A Narrow DMCA Warning About Bypassing Bot Controls
See which Reddit claims survived, why bot-gate bypass matters under DMCA Section 1201, and how public-page, snippet, and API access differ for scrapers.

The Reddit–SerpApi ruling does not make public-web scraping categorically illegal. On July 31, 2026, the court reportedly let Reddit continue with DMCA claims targeting the alleged bypass and supply of technology for bypassing Google’s bot controls, plus civil conspiracy. It dismissed Reddit’s DMCA rights-control theory, unjust-enrichment claim, and unfair-competition claim. Because this was a ruling on motions to dismiss, Reddit has not proved circumvention, liability, or damages.
Choose an access route and role to see which surviving theory it most closely touches, then sort the complete claim table.
Select how content is obtained and who controls the process. The result identifies the surviving allegation with the closest factual match; it is not a legal conclusion.
Access-Method Decision Tree
All Reported Claims
| Claim | Statute | Result | Court’s Reported Reason |
|---|---|---|---|
| Direct circumvention | DMCA §1201(a)(1)(A) | Survived | Reddit plausibly alleged bypass of a technological measure controlling access to protected works. |
| Trafficking in access-control circumvention technology | DMCA §1201(a)(2) | Survived | Reddit plausibly alleged technology designed, produced, or marketed to bypass the access control. |
| Trafficking in rights-control circumvention technology | DMCA §1201(b) | Dismissed | SearchGuard was alleged to control entry, not copying or use after access. |
| Unjust enrichment | New York law | Dismissed | The pleaded state claim was treated as preempted by the Copyright Act. |
| Unfair competition | New York law | Dismissed | The pleaded state claim was likewise treated as preempted by the Copyright Act. |
| Civil conspiracy | — | Survived | Reddit may try to prove coordinated conduct tied to an underlying alleged DMCA violation. |
Survived means legally sufficient at the pleading stage, not proved. The ruling supplies no request-volume threshold or general scraping safe harbor.
Source: reported July 31, 2026 S.D.N.Y. dismissal ruling, as summarized by The Verge and supplied legal analysis; CourtListener docket for the complaint and early case activity. “—” marks a statute not specified in the supplied material.
Source and currency note: This summary covers the pleading-stage ruling as described in supplied legal analysis and reporting published through August 17, 2026. The available docket excerpt records the complaint and early activity but does not include the substantive order, and the current docket has not been independently verified here. Review the full order, operative pleadings, and latest docket before relying on the case for a business or litigation decision.
This is general information, not legal advice for a particular workflow, product, dataset, dispute, or jurisdiction.
Surviving Claims Target Alleged Circumvention, Not Scraping in General
The Verge described the ruling as allowing Reddit’s lawsuit to move forward, not as a finding that SerpApi or Perplexity violated the law. At the dismissal stage, the court asks whether the complaint states a legally plausible claim while generally assuming well-pleaded factual allegations are true.
Reddit’s surviving theories arise from a specific alleged collection chain. Reddit-originated text appeared in Google search-result snippets. Google allegedly protected those result pages with SearchGuard, a system using JavaScript challenges, CAPTCHAs, and bot-detection mechanisms. SerpApi allegedly obtained results despite those controls, and Perplexity allegedly used SerpApi to retrieve Reddit snippets for a retrieval-augmented-generation database.
That is materially different from alleging that someone downloaded an unrestricted, logged-out Reddit page. The alleged barrier was on Google’s search-result pages, and Reddit says the defendants defeated a mechanism intended to distinguish human visitors from automated retrieval systems.
Reddit further alleges that SerpApi used proxy servers, altered or false user-agent strings, human-mimicking technology, and a high-speed feature described as “ludicrous speed.” Those are allegations, not established descriptions of how the service operated or why its features existed. The ruling merely permits Reddit to seek evidence supporting its account.
The same limitation applies to Perplexity. Reddit alleges that Perplexity directed queries through SerpApi and used the resulting snippets in a retrieval system. The court did not find that Perplexity knowingly circumvented an effective access control.
Three propositions must remain separate: Reddit’s allegations, the court’s conclusion that some allegations were legally sufficient to proceed, and ultimate findings based on evidence. Only the first two presently exist in the reported decision.
Sections 1201(a)(1) And 1201(a)(2) Survived
Reddit’s direct-circumvention theory under DMCA Section 1201(a)(1)(A) survived dismissal. In plain terms, Reddit alleges that a defendant bypassed a technological measure controlling access to protected works.
