On February 20, 2026, Texas-based SerpApi filed a motion to dismiss Google’s federal lawsuit, escalating what has become one of the most significant legal battles over web scraping, data access, and the future of the open internet. The motion challenges not just the technical allegations but the fundamental legal basis for Google’s claims, arguing that the search giant is misusing copyright law to create an “information monopoly” over publicly accessible data.
This case represents a watershed moment for the digital economy. At stake is whether companies can use the Digital Millennium Copyright Act (DMCA) to prevent automated access to publicly visible information, potentially reshaping how search engines, competitive intelligence platforms, AI systems, and research tools operate. The outcome could determine whether public data remains accessible or becomes locked behind corporate gatekeeping systems.
Background: How the Google vs SerpApi Legal Battle Began
Google initiated legal action against SerpApi on December 19, 2025, filing a complaint in the United States District Court for the Northern District of California. In its lawsuit, Google alleged that SerpApi violated the DMCA by circumventing SearchGuard, Google’s sophisticated anti-bot detection system, to scrape search results at what Google described as an “astonishing scale” of hundreds of millions of queries daily. Search Engine Land
According to Google’s complaint, SerpApi used “deceptive means” including rotating bot identities, large bot networks, and techniques designed to bypass Google’s technical protections. Google claimed that SerpApi scraped licensed content from search features including images in Knowledge Panels, merchant photos in Shopping results, real-time data feeds, and third-party content appearing in Maps results. Google’s General Counsel Halimah DeLaine Prado stated that the company filed suit to “stop SerpApi’s bots and their malicious scraping, which violates the choices of websites and rightsholders about who should have access to their content.” Google Official Blog
SerpApi, founded by CEO Julien Khaleghy, operates as a search engine results page (SERP) API service, providing structured data from Google search results to developers, researchers, journalists, and businesses. The company has operated for eight years, serving customers who use the data for competitive intelligence, market research, AI training, and application development.
The lawsuit follows a similar October 2025 case in which Reddit sued SerpApi, Perplexity AI, Oxylabs, and AWMProxy for allegedly scraping Reddit content indirectly from Google Search results and reusing or reselling it. Reddit claimed it set a “trap” post visible only to Google’s crawler that later appeared in Perplexity’s results, demonstrating what it called “industrial scale” data scraping. Reuters
SerpApi’s Motion to Dismiss: Core Legal Arguments
SerpApi’s February 20, 2026 motion to dismiss presents a multi-layered defense that challenges Google’s standing to bring the lawsuit, disputes the characterization of its activities as circumvention, and frames the case as an attempt to monopolize public information.
The Standing Argument: Google Doesn’t Own the Content
The centerpiece of SerpApi’s defense is a standing argument: Google lacks the legal right to invoke the DMCA because it doesn’t hold copyrights to the content displayed in search results. In a detailed blog post accompanying the motion, CEO Julien Khaleghy wrote: “Google is a website operator. It is not the copyright holder of the information it surfaces. The underlying content in Google’s search results is sourced from the tens of millions of publishers, authors, and creators across the internet. Google did not create that content.” SerpApi Blog
This argument strikes at the heart of the DMCA’s design. The statute protects copyright holders from unauthorized access to their protected works. SerpApi argues that Google cannot assert DMCA protections on behalf of third parties who never authorized Google to do so and may not even know Google is attempting to invoke copyright law on their behalf.
SerpApi’s motion invokes the Supreme Court’s 2014 ruling in Lexmark International, Inc. v. Static Control Components, Inc., which established that a plaintiff must demonstrate injuries within the “zone of interests” the law was designed to protect. SerpApi contends that Google’s alleged injuries—infrastructure costs, lost advertising revenue from automated queries, and the expense of maintaining bot-detection systems—fall outside what the DMCA was intended to address. Search Engine Journal
Crucially, Google’s own complaint may undermine its DMCA claim. In the filing, Google acknowledged that its bot-detection and anti-scraping technologies exist to protect its advertising business. Khaleghy seized on this admission: “In its complaint, Google itself says its bot-detection and anti-scraping technologies exist to protect its advertising business. Not to protect any copyrighted work. Not to protect any creator or publisher. To protect its ability to generate revenue.” This acknowledgment, SerpApi argues, is “fatal to Google’s DMCA claim” because the statute protects technological measures that control access to copyrighted works, not measures that protect business models.
The Circumvention Argument: Accessing Public Data Isn’t Breaking Locks
SerpApi’s second major argument challenges whether its activities constitute “circumvention” under the DMCA’s definition. The statute defines circumvention as actions “to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure.”
Khaleghy argues that SerpApi does none of these things: “We access publicly visible web pages, the same ones accessible to any browser. We do not break encryption. We do not disable authentication systems. We do not access private data or non-public pages. We read what is already in plain sight.” SerpApi Blog
This distinction matters. The DMCA was designed to prevent actions like breaking DVD encryption or hacking into password-protected systems. SerpApi contends that accessing publicly visible web pages—the same pages any user can view in a browser without logging in—doesn’t meet the statutory definition of circumvention, even if Google employs technical measures to distinguish between human and automated access.
The motion cites the Sixth Circuit’s reasoning in Impression Products, Inc. v. Lexmark International, which explained that the DMCA cannot apply to readily accessible works. The court used an analogy: just as a lock on a back door doesn’t control access to a house whose front door is wide open, Google’s bot-detection measures don’t transform publicly accessible search results into protected works. Google’s search results are the “front door”—open and public. Bot-detection systems on the backend don’t change that fundamental accessibility.
