A Narrow Question, a Consequential Answer
On August 4, 2026, the Ninth Circuit Court of Appeals vacated a preliminary injunction that had barred Perplexity AI's Comet browser from operating on Amazon.com, becoming the first federal appellate court to address whether an AI agent that shops, compares prices, or logs into accounts on a user's behalf can be held liable under the Computer Fraud and Abuse Act. Writing for the panel in Amazon.com Services, LLC v. Perplexity AI, Inc. (No. 26-1444), Judge Milan D. Smith Jr. held that when a Comet user directs the browser's AI "Assistant" to act on Amazon.com, "it was the user who 'accessed' Amazon's computers, with the help of Perplexity's AI agent" — not Perplexity itself.
The distinction sounds technical. It is also decisive. The CFAA imposes liability only on whoever "intentionally accesses a computer without authorization or exceeds authorized access," and Amazon's theory required treating Perplexity's software, rather than the person operating it, as the party doing the accessing. The panel wasn't persuaded, in part because Comet's Assistant does not communicate directly with Amazon's servers; it routes activity through the user's own browser session, the same channel a human clicking through Amazon would use.
Amazon's Case Deserves a Fair Hearing
Before dismissing Amazon's position, it's worth taking seriously what the company argued below. Amazon says Comet's Assistant logs into customer accounts, browses, compares products, and places orders in a way that mimics ordinary browsing traffic, after Amazon sent cease-and-desist notices asking Perplexity to stop. Amazon's underlying worry isn't abstract: an AI agent with standing account credentials that can transact on a marketplace raises real fraud-surface and account-security questions, and merchants have a legitimate interest in knowing whether a purchase came from the account holder or an autonomous script acting on general instructions. A retailer that has spent two decades tuning fraud detection to human shopping patterns is not being paranoid when it asks whether those systems still work against an agent that can complete checkout in milliseconds. That is a real policy problem, and the panel didn't pretend otherwise.
Why the CFAA Was Still the Wrong Vehicle
But a real problem doesn't require reaching for a 1986 anti-hacking statute never written with browser agents in mind. The CFAA and its California analogue, the CDAFA, exist to punish intrusion — someone breaking into a computer system they had no business touching. The panel's reasoning tracks the Supreme Court's 2021 decision in Van Buren v. United States, which narrowed the CFAA's "exceeds authorized access" clause to cases where a defendant enters files or areas genuinely off-limits to them, rejecting a broad reading that would have turned routine terms-of-service violations into federal offenses. Van Buren's 6-3 majority worried openly about criminalizing everyday computer use — checking sports scores on a work computer, using a pseudonym on a dating site — because an expansive CFAA reading hands prosecutors and civil plaintiffs a hacking statute to police conduct that has nothing to do with hacking. Amazon's CFAA theory against Perplexity ran into the same problem: a user asking a browser to click "buy" on their behalf is not intrusion in any sense the statute's text supports, whatever Amazon's terms of service say about it.
That distinction — hacking statute versus contract — is exactly where the panel left Amazon its real remedy. The opinion resolves only the CFAA and CDAFA theories; Amazon's trademark and other state-law claims continue on remand before the district court, and the panel explicitly noted that an AI agent with greater autonomy, or one that communicated directly with a website's servers rather than through the user's own session, could face a different outcome. Website operators keep the tools they've always had against unwanted automated traffic: terms of service, rate limiting, bot detection, and civil suits for breach of contract. Those tools require Amazon to prove Perplexity actually broke a promise or caused measurable harm — a higher and more appropriate bar than treating a browser feature as criminal intrusion the moment an operator objects to it.
The Right Reading for an Agentic Web
This ruling matters well beyond one shopping bot. As agentic browsers proliferate — filling forms, comparing prices, booking travel — any platform annoyed by automated traffic will be tempted to reach for CFAA claims, because a hacking statute carries the threat of outsized civil damages and, in the criminal context, prison time that no ordinary contract claim offers. If courts let "your software displeased us" collapse into "your software committed unauthorized access," the CFAA becomes a general-purpose tool for incumbents to freeze out AI tools that let users do, faster, what they were always allowed to do themselves. The Ninth Circuit's fact-specific, user-centered line — a person directing a tool is not the tool "accessing" anything — keeps hacking law aimed at hacking, while leaving Amazon's legitimate security and contract concerns where they belong: in ordinary civil litigation, not a criminal-adjacent statute. Congress or the FTC could still write a bespoke rule for agentic commerce; until then, courts are right not to stretch a 40-year-old anti-hacking law to do that policymaking for them.