To prevail, Reddit still must establish that qualifying copyrighted works were involved, that SearchGuard effectively controlled access within the meaning of the statute, that the control was circumvented without sufficient authority, that the relevant defendant performed or bears responsibility for the conduct, and that Reddit suffered the required injury.
The trafficking theory under Section 1201(a)(2) also survived. That provision concerns supplying technology designed, produced, or marketed for circumventing an access control. Its inclusion is particularly relevant to scraper vendors rather than only operators running collection jobs.
The ruling does not establish that proxies, browser automation, parsers, user-agent changes, or general-purpose automation products are inherently unlawful. Reddit must prove how the relevant product was designed, how it worked, how it was promoted, and how those facts connected it to the alleged defeat of SearchGuard.
A related civil-conspiracy theory survived as well. Reddit may attempt to prove coordinated conduct connected to an underlying DMCA violation. It still needs evidence of an actionable underlying wrong, the required agreement or participation, and each defendant’s role.
A claim-by-claim legal analysis likewise emphasizes that this was a decision on dismissal motions rather than final liability.
Section 1201(b) And Two State Claims Were Dismissed
The court reportedly dismissed Reddit’s Section 1201(b) theory. That part of the DMCA concerns technology that defeats measures protecting a copyright owner’s rights after access, rather than technology controlling access in the first place.
The reported distinction turns on SearchGuard’s alleged function. It governed whether an automated system could enter Google’s search-result pages. Reddit did not plausibly allege that SearchGuard technologically restricted copying, distribution, or another copyright right after someone obtained access.
The access-versus-use distinction explains the split result. Sections 1201(a)(1) and 1201(a)(2) remained because Reddit characterized SearchGuard as an access gate. Section 1201(b) was dismissed because the same measure was not plausibly characterized as a post-access rights control.
Reddit’s New York unjust-enrichment and unfair-competition claims were also dismissed as preempted by the Copyright Act. The court reportedly concluded that the pleaded state theories overlapped with rights governed by federal copyright law. They cannot proceed in their dismissed form unless amendment or another later procedural development changes the result.
The court reportedly found it plausible that at least some multi-sentence Reddit snippets could meet copyright’s minimal-creativity threshold. It did not decide that every post, title, sentence, fragment, or search snippet is copyrightable. Reddit must connect its claims to actual qualifying expression.
The decision also did not settle the broader debate over whether every DMCA circumvention claim requires a nexus to copyright infringement. The court reportedly found the required connection plausibly alleged on these facts, making a universal answer unnecessary.
Human-Readable Pages Can Still Have A Bot Access Control
The decision’s main practical point is that human visibility and authorization for automated access are not necessarily identical. A person may be able to read a page in an ordinary browser while a technological measure attempts to prevent software from retrieving the same page at scale.
For Reddit’s surviving theory, three elements matter. Protected works must be involved. An effective technological measure must control access to those works. Someone must then avoid, bypass, remove, deactivate, or otherwise impair that control in the legally relevant manner and without adequate authority.
At the pleading stage, the court reportedly accepted that a control could distinguish human access from automated access even when both sought the same visible results. That is why the allegation concerning SearchGuard’s JavaScript challenges, CAPTCHAs, and bot detection survived.
The ruling does not establish that every CAPTCHA, JavaScript dependency, rate limit, robots.txt instruction, login screen, or bot detector is an effective DMCA access control. These mechanisms have different purposes and technical effects. A contractual rule is not automatically a technological measure, while the absence of a direct contract does not necessarily answer whether a technical control was circumvented.
Nor did the court create a numerical threshold at which scraping becomes circumvention. The draft record supplies no request-volume limit, frequency rule, or safe amount. Low volume and public visibility are not automatic exemptions, but scale alone does not establish a Section 1201 violation.
Plain Reading And Authorized APIs Present Different Facts
Reading a logged-out page that presents no technical barrier is less similar to the alleged SearchGuard conduct. The same is true of viewing a search-result snippet normally as a human without defeating a challenge. Those routes may raise copyright, contract, privacy, or other issues, but the access-control element alleged here is missing from the method itself.
An authorized API or licensed feed creates a clearer authorization record, provided the user remains within the permission granted. Exceeding an API’s scope could create a separate dispute, but ordinary use of an approved route does not resemble the pleaded bot-gate bypass.
Automation that stops when a CAPTCHA, JavaScript challenge, bot warning, or block appears also creates a different record. The key change occurs when a collection system recognizes the rejection and then switches identities, rotates proxies, changes fingerprints, emulates human behavior, or solves a challenge specifically to continue.
