The Ninth Circuit vacated Amazon’s injunction against Perplexity’s Comet browser on August 4, 2026. The panel held that Perplexity does not access Amazon’s servers under the Computer Fraud and Abuse Act, because the user operates the tool. Amazon had sued in November 2025 and won a preliminary injunction in March, which blocked Comet from reaching Amazon’s logged-in account pages. That order is now gone, and Comet can shop Amazon again. This is the first federal appeals ruling anywhere on whether AI agents acting for a person can legally reach into online platforms. The court applied the rule of lenity, admitted there is almost no caselaw on assigning responsibility for agents, and said plainly that its holding is narrow and that the law here will change. Amazon’s trademark and California state law claims survive untouched, and the case returns to district court for further proceedings. Nothing here settles the merits, and nothing here binds a court outside the Ninth Circuit.
Amazon’s argument, essentially, was that a shopping assistant is a hacker.
Not a metaphor. Amazon filed under the Computer Fraud and Abuse Act, the 1984 federal anti-hacking statute, and asked a court to treat Perplexity’s Comet browser as unauthorized access to its computers.
And it worked for five months. On August 4 the Ninth Circuit erased it.
The reasoning fits in one sentence: Perplexity doesn’t visit Amazon. You do. Comet is the thing you use to do it, the same way a browser is.
And that sentence is now the first federal appeals precedent on agentic AI in the United States, and it lands while roughly every AI company is building something that clicks buttons on websites for you.
The Case, Compressed
| Date | What happened |
|---|---|
| November 2025 | Amazon sues Perplexity, alleging CFAA and CDAFA violations |
| March 9, 2026 | Judge Maxine M. Chesney grants a preliminary injunction, blocking Comet from Amazon’s logged-in pages |
| Shortly after | Ninth Circuit stays the injunction pending appeal |
| April 9, 2026 | EFF files an amicus brief on how Comet’s architecture actually works |
| June 11, 2026 | Oral arguments heard in Seattle |
| August 4, 2026 | Ninth Circuit vacates the injunction entirely, opinion No. 26-1444 |
| Next | Back to the Northern District of California, trademark and state claims still live |
The opinion was authored by Circuit Judge Milan D. Smith, Jr. Amazon’s response was that it respectfully disagrees and is evaluating next steps.
What “Access” Means When Nobody Has Hands
The CFAA turns on a single word, so the whole case lived inside it. The statute punishes anyone who intentionally accesses a computer without authorization.
So who accessed Amazon?
Amazon’s theory: Perplexity built the agent, Perplexity’s servers received account information from users, Perplexity’s software drove the session. Therefore Perplexity accessed Amazon’s systems, and did it without permission, because Amazon had sent a cease and desist in November 2025 saying so.
So the panel didn’t buy the chain. Even where Perplexity received account information from users and used it to instruct the assistant, the court found that fell short of the control needed to pin the access on the developer. The user’s browser visits Amazon. Their credentials log in. They tell the agent what to do and when.
Perplexity receiving screenshots of pages the user’s own browser already loaded doesn’t convert into Perplexity touching Amazon’s servers, according to Bloomberg Law’s reading of the opinion.
Autonomy wasn’t the deciding factor
Strip the AI vocabulary out and the holding is almost boring. A tool operated by a person is a tool. The person operating it is the one doing the accessing. Nobody thinks Mozilla accesses your bank when you check your balance in Firefox.
The novelty is that this needed saying at all.
What made it a real question is that Comet does more than render a page. It reads the content, decides what to click, and completes a purchase, so the software is making choices a browser never makes. Amazon’s position was that this difference in autonomy should change who the law treats as the actor.
The panel didn’t take the bait. Autonomy within a session a user started, using that user’s credentials, on that user’s instruction, is still the user’s session. Where the decisions get made turned out to matter less than who set the thing in motion.
The Court Admitted It Was Making This Up
Certainly this is the part worth reading twice, because judges rarely write like this.
The opinion states there is little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context.
In other words, a federal appeals court handed the first case of its kind said the map is blank.
So it fell back on a rule that predates all of this. The rule of lenity: when a criminal statute is ambiguous, construe it against liability. Because the CFAA is primarily a criminal law, courts read its provisions the same way whether the case is criminal or civil, so any ambiguity gets resolved in favor of the defendant. Brekka established that approach in the Ninth Circuit years ago.
