What the court did
On August 4, 2026, a Ninth Circuit panel vacated a preliminary injunction that had barred Perplexity AI's Comet browser from letting its "Assistant" feature shop and browse on Amazon on users' behalf. The panel, in an opinion authored by Circuit Judge Milan D. Smith Jr., held that Amazon is unlikely to succeed on its Computer Fraud and Abuse Act claim because the Assistant "is a tool, not a person for statutory purposes" — it is the user, operating the tool with their own credentials, who "accesses" Amazon's servers, not Perplexity (Ninth Circuit opinion, No. 26-1444).
The case has moved fast. Amazon sued Perplexity in the Northern District of California in November 2025, and U.S. District Judge Maxine M. Chesney granted a preliminary injunction on March 9, 2026, blocking Comet's Assistant from touching Amazon's password-protected account pages. Five months later, the Ninth Circuit reversed course entirely (TFTC). The panel's CFAA reasoning also disposed of Amazon's parallel claim under California's Comprehensive Computer Data Access and Fraud Act, which turns on the same "access" language (Eric Goldman, Technology & Marketing Law Blog). Amazon's trademark claims survive and the case returns to the district court (TFTC).
Steelmanning Amazon's case
Amazon's theory was not frivolous. A shopping agent that logs into a user's Amazon account, navigates listings, and completes purchases looks a great deal like the kind of unauthorized, automated scraping the CFAA and its state-law cousins were built to police — especially when it does so without identifying itself to Amazon's systems and, Amazon alleged, in defiance of Amazon's terms of service. Retailers have legitimate reasons to control how their infrastructure is queried: fraud screening, bot mitigation, inventory-manipulation prevention, and simple server load all depend on knowing who — or what — is knocking. If any company can route an AI agent through a rival's authenticated systems by pointing to "the user did it," the argument goes, terms of service become unenforceable against anyone who wraps a scraper in a chat interface. That is a real policy concern, not a pretextual one, and the panel did not wave it away — it merely held that the CFAA specifically is the wrong tool for enforcing it against Perplexity.
Why the panel's reading holds up
The CFAA is a criminal statute repurposed for civil suits, and the Supreme Court's 2021 decision in Van Buren v. United States already pushed lower courts toward a narrower, more literal reading of "authorization" rather than letting the statute swallow ordinary terms-of-service disputes. This panel followed that path and then applied the rule of lenity — construing statutory ambiguity against liability — because, as the court put it, Amazon's theory risked exposing millions of ordinary users to criminal exposure simply for choosing to use an AI browser. That is the correct instinct: a 1986 anti-hacking statute should not be stretched, by inference, into a vehicle for policing which software intermediary a consumer chooses to shop with. The court was candid about the limits of its own footing, noting there is "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents" — an honest acknowledgment that Congress, not judges improvising against a decades-old text, is better positioned to write rules for agentic AI if new ones are needed.
The Electronic Frontier Foundation, which filed an amicus brief the panel credited with articulating "the nature of the system most clearly," and the ACLU, which also weighed in before the Ninth Circuit (ACLU amicus brief), both pressed the same underlying point: treating a browser's code as the legal "accessor" would functionally let any website operator convert a contract dispute — did this tool violate our terms? — into a federal computer-crime case. That conflation has been one of the CFAA's chronic pathologies since long before agentic AI existed, and reining it in here is consistent with, not a departure from, where CFAA doctrine has been heading.
A narrow ruling, not a green light
What the opinion does not do matters as much as what it does. The panel was explicit that it is not "establishing a new legal regime governing agentic AI," and it left open that "different factual circumstances or more autonomous AI systems could produce a different outcome" (EFF Deeplinks). Amazon's contract-based tools — terms of service, technical countermeasures, and its trademark claim, which survives — remain available. So does state contract law. What the ruling forecloses is the shortcut of using a federal hacking statute to resolve what is, at bottom, a dispute about whether a website can dictate which software its own customers use to visit it.
That is the right allocation of legal risk. Consumers who want an AI agent to compare prices or complete a purchase on their behalf should not need Amazon's permission to make that choice, and platforms that want to restrict automated access have narrower, better-targeted tools than a criminal statute built for a different era of computer misuse. As the court itself signaled, this area of law is young and will keep moving — but it should move through legislation calibrated to agentic AI, not through an expansive reading of a 40-year-old anti-hacking law.