The Hyperbole Argument: $7.06 Trillion in Theoretical Damages
SerpApi’s motion includes a striking calculation designed to demonstrate the absurdity of Google’s legal theory. Based on DMCA statutory damages provisions and Google’s alleged violation counts, SerpApi calculated that maximum potential damages could theoretically reach $7.06 trillion—a figure that exceeds the entire GDP of the United States.
While this number reflects potential per-violation penalties rather than an actual damages demand, SerpApi argues it illustrates how Congress could not have intended the DMCA to be weaponized in this manner. The calculation serves a rhetorical purpose: if applying the statute as Google proposes generates damages exceeding the entire American economy, something is fundamentally wrong with the application. Search Engine Land
The Public Interest Argument: Preventing Information Monopolies
SerpApi frames the lawsuit as an attempt to create what courts have warned against: an information monopoly over public data. The motion cites the U.S. Court of Appeals for the Ninth Circuit’s decision in hiQ Labs, Inc. v. LinkedIn Corp., which specifically cautioned against allowing companies to establish “information monopolies that would disserve the public interest.”
In that case, LinkedIn attempted to use legal mechanisms to prevent hiQ Labs from scraping publicly available LinkedIn profiles. The Ninth Circuit ruled that accessing publicly available data likely doesn’t violate the Computer Fraud and Abuse Act (CFAA), establishing precedent that public information should remain accessible even when platform operators wish to restrict automated access. White & Case
SerpApi argues that Google’s lawsuit represents precisely the type of information monopoly the hiQ court warned against. By attempting to use copyright law to lock down publicly accessible search results, Google is trying to control who can access, analyze, and build upon information that has always been public.
Khaleghy invoked Google’s original mission statement—”To organize the world’s information and make it universally accessible and useful”—and suggested Google has abandoned those principles: “Google seems to have abandoned it, forgetting what the words ‘universally,’ ‘accessible,’ and ‘useful’ mean. Forcing SerpApi, a 42-person company, to take over and carry that mission forward.” SerpApi Blog
The Irony Argument: Google Built Its Empire on Scraping
Perhaps the most rhetorically powerful element of SerpApi’s defense is the accusation of hypocrisy. Khaleghy wrote: “Google is the largest scraper in the world. Google’s entire business began with a web crawler that visited every publicly accessible page on the internet, copied the content, indexed it, and served it back to users. It did this without distinguishing between copyrighted and non-copyrighted material, and it did this without asking permission.”
This argument resonates because it highlights an apparent double standard: the company that built a trillion-dollar empire by systematically scraping the entire web now seeks to prevent others from scraping its search results. As one LinkedIn post noted, “Google just sued SerpApi for scraping Google search results. Google. The company that built a trillion-dollar empire by scraping every website on the internet.” The Verge
SerpApi argues it is simply doing “what Google does to everyone else,” but at a much smaller scale. The company contends that if Google’s scraping of the web is legal and foundational to the internet’s information architecture, then SerpApi’s scraping of publicly visible search results should likewise be permissible.
Understanding SearchGuard: The Technology at the Heart of the Lawsuit
Central to Google’s allegations is SearchGuard, the sophisticated anti-bot detection system that Google deployed in January 2025. Understanding how this technology works is essential to evaluating both sides’ legal arguments.
SearchGuard is Google’s internal name for BotGuard when applied specifically to Google Search. BotGuard is Google’s proprietary anti-bot system that protects virtually all Google services including YouTube, reCAPTCHA v3, and Google Maps. According to Google’s complaint, SearchGuard represents “the product of tens of thousands of person hours and millions of dollars of investment.” Search Engine Land – SearchGuard Analysis
Unlike traditional CAPTCHAs that require users to identify traffic lights or crosswalks, SearchGuard operates invisibly in the background. It continuously collects behavioral signals and analyzes them using statistical algorithms to distinguish human users from automated bots. The system tracks four primary categories of behavior:
Mouse Movements: Humans don’t move cursors in straight lines. Natural mouse movements follow curves with acceleration and deceleration—tiny imperfections that reveal humanity. SearchGuard tracks trajectory, velocity, acceleration, and micro-tremors called “jitter.” A “perfect” mouse movement with linear motion and constant speed immediately triggers suspicion. The detection threshold: mouse velocity variance below 10 flags as bot behavior, while normal human variance falls between 50-500.
Keyboard Rhythm: Every person has a unique typing signature. SearchGuard measures inter-key intervals, key press duration, error patterns, and pauses after punctuation. Human typing typically shows 80-150ms variance between keystrokes. Bots often show less than 10ms with robotic consistency. The detection threshold: key press duration variance under 5ms indicates automation, while normal human typing shows 20-50ms variance.
Scroll Behavior: Natural scrolling has variable velocity, direction changes, and momentum-based deceleration. Programmatic scrolling is often too smooth, too fast, or perfectly uniform. SearchGuard measures scroll amplitude, direction changes, timing between scrolls, and smoothness patterns. Scrolling in fixed increments like 100px, 100px, 100px raises red flags. The detection threshold: scroll delta variance under 5px suggests bot activity, while humans typically show 20-100px variance.