Those steps are not a universal judicial test. They are factual signals relevant to Reddit’s allegation that technology was deliberately used to defeat a system intended to stop automated access.
For a tool provider, product design and marketing may matter alongside actual operation. Descriptions such as “anti-detection,” “human-mimicking,” “undetectable,” or CAPTCHA bypass could be used as evidence about purpose or knowledge when connected to a protected target. Marketing language alone does not establish liability.
For a customer, the relevant record may include which target it selected, whether it knew automation had been blocked, whether it requested a workaround, how much control it exercised over queries, and what provenance it received. The ruling does not impose liability on every scraping-service customer or dataset buyer.
Google’s Authority Allegations Help Explain The Result
Google’s separate complaint against SerpApi was reportedly dismissed because Google had not adequately alleged that it owned the relevant result material, possessed exclusive rights, or had authority from rights holders to protect it under the asserted theory. Google received an opportunity to amend, so that result was not a declaration that scraping search results is lawful.
Reddit reportedly supplied more specific allegations about its licensing relationship with Google, restrictions on specified uses of Reddit material, related protection requirements, and Google’s authority to apply controls to Reddit-originated content. The court found those allegations sufficient at the pleading stage.
That does not conclusively establish the scope of the agreements. Discovery could reveal contractual limits, differences between licensed and collected material, or constraints on Google’s role. The contrasting outcomes therefore do not create opposite universal rules. They reflect different allegations about protected works, licensing, and authority.
Scraper Reviews Should Preserve The Acquisition Record
The ruling makes acquisition provenance more useful than the label “public data.” A meaningful record identifies the original source, whether collection was direct or through a search engine, vendor, mirror, or archive, and which technical controls appeared.
When a collection job encounters an active challenge, preserving the response and stopping for review creates a clearer record than automatically routing the request through proxy rotation, browser impersonation, or challenge-solving infrastructure. The review can then identify the requested content, possible rights holders, available authorized routes, customer instructions, and intended downstream use.
Vendors and customers should also retain the scope of any API grant, license, or other permission. For outsourced collection, useful provenance includes subcontractors, proxy or solver use, handling of blocks, request-level source information, transformations, retention, and deletion practices.
These records are evidence, not a safe harbor. They do not resolve direct copyright infringement, contracts, privacy and data-protection duties, computer-access statutes, confidentiality, consumer-protection rules, or restrictions on training, retrieval, publication, and resale.
Mirrors And Local Archives Are Outside This Specific Ruling
The reported decision concerns Reddit snippets allegedly extracted from Google search-result pages protected by SearchGuard. It does not adjudicate direct Reddit scraping, unrestricted pages, cached copies, independent archives, mirrors, or licensed feeds.
A mirror changes the acquisition route but does not establish how the mirror originally obtained the material. Relevant questions include source permissions, copyright interests, deletion practices, treatment of personal data, applicable terms, retention, and downstream use.
RedLens uses a mirror-based, local-first architecture for public Reddit research. Local storage changes where a resulting archive resides and can support user-controlled retention and analysis. It does not prove that an upstream acquisition route or every downstream use is authorized.
Public visibility, mirror use, open-source licensing, lack of an API credential, pseudonymization, local storage, and a research purpose are not safe harbors established by this ruling. They remain facts to evaluate in the context of a specific workflow.
Reddit Still Must Prove Every Surviving Element
Reddit must produce evidence that the particular snippets contain protected expression, SearchGuard effectively controlled access under the asserted DMCA provision, and Google had authority to protect the relevant material. It must also prove actual circumvention, the legally required injury, each defendant’s knowledge and conduct, and the elements of conspiracy.
For Section 1201(a)(2), the product’s design, purpose, operation, marketing, and uses remain disputed. For Perplexity, unresolved questions include what it requested, knew, directed, or controlled. Defenses and statutory limitations may defeat some or all of the surviving claims.
The case began in the Southern District of New York on October 22, 2025, against AWMProxy, Oxylabs UAB, Perplexity AI, Inc., and SerpApi LLC, and was assigned to U.S. District Judge Paul A. Engelmayer. The available CourtListener docket records the complaint and early entries but warns that PACER and RECAP information may not be current.
Discovery, amended pleadings, reconsideration, summary judgment, settlement, trial, or appeal could change the case’s posture. For now, the ruling is a narrow warning: deliberately continuing through a bot-detection gate can support a plausible DMCA access-control claim even when a human can read the same material. Plain reading of unrestricted pages and use of an authorized API remain factually distinct.