In partnership with

Hello again my friend,

This week, a U.S. appeals court overturned an order that had temporarily stopped Perplexity’s shopping agent from operating on Amazon. The court’s reasoning was narrow, but important: when someone sends an AI agent onto Amazon to shop for them, it may be the person, not the company that built the agent accessing the site.

That sounds like a story about online shopping. I think it is the beginning of a much bigger question about who is responsible when an agent acts for us.

Mastercard is already rebuilding systems that spent decades treating bots as threats. While, quietly, five of the world’s largest technology companies have committed roughly $1.09 trillion to future lease payments, mostly for the data centres underneath all of this.

Today’s weekly recap is going to cover a few stories that are probably going to set foundations for future laws and online norms for how agents integrate fully into our lives.

Let’s lock in.

Can you blame it on your AI Agent?

Amazon sued Perplexity last November over Comet, its browser and shopping agent. Amazon argued that the agent was covertly accessing private customer accounts, creating security risks, and violating a federal computer-hacking law. Perplexity argued that Amazon customers were choosing to access their own accounts through an agent, much like they might choose a different browser or accessibility tool.

A California judge initially sided with Amazon and temporarily blocked the shopping tool. On Tuesday, the 9th U.S. Circuit Court of Appeals overturned that order. The appeals court said that, for the purpose of this particular hacking-law claim, it was Perplexity’s users who accessed Amazon through the agent—not Perplexity itself.

The lawsuit is not over, and the court did not decide that every AI agent can freely use every website. It overturned a preliminary restriction because Amazon was unlikely to win on one specific legal argument.

Still, the distinction matters. If my agent is legally treated as an extension of me when it enters a website, how far does that extend when it takes an action?

Shopping is the easy version. Say an agent buys the wrong pair of shoes, sends an email I would not have approved, agrees to a contract, or commissions a video that violates someone else’s rights. In most cases, the money will be gone and I’ll be stuck with the shoes.

Now imagine my agent hired another agent, which hired a third agent, before the mistake happened. Who is ultimately responsible: the vendor that built the first agent, the agent that directly requested the work, or me?

We already deal with versions of this when employees, lawyers, brokers, and other representatives act on someone’s behalf. If a family member with power of attorney makes a huge mistake on someone else’s behalf, there’s no take-backs. They had power of attorney. AI makes the chain faster, less visible, and potentially much harder to reconstruct. A human may set the original goal without seeing every decision made along the way.

The Amazon ruling does not answer that larger question. It shows how quickly we are going to need an answer.

The internet might have to flip completely

For most of the internet’s history, a bot trying to access something valuable was considered a problem. Advertising companies fought fake traffic. Financial companies blocked automated transactions. Websites built CAPTCHAs to prove a human was present (click on all the traffic lights). Fraud systems learned that unusual machine behaviour was a reason to stop and look more closely.

Now legitimate agents need to click, register, authenticate, and buy things for us. Humans now want bots, but obviously not the problems that come with them (it’s pretty annoying for cyber-security people I’m sure). The internet is going to have to learn the difference between a bot attacking a system and a bot that has permission to use it (and whether or not permission is enough to survive mistakes).

Mastercard’s chief AI and data officer, Greg Ulrich, explained the problem at VentureBeat’s Transform conference. He said Mastercard scored 175 billion transactions last year, making each fraud assessment in under 100 milliseconds.

“We’ve built a bunch of risk rules over time that were intended to stop a bot from transacting,” Ulrich said. “Now we need to enable the bot to transact.”

Mastercard is building around five layers:

  • identity,

  • verifiable intent,

  • controls,

  • execution, and

  • ongoing intelligence.

It wants to know who the customer is, which agent is acting for them, what the original instruction said, which merchants the agent may use, and how much it is allowed to spend.

The company calls part of this know your agent, building on the identity checks financial institutions already perform for customers and businesses.

These are Mastercard’s own descriptions of its system, rather than independently audited performance claims, but the underlying problem is unavoidable. Trusting an agent requires more than knowing that it is technically capable of buying something. The rest of the economy needs proof that the agent is legitimate and that the person behind it authorized this particular action. Otherwise, what stops organized crime, or terrorists, from using agents to stay hidden? It’s a whole bitcoin issue again.

The same inversion is coming for systems across the web. CAPTCHAs cannot treat every automated visitor as hostile if authorized agents need to register accounts for people. Advertising systems will have to decide what agent traffic is worth. Merchants will need a way to distinguish a customer’s purchasing agent from a scraper or thief.

For decades, the internet got better at keeping bots out. One of the biggest opportunities now may be helping it decide which bots to let in.

A trillion-dollar bet has already been signed

All of this software still needs somewhere physical to run.

Reuters reviewed company filings from Microsoft, Meta, Oracle, Amazon, and Alphabet and found approximately $1.09 trillion in future payments under leases that have not yet begun. Most of those commitments are for data centres supporting the AI buildout.

That number needs some context. It is not $1.09 trillion of hidden debt that can simply be added to the companies’ balance sheets. These are disclosed, generally undiscounted payments spread over many years. A signed lease usually becomes a recognized liability only when the facility is available for use.

The scale is still enormous. The uncommenced commitments are nearly four times the roughly $285 billion of lease liabilities the five companies have already recognized. Microsoft disclosed $329.1 billion. Oracle disclosed $260 billion, with many of its data-centre leases expected to last between 15 and 19 years. Meta disclosed $278.99 billion before signing another $68 billion of data-centre leases in July.

This is where the AI market starts to look less like a collection of software launches and more like an enormous, long-term financial position.

If demand keeps growing, these facilities support the next phase of the industry. If demand slows, the same companies may be paying for expensive capacity that is difficult to shed. A lot of investor wealth now depends on the belief that AI usage, revenue, and company valuations will keep moving upward long enough to justify what has already been signed.

There’s a reason why so many people hype this up, and need it work, even if they don’t fully believe (or understand) what they’re really promoting.

Intelligence may get cheaper every time we use it. Producing that abundance is becoming one of the largest physical bets the market has ever made.

What stood out

The old bot problem was relatively simple: keep automated systems away from anything important.

The new problem is deciding which agents can enter, what they are authorized to do, and who takes responsibility when they get it wrong. Courts are beginning to define the relationship. Mastercard is building identity and intent into payment rails. Technology companies are signing decades-long commitments to provide the infrastructure.

None of those questions is settled yet. But they are no longer hypothetical either.

As always, thanks for reading.

Darwin

Holiday Creator Calendars Are Filling Up. Q4 Panic Is Optional.

Creators lock in their holiday content calendars 90 days out, before most ecommerce brands finalize their commission strategy and way before Black Friday and October deal events.

Get ahead of the seasonal rush with The 90-Day Holiday Sprint, a practical guide for brands that want creators driving holiday demand while competitors are still recruiting:

  • Structure commissions by lifetime value, not just first-order margin

  • Lead with the right products so creators promote with confidence

  • Recruit and onboard creators with a day-by-day plan for the first 30 days

  • Read performance early and pull program levers by Day 60

  • Brief creators with a holiday checklist before calendars fill up

Your 90-day countdown starts now.