Timing Jitter: This may be the most powerful signal. Humans are inconsistent in their actions, and that inconsistency is precisely what makes us identifiable as human. SearchGuard uses Welford’s algorithm to calculate variance in real-time with constant memory usage. If action intervals have near-zero variance, the system flags the user as a bot. Normal human interaction generates 10-50 events per second; counts exceeding 200 per second indicate automation.
Beyond behavioral analysis, SearchGuard fingerprints browser environments by monitoring over 100 HTML elements including buttons, inputs, navigation elements, text structures, tables, media elements, and interactive components. The system also collects extensive browser and device data including user agent strings, language settings, hardware specifications (CPU cores, device memory, touch points), screen properties, performance metrics, and visibility states.
Critically, SearchGuard includes WebDriver detection, specifically checking for signatures that betray automation tools including Puppeteer markers, Selenium indicators, ChromeDriver signatures, and PhantomJS artifacts.
What makes SearchGuard particularly difficult to bypass is its cryptographic token system. The JavaScript code generates encrypted tokens using an ARX cipher (Addition-Rotation-XOR) similar to Speck, a family of lightweight block ciphers. The cryptographic constant embedded in the cipher isn’t fixed—it rotates with every script update. Even if someone fully reverse-engineers the system, their implementation becomes invalid when Google updates the script, which happens frequently.
SearchGuard’s deployment in January 2025 had an immediate and dramatic effect: nearly every SERP scraper suddenly stopped returning results. SerpApi and similar companies had to scramble to develop workarounds—which Google now characterizes as illegal circumvention.
The Broader Legal Landscape: Precedents and Parallel Cases
The Google vs SerpApi case doesn’t exist in isolation. It’s part of a rapidly evolving legal landscape around web scraping, data access, and AI training that involves multiple overlapping cases and legal theories.
The hiQ Labs v. LinkedIn Precedent
The Ninth Circuit’s ruling in hiQ Labs v. LinkedIn established important precedent. hiQ is a data analytics company that used automated bots to scrape information from public LinkedIn profiles. LinkedIn used legal means to prevent this, sending cease-and-desist letters and implementing technical barriers.
The court ruled that accessing publicly available data likely doesn’t violate the Computer Fraud and Abuse Act (CFAA). The decision warned against allowing companies to create “information monopolies” over public data and emphasized that publicly visible information should remain accessible even when platform operators prefer to restrict automated access. While hiQ ultimately obtained a permanent injunction on December 6, 2022, after six years of litigation, the case established that data scraping of publicly available websites is legal under the CFAA—though it may create liability under breach of contract claims. Fenwick & West
SerpApi’s motion to dismiss heavily relies on this precedent, arguing that Google’s attempt to use the DMCA to restrict access to public search results is analogous to LinkedIn’s failed attempt to use the CFAA for similar purposes.
The Ziff Davis v. OpenAI Robots.txt Ruling
A December 15, 2025 decision in Ziff Davis v. OpenAI provided additional context for how courts are evaluating DMCA claims related to web scraping. U.S. District Judge Sidney Stein dismissed Ziff Davis’s DMCA Section 1201(a) anti-circumvention claim, which alleged that OpenAI circumvented robots.txt directives.
Judge Stein held that Ziff Davis failed to plausibly allege that robots.txt is a “technological measure that effectively controls access” or that OpenAI circumvented it. The judge concluded: “At most, Ziff Davis alleges that OpenAI disregarded the instructions that were contained in robots.txt files.” The ruling emphasized that robots.txt directives are “merely requests” that don’t effectively control access to copyrighted works. Courthouse News
Google’s SearchGuard is significantly more technically complex than robots.txt, but both cases test whether the DMCA can be used to restrict automated access to publicly available content. The Ziff Davis ruling suggests courts may be skeptical of stretching DMCA anti-circumvention provisions to cover access to public information, even when technical measures exist.
The Reddit Lawsuits: Data Laundering Allegations
Reddit’s October 2025 lawsuit against SerpApi, Perplexity AI, Oxylabs, and AWMProxy introduced the concept of “data laundering” into the web scraping discussion. Reddit alleged these companies scraped Reddit content indirectly from Google Search results—content that appeared in search results because Google had crawled it—and then reused or resold the data.
Reddit claimed the defendants hid their identities and scraped at “industrial scale.” The company said it set a “trap” post visible only to Google’s crawler (Googlebot) that later appeared in Perplexity’s results, demonstrating that Perplexity was accessing Reddit content through intermediary scrapers rather than directly. Reddit seeks damages and a ban on further use of previously scraped data. AP News
This case is significant because it involves scraping content from search results rather than directly from source websites—exactly what SerpApi does with Google’s search results. The “data laundering” theory suggests that even if direct scraping might be legal under some circumstances, obtaining data through intermediary platforms could create additional legal exposure.
The Computer Fraud and Abuse Act Landscape
The CFAA has been a primary legal tool for challenging web scraping, but recent court decisions have narrowed its application. The Ninth Circuit’s hiQ decision and subsequent rulings established that scraping public websites likely doesn’t violate the CFAA, particularly when the information is accessible without authentication or bypassing technical barriers.
However, the CFAA remains relevant when scraping involves accessing non-public data, circumventing authentication systems, or violating clearly stated access restrictions tied to computer authorization rather than mere terms of service. Quinn Emanuel
The distinction matters because Google’s lawsuit relies on the DMCA rather than the CFAA, potentially learning from LinkedIn’s unsuccessful CFAA-based approach and attempting a different legal theory that might prove more successful.
