Amazon and Perplexity are fighting over the future of AI shopping

Amazon has sent a cease-and-desist letter to Perplexity that demands that the AI startup prevents its Comet browser from making purchases on Amazon, Bloomberg reports. In a blog post responding to Amazon's letter, Perplexity claims Amazon is "bullying" the company and that its demands pose "a threat to all internet users."

In Amazon's eyes, Comet's agent violates its terms of service, degrades the Amazon shopping experience and introduces privacy vulnerabilities, Bloomberg writes. Amazon's "Conditions of Use" for Amazon.com specifically prohibit "any downloading, copying, or other use of account information for the benefit of any third party" and "any use of data mining, robots, or similar data gathering and extraction tools." Depending on your definition, the agentic capabilities Perplexity offers through Comet could violate both clauses. The browser securely stores log-in credentials for websites locally, and uses them to make purchases for customers on Amazon with a simple command. 

Perplexity and Amazon agreed to pause agentic shopping on Amazon in November 2024, according to the report, but when Comet was released, Perplexity allowed it again. By representing the Comet agent as a Chrome browser user rather than a bot, the company allegedly tried to get around the agreement, until Amazon found out and sent its cease-and-desist letter. 

Amazon posted the statement below on its blog, openly acknowledging the issues it has with Perplexity:

We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions whether or not to participate. This helps ensure a positive customer experience and it is how others operate, including food delivery apps and the restaurants they take orders for, delivery service apps and the stores they shop from, and online travel agencies and the airlines they book tickets with for customers. Agentic third-party applications such as Perplexity’s Comet have the same obligations, and we’ve repeatedly requested that Perplexity remove Amazon from the Comet experience, particularly in light of the significantly degraded shopping and customer service experience it provides.

Complicating Amazon’s claims, Perplexity might be a future shopping rival. Amazon demoed its own AI shopping agent called “Buy for Me” in April 2025. But Perplexity also disagrees with the fundamentals of Amazon's argument. "User agents are exactly that: agents of the user," Perplexity says. "They're distinct from crawlers, scrapers, or bots." Perplexity believes the Comet agent shouldn't run afoul of Amazon's terms and conditions then because it acts on the users' behalf, with the users' permission. 

This isn't the first time Perplexity has been accused of misrepresenting its AI tools to access content. In August, Cloudflare claimed that the company's bots were accessing blocked websites by pretending to be a normal Chrome browser user on macOS. Reddit also sued Perplexity and three other companies earlier this month for accessing Reddit posts without paying for a license.

This article originally appeared on Engadget at https://www.engadget.com/ai/amazon-and-perplexity-are-fighting-over-the-future-of-ai-shopping-215445479.html?src=rss

UK High Court sides with Stability AI over Getty in copyright case

Stability AI has partially succeeded in defending itself against accusations of copyright infringement. As reported by The Guardian, Stability AI prevailed in a high-profile UK High Court case, following Getty first suing the company in 2023 for allegedly using its copyright images to train its Stable Diffusion AI art tool without permission.

Getty’s original claim was that Stability AI had unlawfully copied and processed millions of protected images for training purposes, therefore abusing the rights of the original creators. However, the Seattle-based company eventually withdrew its claims of primary copyright infringement as it reportedly could offer no evidence that unauthorized copying for the training of Stable Diffusion had taken place in the UK.

Today’s ruling concerns claims of secondary infringement, to which the High Court judge, Justice Joanna Smith, ruled that "an AI model such as Stable Diffusion which does not store or reproduce any copyright works (and has never done so) is not an 'infringing copy'" under UK law. This was despite the ruling finding some evidence of Getty’s images being used by Stability, as evidenced by the presence of the former’s watermark. While the judge sided with Getty on some of its claims, she said that the evidence was "both historic and extremely limited in scope."