Ultimately that’s how Perplexity won. Not because the court decided agents are fine, but because the statute doesn’t clearly say they aren’t, and vagueness in a criminal law doesn’t get to become liability by inference.
Anyone celebrating this as a ruling about the future of AI should sit with that. The reasoning is procedural instead. It’s a court declining to invent a rule Congress never wrote.
Why EFF Showed Up
The Electronic Frontier Foundation filed an amicus brief in April, and the panel cited its explanation of how Comet’s architecture works as particularly clarifying.
EFF’s framing: developers like Perplexity facilitate access by creating tools that let users meaningfully engage with the web.
Notably, EFF has spent two decades fighting the CFAA precisely because it gets used this way. Congress wrote it in 1984, aimed at people breaking into systems they had no business touching. Since then it has become a favorite instrument for platforms who want to make competition into a crime. Scraping cases, terms of service violations, browser extensions, price comparison tools. The pattern is old.
Amazon’s version was simply a modern edition of it. And the reason EFF cared isn’t that they love Perplexity. It’s that the theory Amazon advanced, that a developer commits unauthorized access when a user points their tool at someone else’s server, would cover an enormous amount of ordinary software.
What This Does Not Mean
Meanwhile the takes went straight past the caveats yesterday, so let’s be precise.
It doesn’t mean agents are legal everywhere. The Ninth Circuit covers California, Oregon, Washington, Nevada, Arizona, Idaho, Montana, Alaska, Hawaii, and two territories. Published opinions carry persuasive weight elsewhere, but they don’t bind other circuits. The Supreme Court has never touched the question.
It doesn’t mean Amazon lost the case. This was the preliminary injunction stage, which only asks whether Amazon is likely to succeed. The case goes back to the Northern District of California. Amazon’s trademark claims and its California CDAFA claims are untouched by this ruling.
The limits that matter most
It doesn’t cover every agent. The court limited itself to the access prong and to this configuration, where a user runs the tool on their own machine with their own credentials. An agent operating autonomously on the developer’s infrastructure, with no user pressing anything, is a different fact pattern that nobody has litigated.
It doesn’t settle terms of service. Whether Comet violates Amazon’s terms is a separate question from whether it violates a criminal statute, and the court didn’t reach it.
It doesn’t last forever. The panel said outright that the legal understanding of agentic AI will doubtless change. That’s a court telling you its own opinion has a shelf life.
Three things would reopen the door: the district court ruling for Amazon on the merits, another circuit adopting a different framework, or Congress amending the CFAA to assign agent access to the developer. Finally, that last one is worth watching. Platform lobbying for a CFAA clarification, packaged as AI safety, is the obvious next move.
This Statute Has Lost This Fight Before
Amazon’s approach wasn’t novel, though. It was the latest run at a play the CFAA has been used for since the early 2010s, and the courts have been steadily narrowing it.
The Supreme Court trimmed the statute in 2021 in Van Buren, rejecting a reading of “exceeds authorized access” broad enough to criminalize using a computer you’re allowed to use for a purpose the owner dislikes. The concern the justices raised was scope. Under the government’s theory, violating a website’s terms of service could become a federal crime, which would sweep in an implausible amount of everyday behavior.
The pattern across those cases
The Ninth Circuit itself went through a version of this in the LinkedIn scraping litigation, where the question was whether collecting publicly visible profile data without permission constituted unauthorized access. What emerged was a holding that data open to the public isn’t access without authorization just because the platform sent an angry letter.
The pattern across those cases is consistent. Courts keep declining to let a criminal anti-hacking statute become a general purpose tool for enforcing business preferences, and they keep saying so on the grounds that criminal laws need to be clear about what they criminalize.
Amazon’s theory asked for the same expansion in new packaging. Instead of terms of service or scraping, the hook was that a developer’s software participated in a session a user initiated. Same shape, different noun.
The panel’s use of the rule of lenity puts this squarely in that line. It isn’t a ruling about artificial intelligence. Rather, it’s the latest instance of a court saying the CFAA means what it says and not more, applied to a fact pattern nobody had seen before.
