Saturday, 12 September 2026
Est. 2021 · Fashion · Law · Culture · Luxury
Where fashion meets jurisprudence

Or continue with

Member login

Who’s Liable When AI Shops for You? Agentic AI, Fashion, and the Affiliate Marketing Fallout

How AI shopping agents are disrupting fashion retail and affiliate marketing — and why courts, brands, and creators can’t agree on who’s liable.
Who's Liable When AI Shops for You? Agentic AI, Fashion, and the Affiliate Marketing Fallout

As AI agent start shopping, negotiating and checking out on our behalf, retailers, affiliates and regulators are scrambling to work out who answers for what.

Ask an AI agent to find and buy the best deal on a trending teal jacket for a night out, and it will compare a dozen retailers, fill out the checkout form and complete the purchase in under a minute. For the shopper, that is progress. For everyone else in the transaction, it is a liability question with no clear answer: the agent may have bypassed a blogger’s affiliate link, scraped a retailer’s site in violation of its terms of service, and, under the letter of the law, triggered statutes originally written to prosecute hackers.

Agentic AI is fashion’s newest obsession. Not all of the attention it is drawing is welcome.

Screenshot of AI style assistant notifications showing a completed dress purchase, a confirmed boutique appointment, and a back-in-stock alert for saved trousers.

What Is Agentic AI?
(And Why Fashion Adopted It First)

Agentic AI refers to software built on large language models — the technology behind tools like ChatGPT — that can complete tasks on a user’s behalf with minimal supervision. These systems set goals, make decisions and manage complex, open-ended projects without a human directing every step.

In the fashion industry, these systems can be used as prompt-and-response agents efficiently understanding customer queries and recommending products requiring no human intervention and, in some cases, even executing purchases on behalf of the consumers.

The potential for these AI Agents has been broken down into two types i.e. “invisible” and “visible”.

Invisible Intelligence

Invisible intelligence happens behind the scenes requiring no interaction with customers, weaving data together to provide their consumers with more dedicated attention without being intrusive, for example, an agentic AI may be able to scan through a much larger set of complex data before suggesting the sales advisor for a Client A to offer a private boutique appointment on Tuesday, when the product they tried last week is due to be restocked in their correct size.

Visible Intelligence

Visible intelligence on the other hand depends on direct customer interactions. The US-based Alta, being one of the prime examples of it, enables the users to create their personal avatars and upload items from their real-life wardrobes, wishlists and information with respect to their favourite brands as well as providing feedback when it throws up suggestions they wouldn’t wear.

However, while fashion brands seem enthusiastic about the future of this intelligence, and hope to provide a more personalised and detailed shopping experience to their clients, not everyone is happy. It is precisely this visible, transactional layer agents that interact directly with retailrs and checkout flows on user’s behalf that is now drawing legal scrutiny, as the sections below make clear.

Screenshot of a fashion AI chat interface identifying items from a woman's outfit and recommending similar shirt, tights, shoes, and bag with prices and an "Add All to Bag" button.

Amazon v. Perplexity AI — The Case That Tested Agentic AI’s Legal Status

On November 04, 2025 Amazon filed a complaint against Perplexity AI [Amazon.com Services LLC v. Perplexity AI, Inc. (3:25-CV-09514), for “persistent, covert and unauthorised access” into Amazon’s protected computer systems thereby violating federal and California computer fraud and abuse statutes.

The crux of Amazon’s complaint was that Perplexity’s agentic AI application “Comet” was masquerading itself as a human user, evading Amazon’s technological barriers and accessing private customer accounts without Amazon’s permission. Amazon claimed that Perplexity’s Comet browser and AI agent are vulnerable to attacks from cyber criminals and could be leverages to compromise personal and private data from Amazon’s customers who use the Comet AI agent. Amazon also claimed that beyond the risk to private data, Perplexity’s Comet AI was also degrading customer’s shopping experience and interfered with Amazon’s ability to provide benefits of individualised shopping to its customers.

In March 2026, the Court held a hearing on the motion and issued a tentative ruling in Amazon’s favour and soon after issued a written order granting Amazon’s requested preliminary injunction on the grounds that Amazon had shown a likelihood of success on its CFAA claims under Section 1030 (a)(2) and its CDAFA claims.

However, under a recently the United States Court of Appeals for the Ninth Circuit overturned the March, 2026 order. The Court of Appeal “emphasised that agentic AI is an emerging technology, thus there is little to no existing case law directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone case law specifically dealing with agentic AI in the CFAA context. Furthermore, CFAA cases dealing with more established technologies do not provide a perfect analogue to the present case.”

The Court held that for the purposes of CFAA and California’s CDAFA, the relevant act of “access” must be attributed to the person who enters or interacts with the computer system. An AI agent in its present form was only a “tool” assisting the user and is not itself a person capable of accessing a computer within the meaning of these statutes.

Screenshot of a digital wardrobe app displaying detected clothing items, styling suggestions, and outfit ideas for a look.

Furthermore, Amazon had been unable to prove that Perplexity’s Assistant had itself accessed Amazon’s protected computers, above and beyond the instructions of the user. Adopting the “rule of lenity” it was noted that extending the scope of CFAA to impose liability on an AI provider would potentially expose ordinary users who employ AI agents to criminal liability which would go beyond the intent of the law makers.

For the present, the Ninth Circuit’s position is that the use of an AI agent does not, by itself, transform the AI provider into the person who “accessed” the website for purposes of the CFAA or CDAFA. On that basis, the preliminary injunction against Perplexity was vacated and the matter was remanded for further proceedings.

