欢迎访问北京嘉润律师事务所官网!
您现在的位置: 首页   >  新闻资讯

Amazon v. Perplexity: AI Agents, Platform Access, Viewed Through Chinese Law

发布时间:2026-09-30信息来源:嘉润律师

图片


Author's Update
作者更新
Since this article was completed, Amazon has also blocked Meta's AI agent Muse from shopping on Amazon.com on users' behalf. The Muse dispute further shows that the issues examined in this article—including AI-agent access, identification, platform rules, privacy, and security—continue to develop, underscoring their practical significance.
本文成稿后,亚马逊又阻止了Meta的AI代理Muse代表用户在Amazon平台购物。Muse争议进一步表明,本文讨论的AI代理访问权限、身份标识、平台规则、隐私与安全等问题仍在持续发展,并凸显了本文所讨论问题的现实意义。


Amazon v. Perplexity: AI Agents, Platform Access, Viewed Through Chinese Law

亚马逊诉Perplexity案:从中国法视角审视AI代理与平台访问规则


The Ninth Circuit’s ruling in Amazon.com Services, LLC v. Perplexity AI, Inc. addresses a question likely to recur as AI agents increasingly operate within users’ online accounts: when an AI assistant searches for products, compares options, and navigates a platform on a customer’s behalf, who has legally “accessed” the platform—the customer or the AI provider?

在美国亚马逊服务有限责任公司诉Perplexity人工智能公司一案中,第九巡回上诉法院作出的裁决回应了一个随着AI代理越来越多地在用户平台账户中运行而将反复出现的法律问题:当AI助手代表用户搜索商品、比对选项并在平台内执行操作时,在法律上究竟是谁“访问”了平台——是用户本人,还是AI服务提供者?

The court answered that question narrowly under the U.S. Computer Fraud and Abuse Act (CFAA). Because Perplexity’s Comet browser operated on the user’s local device and Perplexity’s servers did not communicate directly with Amazon’s servers, the court treated the customer as the person accessing Amazon and the Assistant as a tool used by that customer. A Chinese court or regulator would likely consider the same technical architecture but undertake a broader inquiry into user authorization, technical circumvention, data acquisition and use, personal-information protection, platform operations, and market competition.

法院依据美国《计算机欺诈与滥用法》(CFAA)对该问题作出了限缩性认定。由于Perplexity旗下的“彗星”(Comet)浏览器运行在用户本地设备上,且Perplexity的服务器并未直接与亚马逊的服务器通信,法院认定实施平台访问行为的主体是用户,AI助手仅为用户使用的工具。中国法院或监管机构面对相同的技术架构时,审查范围可能会更为宽泛,并综合考察用户授权、技术规避行为、数据获取与使用方式、个人信息保护、平台运营秩序以及市场竞争等多重维度。


1. Case Summary: Amazon.com Services, LLC v. Perplexity AI, Inc.

一、案情概要:亚马逊服务有限责任公司诉Perplexity人工智能公司案


The Technology

1.1 技术背景

Perplexity developed Comet, an AI-enabled web browser featuring an optional “Assistant” that performs tasks at a user’s direction. When a user instructs the Assistant to navigate Amazon—for example, to search for products, compare options, or assist with a purchase—the user’s browser communicates directly with Amazon’s servers. The Assistant sends screenshots of the browser view to Perplexity’s servers for analysis, which then return navigation instructions to the user’s browser.

Perplexity公司开发了搭载AI功能的网页浏览器“彗星”(Comet),内置可选的“助手”功能,可根据用户指令执行各项操作。当用户指令助手访问亚马逊平台(例如搜索商品、比对选项或协助下单)时,用户的浏览器直接与亚马逊服务器通信;助手会将浏览器页面的截图发送至Perplexity服务器进行分析,再将导航指令回传至用户本地的浏览器。


The Dispute

1.2 争议焦点

Amazon objected to the Assistant’s operation on its platform. It alleged that Perplexity continued providing the service after Amazon had expressly withheld authorization. Amazon also challenged the Assistant’s user-agent identification, arguing that the way the Assistant identified itself made it more difficult for Amazon to detect and block AI-assisted access. Amazon sued under the CFAA and California’s Comprehensive Computer Data Access and Fraud Act (CDAFA) and initially obtained a preliminary injunction.