The High Court ruling likely won’t fill companies and creators concerned about AI-related copyright infringement with a huge amount of optimism, but unsurprisingly, both Getty and Stability AI have been quick to celebrate their respective victories. Getty's statement reads, in part:

Today’s ruling confirms that Stable Diffusion’s inclusion of Getty Images’ trademarks in AI‑generated outputs infringed those trademarks. Crucially, the Court rejected Stability AI’s attempt to hold the user responsible for that infringement, confirming that responsibility for the presence of such trademarks lies with the model provider, who has control over the images used to train the model. This is a significant win for intellectual property owners. The ruling delivered another key finding; that, wherever the training and development did take place, Getty Images' copyright‑protected works were used to train Stable Diffusion. The ruling also established a powerful precedent that intangible articles, such as AI models, are subject to copyright infringement claims in the same way as tangible articles. We will be taking forward findings of fact from the UK ruling in our US case.

The company added that it was "deeply concerned" that even "well-resourced companies" remain at risk of infringement due to a "lack of transparent requirements." It also urged the UK government to build on the current laws around this issue. Christian Dowell, general counsel to Stability AI, said the final ruling from the court "ultimately resolves the copyright concerns that were the core issue."

The ruling comes just days after Getty announced a new agreement with Perplexity AI that permits the latter to access Getty’s huge media library as part of its search and discovery tools. In a press release, Getty said a condition of the licensing deal was Perplexity committing to "making improvements on how it displays imagery, including image credit with link to source, to better educate users on how to use licensed imagery legally."

This article originally appeared on Engadget at https://www.engadget.com/ai/uk-high-court-sides-with-stability-ai-over-getty-in-copyright-case-180029461.html?src=rss

Italy will be the latest country to require age verification for porn sites

Later this month, Italian citizens will have one extra step to go through before getting on porn sites. On Friday, Italy's regulatory agency for communications, known as AGCOM, announced an age verification system that's meant to prevent minors from accessing websites with pornographic content. The initial list of sites covers around 50 sites, including Pornhub, XHamster and OnlyFans.

The new rule will require users to get verified through "certified third parties," which could be another company, bank or mobile operator that already has the relevant info. Once the third party verifies the user's age, it will issue a code that grants access to the porn site. While the legislation's stated goal is to prevent harm to minors, the age verification process uses a "double anonymity" system to quell privacy concerns. In order to protect user privacy, porn sites can only see if a user is of age and not their identity, while the third-party verifier can only see the user's identity and not the website they're trying to get on.

According to the legislation, users have to do this each time they try to get on affected porn sites. AGCOM said the new rule goes into effect on November 12, and any porn sites that are found non-compliant could be hit with penalties of up to 250,000 euros. 

Italy is the latest in the European Union to implement age verification rules, after France put a similar system into place in the summer. Just outside the EU, the UK also recently introduced its own age verification process that requires either a selfie or government ID. Since then, Pornhub said that UK visitors to its site have plummeted 77 percent.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/italy-will-be-the-latest-country-to-require-age-verification-for-porn-sites-170913842.html?src=rss

Samsung’s web browser arrives on Windows, with an AI future on its radar

On Thursday, Samsung launched a desktop version of its web browser. Why bother putting its mobile browser on Windows? Well, the company offers a hint in describing Samsung Internet as "evolving from a PC browser that waits for input to an integrated AI platform." So, surprise, surprise: It's about AI.

As one would imagine, Samsung Internet on Windows supports cross-platform syncing of data like bookmarks, browsing history and autofill. The company says it also prioritizes privacy and security, offering standard features like tracker blocking and a privacy dashboard.

But those aren't likely the main reasons Samsung is launching a desktop web browser in 2025. (Incidentally, Samsung briefly launched Samsung Internet for Windows in 2024, before pulling it from the Microsoft Store without fanfare.) Instead, this launch appears to be about positioning it in the rapidly emerging landscape of AI browsers.

AI browsers have been all the rage lately. Samsung's move follows the launch of OpenAI's ChatGPT Atlas, Microsoft's Edge Copilot Mode updates, Opera Neon's early access and general availability for Perplexity's Comet browser. Samsung says its cross-platform browser will advance its "vision for ambient AI," anticipating your needs and offering more personalized assistance. If Samsung wants to be part of that fray, it makes sense for its software to be available on the desktop, too.

