One Bot Check, Two Courts, Opposite Answers
Eleven days apart this summer, two federal judges looked at the same Google bot check, the same defendant and the same kind of claim. They came out on opposite sides.
On July 20, 2026, Chief Judge Yvonne Gonzalez Rogers of the Northern District of California dismissed Google's DMCA claims against SerpApi, the company that sells Google results through an API. On July 31, Judge Paul Engelmayer of the Southern District of New York predominantly denied the motions by SerpApi and Perplexity to dismiss Reddit's suit, which rests on the same Google system.
| Case | Court | Ruled | DMCA claims |
|---|---|---|---|
| Google v. SerpApi | N.D. California | July 20, 2026 | Dismissed |
| Reddit v. SerpApi | S.D. New York | July 31, 2026 | Mostly survive |
The Google SerpApi lawsuit got the headlines, and much of the coverage scored July as one win and one loss for scrapers. We read it differently. Getting past the check isn't what separated the two outcomes. What sat behind the check, and who holds the rights to it, did. For anyone collecting web data, that's a far more useful rule than either headline.
What SearchGuard Looks Like From the Receiving End
SearchGuard is the JavaScript challenge Google put in front of Search in January 2025. By Google's own account, a query from a source it doesn't recognize gets code to run. A person's browser answers without anyone noticing; most automated clients can't, and they get refused.
We meet it ourselves. In tests we ran on September 17, 2026, Google Search answered some automated requests with a 92 KB page titled just "Google Search": HTTP 200, no results, and a prompt to switch JavaScript on. Reddit's own gate looks much the same from the wire (a 200 titled "Reddit - Prove your humanity"). Anything that judges success by status code logs both as delivered pages.
Here's the part that got lost in the headlines. Judge Gonzalez Rogers didn't find that SerpApi never got around SearchGuard. She held that Google had adequately alleged a DMCA Section 1201 claim, and she rejected SerpApi's argument that Google, as a non-owner, couldn't sue at all. Google lost anyway.
What this means: courts aren't treating "did you get past the check?" as the deciding question. They're treating it as the start of one.
Why Google Lost and Reddit Didn't
Section 1201 of the DMCA bars getting around a measure that controls access to "a work protected under this title," which means a copyrighted work. Google's own complaint described its results as compilations of public information, with Knowledge Panels that "may contain some copyrighted content." The order took Google at its word: "To the extent that Google Search results do not contain any copyrighted content, SearchGuard cannot be said to effectively control access to a work protected under the Copyright Act." That half of the case was dismissed without leave to amend.
The Knowledge Panel half failed a second test. The measure has to operate "with the authority of the copyright owner," and Google hadn't pleaded a single term of the licenses behind those images. Google runs the gate. It doesn't own most of what's behind it.
Reddit stands somewhere else. Its users' posts are copyrighted, and its user agreement gives Reddit a license to all of them. Engelmayer sustained the claims under section 1201(a)(1)(A) against both defendants and under section 1201(a)(2) against SerpApi, while dismissing a 1201(b) claim and the state-law unjust enrichment and unfair competition counts. Same check, but this plaintiff had rights in the content it guarded. The court did leave open whether the short snippets that appear on Google's pages are protected at all, and Oxylabs, also named in the suit, still has its own motion to dismiss pending.
The License Is Becoming the Lock
Google took the hint. Its amended complaint, filed August 10, rebuilds the case around contracts. It says licensors authorized access controls "and in some cases insisted that Google do so." It says one unnamed partner has obliged Google since 2017 to "use commercially reasonable efforts to safeguard the licensed content against unauthorized third-party access," and that the Reddit deal "directs Google not to enable third parties to extract and independently commercialize the licensed content." It even offers Google's own Privacy Policy as authority from users.
SerpApi's second motion to dismiss answers that none of those agreements is actually in front of the court, and that "an anti-download provision is not an anti-access provision." On September 15 the judge denied SerpApi's request to force Google to produce the licenses. The hearing on the motion itself is set for October 13, 2026, according to the docket.
We think the October ruling matters less than the playbook it has already written. A clause telling a licensee to protect content from unauthorized access used to be boilerplate. After this summer, it's the missing element in a claim for statutory damages of $200 to $2,500 per violation. So expect every content deal signed from here on to carry one, including the paid-access arrangements that started forming around pay-per-crawl.
Accounts Were Never the Open Question
One corner of this didn't move at all. In mid-September a California federal judge finalized a consent judgment between LinkedIn and ProAPIs, along with its partner Netswift: stop scraping, stop selling or transferring the data, stop using fake accounts, delete what was taken. LinkedIn's complaint described bogus accounts in the millions, with hundreds or thousands created every day.
Those allegations centered on accounts, not on getting past a check. And the outcome was total: no access, no resale, no data.
What This Means for Data Teams
We're engineers, not lawyers, and both July rulings came at the motion-to-dismiss stage rather than at trial. Read what follows as a map of where the arguments are heading, and take the real questions to counsel.
- Sort your targets by what you keep. Prices, stock levels, rankings, links and listings are facts. Posts, reviews, articles, photos and lyrics are expression. The permanent half of the July 20 order covers the first kind; the Reddit case lives in the second.
- The route doesn't clean the content. Reddit's surviving claims concern posts allegedly taken from Google's results pages, not from reddit.com. Pulling user content through a search intermediary brings the owner's claim along with it.
- An owner's own check is the strong case. Google's weakness was running a gate over other people's work. A publisher that owns its articles and bought a bot product to guard them doesn't share that weakness, and per Zyte's State of Web Access 2026, 18.5% of top sites run a dedicated bot-detection service, each of them by choice.
- Count the logins. If any step of your pipeline signs in, that's where your exposure concentrates, whatever the courts end up saying about bot checks.
- Budget for friction no court will remove. Google confirmed on August 26 that result links now pass through a google.com/goto redirect. Derek Perkins of Nozzle reported that the links can't be decoded locally and that resolving one five-page ranking takes 500 to 1,000 requests. Add the num=100 removal from September 2025 (what that did to rank tracking) and search data got more expensive twice, with no judge involved.
From Code to Contracts
For years the scraping argument was about whether a bot check counts as a lock. This summer's answer is sharper than yes or no: it can, when the lock belongs to whoever owns what's inside, or to someone they've authorized in writing.
That moves the fight out of engineering and into licensing departments. Add Cloudflare's move to sort bot traffic by declared purpose, and the direction looks settled: access gets decided by who you are and what you've signed, and less and less by what your requests look like.
If you collect public facts, July made your position clearer. If you collect other people's words through someone else's gate, it just got a lot harder to defend.