亚马逊对该助手在其平台上的运行提出异议,主张在亚马逊明确不予授权后,Perplexity仍持续提供相关服务。亚马逊同时对助手的用户代理标识(user-agent)提出质疑,认为该助手的身份标识方式加大了亚马逊检测并拦截AI辅助访问的难度。亚马逊依据《计算机欺诈与滥用法》及加州《计算机数据访问与欺诈综合法案》(CDAFA)提起诉讼,并最初获得了初步禁令。


The Ruling

1.3上诉法院裁定

On August 4, 2026, the Ninth Circuit vacated the preliminary injunction and remanded the case. The court held that Amazon was unlikely to establish that Perplexity itself had “accessed” Amazon’s computers within the meaning of the two computer-access statutes. On the record before the court, the customer accessed Amazon through the customer’s own browser, while Perplexity’s Assistant functioned as an AI tool used by that customer.

2026年8月4日,第九巡回上诉法院作出判决:撤销初步禁令,将案件发回下级法院继续审理。法院认为,亚马逊很可能无法证明Perplexity本身构成上述两部计算机访问法案所定义的对亚马逊计算机系统的“访问”行为。根据在案证据,实施亚马逊平台访问行为的是用户本人,通过用户自有浏览器完成;Perplexity的AI助手仅作为用户使用的AI工具发挥作用。


Scope and Limitations

1.4 裁定范围与局限

The ruling is narrow. It does not finally adjudicate the merits, create a general legal regime for AI agents, confer a blanket right to scrape data from or otherwise operate on third-party platforms, or foreclose possible liability under contract, privacy, unfair-competition, or other law. The court also did not finally resolve the parties’ dispute over the Assistant’s user-agent string.

本次裁决的适用范围较为有限,既未对案件实体争议作出终局裁判,也未为AI代理行为确立普适性法律规则,更未赋予主体普遍抓取第三方平台数据或以其他方式在第三方平台开展操作的权利,亦不排除依据合同、隐私、反不正当竞争等其他法律承担责任的可能性。此外,法院也未就双方关于助手用户代理字符串的争议作出终局认定。


3.jpg


Figure 1. Technical architecture and procedural posture of Amazon.com Services, LLC v. Perplexity AI, Inc. The Ninth Circuit treated the customer as accessing Amazon through the customer’s browser and the AI Assistant as a technological tool. AI-generated illustration.

图1 亚马逊诉Perplexity案的技术架构与诉讼程序示意图。第九巡回法院认定用户通过自有浏览器访问亚马逊平台,AI助手仅为技术工具。本图为AI生成示意图。


2. Chinese-Law Perspective

二、中国法视角下的分析


2.1 Cybersecurity and Unauthorized Access

2.1 网络安全与未经授权访问

Article 18 of China’s Regulations on Network Data Security Management, effective January 1, 2025, addresses automated tools used to access or collect network data. It requires an assessment of their effect on network services and prohibits illegal intrusion or interference with normal operations. Automation is therefore not unlawful in itself; method, scope, and effects matter.

自2025年1月1日起施行的《网络数据安全管理条例》第十八条对自动化工具访问、收集网络数据的行为作出了规范,要求评估其对网络服务的影响,禁止非法侵入、干扰网络正常运行。据此,自动化工具本身并不必然违法,其行为的方式、范围与造成的影响都是判断时需要考虑的重要因素。

The criminal-law boundary is illustrated by Ding’s Case on Providing Programs for Intruding into Computer Information Systems. The software bypassed a short-video platform’s security protections to obtain access-restricted data without authorization, and the court treated it as a program specifically used to intrude into a computer information system under Article 285(3) of the Criminal Law.

“丁某提供侵入计算机信息系统程序案”说明了刑事追责边界应如何划定。该案中,涉案软件绕过某短视频平台的安全防护机制,未经授权获取权限受限的数据,法院依据《刑法》第二百八十五条第三款,认定该程序属于专门用于侵入计算机信息系统的程序。

Applied to Perplexity, use of the customer’s local browser within the customer’s lawful account permissions would weigh against treating the Assistant as an intrusion tool. Risk would increase if the system defeated authentication or security controls, accessed information beyond the customer’s permissions, or deliberately evaded effective blocking.

将该规则适用于Perplexity案场景:AI助手通过用户本地浏览器、在用户合法账户权限范围内开展操作,会降低将该助手认定为侵入工具的可能性。但如果系统突破了身份认证或安全管控机制、访问超出用户权限的信息,或者刻意规避平台的有效拦截措施,其法律风险将显著上升。


2.2 Anti-Unfair Competition and Platform Data

2.2 反不正当竞争与平台数据保护

Article 13 of the revised Anti-Unfair Competition Law, effective October 15, 2025, prohibits obtaining or using another operator’s lawfully held data through improper means—including fraud, coercion, or avoiding or destroying technical management measures—where lawful interests are harmed, and market competition is disrupted. Circumvention is therefore relevant, but not dispositive by itself.