Samsung Internet is available (via a beta program) for Windows 11 and Windows 10 (version 1809 and up). You can sign up on the product page.

This article originally appeared on Engadget at https://www.engadget.com/computing/samsungs-web-browser-arrives-on-windows-with-an-ai-future-on-its-radar-163526726.html?src=rss

YouTube is offering employees buyouts as part of an AI-focused reorganization

As part of an AI-focused reorganization, YouTube CEO Neal Mohan told employees that it will offer voluntary buyouts, according to an internal company memo. At the same time, he emphasized that there would be no specific role eliminations as part of new structure.

"Looking to the future, the next frontier for YouTube is AI, which has the potential to transform every part of the platform," Mohan wrote. "We also understand some of you may be ready for a new challenge, so we've decided now is the right time to offer a voluntary exit Program." 

The restructuring is designed to help YouTube focus on fast-growing areas like AI while "driving faster decision making and execution," the memo states. To that end, the platform is organizing into three separate product organizations: viewer products, creator and community products, and subscription products. 

Viewer products will focus on the viewer experience by making improvements to search & discovery, engagement, the living room experience and "our foundation of responsibility." Creator and community products, meanwhile, is "driving creation through genAI tools, Shorts, Live and creator support. Subscription products, as you'd expect, will operate around subscription growth across Music, Premium and OTT (YouTube TV) platforms. 

Mohan noted that YouTube has been the number one streamer in the US for the last two years. So far, it has signed up 125 million Premium and Music subscribers, along with 8 million YouTube TV subs. The platform has paid out $100 billion to its ecosystem (presumably, creators and recording artists). 

YouTube isn't the only tech giant reducing headcount while citing AI as an impetus. Amazon recently announced that it had laid off 14,000 people, while citing the need to be "lean" due to transformative technology like AI. Meanwhile, YouTube parent Alphabet announced its first-ever $100 billion quarter, largely on the strength of cloud services and search.

This article originally appeared on Engadget at https://www.engadget.com/big-tech/youtube-is-offering-employees-buyouts-as-part-of-an-ai-focused-reorganization-120047466.html?src=rss

Proton launches ‘Data Breach Observatory’ to track personal info leaks

Proton, the company behind Proton VPN and other encrypted apps like Proton Mail and Proton Drive, just launched a new web page called the Data Breach Observatory that aims to make accurate cybercrime data more widely accessible. The Observatory is intended to be a continually updated report that records any data leak detected on the dark web, with information sourced from the underground data marketplaces themselves.

The reason for the Observatory, according to Proton, is that too many studies of cyberattacks depend on organizations reporting when they've been hacked. A company might not make a data breach public for fear of backlash from customers, regulators or stockholders. Although it's impossible to tell how many breaches aren't reported, Proton believes it's a significant portion.

Compounding the transparency problem, most stolen data is advertised and traded on dark web markets that are hard to trace without specialized knowledge, like how diamond thieves don't tend to fence their loot at above-board jewelry stores. In other words, while most people know that personal information is frequently stolen and leaked, it's very difficult to know how much data is getting stolen, how often breaches occur and who's buying and selling the goods.

Proton's solution is to monitor the dark web itself, watching locations where data thieves go to advertise stolen information. By keeping an eye on these exchanges, Proton believes the Data Breach Observatory will be able to warn victims as early as possible, including before the targets themselves are aware of the leak. Making breach reports available in one place is also meant to educate the public about the actual size and scope of cybercrime, while making it harder for companies to keep quiet about getting hacked.

Proton plans to update the Observatory in "near real time," working with a risk detection firm called Constella Intelligence. It remains to be seen whether they'll be able to keep up the workload — according to Proton's own research, around 1,571 data breaches have occurred in 2025 so far, compromising well over 100 billion records. A clearing house for reporting on all of those definitely sounds valuable, but at around five breaches a day, it'll be a busy page.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/proton-launches-data-breach-observatory-to-track-personal-info-leaks-110047833.html?src=rss

Character.AI to ban teens from talking to its chatbots

Character.AI will no longer permit teenagers to interact with its chatbots, as AI companies face increasing pressure to better safeguard younger users from harm. In a statement, the company confirmed that it is removing the ability for users under 18 to engage in any open-ended chats with AI on its platform, which refers to back-and-forth conversations between a user and a chatbot.

