Devlery
Blog/Amazon

Ninth Circuit Vacates Amazon's Injunction: The Agent Is a Tool, the User Did the Accessing

The Ninth Circuit vacated Amazon's injunction against Perplexity's Comet on August 4. Under the CFAA an AI agent is a tool, not a person, so the user is who accessed Amazon, and the fight moves to terms of service.

Ninth Circuit Vacates Amazon's Injunction: The Agent Is a Tool, the User Did the Accessing
AI 요약
  • The Ninth Circuit vacated Amazon's injunction against Perplexity's Comet agent on August 4.
  • Under the CFAA the Assistant is a tool, not a person, so the user is who accessed Amazon.
  • A footnote leaves terms of service open as the way to block agents.

Amazon sued Perplexity in November 2025. The claim was that the AI agent inside the Comet browser, signing into a user's Amazon account to find and order products, amounted to entering someone else's computer without permission. In March 2026 the Northern District of California agreed and issued a preliminary injunction barring the agent from Amazon.

On August 4 the Ninth Circuit vacated that injunction outright. The case is No. 26-1444, decided by Circuit Judges Milan D. Smith Jr. and Eric C. Tung, sitting with District Judge John Charles Hinderaker by designation. Firms including Cooley and Wilson Sonsini called it the first federal appellate ruling on an AI agent accessing a website on a user's behalf. The opinion is marked "FOR PUBLICATION," so it binds later cases in the circuit.

First page of the Ninth Circuit opinion in Amazon.com Services, LLC v. Perplexity AI, Inc.

The case turned on where the request originates

Amazon sued under the CFAA (Computer Fraud and Abuse Act), the 1984 US anti-hacking statute that criminalizes accessing a computer without authorization and lets victims sue civilly once losses exceed $5,000. California has a parallel statute, CDAFA, and Amazon pleaded both.

The panel started with how Comet actually works. The opinion's findings: Comet is a browser that runs on the user's own device, like Chrome. When a user asks the Assistant to find a product, the Assistant screenshots the rendered page, sends that screenshot from the user's computer to Perplexity's servers, and gets back instructions on what to click.

The court quoted an amicus brief from EFF, Mozilla, EleutherAI and others, which describes the architecture in the fewest words:

When a user visits an Amazon.com page, the browser requests the page content from Amazon's servers and displays it to the user. The Assistant analyzes the content of that displayed page on the user's computer. Perplexity's servers never connect directly to Amazon's servers.

Comet's architecture (what was decided)

Browser on the user's device → Amazon servers

↑ screenshot ↓ click instructions

Perplexity servers (no direct link to Amazon)

Holding: the user is the one who accessed

The architecture left undecided

Cloud browser on the vendor's servers → Amazon servers

↑ only results returned to the user

The user's device only watches the screen

Opinion: a different record could come out differently

On those facts the legal analysis is short. CFAA § 1030(a)(2) punishes "[w]hoever ... intentionally accesses," and the panel read that text as presupposing a human actor. It then held that "however advanced the Assistant currently is, it is a tool, not a person for statutory purposes." For the meaning of access the court used the Supreme Court's 2021 decision in Van Buren: entering the computer system itself, or a particular part of it such as a file, folder, or database.

The conclusion follows. The user is who entered Amazon's computers; the Assistant helped carry out specific acts once there. Receiving a screenshot and sending back instructions does not, on this record, mean Perplexity gained entry to Amazon's servers.

The panel added a second reason. The CFAA is a criminal statute, so ambiguity is read against the government under the rule of lenity. Adopting Amazon's reading would create a further problem: a user who turned the agent on could face criminal exposure as a conspirator or aider for helping Perplexity access without authorization. Citing precedent against turning ordinary conduct into a federal crime merely because a computer was involved, the court wrote that Congress could not have intended that result.