2025年10月15日起施行的修订后《反不正当竞争法》第十三条规定,经营者不得采用欺诈、胁迫、避开、破坏技术管理措施等不正当手段,获取、使用其他经营者合法持有的数据,损害他人合法权益,扰乱市场竞争秩序。据此,技术规避行为是违法性判断的考量因素,但单凭这一点不足以认定违法。

A particularly close Chinese analogue to Amazon v. Perplexity is Guiding Case No. 263. A recruitment-management platform allowed employer-users to enter their credentials for another recruitment website, automatically log in, and transfer résumés they had already lawfully obtained into their private accounts. Although the originating platform alleged that the service avoided its image-verification mechanism, the courts rejected the unfair-competition claim. The users voluntarily linked their accounts and chose whether to synchronize the résumés; the data remained within each employer’s private account and were not searchable by others. The program’s reading of the verification code was treated, on those facts, as a technical means of implementing the linked-account function rather than improper interference with the originating platform.

与亚马逊诉Perplexity案最为贴近的中国先例是最高人民法院第263号指导性案例。该案中,某招聘管理平台允许企业用户输入其在另一招聘网站的账号密码,实现自动登录并将用户已合法获取的简历迁移至其各自的私有账户。尽管被访问的招聘平台主张该服务规避了其图形验证码机制,但法院未支持其不正当竞争的诉讼请求。法院认为,用户系自愿绑定账号并自主选择是否同步简历,数据始终存储于各企业的私有账户中,其他用户无法搜索获取;在此事实基础上,程序识别验证码的行为属于实现账号关联功能的技术手段,不构成对被访问平台的不正当干扰。

No. 263 therefore supports a limited proposition: user-authorized automation can facilitate access to and reasonable processing of data the user is already entitled to obtain. It does not establish that user authorization automatically overrides platform controls. The Supreme People’s Court selected the case in August 2025 as part of its first group of data-rights guiding cases. The Court subsequently explained that, after the revised Anti-Unfair Competition Law took effect, courts should apply the data-specific provision of Article 13 and related provisions while taking those guiding cases into account.

因此,第263号指导性案例的适用意义是有限的:经用户授权的自动化工具,可以帮助用户访问并合理处理其本身有权获取的数据。但该案并不意味着用户授权当然可以优先于平台的技术管控措施。2025年8月,最高人民法院将该案纳入首批数据权益司法保护专题指导性案例。最高人民法院随后明确,修订后的《反不正当竞争法》施行后,法院审理相关案件应当适用第十三条等数据专门条款,并结合上述指导性案例进行审理。

Two 2026 Internet Court proceedings sharpen the boundary. In Guangzhou, an AI conversational agent allegedly used operating-system accessibility permissions to automate operations on a third-party platform. The court issued a conduct-preservation order requiring the defendant to stop providing the software, stop using system-level permissions to evade the platform’s technical management measures, remove evasion tutorials, and delete user data already obtained. The merits remain pending. “Dual authorization” was among the issues debated, but the case has not established a categorical rule requiring both user and platform authorization.

2026年两起互联网法院案件进一步明晰了行为边界。广州互联网法院审理的一起案件中,某AI对话类产品被指利用操作系统无障碍权限,在第三方平台上自动化执行操作。法院作出行为保全裁定,要求被告停止提供涉案软件,停止利用系统级权限规避平台技术管理措施,下架相关规避教程,并删除已获取的用户数据。该案实体审理尚未审结,庭审中双方就“双重授权”(用户授权+平台授权)等问题展开辩论,但该案并未确立一律要求同时取得用户与平台双重授权的绝对性规则。

In Beijing, the Internet Court has already applied the data-specific provision of Article 13 in an effective judgment. The defendant used multiple paid accounts, webpage source code, and a crawler to circumvent login verification and access-control measures, copied platform user data to another website, and sold access to the data. The court found unfair competition and identified four elements for applying the provision: (1) the data are lawfully held by another operator; (2) the defendant is an operator; (3) the defendant obtains or uses the data through improper means; and (4) the conduct harms the other operator’s lawful interests and disrupts market competition.

