← All dispatches
Dispatches · #intelligence · DLBrowser

Google's DMCA Scraping Lawsuit Against SerpApi Collapses

July 24, 2026 · Abhishek Gupta
Infographic: Google's DMCA lawsuit against SerpApi dismissed July 20, 2026, with the $7.06 trillion damages figure SerpApi used to show the claim's absurdity

On July 20, 2026, a federal judge threw out Google's DMCA lawsuit against SerpApi — both claims, filed seven months earlier over scraping Google's own search results.

The case mattered beyond these two companies. Google had tried to use the DMCA's anti-circumvention provision, written for DVD copy protection, to punish a company for beating its bot detection. If that theory had won, every anti-bot system — Cloudflare's, DataDome's, Akamai's — would have doubled as a federal copyright weapon against anyone automating a browser.

The short version

  • Google sued SerpApi on December 19, 2025, in the Northern District of California, alleging SerpApi circumvented SearchGuard — Google's anti-scraping system — in violation of the DMCA.
  • SerpApi's February 20, 2026 motion to dismiss argued Google doesn't hold copyright in its own search results pages and can't use anti-circumvention law to protect an ad business.
  • Chief Judge Yvonne Gonzalez Rogers dismissed the claim with prejudice everywhere SearchGuard gated results with no copyrighted content, and without prejudice for results containing Knowledge Panel content — Google gets 21 days to refile that narrower slice.
  • SerpApi calculated Google's theoretical statutory damages at $7.06 trillion — larger than U.S. GDP — to argue the DMCA theory couldn't be what Congress intended.
  • The ruling landed three weeks after Cloudflare set a September 15, 2026 deadline forcing AI companies to separate search crawlers from training and agent crawlers or face default blocking.

Why did Google's DMCA claim fail?

Because the DMCA's anti-circumvention rule only protects access to copyrighted works, and a bare list of search results — links, snippets, rankings — isn't one. Judge Gonzalez Rogers ruled that wherever SearchGuard blocked access to pages without copyrighted content, there was nothing for the DMCA to protect, so the claim failed as a matter of law.

Google's narrower path forward covers only Knowledge Panels, which do pull in copyrighted material from third parties. Even there, the court found Google hadn't alleged it was authorized by those copyright owners to use SearchGuard to protect their content — a gap Google now has three weeks to close or drop the claim.

Is bypassing anti-bot detection illegal?

Not automatically, and this ruling says so directly: getting past a bot-detection system isn't circumvention under the DMCA unless the thing being protected is a copyrighted work the plaintiff actually controls. SearchGuard protects Google's ad revenue and crawl economics — legitimate business interests, but not copyright.

That's a narrower reading than the industry has been operating under. SearchGuard itself is serious infrastructure: Google has said it represents "tens of thousands of person hours and millions of dollars," tracking mouse velocity, keyboard rhythm, scroll timing, and over 100 browser fingerprint signals. None of that engineering effort translates into DMCA leverage if there's no copyrighted content behind the gate.

How does this fit the bigger scraping-legality fight?

This isn't an isolated case. Amazon has a live suit against Perplexity alleging its Comet agent concealed itself to keep scraping after being told to stop, and Reddit has sued Anthropic over similar unauthorized-scraping claims with a hearing scheduled for January 2026. Every one of these cases is really about the same question: what legal theory, if any, turns "got past bot detection" into a violation.

CaseClaimStatus (as of July 2026)
Google v. SerpApiDMCA anti-circumventionDismissed July 20; narrow refile window open
Amazon v. PerplexityUnauthorized access / concealmentCourt found "strong evidence" against Perplexity
Reddit v. AnthropicUnauthorized scraping after cease-and-desistHearing pending, January 2026

The SerpApi outcome doesn't resolve the other two — they're built on different legal theories — but it narrows the DMCA's usefulness as a blunt instrument against scraping specifically, which is the theory Google reached for first.

What does this mean if you're running automation at scale?

It means the legal risk in bot-detection circumvention is real but theory-specific, not blanket. Google's DMCA approach — treat a bypassed anti-bot system like a bypassed DVD lock — didn't survive contact with a judge asking what copyrighted work was actually at stake. That's a meaningfully different exposure than the unauthorized-access and deception theories still alive in the Amazon and Reddit cases.

None of this changes the technical reality: sites are still layering Cloudflare, DataDome, and Akamai defenses, and Cloudflare's own September 15 deadline is about to default-block a lot more traffic regardless of what any court decides. DLBrowser exists for the technical side of that problem — reaching pages reliably on a real, unmodified browser runtime rather than a patched-together stealth layer — but the legal side is worth tracking separately, because it's moving just as fast as the detection arms race.

For more on the detection side of this, see our recent breakdown of why Cloudflare misses most AI browsing agents, and browse the research desk for more primary-source case coverage like this one.

The bigger story here isn't that SerpApi won — it's that a federal judge just drew a line between "you got past our defenses" and "you broke copyright law," and that line was blurrier than most scraping teams assumed. Google still has 21 days to try again on the narrow Knowledge Panel slice. Whether it bothers will say a lot about how much of this lawsuit was ever about copyright at all.

Frequently Asked Questions

What happened in the Google v. SerpApi lawsuit? On July 20, 2026, Chief Judge Yvonne Gonzalez Rogers dismissed Google's DMCA anti-circumvention claims against SerpApi. Google had alleged SerpApi bypassed its SearchGuard anti-bot system since a December 19, 2025 filing; the court found no copyrighted work was at stake for most of the claim.

Can Google refile its case against SerpApi? Partially. The judge dismissed with prejudice any claim tied to search results without copyrighted content. Claims involving Knowledge Panel content were dismissed without prejudice, giving Google 21 days to allege it had copyright-owner authorization to protect that content with SearchGuard.

Does this ruling mean bypassing bot detection is always legal? No. It means the DMCA specifically doesn't apply unless a copyrighted work is being protected. Other legal theories — unauthorized access, breach of terms, deceptive concealment — are still live in separate cases like Amazon v. Perplexity and Reddit v. Anthropic.

Why did SerpApi cite a $7.06 trillion damages figure? SerpApi calculated the theoretical maximum DMCA statutory damages under Google's own theory to argue the claim was legally absurd — the number exceeds U.S. GDP, which SerpApi used to show the interpretation couldn't be what Congress intended when it wrote the statute.

Abhishek Gupta is Co-Founder at Dekrypt Labs, building DLBrowser — a stealth browser runtime for real-world data collection. dekryptlabs.com