Amazon's evidence of harm was thin

A preliminary injunction does not rest on likelihood of success alone. It also requires irreparable harm, a balance of the equities, and the public interest. The panel found the district court wrong on all three of the remaining factors.

Amazon's harm declarations said the Assistant might fail to select the optimal price, shipping method, or product recommendation. The panel called that an abstract claim of degraded shopping experience, far more remote than precedent where goods were stuck in customs and could not reach customers who had already ordered. It also noted that users might not blame Amazon for the degradation at all, since the user is the one who switched the agent on.

The security argument collapsed too. Amazon said multiple security researchers had confirmed risks in Perplexity, but the opinion records that Amazon's own expert testified he could not fully reproduce those risks.

The trigger for the whole dispute was technically small. The opinion states that "at the heart of the dispute is Perplexity's decision not to use a user-agent string." A user-agent string is the short identifier a browser sends when it connects. Only if it flags that an AI agent is active can Amazon block that traffic selectively. Whether Perplexity deliberately changed the string after Amazon first managed to identify and block the Assistant is disputed between the parties, and the panel left it in a footnote without deciding.

November 2025

Amazon sues under the CFAA and CDAFA and moves for a preliminary injunction

March 2026

District court calls it a close call but grants the injunction. Perplexity appeals and the Ninth Circuit stays enforcement

June 11, 2026
Oral argument in Seattle
August 4, 2026

Injunction vacated and remanded. The merits case continues in district court

Three doors the court deliberately left open

The opinion closes with a paragraph restating what the decision is not. It does not create a legal regime for agentic AI, and it decides only the meaning of "access" under the CFAA on the technology in this record. Three questions stay open.

First, differently built agents. The opinion says it does not address "whether, on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon's servers." Where an agent opens the web varies by product. Some run on the user's machine in an isolated profile, like Claude Code's built-in browser. Others run a cloud browser on the vendor's servers that issues requests to the target site directly. The second shape does not inherit this reasoning cleanly.

Second, terms of service. Footnote 5 is the sentence with the longest practical shelf life: "This outcome does not impair Amazon's ability to regulate access to Amazon.com via private terms of service for its users." Criminal law cannot block the agent, but a contract can. The site operator's next move is a TOS clause and account suspension, not a hacking statute.

Third, other claims. The panel did not address whether Perplexity can avoid liability for the Assistant's actions in other contexts, including tort claims. It also left the CFAA's remaining elements, such as the $5,000 loss threshold, undecided. The merits case continues in the Northern District of California, and Amazon can seek rehearing en banc or certiorari. Amazon said it respectfully disagrees with the ruling and is evaluating next steps.

What this ruling reaches, and what it does not

ItemCurrent status
Binding effectOnly in the Ninth Circuit (California, Washington, and seven other western states plus territories). No effect outside US courts
Using CometFree. Paywall removed March 18, 2026, distributed worldwide on iOS, Android, Windows, and macOS
Pro and Max subscriptionsInclude Comet Plus, but the free tier covers the browser itself
Merits outcomeUndecided. Still pending in district court

If you operate outside the United States, this ruling does not apply to you directly, and national anti-intrusion statutes are worded differently enough that the reasoning does not transfer on its own. South Korea's Information and Communications Network Act Article 48(1), for example, bars intrusion "without legitimate access authority or beyond permitted access authority," a different text and structure from the CFAA. What does reach you is the other direction: any company with US West Coast entities or servers, and any service taking US users, is inside the circuit. And if you want to keep someone else's agent off your own site, the criminal-law card just got weaker in the United States, so terms of service and account policy are where the leverage is.

If you are shipping a product where an agent visits third-party sites for the user, the thing to check this week is not the model but where the request leaves from. Read the code and confirm whether the browser on the user's device is what talks to the target server while your backend only decides what to click, or whether your servers hit the target directly. The second case falls outside what this opinion protects. Either way, read the target site's terms of service for a clause barring agent access. How large US sites rewrite those terms after August 4 will decide the next round of this fight.