北京互联网法院则在已生效的判决中适用了《反不正当竞争法》第十三条的数据专门条款。该案被告利用多个付费账号、网页源代码及爬虫程序,绕过平台登录验证与访问控制措施,将平台用户数据复制至第三方网站并对外售卖数据访问权限。法院认定其构成不正当竞争,并明确了该条款的四项适用要件:(1)涉案数据为其他经营者合法持有;(2)行为主体为经营者;(3)行为人采用不正当手段获取、使用数据;(4)行为损害了其他经营者的合法权益,扰乱了市场竞争秩序。

Guiding Case No. 262 and the Ningbo e-commerce crawling case mark the more clearly unlawful end of the spectrum. No. 262 involved mass copying and public display that substantially substituted for the originating platform’s products or services. In Ningbo, the defendants bypassed anti-crawling and risk-control protections, scraped product data at scale, and commercialized the extracted data through price monitoring, market analysis, and customized API-based data services.

第262号指导性案例与宁波电商数据爬取案,则属于违法性更为明显的情形。第262号指导性案例涉及大规模数据复制与公开展示行为,该行为实质性替代了被访问平台的产品或服务。宁波案件中,被告绕过平台反爬与风控防护机制,批量抓取商品数据,并通过价格监测、市场分析及定制化API数据服务等方式将所获取的数据商业化利用。

Taken together, these authorities do not support a categorical rule that violating a Robots protocol, reading a verification code, or bypassing another technical measure is unlawful per se. A court would likely consider the user’s lawful entitlement, the scope of access, the means used, harm to platform operations or lawful interests, and whether the data were retained, aggregated, publicly redistributed, used as a substitute for the originating service, or commercially exploited.

综上,中国现行法律规则并未确立违反Robots协议(网络爬虫排除协议)、识别验证码或绕过其他技术措施即“当然违法”的一概性规则。法院很可能会综合考量以下因素:用户的合法权限、访问行为的范围、采用的技术手段、对平台运营或合法权益造成的损害,以及数据是否被留存、聚合、公开再传播、用于替代原平台服务,或者被商业化利用。


2.3 Personal Information and Screenshots

2.3 个人信息与截图数据

Comet’s screenshot-based architecture creates a separate personal-information issue. An e-commerce account may display names, addresses, order histories, recommendations, return information, and financial-account details. Capturing, transmitting, analyzing, or retaining screenshots containing identifiable information would constitute personal-information processing under China’s Personal Information Protection Law (PIPL).

Comet浏览器基于截图的技术架构,还会触发独立的个人信息保护问题。电商账户页面可能会展示姓名、地址、订单历史、推荐内容、退换货信息以及金融账户信息等内容。根据中国《个人信息保护法》,捕获、传输、分析或留存包含可识别个人身份信息的截图,均属于个人信息处理活动。

The provider would need a lawful basis and should explain what is captured, why it is necessary, how long it is retained, whether it is used for model training, who receives it, and whether it is transferred outside China. The PIPL does not require separate consent for every screenshot; separate consent is required in circumstances specified by law.

AI服务提供者需要具备合法的处理依据,并向用户说明截图所包含的内容、处理必要性、留存期限、是否用于模型训练、接收方主体,以及是否出境传输等事项。《个人信息保护法》并未要求每一次截图都需单独取得用户同意,仅在法律明确规定的情形下才需单独同意。

Guiding Case No. 265 reinforces the requirements of necessity and voluntary consent. The court found an infringement where a service collected user-profile information unnecessarily for its basic service while providing no meaningful alternative to users unwilling to submit it. Applied by analogy, broad authorization for “screen access” should not by itself justify collecting or retaining personal information unrelated to the user’s requested task.

第265号指导性案例进一步强化了“必要原则”与“自愿同意”的要求。该案中,法院认定涉案服务在提供基础服务时非必要地收集用户画像信息,且对不同意提供信息的用户未提供合理替代方案,构成侵权。参照该裁判精神,用户笼统授予的“屏幕访问权限”,不能单独成为收集、留存与用户指令任务无关的个人信息的合法依据。

Personal-information consent is distinct from platform-access authorization; one does not automatically answer the other.

用户同意AI处理其个人信息,并不等于平台也同意AI访问;平台同意AI访问,也不等于用户同意其个人信息被处理。


2.4 AI-Agent Transactions, Platform Rules, and Provider Responsibility

2.4 AI代理交易、平台规则与服务提供者责任

Article 48 of China’s E-Commerce Law provides that when a party uses an automated information system to conclude or perform an e-commerce contract, the resulting act has legal effect on that party. Thus, where a customer deliberately instructs an AI agent to purchase a specified product, the transaction would ordinarily have legal effect for the customer rather than for the AI agent itself.