The changes come into effect on November 25, and until that date, Character.AI will presents users with a new under-18 experience. It'll encourage its users to use chatbots for creative purposes that might include, for example, creating videos or streams, as opposed to seeking companionship. To manage the transition, under-18s can now only interact with bots for up to two hours per day, a time limit the company says it will reduce in the lead-up to the late November deadline.

Character.AI is also introducing a new age assurance tool it has developed internally, which it says will "ensure users receive the right experience for their age." Along with these new protections for younger users, the company has founded an "AI Safety Lab" that it hopes will allow other companies, researchers and academics to share insights and work collaboratively on improving AI safety measures.

Character.AI said it has listened to concerns from regulators, industry experts and concerned parents and responded with the new measures. They come after The Federal Trade Commission (FTC) recently launched a formal inquiry into AI companies that offer users access to chatbots as companions, with Character.AI named as one of seven companies that had been asked to participate. Meta, OpenAI and Snap were also included.

Both Meta AI and Character AI also faced scrutiny from Texas Attorney General Ken Paxton in the summer, who said chatbots on both platforms can "present themselves as professional therapeutic tools" without the requisite qualifications. Seemingly to put an end to such controversy, Character.AI CEO Karandeep Anand told TechCrunch that the company’s new strategic direction will see it pivot from AI companion to a "role-playing platform" focused on creation rather than mere engagement-farming conversation.

The dangers of young people relying on AI chatbots for guidance has been the subject of extensive reporting in recent months. Last week, the family of Adam Raine, who claim that ChatGPT enabled their 16-year-old son to take his own life, filed an amended lawsuit against OpenAI for allegedly weakening its self-harm safeguards in the lead-up to his death.

This article originally appeared on Engadget at https://www.engadget.com/ai/characterai-to-ban-teens-from-talking-to-its-chatbots-180027641.html?src=rss

Google is once again disputing Gmail was breached

Not for the first time this year, Google has been forced to reassure its users that it has not suffered a large-scale data breach that could affect their Gmail accounts. A few months ago the company released an unusual statement intended to put to bed allegations that its email service had been hit with a serious security issue. And it did so again this week, after numerous news outlets published stories suggesting that 183 million passwords may have been compromised in a new breach.

Google has since claimed that this isn’t true in posts on X. It says the listed accounts are likely not fresh victims of an attack, but instead recent additions to the Have I Been Pwned data breach search engine’s database. The website is a free resource that can quickly tell users if their personal data has been hacked. As noted by Bleeping Computer, HIBP’s creator, Troy Hunt, has said in a blog post that over 90 percent of the millions of stolen credentials have been seen before, so are in no way new (16.4 million of addresses were however showing up for the first time in a data breach, according to Hunt).

"Reports of a 'Gmail security breach impacting millions of users' are false," Google said in a statement. "Gmail’s defenses are strong, and users remain protected. The inaccurate reports are stemming from a misunderstanding of infostealer databases, which routinely compile various credential theft activity occurring across the web. It’s not reflective of a new attack aimed at any one person, tool, or platform."

Google does use compilations of open credentials like the one recently uploaded to HIBP to alert its users of possible breaches, and has advised users that turning on 2-step verification and adopting passkeys is more secure than relying on passwords alone, which it notes should always be reset immediately if compromised.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/google-is-once-again-disputing-gmail-was-breached-180031380.html?src=rss

Google Chrome will finally default to secure HTTPS connections starting in April

The transition to the more-secure HTTPS web protocol has plateaued, according to Google. As of 2020, 95 to 99 percent of navigations in Chrome use HTTPS. To help make it safer for users to click on links, Chrome will enable a setting called Always Use Secure Connections for public sites for all users by default. This will happen in October 2026 with the release of Chrome 154. 

