TL;DR: Almost every tool that tells you “this client ranks #4” gets that number the same way. A company sends automated requests to Google, reads the results page, and sells what it finds. Google is suing one of the biggest suppliers of that data, a firm called SerpApi. A judge threw out most of Google’s case on 20 July. On 10 August Google filed a new, narrower version: it now argues that some of what shows up in its results is content it licenses from other companies — Reddit is named — and those partners asked Google to keep third parties away from it. Nothing breaks in your reports today. But the question in front of the court is who is allowed to supply search-results data at all, and that is worth knowing about before it lands.
First, what is a “SERP scraper”, and why are you paying for one?
SERP just means search engine results page — what you see after you type something into Google. Scraping means having a program load that page automatically and pull out the useful parts: which sites are listed, in what order, which ones got quoted in an AI Overview, which ones paid for the ad slot.
You almost certainly buy this without thinking about it. When a rank tracker reports that a client moved from position 9 to position 6, nobody at that company typed the keyword by hand. A machine did, thousands of times a day, from many locations. The same plumbing sits under keyword databases, share-of-voice dashboards, competitor reports, and the newer tools that count how often a brand turns up in AI Overviews.
Some tools scrape for themselves. Plenty buy it wholesale. SerpApi is one of the larger wholesalers — it sells structured Google results through an API, which is just a way for one program to request data from another.
That pipe is what the lawsuit is about.
Google’s case, and the July ruling that gutted it
Google announced the suit on 19 December 2025. Its version of events: SerpApi disguises its traffic, runs large networks of bots, gives its crawlers fake and shifting names, and resells material Google licenses from other people — images in Knowledge Panels, real-time data. Court filings, as reported by MediaPost, put the volume at hundreds of millions of automated searches a day and name Google’s anti-bot system SearchGuard.
Notice what Google did not sue over: copyright itself. It can’t, really. Google doesn’t own the web pages that appear in its own results. So it used a different law — the DMCA’s anti-circumvention rule, a provision originally written for things like DVD copy protection. In plain terms it makes it illegal to break a lock that guards someone’s copyrighted work, even if you never copy the work.
SerpApi moved to dismiss on 20 February 2026, arguing that a bot-detection system protects ad revenue rather than copyright, and that public information stays public: “We provide structured access to publicly available information,” the company wrote, pointing at the hiQ Labs v. LinkedIn line of cases.
On 20 July, Judge Yvonne Gonzalez Rogers in the Northern District of California agreed with a lot of that. Claims about results containing no copyrighted material were dismissed permanently. For results that do contain copyrighted material, the court found Google hadn’t shown that SearchGuard was put in place with the authority of the copyright owner — protecting someone else’s work on your own initiative isn’t the same as being asked to. Google held on to two things: it can bring a DMCA claim without owning the underlying content, and the court accepted that circumvention had been adequately alleged. It got 21 days to try again.
What changed on 10 August
Google refiled, in the same court, adding allegations about licensed content. The amended complaint goes straight at the gap the judge left: authority from the owner. Google now says its licensing partners expressly asked it to keep unauthorised parties away from their content, and it names Reddit — which licenses its content to Google — as having told Google not to let third parties extract and independently commercialise it. SerpApi’s counsel said the company is confident and will respond.
This is a smaller case than the one Google filed in December. It is also pointed at a specific slice of the results page: the licensed slice. Reddit threads, Knowledge Panel imagery, real-time feeds. If you have watched which sources AI Overviews lean on this year, you will recognise that list.
What agencies should actually do about it
Nothing is broken this week, and panic is not a plan. Four things are worth doing anyway.
Find out where your data comes from. Ask each vendor in your stack, in writing, whether they scrape Google themselves or buy it. Many resell. A supplier-level ruling would hit several dashboards you think of as independent.
Export your history. Rank history is the one thing you cannot rebuild later. Quarterly CSV exports of client rank and visibility data cost you an hour and remove a whole category of bad day.
Stop treating one API as a source of truth in client reporting. If a single vendor outage would leave a monthly report with a hole in it, that’s a reporting design problem regardless of how this case ends.
Separate measurement from the work. Position numbers are a scoreboard. What actually moves them — clean crawlable pages, correct directives, content that answers the question — doesn’t depend on the scoreboard’s supply chain at all.
That last point is where Preferium fits. The technical side of our system doesn’t consume third-party SERP data: 47 automated checks crawl the client’s own pages, score the site 0–1000, then fix, deploy and re-verify with a real browser. Visibility measurement asks the answer engines directly — ChatGPT, Claude, Perplexity and Gemini, with Google AI Overviews and AI Mode tracked separately — rather than inferring AI presence from blue-link positions bought from a data broker. It doesn’t make anyone immune to how this case turns out; it does mean the fixing half of the work keeps running either way. More on how the system works, and if you’re building an AI-visibility measurement process from scratch, we wrote up the method here.
Key takeaways
- Google filed an amended complaint against SerpApi on 10 August 2026, three weeks after Judge Yvonne Gonzalez Rogers dismissed most of the original DMCA claims on 20 July.
- The new argument is narrower: Google says its licensing partners, Reddit among them, asked it to prevent third-party extraction of their content.
- Claims about search results containing no copyrighted material were dismissed permanently; Google’s standing to sue without owning the content survived.
- Rank trackers, keyword tools and AI-visibility dashboards mostly run on scraped or wholesale SERP data — ask your vendors which, and get it in writing.
- Export client rank history regularly. It is the only part of your reporting you cannot reconstruct after a supplier disappears.
