A federal appeals court has ruled that when an AI agent browses a website on someone's behalf, it is the user rather than the agent's developer who accesses that site under the main US anti-hacking statute. The Ninth Circuit vacated an injunction that had barred Perplexity's Comet browser from Amazon, in a decision issued August 4.

Amazon sued in November 2025 and won a preliminary injunction on March 9 from Judge Maxine Chesney in San Francisco, arguing that Comet's shopping assistant violated the Computer Fraud and Abuse Act by reaching password-protected pages without authorization, even where the user had supplied their own credentials. Chesney found Amazon had shown "strong evidence" that Perplexity accessed accounts "with the Amazon user's permission but without authorization by Amazon." The Ninth Circuit stayed that order, heard argument in Seattle on June 11, and has now held that Amazon is unlikely to succeed on the access question, because Perplexity does not access Amazon's servers. Its users do.

Judge Milan Smith Jr. wrote the opinion, joined by Judge Eric Tung and District Judge John Hinderaker sitting by designation. The CFAA punishes whoever intentionally accesses a protected computer, which the panel read as contemplating a person. "However advanced the Assistant currently is, it is a tool, not a person for statutory purposes," the opinion said. The panel credited a joint amicus brief from the Electronic Frontier Foundation, Mozilla, EleutherAI and two other groups with describing the system most clearly: the user's browser requests the page, the assistant analyzes what the browser has already displayed, and Perplexity's servers never directly touch Amazon's.

The court was candid about how little law it had to work with. There is "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context," the opinion said. Facing that ambiguity in a statute carrying criminal penalties, the panel applied the rule of lenity and construed it against liability. It added that "the legal understanding of agentic AI will doubtless change."

The panel reached the same result under California's Comprehensive Computer Data Access and Fraud Act, which also turns on the person causing the access; the claims rise and fall together. It found the equitable factors did not favor an injunction either, vacated the order and remanded. The holding is narrow by design, limited to access "as applied to the Assistant's interactions with Amazon.com on the record before us, not the broader legal landscape surrounding agentic AI."

The ruling addresses a question every agent vendor has been operating around. Tools that shop, book and file on a user's behalf have assumed that acting with a user's credentials is equivalent to the user acting, without an appellate court confirming it. Platforms have meanwhile leaned on terms of service and the CFAA to keep automated clients out, even as permission layers for agent API access emerged to handle the traffic. The court left the contractual route intact, noting in a footnote that the outcome "does not impair Amazon's ability to regulate access to Amazon.com via private terms of service for its users."

It also lands on an unsettled identity question. Standards bodies have been competing to define how agents authenticate on a user's behalf, and security vendors have moved to govern agents as enterprise identities with credentials of their own. A legal test that treats the agent as the user's instrument sits awkwardly beside technical work that gives the agent its own identity to authenticate with.

Perplexity launched Comet earlier this year to compare prices, complete checkout forms and place orders on a user's behalf.

Sources: US Court of Appeals for the Ninth Circuit, Courthouse News, Electronic Frontier Foundation


By the Control Plane Editorial Team