The change will happen earlier for those who have switched on Enhanced Safe Browsing protections in Chrome. Google will enable Always Use Secure Connections by default in April when Chrome 147 drops. When this setting is on, Chrome will ask for your permission before it first accesses a public website that doesn't use HTTPS. 

Google has been moving in this direction for some time. Chrome started alerting users to unsecure HTTP websites in 2018 and it began defaulting to HTTPS in April 2021. The following year, it started offering Always Use Secure Connections on an opt-in basis. 

When HTTPS isn't used, an attacker can reroute the connection with relative ease and target a user with malware, social engineering attacks or other exploits. "Attacks like this are not hypothetical — software to hijack navigations is readily available and attackers have previously used insecure HTTP to compromise user devices in a targeted attack," the Chrome team wrote in a blog post. "Since attackers only need a single insecure navigation, they don't need to worry that many sites have adopted HTTPS — any single HTTP navigation may offer a foothold. What's worse, many plaintext HTTP connections today are entirely invisible to users, as HTTP sites may immediately redirect to HTTPS sites." Always Use Secure Connections is one of the Chrome team's attempts to mitigate such risks.

HTTP connections still persist in navigations to private sites, such as local IP addresses and company intranets. It's complicated for a private site to obtain an HTTPS certificate (something Engadget has had since 2016, fact fans), because the same private name can point to different hosts on multiple networks. For instance, many router manufacturers use "192.168.0.1" as a local IP address for accessing the hardware's admin panel. Still, HTTP navigations to private sites are inherently less risky than on the public web. They aren't entirely safe, but the only vector of attack for HTTP on private sites is from within the local network.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/google-chrome-will-finally-default-to-secure-https-connections-starting-in-april-170000603.html?src=rss

Department of Justice confirms that it wants Google to sell off Chrome

The US Department of Justice (DoJ) has released a 23-page document calling for the breakup of Google, including a sale of the Chrome web browser and restrictions on Android, confirming previous reports. Selling Chrome "will permanently stop Google’s control of this critical search access point and allow rival search engines the ability to access the browser that for many users is a gateway to the internet," DoJ lawyers argued in the filing. 

The regulator said that Google must also stop favoring its own search engine in Android. If the company fails to do that, DoJ lawyers argued that it should also be required to divest its mobile device operating system. They also proposed that Google syndicate search results separately and sell its click and query data to aid rival search engines and AI startups.

In a response on its Keyword blog, Google said the DoJ's "staggering proposal" would harm consumers and affect US tech leadership. "[The] DoJ chose to push a radical interventionist agenda that would harm Americans and America's global leadership," wrote Global Affairs president and chief legal officer, Kent Walker. "DoJ’s wildly overbroad proposal goes miles beyond the Court’s decision. It would break a range of Google products — even beyond Search — that people love and find helpful in their everyday lives."

All of this started back in 2020, when the DoJ and multiple states filed a lawsuit arguing that Google paid billions to device manufacturers to secure default status for its search engine. Then in August this year, federal judge Amit Mehta ruled that Google "is a monopolist" in the industry and used its power to charge "supracompetitive prices for general search text ads." (As of last year, Google controlled around 90 percent of the search engine market, processing nearly 9 billion searches per day.)

The DoJ's proposals to breakup Google are based on that ruling, but the makeup and philosophy of the department is likely to change drastically in a Trump administration. Indeed, Google's Keyword blog seems to be aimed directly at the incoming president, invoking dangers to security, required disclosure to foreign companies and the mandating of "government micromanagement." Recently, Trump himself weighed in on the matter, suggesting a breakup might be too drastic. "What you can do without breaking it up is make sure it’s more fair," he said last month. 

All of this is still at an early stage, with many court cases and appeals likely to come. Still, it would represent a seismic shift in how Google, a company with 182,500 employees, does business. More importantly, it could drastically affect how the internet works, as over 60 percent of web interactions start with a search query — and most of those are done using Google search. 

This article originally appeared on Engadget at https://www.engadget.com/big-tech/department-of-justice-confirms-that-it-wants-google-to-sell-off-chrome-094929822.html?src=rss