While the courts noted that the Agentic AI cannot be held liable here for the criminal conduct of unauthorized access of computer system or network of Amazon since it was merely a guided task rather than an autonomous act with mala fide intention, the judgement limits itself only to the CFAA and remains inapplicable to determine the agent’s liability under any other law including tort law. The judgement neither addresses nor does it establish any broader AI regime and encouraged sophisticated reasoning to be made in future with the emerging technology of AI.

While longstanding legal principles provide a guide to potential legal liability, a more stringent and precise approach to the hacking incidents still remain to be addressed. Certain civil lawsuits have been noticed to be filed against the AI companies with regards to negligence in order to form or deploy the AI Agents in such a manner to prevent or minimize foreseeable harm. However, the hacking incidences are still yet to become a ‘foreseeable harm’ and the criminal liability clearly remains inconclusive about at the commercial side, with no said procedure or way out to establish/determine the intent of an AI agent causing any intrusion.

While laws like CFAA or CFADA remain insufficient in providing the broader scope of protection to the companies, contractual regulations and reliance of strict terms of services pose a way out of this problem. If not to uphold liability but prevent costs, The court noted that its decision does not impair Amazon’s ability to regulate access to Amazon.com through its private terms of service. It held only that, on the current record, Amazon was unlikely to succeed in doing so under the CFAA and CDAFA.

The personal use- agentic AI shopping thus remains a broad category of grey zone, and one can expect them to turn out more common and prominent in the next few decades with the ease of growing businesses and rapid commercialization. What one can hope for now at the very least is the recognition of its prominence and substantial statutes addressing the liabilities of our favourite AI shopping buddies.

Screenshot of a fashion AI chat where a user asks it to find a bag, receives matching options, and instructs the assistant to complete the purchase, with an order confirmation shown.

The Affiliate Commission Fallout — How Agentic AI Is Disrupting Affiliate Marketing

Here is a version of a fight already playing out: an influencer posts a teal cardigan on Instagram, links it through a bio tool, and a follower clicks through and buys. In the background, a shopping assistant — Phia, in this case — allegedly opens a hidden pop-up, swaps in its own tracking cookie, and claims the commission for a sale it did not generate. The influencer, who built the audience and drove the sale, gets nothing. That right there is an affiliate commission fallout.

So, What is Exactly Affiliate Marketing?

Affiliate marketing typically is a performance-based arrangement where marketers promote products to a broad audience and earn a commission on sales, leads or clicks. It’s generally a B2C (business-to-consumer) model, though sometimes even B2B affiliate programs exist.

An affiliate (or marketer) typically stands at the job of persuading the consumers to promote the seller’s or brand’s products, making them appear purchase-worthy to engage well with the consumers. With each affiliate link, if a sale is made and a consumer chooses to purchase, the affiliate earns themselves a certain commission. Your favourite influencer sharing their latest fashion haul or sharing a new lipstick combo is exactly what best describes affiliate marketing.

Cookie tracking assigns each affiliate with a unique link, tagged with a small snippet of code — a cookie — that identifies which affiliate sent the traffic.

“Cookie stuffing” abuses that system i.e. a bad actor plants its own cookie without a genuine referral, and collects a commission it did not earn.

AI shopping agents complicate this further. Affiliate-industry reporting and early litigation have flagged agents bypassing referral links entirely via direct API calls, cached product data, or agent-native checkout flows, cutting the human blogger, influencer, or deal site out of a sale they generated..

Screenshot of a fashion AI tool detecting a striped shirt's features and displaying similar shirts from multiple retailers with prices.

The Phia Allegations

Phia, an AI shopping assistant, is at the centre of one such allegation. According to reports, when a user with Phia installed clicked an affiliate link belonging to someone else, the app would open a background pop-up and insert its own cookie — claiming a commission for a sale it had no part in generating. The claims are notable partly because of who is behind Phia: the app was co-founded by Phoebe Gates, daughter of Bill Gates, and her Stanford classmate Sophia Kianni, and counts Khóle Kardashian among its investors.

The allegations were first reported by Bloomberg alongside an independent researcher Ben Endelman, who has argued the pattern to be of a deliberate nature rather than accidental.

Whether or how the matter is resolved, it raises a bigger question for the industry: how accountable should agentic AI tools be for the commercial ecosystems they operate inside of?

Why This Is Hard to Regulate ?

While cookie stuffing remains one of the major aggregators, some AI agents are also known to auto-apply a “better” but unaffiliated discount code, overriding the original referral given by the creator/ influencer, costing the creator not just the commission but also cause an irreparable harm to their credibility with the brands and audiences that rely on them.

As with the hacking cases above, courts have little basis for establishing intent, and by the time a pattern becomes legally “foreseeable,” the damage may already be done. Another point of discussion also remains the lack of transparency as to the internal operations of such Agentic AI. Such AI companies are rarely able to explain to the consumers or regulators, why they ranked or recommended one product over another.

Australia’s Competition and Consumer Commission, in its Digital Platform Services Inquiry, found that only 29 percent of online marketplace users believed platforms clearly explained how products were ranked and displayed. Recommender systems, the ACCC found, use consumer data and behaviour to personalise and present choices in ways that remain difficult for both consumers and regulators to interrogate.

The Unresolved Question

For now, the gap is being filled piecemeal by terms-of-service enforcement rather than statute, and by investigative reporting rather than regulatory audit. Whether that holds as agentic shopping scales, or whether it forces legislators and platforms to build purpose built rules for autonomous agents, is the next chapter of this story.

The legal questions raised by agentic shopping are not confined to protecting affiliates or retailers from bad actors. They extend to a broader public interest: whether consumers can trust systems that are, by design, built to act without being watched.

Previous Article

When the Joke Becomes Evidence: How India's Panel Show Boom Is Rewriting Media Law