Court Says Your AI Agent, Not Its Maker, 'Accesses' Websites

A Ninth Circuit ruling for Perplexity over Amazon draws an early legal line around AI shopping agents, treating them as user-controlled tools rather than independent actors.

On August 4, the Ninth Circuit Court of Appeals lifted an injunction that had barred Perplexity’s Comet browser from making purchases on Amazon, and in doing so handed down one of the first appellate rulings anywhere on who is legally responsible when an AI agent acts on a website. The court’s answer: the user is, not the company that built the tool. It’s a narrow ruling on a specific statute, but it’s the kind of narrow ruling that ends up shaping how every AI agent that clicks buttons on someone else’s website gets built from here on out.

How the case got here

Amazon sent Perplexity a cease-and-desist letter in November 2025 over Comet, an AI browser that can log into a user’s Amazon account and complete purchases on their behalf. Amazon argued this violated the Computer Fraud and Abuse Act (CFAA) — the federal anti-hacking law — because Comet was accessing password-protected accounts without authorization. A district court agreed enough to grant Amazon a preliminary injunction in spring 2026, stopping Comet’s shopping agent from operating on Amazon while the underlying case proceeded. Perplexity appealed, and the Ninth Circuit just sided with it, vacating the injunction and sending the case back to the district court in San Francisco.

The reasoning: a tool isn’t a trespasser

The core legal question was deceptively simple: under the CFAA, who “accesses” a computer when an AI agent completes an action a human asked for? Amazon’s theory was that Perplexity itself was doing the accessing, since Comet is the thing logging in and clicking “buy.” The three-judge panel rejected that framing. As the court put it, Comet functions as “a tool, not a person for statutory purposes” — it receives screenshots that the user’s own browser session captured and forwarded, and it acts only because a user directed it to. Under that reading, the user is the one accessing Amazon’s servers, the same way a person using a screen reader or a browser extension is the one accessing a site, not the maker of the screen reader.

The Electronic Frontier Foundation, which filed an amicus brief backing Perplexity, argued exactly this: that CFAA liability requires unauthorized access by the defendant, not merely by someone using the defendant’s software. The court adopted that framing, saying it “articulates the nature of the system most clearly,” and applied the rule of lenity — the principle that ambiguous criminal statutes should be read narrowly — to resolve the question against liability. EFF’s broader point is one worth sitting with: large companies have a long history of reaching for the CFAA, a law written in 1986 for hacking prosecutions, to shut down smaller tools and browser extensions that access their sites in ways they don’t like. This ruling makes that harder to do against AI agents specifically.

What the court didn’t decide

The panel was careful to flag how limited its holding is. It explicitly noted there is “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents” under the CFAA, and said outright that the law here “will doubtless change” as agentic AI matures. Notably, the court also said the thornier philosophical question — whether an AI agent has enough independent “intent” to be treated as an actor in its own right — didn’t need to be answered here, because Comet’s user-directed design settled the question without it. That’s a deliberately narrow off-ramp: a future agent that acts with less direct user control, or that a court decides is exercising more autonomy, could come out the other way.

It’s also worth being precise about what didn’t happen: Amazon didn’t lose the case, it lost the injunction. The underlying CFAA claim, along with Amazon’s trademark and state-law claims, goes back to the district court to be litigated on the merits. Amazon’s statement made clear it isn’t done — “we respectfully disagree with today’s decision… we remain confident in our case and are evaluating our next steps” — which leaves open a petition for rehearing or an eventual Supreme Court appeal.

Why this matters beyond one shopping bot

This ruling lands at a moment when agentic AI is showing up everywhere in daily software, from office productivity tools to shopping assistants, and the legal system is only just starting to catch up with basic questions about who’s accountable when an agent acts. Every company building a browsing or purchasing agent — not just Perplexity — has been operating without a clear answer to “is this legally more like a browser or more like unauthorized access.” The Ninth Circuit’s answer, at least for now, favors the browser framing, and that matters for the whole category of AI shopping and browsing agents that platforms like Amazon would rather keep out.

It also fits a pattern that’s shown up elsewhere this year: incumbents reaching for existing legal tools — trade secrets claims, anti-hacking statutes, copyright suits — to slow down AI products that route around their preferred interfaces, the same dynamic behind Apple’s trade-secrets suit against OpenAI a few weeks back. Courts are now starting to hand down actual rulings on these theories rather than just temporary injunctions, and so far the theories aren’t holding up as cleanly as the plaintiffs hoped. That doesn’t mean AI agents get a free pass — Amazon’s other claims survive, and the CFAA question itself is headed back to a full trial rather than being resolved for good. But the message for now is that building a tool users direct is legally different from a company itself breaking into a walled garden, and that distinction is going to keep mattering as more of the software people use starts acting on their behalf instead of just displaying information to them.

Sources: Courthouse News Service, Engadget, Electronic Frontier Foundation, TFTC