US computer crime law and AI agents

Ninth Circuit: An AI Browser That Shops for You Doesn't Violate the CFAA — Its User Does

The Ninth Circuit vacated Amazon's injunction against Perplexity's Comet browser, ruling AI assistants are user-operated tools, not independent CFAA violators.

Amazon v. Perplexity: The CFAA Timeline People of Internet Research · US ~5 months Injunction duration before reversal District court blocked Comet's Ama… Up to 5 yrs First-offense CFAA penalty Maximum prison term under 18 U.S.C… 3-0 Panel vote to vacate injunction Ninth Circuit panel unanimously si… peopleofinternet.com
Amazon v. Perplexity: The CFAA Timelin… People of Internet Research · US ~5 months Injunction duration before … Up to 5 yrs First-offense CFAA penalty 3-0 Panel vote to vacate injunction peopleofinternet.com

Key Takeaways

What Happened

Amazon sued Perplexity AI in November 2025, alleging that the AI Assistant built into its Comet browser violated the Computer Fraud and Abuse Act (CFAA) and California's Comprehensive Computer Data Access and Fraud Act by navigating into customers' password-protected Amazon accounts to shop, compare prices, and complete purchases on their behalf. U.S. District Judge Maxine M. Chesney agreed there was strong evidence of unlawful access and granted Amazon a preliminary injunction on March 9, 2026, blocking Comet's assistant from touching logged-in Amazon pages.

That injunction lasted about five months. On August 4, 2026, a unanimous Ninth Circuit panel, in an opinion by Judge Milan D. Smith Jr., vacated it. The court's holding is narrow but consequential: when a user directs an AI agent to act on a website, "it is the user who 'accessed' Amazon's computers," not the company that built the software. The Assistant, the panel wrote, is "a tool, not a person for statutory purposes" — closer to a browser extension or a macro than to an independent hacker (Ninth Circuit opinion, No. 26-1444).

Steelmanning Amazon's Case

Amazon's position is not frivolous. Retailers have a real interest in controlling how automated systems interact with their sites at scale — preventing inventory-gaming, price-scraping that undercuts merchants, and checkout flows that bypass fraud controls built around a human clicking "buy." An AI agent that logs into a saved account and completes purchases autonomously also raises genuine security questions: who is liable if it buys the wrong item, triggers a fraud false-positive, or gets tricked by a malicious page into taking an unintended action on a user's behalf? Amazon framed Comet as functionally indistinguishable from a bot that evades technical access controls, and CFAA claims against unauthorized scraping and credential-based intrusion have succeeded before, including in Facebook, Inc. v. Power Ventures, Inc., where a third party's servers communicated directly with Facebook's.

Why the Panel Rejected That Framing

The Ninth Circuit's answer turned on architecture, not intent. It distinguished Power Ventures precisely because Perplexity's servers never talk to Amazon's directly — Comet's assistant operates through the user's own browser session, on the user's own device, using the user's own login. The company doesn't access Amazon; it hands a person a more capable steering wheel. The court also described the CFAA as "principally an anti-hacking statute," a criminal law with penalties up to five years for a first offense under 18 U.S.C. § 1030(a)(2) (Cornell Legal Information Institute) — and applied the rule of lenity, construing statutory ambiguity against liability given "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents."

The court found Amazon unlikely to prevail on the merits, effectively treating agentic browsing as an extension of ordinary user-directed automation rather than a new category of unauthorized intrusion.

EFF, which had weighed in against Amazon's theory, called the result a correction of an overreaching reading of a statute already notorious for its vagueness — the same vagueness the Supreme Court narrowed in Van Buren v. United States (2021) by rejecting broad "exceeds authorized access" theories tied to terms-of-service violations (EFF Deeplinks).

The Right Call, With Real Limits

This is the correct outcome, and the reasoning matters more than the result. Letting a felony-adjacent hacking statute become the default weapon against AI tool-makers would have chilled a wide swath of ordinary software — ad blockers, accessibility readers, password managers, comparison-shopping extensions — all of which act on a user's behalf inside sites the user is authorized to visit. Site operators already have better-tailored remedies: contract claims for terms-of-service breaches, trespass-to-chattels for server strain, and technical countermeasures like rate-limiting or bot-detection. Routing every dispute over automated browsing through a criminal-access statute designed for credential theft and server intrusion was always a mismatch, and courts applying lenity to an ambiguous criminal statute is exactly the right posture.

But the ruling is genuinely narrow, and both critics and Amazon are right to say so. Legal analysts flagged that the decision, by locating "access" with the user, could leave individual consumers more exposed to liability theories the company itself now escapes (Technology & Marketing Law Blog). Cooley's litigation team notes the protection is architecturally conditional: an agent that moves from routing through the user's device to direct server-to-server communication with a target site could land back inside Power Ventures territory (Cooley). And this was only a preliminary-injunction ruling — Amazon's trademark and state-law claims return to the district court, and Amazon says it is evaluating its options (PYMNTS; TFTC).

The deeper fight — over whether platforms can contractually or technically wall off their sites from AI agents shopping for their owners — hasn't been resolved. It's just been correctly routed away from a hacking statute that was never built to referee it.

Sources & Citations

  1. Ninth Circuit opinion, Amazon v. Perplexity (No. 26-1444)
  2. 18 U.S.C. § 1030 (CFAA statute text), Cornell LII
  3. EFF: Appeals Court Agrees Building a Web Browser Doesn't Violate the CFAA
  4. Cooley: Ninth Circuit Rules on AI Agent 'Access' Under CFAA
  5. PYMNTS: Ninth Circuit Narrows CFAA Reach in Perplexity Ruling
  6. Technology & Marketing Law Blog: Ninth Circuit Lifts Restrictions on Agentic AI
  7. TFTC: Ninth Circuit Vacates Amazon's CFAA Injunction