A Shopping Bot, an Anti-Hacking Law, and a Question Congress Never Anticipated
On August 4, 2026, a three-judge panel of the Ninth Circuit Court of Appeals vacated a preliminary injunction that had barred Perplexity's Comet browser from letting its AI "Assistant" shop on Amazon.com on users' behalf. The underlying question was narrow but consequential: when an AI agent clicks through a website at a user's direction, who is doing the "accessing" under the Computer Fraud and Abuse Act (CFAA)? The panel's answer — it's the user, not the software — is the first appellate ruling to address CFAA liability for agentic AI tools, and it draws a sensible line around a 1986 statute that was never built for browsers that can act on your behalf.
How the Case Got Here
Amazon sued Perplexity in the Northern District of California in November 2025, arguing that Comet's Assistant feature — which can log into a user's Amazon account to browse, compare prices, and check out — violated both the federal CFAA and California's Comprehensive Computer Data Access and Fraud Act (CDAFA). On March 9, 2026, U.S. District Judge Maxine M. Chesney agreed, granting Amazon a preliminary injunction that blocked the Assistant from password-protected pages: account information, order history, checkout. The Ninth Circuit stayed that order a week later and heard oral argument in June. Its August 4 ruling reverses Judge Chesney, finding Amazon unlikely to succeed on either claim (Ninth Circuit opinion, No. 26-1444; Cooley client alert).
What the Panel Actually Held
The CFAA makes it unlawful to "intentionally access a computer without authorization or exceed authorized access" — language written for hackers, not software vendors (18 U.S.C. § 1030(a)(2)). The panel held that when a Comet user directs the Assistant to buy something on Amazon, the user is the one who "accessed" Amazon's computers; Perplexity supplies a tool, not an independent actor with its own intent. As the Electronic Frontier Foundation — which filed an amicus brief alongside the Alliance for Responsible Data Collection — summarized it, the Assistant functions as "a tool, not a person for statutory purposes," making the CFAA's authorization-focused framework a poor fit for policing it (EFF Deeplinks).
Amazon's Concerns Are Not Frivolous
Before dismissing Amazon's litigation strategy, it's worth taking its underlying worry seriously. Amazon has spent two decades building a checkout flow, a recommendation engine, and fraud-detection systems tuned to how humans browse. An AI agent that logs into a customer's account and transacts at machine speed can strain that infrastructure, sidestep the merchandising and advertising that fund the free storefront, and — if an agent is compromised, misconfigured, or simply hallucinates a wrong SKU — create fraud and account-security exposure Amazon didn't design for. Any platform that lets third-party software act inside a logged-in account is taking on real operational risk, and it's reasonable for that platform to want a say in how it happens. That's a legitimate business and security concern deserving a legal remedy.
The question is whether the CFAA — a criminal anti-hacking statute — is the right remedy. It isn't. The Ninth Circuit has been here before: in hiQ Labs v. LinkedIn (2019), it held the CFAA doesn't transform a website's terms-of-service preferences into a hacking prosecution, and the Supreme Court reinforced a narrow reading of "exceeds authorized access" in Van Buren v. United States (2021), warning that an expansive interpretation would criminalize routine, authorized computer use. Applying that same statute to a user-directed shopping assistant would have meant a federal anti-hacking law effectively deciding which software architectures American consumers are allowed to run on their own logged-in accounts — a far bigger reach than Congress intended when it wrote the CFAA to punish unauthorized intrusion into remote systems, not consumer tool choice.
The Win Is Real but Narrow
Crucially, the panel did not grant AI agents blanket immunity. It expressly left Amazon's other claims — breach of contract, breach of terms of service, and potential tort theories — alive on remand to the Northern District of California. And it flagged, pointedly, that its reasoning turns on how Comet's Assistant works: routed through the user's own session, not communicating directly with Amazon's servers. A more autonomous agent, or one that talks to a merchant's backend independent of a live user session, could land differently under the same statute. Website operators retain real tools short of the CFAA — rate limiting, bot detection, and enforceable contract terms chief among them — to manage how agents interact with their platforms.
Why This Matters Beyond One Browser
Agentic browsers are still new enough that almost no case law addresses them. This ruling gives the fast-growing agentic AI sector — Perplexity's Comet is one of several agent-enabled browsers now competing for consumers — a measure of legal clarity: building a tool that acts on explicit user instruction is not, by itself, a federal crime. That is the right default for an anti-hacking statute, and it pushes disputes between platforms and AI developers toward the venues built for them — contract, tort, and negotiated API terms — rather than a blunt criminal-liability threat that would have chilled a nascent product category before consumers ever got to choose whether they wanted it.
"It was the user who 'accessed' Amazon's computers," the panel wrote — not Perplexity.
That sentence won't settle the broader fight over agentic commerce. But it correctly keeps a 1986 hacking statute out of a 2026 argument about who controls a browser.