中国《电子商务法》第四十八条规定,当事人使用自动信息系统订立或者履行电子商务合同的,该行为对该当事人具有法律效力。因此,当用户明确指令AI代理购买特定商品时,该交易行为通常对用户本人发生法律效力,而非对AI代理本身产生约束力。

That rule does not relieve the AI provider of responsibility for its own conduct. The provider may still face independent liability arising from system design or operation, unlawful data processing, improper circumvention, or unfair competition. Appropriate confirmation mechanisms for material transaction terms can also reduce the risk that an agent exceeds or misinterprets the customer’s instructions.

但该规则并不免除AI服务提供者对自身行为的责任。服务提供者仍可能因系统设计与运行、违法数据处理、不当技术规避或不正当竞争行为,独立承担法律责任。针对重要交易条款设置合理的确认机制,也有助于降低AI代理超出或误读用户指令的风险。

Platforms may regulate automated access through terms of service, account rules, and technical controls. Breach of those rules may justify account restrictions or support contractual claims, but it does not automatically constitute computer intrusion or unfair competition. Guiding Case No. 263 supports the view that platform investment does not necessarily create absolute control over data lawfully obtained by users; the Beijing and Ningbo cases show greater risk when controls are improperly bypassed, and data are extracted or commercially exploited.

平台可以通过服务协议、账户规则及技术管控措施,对自动化访问行为进行规范。违反上述规则可能导致账号受到限制,或为合同请求提供依据,但并不当然构成计算机侵入或不正当竞争。第263号指导性案例表明,平台的投入并不必然使其对用户合法获取的数据享有绝对控制权;而北京、宁波两案则显示,当行为人不正当地绕过平台管控、提取数据并进行商业化利用时,法律风险更高。

Where the Interim Measures for the Management of Generative Artificial Intelligence Services apply, providers remain subject to obligations concerning personal information, user inputs and records, network information security, and training data. Article 7 governs pre-training and optimization training data; Article 9 addresses providers’ network information security and personal information protection responsibilities; and Article 11 addresses the protection of user inputs and usage records. The distinction matters because screenshot processing used only to carry out a user’s immediate instruction is not necessarily training-data processing under Article 7. Even so, Articles 9 and 11 may still apply because such screenshots can involve personal information, user inputs, and usage records, and may also raise network information security concerns.

For an AI agent such as Perplexity’s Assistant, these provisions therefore create a separate layer of provider responsibility beyond platform access.

若涉案服务适用《生成式人工智能服务管理暂行办法》,服务提供者仍需遵守个人信息保护、用户输入与记录管理、网络信息安全以及训练数据管理等相关义务。其中,第七条规范预训练与优化训练数据;第九条规定服务提供者的网络信息安全和个人信息保护责任;第十一条则规定对用户输入信息和使用记录的保护义务。这一区分很重要:仅为执行用户当前指令而处理截图,并不当然属于第七条所规制的训练数据处理。即便如此,如果截图涉及个人信息、用户输入或使用记录,或者引发网络信息安全问题,第九条和第十一条仍可能适用。

因此,对于Perplexity助手这类AI代理而言,除平台访问问题外,这些规定还涉及服务提供者的另一层责任。


3. Comparative Summary

三、中美规则对比总结

The comparison reveals a difference in legal framing rather than a simple contrast between a permissive U.S. approach and a restrictive Chinese one. The Ninth Circuit focused on the threshold statutory question of who “accessed” Amazon’s computers; Chinese law would likely distribute the inquiry across several overlapping regimes.

对比可见,中美两国的差异并非简单的“美国宽松、中国严格”,而是法律分析框架的不同。第九巡回法院聚焦于“谁实施了访问行为”这一法定前提性问题;中国法则很可能从多个相互交叉的法律规则进行审查。

In terms of the primary inquiry, the U.S. ruling centers on whether Perplexity itself “accessed” Amazon’s computers, while Chinese law conducts a broader inquiry into authorization, access methods, data use, platform operations, personal information, and competition.

就核心审查方向而言,美国裁定关注的是Perplexity本身是否构成对亚马逊计算机系统的“访问”行为;中国法则围绕授权、访问手段、数据使用、平台运营、个人信息及市场竞争展开多维度审查。

On the issue of user authorization, under the U.S. ruling it is relevant to identifying the customer as the party accessing Amazon, but not a defense to all claims. Under Chinese law, it is central under Guiding Case No. 263, yet not sufficient if lawful access is exceeded or competition is disrupted.

在用户授权方面,美国裁定中用户授权是认定访问主体为用户的一个重要因素,但并不能成为对所有诉求的抗辩理由;中国法下,用户授权是第263号指导性案例的重要考量因素,但若超出合法访问范围或扰乱竞争秩序,仅有用户授权也不足以排除法律责任。

Regarding technical controls and identification, the U.S. court noted the user-agent-string issue but did not resolve it. Under Chinese law, concealment or circumvention may support liability but is not dispositive by itself.