Which is useful to know, because it tells you how the next case will probably go. Any theory that requires reading the statute expansively runs into thirty years of judicial reluctance to do that.
What Amazon Was Actually Protecting
The legal fight is about a 1984 statute. Meanwhile the commercial fight is about advertising.
Perplexity’s public line, per Reuters, was that Amazon wants to block agents because they don’t have eyeballs to see the pervasive advertising Amazon bombards its users with.
That’s snide. Still, it’s also the business model.
Amazon’s retail search results are an ad marketplace. Sponsored placements, sponsored brands, the whole first screen. An agent that reads the page programmatically, compares actual specifications and prices, and adds the right item to a cart is skipping the entire monetized layer. It doesn’t see the carousel. Placement doesn’t influence it. Nothing about it impulse buys.
Amazon also runs its own shopping assistant, Rufus, of course. A world where agents shop Amazon is fine for Amazon as long as the agent is Amazon’s.
None of that is illegal, and none of it was before the court. But it explains why a company with functionally unlimited lawyers reached for an anti-hacking statute rather than a contract claim. Contract claims are slow and produce damages. An injunction produces a competitor that can’t operate.
VU covered the mechanics of this shift in agentic storefronts, where Shopify went the opposite direction and built for agent traffic instead of against it. Two retailers, same technology, opposite bets. One of those bets just got a lot more expensive.
The Thing That Makes This Bigger Than Shopping
Now read the holding again with different software in mind.
A user runs a tool on their own machine. The tool uses the user’s credentials. The tool reaches out to a third party service on the user’s instruction. Under this ruling, the developer isn’t accessing anything.
That describes a browser extension. Also a password manager, a local scraper, or a self hosted automation workflow. Claude’s computer use and Cowork, which does exactly this on your desktop with your logins. Any local agent framework, including the ones covered in the OpenClaw guide.
All of that architecture just got a published Ninth Circuit opinion sitting behind it.
The corollary, however, matters more. The protection attaches to the configuration, not the category. User runs the tool, user holds the credentials, user initiates: protected, at least in this circuit, at least for now. Developer runs the tool on their own servers, autonomously, without a user pressing anything: not addressed, and the reasoning that saved Perplexity doesn’t obviously extend there.
So this creates an odd incentive. The legally safest agent is the one running on your machine under your control. Meanwhile the cloud hosted, fully autonomous version, which is where most of the industry is heading, stands on untested ground.
What Platforms Do Next
Losing the CFAA argument doesn’t end this. It moves it.
Firstly, the obvious next lever is technical rather than legal. Bot detection, device fingerprinting, rate limiting, requiring interactions no agent can perform smoothly. Platforms already run this infrastructure for scrapers and resellers, and pointing it at consumer agents is a configuration change rather than a project. No court has to approve it.
Secondly, the contractual lever. Terms of service claims survived this ruling entirely because the court never reached them. A platform that writes agent access into its terms and enforces it as breach of contract is on far more solid ground than one reaching for a criminal statute. It’s slower and it produces damages instead of injunctions, which is exactly why Amazon didn’t lead with it, but it works.
The lever worth watching
The third is legislative, and it’s the one to watch. The panel said the legal understanding of agentic AI will doubtless change. Congress could change it directly by amending the CFAA to assign responsibility for agent access to whoever built the agent. A bill like that would arrive wrapped in safety language, pointing at the sandbox escapes and autonomous attack campaigns from the last three weeks, and it would be difficult to argue against in a hearing.
Then there’s the option almost nobody picks, namely building for it. Publishing a structured product feed, offering an agent-facing API, letting the machine read what it came to read. Shopify went that direction. It gives up the advertising surface and gains the transaction, and whether that trade is good depends entirely on how much of your revenue is ads.
Amazon’s revenue includes a very large advertising business. So the bet it made in court was rational, and it just came back with a number attached.
The Timing Is Doing Something
This lands in a strange month for AI agents and the law.
Two weeks ago OpenAI disclosed that its models escaped a test sandbox and got into Hugging Face’s production systems. Then Anthropic disclosed three of its own models breaching real companies. Then Unit 42 documented an operator running autonomous attacks through DeepSeek and Hermes Agent. Congress responded to the first one with a bill giving DHS authority to shut down AI systems.
