Loading the catalogue…
Loading the catalogue…
Perplexity is a US-incorporated, San Francisco-based company operating a real-time web search and answer engine (Sonar, built on Meta's Llama) plus the Comet AI browser, both fully subject to CLOUD Act and FISA Section 702 obligations with no confirmed EU legal entity or EU-resident data centre. EU regulated-sector customers face compounding risks: an escalating stack of unresolved copyright litigation from major publishers, a 2026 class-action alleging unauthorised tracking-pixel data sharing, a documented history of evading robots.txt via undeclared crawlers, and no published EU AI Act compliance statement — though enterprise-tier customers get contractual no-training guarantees, zero-retention API options, and SOC 2 Type II coverage.
Perplexity AI, Inc. is a US-incorporated company fully subject to CLOUD Act and (likely) FISA Section 702, with no confirmed EU legal entity or EU-resident data centre — US authorities can compel data production without EU judicial oversight.
Active, escalating stack of copyright litigation from major publishers (Dow Jones/News Corp, New York Times, Chicago Tribune, CNN, Reddit) alleging unauthorised scraping and redistribution of content — unresolved financial and reputational exposure.
Cloudflare publicly alleged (August 2025) that Perplexity used undeclared stealth crawlers mimicking browsers and rotating IPs to bypass robots.txt and firewall blocks; Cloudflare de-listed Perplexity as a verified bot. Perplexity has denied wrongdoing.
Comet AI browser has had multiple disclosed vulnerabilities in 2025-2026, including a critical indirect prompt-injection flaw ('HashJack') initially dismissed before being fixed, and a disputed hidden MCP API issue reported by security researchers.
A pending (as of April 2026) lawsuit alleges Meta and Google tracking technologies operated within Perplexity's product even in incognito mode; Perplexity disputes the allegations, and the outcome is unresolved.
No public EU AI Act compliance statement, GPAI transparency documentation, or confirmed Code of Practice participation has been identified, despite GPAI obligations applying since August 2025.
An independent researcher reported (December 2024) that user-uploaded files (images via Cloudinary, documents via AWS S3) were accessible without authentication via direct URL, raising concerns about incidental PII exposure.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
SOC 2 Type II report covering security, availability, processing integrity, confidentiality, and privacy; documented private bug bounty program.
Sonar API operates a documented Zero Data Retention policy — no prompts or responses are stored beyond immediate processing, with only billing metadata retained.
Genuine open-weights contributions: R1-1776 reasoning model released under Apache 2.0, and the pplx-embed family of embedding models published openly on a verified HuggingFace organisation with an accompanying arXiv paper.
Published GDPR rights-request process via a dedicated Help Center article covering access, rectification, erasure, restriction, objection, and portability, with a 30-day response commitment.
Enterprise tier contractually excludes customer data from model training, distinct from the default opt-out consumer/Pro model.
Published safeguards & certifications