在技术管控与身份标识问题上,美国法院提及了用户代理字符串争议,但未作终局认定;中国法下,隐瞒身份或规避技术措施可能成为认定法律责任的依据,但单凭这些行为并不足以判定是否构成违法。

As for platform data rights, the U.S. court did not decide broader data-misappropriation or unfair-competition theories. Under Chinese law, private, user-directed processing may be lawful, while bulk extraction, public redistribution, or commercial exploitation creates greater risk.

在平台数据权益方面,美国法院未对数据不当获取或使用、不正当竞争等更广泛的法律主张作出认定;中国法下,由用户主导、限于私人账户内的数据处理可能合法,而批量提取、公开再传播或商业化利用则面临更高的法律风险。

On the personal information front, this issue was not resolved in the U.S. appellate ruling. Under Chinese law, the PIPL requires a lawful basis, necessity, transparency, security, and separate consent where required by law.

在个人信息保护维度,美国上诉法院的裁定并未解决该问题;中国法下,《个人信息保护法》要求个人信息处理具备合法依据、遵循必要原则、保障透明与安全,法定情形下需取得单独同意。

The difference should not be overstated. Both systems distinguish the user’s conduct from the technology provider’s own conduct. Chinese law, however, places greater emphasis on the means of data acquisition, downstream use of platform data, personal-information interests, effects on platform operations, and competitive harm.

不应过度夸大两国规则的差异。两国法律体系均区分用户行为与技术服务提供者自身行为。不同之处在于,中国法更侧重考察数据获取手段、平台数据的后续使用、个人信息权益、对平台运营的影响以及竞争损害等要素。


4. Conclusion

四、结论

The Ninth Circuit framed Amazon v. Perplexity around a narrow statutory question: Who accessed Amazon’s computers?

第九巡回法院将亚马逊诉Perplexity案的核心归纳为一个范围较窄的法定问题:谁访问了亚马逊的计算机系统?

Chinese law would likely frame the dispute more broadly: Who authorized the activity, what data was accessed, by what means, for whose benefit, and with what effects on privacy, platform operations, and competition?

中国法则更可能从更广泛的角度审视这一争议: 谁授权了该行为?访问了哪些数据?通过何种手段?为谁的利益实施?对隐私权益、平台运营与市场竞争造成了何种影响?

Guiding Case No. 263 provides a particularly close functional analogue. It supports legitimate user-directed AI assistance and data transfer within the scope of information the user is lawfully entitled to access. Chinese law does not necessarily treat a third-party technology provider as acting unlawfully merely because it automates a user-authorized process.

第263号指导性案例在功能层面与本案具有较强的可比性,其支持在用户合法访问的信息范围内,由用户主导的AI辅助操作与数据传输行为。中国法并不会仅因为第三方技术服务提供者将用户授权的流程自动化,就当然认定其行为违法。

Technology may change, but the underlying legal questions remain. Guiding Case No. 263 remains important because its core principles—user authorization, lawful access, reasonable data use, and assessment of competitive effects—are sufficiently technology-neutral to inform the analysis of newer AI-agent scenarios. The 2026 Beijing and Guangzhou Internet Court proceedings show those principles being tested against a new statutory data provision and more agentic forms of platform interaction.

技术不断迭代,但底层的法律命题始终如一。第263号指导性案例的价值之所以具有延续性,是因为其所体现的核心原则——用户授权、合法访问、合理数据使用、竞争影响评估——具备足够的技术中立性,能够为新型AI代理场景的法律分析提供指引。2026年北京与广州互联网法院审理的案件,则显示上述原则正在新的数据专门条款和更具自主性的AI代理交互场景中接受检验。

The legal position changes, however, when an automated tool exceeds lawful access, circumvents technical protections through improper means, extracts data at scale, commercially exploits platform data, or otherwise harms lawful interests and disrupts market competition.

但当自动化工具超出合法访问范围、以不正当手段规避技术保护、批量提取数据、对平台数据进行商业化利用,或者以其他方式损害合法权益、扰乱市场竞争秩序时,对其行为的法律判断也会随之发生变化。

The likely approach under Chinese law is therefore a balanced one: an AI agent may function as a user’s tool when it operates within the user’s lawful access, processes only necessary information, complies with personal-information requirements, and does not improperly interfere with the platform. User authorization, however, does not immunize the AI provider from independent responsibility for technical evasion, unlawful data processing, or unfair commercial exploitation.

