la risposta è negativa per l’appello del 9 circuito 4 agosto 2026, No. 26-1444, Amazon [A.] v. Perplexity [P.]. Il broweser Comet di P. che può funzionare come Agentic AI, infatti, da un lato è vero che entra nel sito di A. ma lo fa solo su istruzione dell’utente; dall’altro, trasmette poi a P. screenshot dei prodotti di interesse dell’utente dopo averli caricati nel PC di questi, per cui P. non effettua alcun accesso ai server di A.
La normativa di riferimento è il Computer Fraud and Abuse Act codificato nel 18 U.S. Code § 1030 (da noi suppergiù l’art. 615 ter cp).
Dall’amicus brief riportato in sentenza:
When a user visits a website, only . . . the browser . . . communicates with the website’s server. Specifically, when a user visits an Amazon.com webpage, the browser requests the contents of the page from Amazon’s server and displays the page to the user. If the user activates the Assistant, the Assistant will analyze the contents of the page that has been displayed by the browser on the user’s computer. . . . If necessary to carry out the task requested by the user, the Assistant may communicate the user’s instructions, along with information received from the browser pertaining to the page accessed by the user and any potentially relevant browsing history, to Perplexity’s AI servers. Perplexity’s servers never directly access Amazon’s servers.
per cui osserva la corte:
“What is clear from this description—and how the parties themselves describe the systems at issue—is that Perplexity itself does not directly communicate with Amazon’s servers.
We must nevertheless determine whether Perplexity accesses Amazon.com through the Assistant. The CFAA’s plain language suggests the Assistant itself cannot “access” Amazon’s servers. The relevant provision of the CFAA punishes “[w]hoever . . . intentionally accesses” a “protected computer.” 18 U.S.C. § 1030(a)(2) (emphasis added). In other words, the CFAA contemplates access by a person. However advanced the Assistant currently is, it is a tool, not a person for statutory purposes”.
e poi:
“It is the user who “accesses” Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com. To be sure, Perplexity may receive screenshots of the user’s browser and may communicate instructions to the Assistant. But those activities, by themselves, do not mean that Perplexity has “accessed” (gained entry) to Amazon’s servers”.
Strana (“perplessa”) motivazione. O la ragione è la necessità della persona fisica oppure è oscuro come mai l’azione del tool Comet non sia imputabile al soggetto Perplexity.
Da noi, non potrebbe essere corresponsabile ex art. 2055 cc? Se Comet è progettato proprio per gli accessi non autorizzati , come si fa a negare la responsabilità del suo produttore?
Notizia di Andrea Monti su Repubblica.
