to every non-human reader on the page. Item Highlights populated as a readable phrase. All of this is correct under either answer to any question in this post, which is exactly why it's the move.
  3. Add one column to your tool inventory: does this thing identify itself under Section 19. You already have tool, model string, pinned-or-floating, current rate, re-check date, retirement date. This is the one with an Amazon enforcement date behind it rather than a vendor's pricing page. Most operators can't produce that list, and the list takes an afternoon.
  4. Diary a re-check, not a plan. The case was remanded. Amazon can seek en banc review or go further, the terms-of-service and contract theories weren't resolved, and the holding was explicitly narrow. Put a date on your calendar for late Q1 to go look at where it landed. A cost model built around a number is fragile; one built around a re-check date isn't. I've learned that one the expensive way this month.
  5. Do nothing else. We are ten weeks from peak. The list of things likely to cost you real money between now and January is short and none of them are on this page.

What I'd ignore

The CFAA doctrine coverage. The rule of lenity, the tool-versus-user distinction, whether the Ninth Circuit got the statute right โ€” genuinely interesting, and there are zero decisions in it for anyone selling physical products. Read the law firm alerts if you enjoy them. Don't bill against them.

"Agentic commerce readiness" as a service line. It's attribute completeness and readable A+ copy with a new name on the invoice. Make anyone pitching it describe the deliverable in one sentence and watch what happens.

The trillion-dollar-by-2030 market sizing. Every one of these numbers is a forecast, none of them changes what you ship in September, and quoting them is how people signal they read a press release.

Any advice to "rewrite your listings for AI agents." Nobody outside these companies knows the weights. What is knowable is that a listing with 40% of its attributes blank is illegible to every machine reader on the page, and that was true in 2024.

The urge to block them. It isn't your button. You don't control who Amazon lets onto the detail page and you never did.


For most of a decade, "who is reading this listing" had one answer and everybody in this industry optimized against it. Then it had two, and the second one was Amazon's, which at least meant Amazon had a reason to help you be legible to it.

Now there's a third, it doesn't work for anyone whose interests are aligned with yours, and the only useful response available is the boring one: make the page make its case with the pictures turned off. Which, inconveniently, is a thing I'd have told you to do anyway.

Put AI to work inside the business you already run.

The Operator Intelligence: Multi-Agent OS is a 4-week live build: second brain, Claude Code workflows, Codex execution — on your real business. The next cohort is forming now.

Get first access →

Not ready? Get the free newsletter — the AI workflows I actually ship, when they're worth your inbox.