Industry Impact: What This Lawsuit Means for SEO, AI, and Data Access
The Google vs SerpApi lawsuit has profound implications extending far beyond the two parties involved.
Impact on SEO Tools and Competitive Intelligence
SEO professionals and digital marketers have long relied on tools that programmatically access Google Search results to track rankings, analyze competitors, identify keyword opportunities, and measure search visibility. These tools fundamentally depend on the ability to access and analyze search results at scale.
If Google prevails and courts accept that SearchGuard qualifies as a DMCA-protected technological measure, the entire SERP data industry faces existential risk. Third-party rank tracking tools, competitive intelligence platforms, and SEO analytics services could become legally untenable in their current form.
The practical impact has already been significant. When SearchGuard deployed in January 2025, nearly every SERP scraper experienced immediate disruption. Then in September 2025, Google removed the num=100 parameter, which had allowed tools to retrieve 100 results in a single request instead of 10. While Google claimed this was because the parameter “was not a formally supported feature,” many analysts viewed the timing as telling: forcing scrapers to make 10x more requests dramatically increased operational costs. Some suggested the move specifically targeted AI platforms like ChatGPT and Perplexity that relied on mass scraping for real-time search data.
The combined effect has made traditional scraping approaches increasingly difficult and expensive to maintain. If the lawsuit establishes that circumventing anti-bot measures violates the DMCA, companies might abandon SERP scraping entirely rather than face potential statutory damages.
Impact on AI Development and Training
The OpenAI connection adds another dimension to the case. SerpApi listed OpenAI as a customer on its website as recently as May 2024, before the reference was quietly removed. OpenAI had requested direct access to Google’s search index in 2024, but Google declined. Yet ChatGPT still needed fresh search data to provide real-time answers and compete effectively with Google Search.
The solution appears to have been indirect: using third-party scrapers like SerpApi to access Google’s search results and integrate that data into ChatGPT’s responses. Google isn’t attacking OpenAI directly, but the lawsuit effectively targets a key link in the supply chain feeding its main AI competitor.
If Google succeeds in shutting down access to scraped search data, AI companies will face significant challenges in providing current information. They would need to either build their own search indexes from scratch (an enormous undertaking), negotiate direct licensing deals with Google (unlikely given competitive dynamics), or rely on alternative data sources that may be less comprehensive.
The timing is notable: Google is striking at the infrastructure powering rival search products without naming those products in the complaint. This indirect approach may be strategic, avoiding antitrust concerns that could arise from directly targeting competitors while still disrupting their data supply chains.
Impact on Research and Innovation
Academic researchers, journalists, and data scientists have used SERP data for studies on search bias, information quality, algorithmic fairness, and digital market dynamics. If automated access to search results becomes legally restricted, this research could become impossible or require direct relationships with Google that introduce conflicts of interest and limit independence.
Similarly, developers building innovative applications that leverage search data—from personal assistants to specialized research tools to accessibility applications—could lose access to the foundational data their products require. The consolidation of control over search data in Google’s hands would reduce innovation in adjacent markets.
The Impossible Choice for Publishers
An uncomfortable reality underlies this entire dispute: publishers face an impossible choice regarding their content and AI. Google’s robots.txt controls offer limited options. Google-Extended allows publishers to opt out of AI training for Gemini models and Vertex AI, but it doesn’t apply to Search AI features including AI Overviews.
According to Google’s documentation: “AI is built into Search and integral to how Search functions, which is why robots.txt directives for Googlebot is the control for site owners to manage access to how their sites are crawled for Search.” Search Engine Land – SearchGuard Analysis
Court testimony from DeepMind VP Eli Collins during Google’s antitrust trial confirmed this separation: content opted out via Google-Extended could still be used by the Search organization for AI Overviews because Google-Extended isn’t the control mechanism for Search.
The only way for publishers to fully opt out of AI Overviews is to block Googlebot entirely—which means losing all search traffic. Publishers must choose between accepting that their content feeds Google’s AI search products or disappearing from search results altogether. This dynamic raises questions about whether Google’s objections to SerpApi ring hollow when Google itself gives publishers no meaningful choice about how their content is used.
Legal Analysis: Strengths and Weaknesses of Each Side’s Position
SerpApi’s Strongest Arguments
Standing Challenge: The argument that Google lacks standing because it doesn’t own the copyrighted content in search results is legally sophisticated and potentially dispositive. If the court agrees that only copyright holders can invoke DMCA protections and that Google is merely a conduit for third-party content, the case could be dismissed without reaching the merits of the circumvention allegations. The Supreme Court’s Lexmark decision on statutory standing provides strong support for this theory.
Public Access Argument: The contention that accessing publicly visible information doesn’t constitute circumvention aligns with the policy goals behind copyright law and First Amendment principles. Courts have generally been skeptical of using intellectual property law to restrict access to public information, particularly when that information serves important research, competitive, and democratic functions.
Ninth Circuit Precedent: The hiQ v. LinkedIn decision, while based on the CFAA rather than the DMCA, establishes a judicial philosophy skeptical of information monopolies. Federal courts in the Ninth Circuit (where this case is pending) have already demonstrated willingness to protect access to public data against platform operators’ attempts at control.