因此,中国法下对此问题可能采取较为平衡的处理方式:AI代理在用户合法权限内运行、仅处理必要信息、遵守个人信息保护要求且不对平台造成不当干扰的,可以认定为用户使用的工具。但用户授权并不能免除AI服务提供者因技术规避、违法数据处理或不正当商业利用所应独立承担的法律责任。


Authorities and Sources

法规与案例来源

[1] Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444, D.C. No. 3:25-cv-09514-MMC (9th Cir. Aug. 4, 2026). Opinion of the U.S. Court of Appeals for the Ninth Circuit.

[1] 亚马逊服务有限责任公司诉Perplexity人工智能公司案,案号:26-1444,地区法院案号:3:25-cv-09514-MMC,美国第九巡回上诉法院,2026年8月4日裁定。

[2] Regulations on Network Data Security Management (《网络数据安全管理条例》), State Council Order No. 790, promulgated September 24, 2024, effective January 1, 2025.

[2] 《网络数据安全管理条例》,国务院令第790号,2024年9月24日公布,2025年1月1日施行。

[3] Ding’s Case on Providing Programs for Intruding into Computer Information Systems (丁某提供侵入计算机信息系统程序案), People’s Court Case Database Reference Case No. 2024-18-1-253-001; (2022) Su 0213 Xing Chu No. 223, Wuxi Liangxi District People’s Court, May 10, 2022.

[3] 丁某提供侵入计算机信息系统程序案,人民法院案例库入库编号:2024-18-1-253-001;(2022)苏0213刑初223号,无锡市梁溪区人民法院,2022年5月10日。

[4] Anti-Unfair Competition Law of the People’s Republic of China (《中华人民共和国反不正当竞争法》), revised June 27, 2025, effective October 15, 2025.

[4] 《中华人民共和国反不正当竞争法》,2025年6月27日修订,2025年10月15日施行。

[5] A Network Information Technology Co. v. An Information Technology Co. (某网络信息技术有限公司诉某信息科技有限公司不正当竞争纠纷案), Guiding Case No. 263; (2017) Hu 0110 Min Chu No. 25167, aff’d (2019) Hu 73 Min Zhong No. 263. Issued by the Supreme People’s Court on August 28, 2025.

[5] 某网络信息技术有限公司诉某信息科技有限公司不正当竞争纠纷案,指导性案例第263号;(2017)沪0110民初25167号,二审维持:(2019)沪73民终263号,最高人民法院2025年8月28日发布。

[6] Q&A with the Head of the Research Office of the Supreme People’s Court on Guiding Cases Concerning the Judicial Protection of Data Rights and Interests (《最高人民法院研究室负责人就数据权益司法保护专题指导性案例答记者问》), discussing Article 13(3) of the revised Anti-Unfair Competition Law and Guiding Cases Nos. 262 and 263. Published by the Supreme People’s Court News Bureau on August 28, 2025.

[6] 《最高人民法院研究室负责人就数据权益司法保护专题指导性案例答记者问》,就修订后《反不正当竞争法》第十三条第三款及第262、263号指导性案例作出解读,最高人民法院新闻局2025年8月28日发布。

[7] Guangzhou Internet Court, “AI Agent ‘Overstepping’ Operations? Public Hearing of an AI-Conversational-Software Unfair Competition Dispute”, April 30, 2026. The court issued a conduct-preservation order; the merits were stated to be pending.

[7] 广州互联网法院,《AI代理“越界”操作?AI对话软件不正当竞争纠纷案公开庭审》,2026年4月30日。法院作出行为保全裁定,实体审理尚未审结。

[8] Beijing Internet Court, “Unfair Acquisition and Use of Platform User Data Constitutes Unfair Competition”, June 5, 2026. The court described the case as its first application of the revised Anti-Unfair Competition Law’s data-specific provision. The judgment became effective after no party appealed.

[8] 北京互联网法院,《不正当获取、使用平台用户数据构成不正当竞争》,2026年6月5日。该案系北京互联网法院审结的首起适用修订后《反不正当竞争法》新增数据专款的案件;判决作出后,各方当事人均未上诉,判决已生效。

[9] A Technology Co. v. A Culture Media Co. (某科技有限公司诉某文化传媒有限公司不正当竞争纠纷案), Guiding Case No. 262; (2019) Jing 0108 Min Chu No. 35902, aff’d (2021) Jing 73 Min Zhong No. 1011. Issued by the Supreme People’s Court on August 28, 2025.

