What the court actually decided
On August 4, 2026, the Ninth Circuit Court of Appeals vacated a preliminary injunction that had barred Perplexity's Comet browser from operating its AI shopping agent on Amazon.com. The core legal question was narrow but consequential: when an AI agent browses and buys on a website at a user's direction, who is doing the "accessing" under the Computer Fraud and Abuse Act, the person or the software?
The court's answer: the user. Because Comet only acts when a person directs it to, the panel found that it's the user, not Perplexity, who "accesses" Amazon's computers under the CFAA. An injunction against conduct that likely isn't illegal, the court reasoned, doesn't serve the public interest.
The court also leaned on the rule of lenity, a principle that says ambiguous language in a law with criminal penalties should be read narrowly rather than broadly. The CFAA is exactly that kind of statute, and the panel explicitly noted there's "little to no existing caselaw" on how to assign responsibility for AI agents acting on someone's behalf. Rather than fill that gap with an expansive reading that would treat every AI browsing tool as a potential hacking violation, the Ninth Circuit chose the narrower one.
What this doesn't settle
This is a preliminary ruling on an injunction, not a final verdict. The underlying lawsuit between Amazon and Perplexity continues in federal court in San Francisco. Amazon has said it "respectfully disagrees" with the decision and is weighing next steps, which could include asking the Supreme Court to take the case.
The Ninth Circuit was also careful to describe its own holding as narrow, and said explicitly that the law around agentic AI "will doubtless change" as more cases like this one work through the courts. This is one data point in a legal argument that's just getting started, not a settled rule for how AI agents interact with any website.
Why this matters beyond Amazon and Perplexity
Strip away the specific parties and the question underneath this case applies to every company building an AI agent that acts on the open web: browsing agents, shopping assistants, form-fillers, anything that clicks buttons and reads pages on a user's behalf without that site's blessing. Website operators have used the CFAA for years to threaten scrapers and unwanted automated traffic. If courts had gone the other way here, treating the agent's actions as the user's own would have made every consumer-directed AI browsing tool a legal liability the moment a site owner objected.
The Electronic Frontier Foundation, which has argued for years that the CFAA gets stretched too far to cover ordinary computer use, backed Perplexity's position here. That's a useful signal: this isn't just an AI industry talking point, it's consistent with the narrower reading of the CFAA that digital rights groups have pushed since long before agentic browsers existed.
The practical takeaway
If you build or use tools that act on your behalf across the web, this ruling is good news, but it's not a green light. Amazon can still fight the underlying case, other circuits could rule differently on similar facts, and Congress could always rewrite the CFAA itself. What changed on August 4 is that one of the country's most influential appeals courts looked at an AI shopping agent and declined to treat "the AI did what I told it to" as a federal hacking crime. For an industry that's been building agentic tools ahead of any clear legal framework, that's meaningfully less exposure than it had a week ago, even if it's far from a permanent resolution.
It also lands in the middle of a busier year for AI regulation generally. The EU's [Article 50 transparency rules](https://questloops.com/blog/the-eu-ai-act-s-transparency-rules-just-went-live-what-article-50-actually-requires) and [California's SB 942](https://questloops.com/blog/california-s-ai-transparency-act-sb-942-is-now-in-effect-what-changes-on-august-2) both went into effect this month, and Anthropic just [hired its first Chief Global Affairs Officer](https://questloops.com/blog/anthropic-names-its-first-chief-global-affairs-officer) to navigate exactly this kind of legal terrain. Courts, regulators, and AI labs are all working out the same question from different angles at the same time: what is an AI agent actually allowed to do on your behalf.