SerpApi’s Weaknesses
Technical Circumvention: The strongest part of Google’s case is the technical evidence showing that SerpApi didn’t simply access publicly visible pages in a straightforward manner. Google alleges SerpApi used rotating IP addresses, solved JavaScript challenges, mimicked human browser behavior, and employed other techniques specifically designed to defeat SearchGuard. These actions could meet the DMCA’s definition of circumvention even if the underlying content is public.
Commercial Nature: SerpApi is not a researcher, journalist, or non-profit organization acting in the public interest. It’s a commercial enterprise that charges fees for access to Google’s search data. Courts may be less sympathetic to fair use arguments and public interest claims when the defendant profits directly from the challenged activity.
Scale: The allegation of “hundreds of millions” of queries daily suggests SerpApi’s operations go far beyond occasional or incidental access. The industrial scale of the scraping could make the “publicly accessible” argument less persuasive—there’s a difference between a person viewing search results in a browser and an automated system making hundreds of millions of requests.
Google’s Strongest Arguments
Investment in Protection: Google can demonstrate substantial investment in SearchGuard, including tens of thousands of person-hours and millions of dollars. This evidence supports the claim that SearchGuard is a legitimate technological protection measure deserving of DMCA protection.
Licensed Content: Some content in search results is licensed by Google from third parties (images in Knowledge Panels, merchant photos in Shopping, real-time data feeds). For these specific elements, Google can argue it has direct relationships with copyright holders and potentially authorization to enforce their rights.
Clear Intent to Protect: SearchGuard’s sophisticated design demonstrates clear intent to control access and distinguish between authorized and unauthorized users. Unlike passive measures like robots.txt, SearchGuard actively challenges and blocks suspected bots, which could strengthen the argument that circumventing it meets the DMCA’s statutory definition.
Google’s Weaknesses
Own Admission: Google’s statement in its complaint that SearchGuard exists to protect its advertising business could be fatal to the DMCA claim. The statute protects measures that control access to copyrighted works, not measures that protect business models. This admission hands SerpApi a powerful argument that SearchGuard isn’t a valid DMCA technological protection measure.
Hypocrisy Perception: While not a formal legal defense, the perception that Google built its business on web scraping and now seeks to prevent others from scraping Google creates a credibility problem. Courts deciding cases that could set important precedents about the open internet may be influenced by concerns that ruling for Google would legitimize large platforms locking down public information.
Antitrust Context: Google is currently subject to antitrust remedies requiring it to share index data with competitors. A lawsuit seeking to prevent access to the same data creates tension with those remedies and could lead courts to view Google’s position skeptically.
First Amendment Considerations
While neither party has prominently featured First Amendment arguments in their initial filings, the case implicates important free speech principles. Federal courts have increasingly recognized that automated data collection from public sources receives First Amendment protection.
In a 2023 decision involving scraping of public court records, a federal judge ruled that “a categorical prohibition on scraping public court records implicates the First Amendment.” The ACLU, representing plaintiffs challenging anti-scraping restrictions, argued that accessing public records is protected speech activity. ACLU Press Release
SerpApi could strengthen its position by framing access to public search results as a First Amendment issue. Search results reflect how information is organized and prioritized in society—a matter of significant public concern. Researchers, journalists, and watchdog organizations use SERP data to study search bias, track disinformation, monitor market dynamics, and hold powerful institutions accountable. Restricting automated access to this public information could implicate both the right to gather information and the right to speak about what that information reveals.
However, First Amendment defenses face challenges in commercial contexts. Because SerpApi operates as a for-profit business reselling access to search data, courts might view the activity as commercial speech entitled to less protection than journalism or academic research. Additionally, the First Amendment doesn’t create unlimited rights to access private property or bypass technical restrictions, even when the ultimate goal involves protected speech.
What Happens Next: Procedural Timeline and Possible Outcomes
The motion to dismiss hearing is scheduled for May 19, 2026. Before that date, Google will file its opposition brief responding to SerpApi’s arguments. SerpApi will then have an opportunity to file a reply brief. Judge Yvonne Gonzalez Rogers of the U.S. District Court for the Northern District of California will preside over the hearing.
Possible Outcomes
Motion Granted (Case Dismissed): If Judge Rogers agrees with SerpApi’s standing argument or concludes that accessing publicly visible information doesn’t constitute DMCA circumvention, she could dismiss the case entirely. Dismissal could be with prejudice (ending the case permanently) or without prejudice (allowing Google to refile with amended allegations). This outcome would represent a significant victory for SerpApi and establish precedent limiting how platforms can use the DMCA to restrict access to public data.
Motion Denied (Case Proceeds): If Judge Rogers finds that Google has adequately alleged both standing and circumvention, the case would proceed to discovery. Both parties would exchange documents, sit for depositions, and gather evidence. Discovery could reveal additional details about SearchGuard’s operation, SerpApi’s techniques, the extent of any relationships with AI companies, and the practical impact of the scraping. The case would likely proceed toward summary judgment motions or trial, which could take one to two years.
Partial Grant: Judge Rogers could grant parts of the motion while denying others. For example, she might dismiss claims related to general search results while allowing claims to proceed for specific licensed content like Knowledge Panel images. This outcome would narrow the case’s scope while allowing core issues to be litigated.
Settlement: At any point, the parties could negotiate a settlement. Given the high stakes and uncertain legal landscape, both sides might have incentives to reach agreement rather than risk an unfavorable precedent. A settlement could include licensing arrangements, technical modifications to SerpApi’s operations, or agreements about acceptable use cases.