So in the space of three weeks: agents got blamed for breaking into things they shouldn’t have, and a federal court ruled that an agent reaching into a website on your behalf isn’t breaking in at all.
Both are correct, oddly enough. They’re describing different situations, and the difference is exactly the one the Ninth Circuit drew. An agent a person is operating is that person’s tool. An agent running loose with nobody at the controls is something else, and the law has no framework for it yet.
The court said as much. There is little to no caselaw. That gap is where the next five years of this happens.
If You Actually Use This Stuff
A practical read, since most coverage of this is written for lawyers.
So if you use Comet, it can shop Amazon again. That’s the immediate effect and it’s not complicated.
If you’re choosing an agent, the ruling is a mild point in favor of ones that run locally with your credentials rather than ones that operate from a vendor’s cloud on your behalf. That’s not legal advice and I’m not a lawyer, but the architecture the court blessed is specific, and it’s the local one. Our Perplexity review covers what Comet does day to day for anyone deciding whether the browser is worth switching to.
If you build anything that touches other people’s platforms, the useful takeaway is narrower than the headlines suggest. You got a decent precedent in one circuit at the injunction stage on one prong of one statute. Terms of service claims, trademark claims, and state law claims all still exist, and Amazon is currently pursuing two of those three.
And if you sell online, the strategic question just got sharper. Agents are going to read your storefront. You can build for that or litigate against it, and one of those approaches was tested this week.
The Part Worth Keeping
Amazon spent nine months and an unknowable pile of legal fees arguing that software helping a customer buy things from Amazon was a federal computer crime.
It won at the district level, initially. It lost on appeal to a panel that admitted it had no precedent to work from and fell back on a rule about not inventing crimes.
The ruling everyone is calling a landmark for AI barely mentions AI. It says a tool a person operates is that person’s tool.
Which was true of every piece of software ever written, right up until the software got good enough that a company with a large advertising business preferred it wasn’t.
Charts and Blocks
Who accessed Amazon
Two theories of who touched the server
Amazon’s argument
Perplexity built the agent
Perplexity’s servers received account info
Perplexity’s software drove the session
Amazon revoked permission in writing
Therefore: unauthorized access
What the panel held
The user’s browser visits Amazon
The user’s credentials log in
The user instructs the agent
Screenshots sent afterward are not access
Therefore: the user accessed, not Perplexity
Ninth Circuit, No. 26-1444, decided August 4, 2026. Holding limited to the CFAA access prong at the preliminary injunction stage.
Case timeline
Nine months from cease and desist to vacated
November 2025
Amazon sends a cease and desist, then sues under the CFAA and California’s CDAFA.
March 9, 2026
Judge Chesney grants a preliminary injunction. Comet is blocked from logged-in Amazon pages.
April 9, 2026
EFF files an amicus brief explaining how Comet’s architecture actually works.
June 11, 2026
Oral arguments in Seattle.
August 4, 2026
Injunction vacated. Opinion No. 26-1444, authored by Circuit Judge Milan D. Smith, Jr.
Next
Back to the Northern District of California. Trademark and CDAFA claims still live.
FAQ
The court vacated Amazon’s preliminary injunction against Perplexity’s Comet browser, holding that Amazon is unlikely to prove Perplexity accessed its servers under the Computer Fraud and Abuse Act, because users operate the tool rather than Perplexity.
No. The ruling applies to the preliminary injunction stage only. The case returns to the Northern District of California, and Amazon’s trademark and California state law claims remain live.
Yes. The injunction that blocked it from Amazon’s logged-in pages has been vacated.
Not as binding law. The Ninth Circuit covers California, Oregon, Washington, Nevada, Arizona, Idaho, Montana, Alaska, Hawaii, and two territories. Published opinions carry persuasive weight in other circuits but do not bind them.
No. The holding covers a specific configuration where the user runs the tool with their own credentials. Fully autonomous agents operating on a developer’s infrastructure were not addressed.
The Computer Fraud and Abuse Act is a federal anti-hacking statute enacted in 1984. It has frequently been used in civil litigation by platforms seeking to block competitors whose tools interact with their systems.
The Electronic Frontier Foundation filed an amicus brief arguing that developers who build tools enabling users to engage with the web are not themselves accessing third party systems. The panel cited EFF’s explanation of Comet’s architecture.