[9] 某科技有限公司诉某文化传媒有限公司不正当竞争纠纷案,指导性案例第262号;(2019)京0108民初35902号,二审维持:(2021)京73民终1011号,最高人民法院2025年8月28日发布。

[10] Unfair Competition Case Involving the Scraping of Online Platform Data (爬取网络平台数据不正当竞争案), (2024) Zhe 02 Min Chu No. 562, Ningbo Intermediate People’s Court. Selected as a 2025 People’s Courts Intellectual Property Typical Case.

[10] 爬取网络平台数据不正当竞争案,(2024)浙02民初562号,宁波市中级人民法院。入选2025年人民法院知识产权典型案例。

[11] Personal Information Protection Law of the People’s Republic of China (《中华人民共和国个人信息保护法》), adopted August 20, 2021, effective November 1, 2021.

[11] 《中华人民共和国个人信息保护法》,2021年8月20日通过,2021年11月1日施行。

[12] Luo v. A Technology Co. (罗某诉某科技有限公司隐私权、个人信息保护纠纷案), Guiding Case No. 265; (2021) Jing 0491 Min Chu No. 5094, aff’d (2022) Jing 04 Min Zhong No. 494. Issued by the Supreme People’s Court on August 28, 2025.

[12] 罗某诉某科技有限公司隐私权、个人信息保护纠纷案,指导性案例第265号;(2021)京0491民初5094号,二审维持:(2022)京04民终494号,最高人民法院2025年8月28日发布。

[13] E-Commerce Law of the People’s Republic of China (《中华人民共和国电子商务法》), adopted August 31, 2018, effective January 1, 2019.

[13] 《中华人民共和国电子商务法》,2018年8月31日通过,2019年1月1日施行。

[14] Interim Measures for the Management of Generative Artificial Intelligence Services (《生成式人工智能服务管理暂行办法》), Order No. 15, jointly issued July 10, 2023, effective August 15, 2023.

[14] 《生成式人工智能服务管理暂行办法》,第15号令,2023年7月10日联合发布,2023年8月15日施行。Note: 民初 (minchu) denotes a first-instance civil case; 民终 (minzhong) denotes a second-instance civil case, ordinarily the final appellate stage under China’s two-instance system. 刑初 (xingchu) denotes a first-instance criminal case.注:“民初”指民事一审案件;“民终”指民事二审案件,系中国两审终审制下通常的终审程序;“刑初”指刑事一审案件。


Disclaimer: The analysis and conclusions are the author’s own and do not constitute legal advice. AI tools assisted with research and drafting; the author independently reviewed, verified, revised, and approved the final text.

免责声明:本文分析与结论仅代表作者个人观点,不构成法律意见。本文撰写过程中使用AI工具辅助研究与起草,作者对最终文本进行了独立审核、验证、修订与确认。

相关人员
  • 安钢

    北京

    权益合伙人

    党总支副书记、管委会委员

    专业领域

    • 金融法律业务
    • 诉讼仲裁业务
    • 反垄断业务
    • 投融资业务
    • 公司业务

    安钢

    权益合伙人

  • 丁红涛

    北京

    权益合伙人

    监督委员会主任

    专业领域

    • 诉讼仲裁业务
    • 金融法律业务
    • 快递物流与供应链业务

    丁红涛

    权益合伙人

  • 丁恒

    北京

    权益合伙人

    党总支书记、事务所主任

    专业领域

    • 公司业务
    • 国有企业法律业务
    • 政府机关、事业单位法律业务
    • 基础设施建设业务
    • 环境与自然资源业务
    • 诉讼仲裁业务

    丁恒

    权益合伙人

  • 董宇轩

    北京

    权益合伙人

    专业领域

    • 公司商事业务
    • 大中型国企业务
    • 政府与事业单位业务
    • 诉讼仲裁业务​

    董宇轩

    权益合伙人

  • 杜超

    北京

    权益合伙人

    专业领域

    • 政府机关、事业单位法律业务
    • 建设工程与房地产业务

    杜超

    权益合伙人

  • 范新梅

    北京

    权益合伙人

    专业领域

    • 公司股权
    • 公司治理
    • 民商事诉讼

    范新梅

    权益合伙人

  • 龚志忠

    北京

    权益合伙人

    专业领域

    • 公司业务
    • 企业合规业务
    • 资本市场业务(证券、私募基金等)
    • 境外投资与并购
    ​• 诉讼仲裁业务
    • 刑事合规与辩护业务

    龚志忠

    权益合伙人

  • 郭子扬

    天津

    权益合伙人

    专业领域

    • 公司商事业务
    • 政府机关、事业单位法律业务
    • 建设工程与房地产业务
    • 投融资业务
    • 诉讼仲裁业务

    郭子扬

    权益合伙人