Broader Implications for Data Access and the Open Internet
The Google vs SerpApi lawsuit represents a critical juncture in the evolving relationship between platform control and information access. The case crystallizes tensions that have been building for years as data has become increasingly central to economic competition, technological innovation, and democratic discourse.
At its heart, the case asks fundamental questions: Who owns public information? Can companies use technical measures backed by legal threats to control access to data that anyone can view? Should copyright law—designed to protect creative works—be repurposed to protect business models?
The answers will have consequences extending far beyond search results. If platforms can successfully use the DMCA to prevent automated access to public information, similar restrictions could proliferate across the digital ecosystem. Social media platforms could block research into algorithmic amplification of misinformation. E-commerce sites could prevent price comparison tools. Government websites could restrict civic monitoring organizations. The cumulative effect would be a less transparent, less competitive, and less innovative internet.
Conversely, if courts establish that accessing publicly visible information cannot be restricted by bot-detection measures, platforms lose a powerful tool for controlling how their services are used. This could accelerate scraping, increase infrastructure costs, complicate efforts to combat abuse, and potentially undermine business models built on exclusive access to aggregated data.
The case also occurs against the backdrop of AI development, where access to training data has become a central competitive factor and legal battleground. How courts resolve questions about scraping public data will directly impact which organizations can build competitive AI systems and whether data access concentrates in the hands of a few dominant platforms or remains available to researchers, startups, and the public.
Frequently Asked Questions
What is the SerpApi vs Google lawsuit about?
The lawsuit involves Google suing SerpApi for allegedly violating the Digital Millennium Copyright Act (DMCA) by circumventing Google’s SearchGuard anti-bot system to scrape search results. Google claims SerpApi used deceptive means including rotating IP addresses, bot networks, and techniques to mimic human behavior to access and resell search data at a scale of hundreds of millions of queries daily. SerpApi filed a motion to dismiss on February 20, 2026, arguing that Google lacks legal standing to bring the case and that accessing publicly visible search results doesn’t constitute illegal circumvention.
What is SerpApi and what does the company do?
SerpApi is a Texas-based company founded by CEO Julien Khaleghy that operates as a search engine results page (SERP) API service. The company provides structured data from Google search results to developers, researchers, journalists, and businesses who use it for competitive intelligence, market research, AI training, application development, and various analytical purposes. SerpApi has operated for eight years and describes itself as providing access to the same public information any person can see in a browser without logging in.
What is Google SearchGuard?
SearchGuard is Google’s sophisticated anti-bot detection system deployed in January 2025 to protect Google Search from automated scraping. It’s the internal name for BotGuard when applied specifically to search. SearchGuard operates invisibly in the background, continuously collecting behavioral signals to distinguish human users from bots. The system analyzes mouse movements, keyboard rhythms, scroll behavior, timing patterns, and browser fingerprints. It monitors over 100 HTML elements and uses statistical algorithms including Welford’s algorithm for real-time variance calculation. SearchGuard employs cryptographic tokens that rotate frequently, making bypasses obsolete within minutes. Google’s complaint states SearchGuard represents “tens of thousands of person hours and millions of dollars of investment.”
Why does SerpApi say Google lacks standing to sue?
SerpApi argues that the DMCA protects copyright holders, not companies that merely display others’ content. Google doesn’t own the underlying content in search results—that content belongs to millions of publishers, authors, and creators across the internet. SerpApi contends that only copyright holders can authorize access controls under the DMCA, and that Google cannot assert these rights on behalf of third parties without their knowledge or consent. Additionally, Google admitted in its complaint that SearchGuard exists to protect its advertising business, not specific copyrighted works, which SerpApi argues undermines the DMCA claim since the statute protects measures controlling access to copyrighted works, not business models.
What is the hiQ Labs v. LinkedIn case and why does it matter?
hiQ Labs v. LinkedIn was a Ninth Circuit case in which LinkedIn tried to prevent hiQ Labs from scraping publicly available LinkedIn profiles. The court ruled that accessing publicly available data likely doesn’t violate the Computer Fraud and Abuse Act (CFAA) and warned against allowing companies to create “information monopolies” over public data. While the case involved the CFAA rather than the DMCA, SerpApi cites it as precedent establishing that publicly visible information should remain accessible even when platform operators prefer to restrict automated access. The decision establishes judicial skepticism toward platform attempts to lock down public information, which supports SerpApi’s defense.
Did Google build its business on web scraping?
Yes. Google’s entire business model began with a web crawler (Googlebot) that systematically visited every publicly accessible page on the internet, copied the content, indexed it, and served it back to users in search results. Google did this without distinguishing between copyrighted and non-copyrighted material and without requiring permission from website owners (though sites could opt out via robots.txt). SerpApi emphasizes this history in its defense, arguing that Google is “the largest scraper in the world” and pointing out the apparent inconsistency in Google building a trillion-dollar empire through scraping while now suing others for scraping Google’s search results. Google continues to operate the world’s most extensive web crawling infrastructure.
What happened in the Ziff Davis v. OpenAI robots.txt case?
On December 15, 2025, U.S. District Judge Sidney Stein dismissed Ziff Davis’s DMCA anti-circumvention claim that alleged OpenAI violated the law by ignoring robots.txt directives. Judge Stein held that Ziff Davis failed to show that robots.txt is a “technological measure that effectively controls access” under the DMCA or that OpenAI circumvented it. The judge concluded that robots.txt directives are “merely requests” that don’t effectively control access to copyrighted works. While Google’s SearchGuard is far more sophisticated than robots.txt, this ruling suggests courts may be skeptical of stretching DMCA anti-circumvention provisions to restrict automated access to publicly available content.
How does this lawsuit affect SEO tools and rank tracking software?
If Google prevails, the SERP data industry faces existential risk. SEO professionals rely on tools that programmatically access Google search results to track rankings, analyze competitors, and measure search visibility. If courts accept that circumventing bot-detection measures violates the DMCA, third-party rank tracking tools, competitive intelligence platforms, and SEO analytics services could become legally untenable. The practical impact is already significant—SearchGuard’s January 2025 deployment immediately disrupted nearly every SERP scraper. Combined with Google’s removal of the num=100 parameter in September 2025, traditional scraping approaches have become increasingly difficult and expensive. A Google victory could force these tools to either negotiate direct licensing agreements with Google or cease operations.
What is the connection between SerpApi and OpenAI?
SerpApi listed OpenAI as a customer on its website as recently as May 2024, before the reference was quietly removed. According to industry analysis, OpenAI requested direct access to Google’s search index in 2024, but Google declined. ChatGPT needed fresh search data to provide real-time answers and compete with Google Search, so OpenAI apparently used SerpApi as an intermediary to access scraped Google search results. While Google doesn’t name OpenAI in its lawsuit, the legal action effectively targets a key link in the data supply chain feeding Google’s main AI competitor. This strategic approach disrupts rival AI products without raising antitrust concerns that might come from directly targeting competitors.
What are Reddit’s lawsuits about data scraping?
In October 2025, Reddit sued SerpApi, Perplexity AI, Oxylabs, and AWMProxy for allegedly scraping Reddit content indirectly from Google Search results. Reddit claimed these companies scraped at “industrial scale” and introduced the concept of “data laundering”—obtaining content through intermediary platforms rather than directly from sources. Reddit said it set a “trap” post visible only to Google’s crawler that later appeared in Perplexity’s results, demonstrating the indirect scraping pathway. Reddit seeks damages and a ban on further use of previously scraped data. This case is significant because it involves scraping content from search results rather than directly from source websites, exactly what SerpApi does with Google’s search results.
Can publishers opt out of having their content used in Google’s AI features?
Publishers face an impossible choice. Google-Extended allows publishers to opt out of AI training for Gemini models and Vertex AI, but it doesn’t apply to Search AI features including AI Overviews. According to Google’s documentation and court testimony during the antitrust trial, AI is “built into Search and integral to how Search functions,” so robots.txt directives for Googlebot are the only control mechanism. The only way for publishers to fully opt out of AI Overviews is to block Googlebot entirely, which means losing all search traffic. Publishers must choose between accepting that their content feeds Google’s AI products or disappearing from search results altogether—there is no middle ground for opting out of just AI features while maintaining search visibility.
What is the $7.06 trillion figure mentioned in SerpApi’s motion?
SerpApi calculated that under Google’s interpretation of the DMCA, theoretical maximum statutory damages could reach $7.06 trillion—a figure exceeding U.S. GDP. This calculation reflects potential per-violation penalties based on DMCA statutory damages provisions and Google’s alleged violation counts, not an actual damages demand. SerpApi included this figure to demonstrate what it characterizes as the absurdity of Google’s legal theory: if applying the statute as Google proposes generates damages exceeding the entire American economy, something is fundamentally wrong with the application. The calculation serves a rhetorical purpose showing that Congress couldn’t have intended the DMCA to be weaponized in this manner.
What does “circumvention” mean under the DMCA?
The DMCA defines circumvention as actions “to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure.” The statute was designed to prevent actions like breaking DVD encryption or hacking password-protected systems. SerpApi argues it doesn’t descramble, decrypt, or impair any technological measures—it simply accesses publicly visible web pages that anyone can view in a browser without authentication. Google argues that SerpApi used techniques including rotating IP addresses, solving JavaScript challenges, and mimicking human behavior specifically designed to defeat SearchGuard, which constitutes circumvention even if the underlying pages are public. The legal question is whether accessing public information through methods designed to bypass bot detection meets the statutory definition of circumvention.
When will the court decide on SerpApi’s motion to dismiss?
The hearing on SerpApi’s motion to dismiss is scheduled for May 19, 2026. Before that date, Google will file its opposition brief responding to SerpApi’s arguments, and SerpApi will have an opportunity to file a reply brief. Judge Yvonne Gonzalez Rogers of the U.S. District Court for the Northern District of California will preside. After the hearing, the judge will issue a ruling that could dismiss the case, allow it to proceed to discovery, or grant parts of the motion while denying others. If the case isn’t dismissed, discovery and subsequent proceedings could extend the litigation by one to two years or more.
How might this lawsuit affect AI development?
The outcome could significantly impact AI companies’ ability to access training data and provide real-time information. Many AI systems rely on scraped search data to deliver current answers beyond their knowledge cutoff dates. If Google succeeds in shutting down third-party SERP scraping, AI companies would need to either build their own search indexes from scratch (an enormous undertaking requiring billions in investment), negotiate direct licensing deals with Google (unlikely given competitive dynamics), or rely on alternative data sources that may be less comprehensive. The lawsuit represents an indirect attack on the data supply chains feeding Google’s AI competitors without raising the antitrust concerns that might arise from directly targeting those competitors.
What are the First Amendment implications of restricting access to public search results?
Courts have increasingly recognized that automated data collection from public sources receives First Amendment protection. A 2023 federal judge ruled that “a categorical prohibition on scraping public court records implicates the First Amendment.” Researchers, journalists, and watchdog organizations use SERP data to study search bias, track disinformation, monitor market dynamics, and hold institutions accountable. Restricting automated access to this public information could implicate both the right to gather information and the right to speak about what that information reveals. However, First Amendment defenses face challenges in commercial contexts like SerpApi’s for-profit business model. The Supreme Court has held that commercial speech receives less protection than journalism or academic research, and the First Amendment doesn’t create unlimited rights to bypass technical restrictions even when the ultimate goal involves protected speech.
What precedent could this case set for other platforms?
If Google prevails and courts accept that sophisticated bot-detection measures qualify as DMCA-protected technological measures, every platform could deploy similar systems with legal backing. Social media platforms could legally block research into algorithmic amplification. E-commerce sites could prevent price comparison tools. News aggregators could restrict monitoring services. The cumulative effect would be less transparency, reduced competition, and diminished innovation across the digital ecosystem. Conversely, if courts establish that accessing publicly visible information cannot be restricted by bot-detection measures, platforms lose a powerful tool for controlling how their services are used, which could accelerate scraping, increase infrastructure costs, and potentially undermine business models built on exclusive data access.
Is web scraping legal in the United States?
The legality of web scraping depends on multiple factors including what is being scraped, how it’s being accessed, and what it’s being used for. The Ninth Circuit’s hiQ v. LinkedIn decision established that scraping publicly available data likely doesn’t violate the Computer Fraud and Abuse Act (CFAA). However, scraping can create legal liability under various theories including breach of contract (violating terms of service), trespass to chattels (in some jurisdictions), copyright infringement (if copyrighted content is reproduced), and potentially DMCA anti-circumvention (if technical protection measures are defeated). The Google vs SerpApi case will help determine whether the DMCA applies to bot-detection systems protecting publicly visible content. Currently, scraping public websites is generally legal under the CFAA, but the legal landscape remains unsettled and varies by jurisdiction.
What happens if SerpApi wins the motion to dismiss?
If Judge Rogers grants SerpApi’s motion to dismiss, Google’s lawsuit could end (if dismissed with prejudice) or Google could attempt to refile with amended allegations (if dismissed without prejudice). A dismissal would establish precedent in the Northern District of California that accessing publicly visible search results doesn’t violate the DMCA, at least under the circumstances alleged. This would be a significant victory for data access advocates, researchers, and companies building on search data. It would limit platforms’ ability to use copyright law to restrict access to public information. However, Google could appeal the decision, potentially taking the case to the Ninth Circuit Court of Appeals, which could extend litigation for years.
What happens if Google wins and the case proceeds?
If Judge Rogers denies the motion to dismiss, the case would proceed to discovery where both parties exchange documents, sit for depositions, and gather evidence. This could reveal additional details about SearchGuard’s operation, SerpApi’s specific techniques, relationships with AI companies, and the practical and economic impact of the scraping. The case would then proceed toward summary judgment motions or trial, likely taking one to two years. A Google victory at trial would establish precedent that sophisticated bot-detection measures qualify as DMCA-protected technological measures, creating legal risk for any company circumventing such systems to scrape public data. This could fundamentally reshape the data access landscape and concentrate control over public information in the hands of large platforms.
The legal battle between Google and SerpApi represents far more than a dispute between two companies over search data. It embodies fundamental questions about who controls public information in the digital age, whether platforms can use copyright law to create information monopolies, and how society balances innovation, competition, and access against platform operators’ interests in controlling their services.
As the case proceeds toward the May 19, 2026 hearing, the technology industry, legal community, research organizations, and civil liberties advocates will watch closely. The court’s decision will help define the boundaries of permissible data access in an era when information has become the most valuable economic resource and the foundation of competitive advantage in artificial intelligence.
Whether the judge sides with Google’s property-rights framing or SerpApi’s public-access arguments, the ruling will send ripples through the digital ecosystem, affecting how search engines operate, how AI systems access training data, how researchers study online platforms, and ultimately, how open or closed the internet becomes in the years ahead.
For now, both sides have presented their strongest legal arguments, and the court must decide whether the company that built its empire by scraping the web can prevent others from scraping its search results, or whether the mission to make the world’s information universally accessible still has meaning in 2026.
About ALM Corp
ALM Corp provides comprehensive legal technology consulting and digital strategy services for law firms, legal departments, and technology companies navigating complex regulatory landscapes. Our expertise spans intellectual property litigation support, DMCA compliance advisory, web scraping legal risk assessment, and digital rights management strategy.
In cases like Google v. SerpApi, where cutting-edge technology intersects with evolving legal frameworks, ALM Corp helps clients understand their legal exposure, develop compliant data access strategies, and navigate litigation risks. Our team provides technical analysis of anti-circumvention measures, expert witness testimony on bot detection systems, and strategic counsel on balancing business objectives with legal compliance.
Whether you’re a platform operator seeking to protect your technical infrastructure, a data company building services on publicly accessible information, or an organization requiring clarity on web scraping legality, ALM Corp delivers practical guidance grounded in deep understanding of both technology and law. We help clients turn complex legal challenges into strategic opportunities, ensuring your operations remain compliant as courts define the boundaries of permissible data access in the digital economy.



